Cross-Core Interrupt Detection: Exploiting User and Virtualized IPIs
Fabian Rauscher, Daniel Gruss
Abstract
Interrupts are fundamental for inter-process and cross-core communication in modern systems. Controlling these communication mechanisms historically requires switches into the kernel or hypervisor, incurring high-performance costs. To alleviate these costs, Intel introduced new hardware mechanisms to send inter-processor interrupts (IPIs) from user space without switching into the kernel and from virtual machines without switching into the hypervisor. However, it is unclear whether this direct, unsupervised interaction between unprivileged (or virtualized) workloads and the underlying hardware introduces a significant change in the attack surface. In this paper, we present the IPI side channel, a novel sidechannel attack exploiting the recently introduced user interrupts and IPI virtualization features on Intel Sapphire Rapids and the upcoming Intel Arrow Lake processors. The IPI side channel is the first cross-core interrupt detection side channel, allowing an attacker to monitor interrupts delivered to any physical core of the same processor. Our attack is based on precise measurements of the hardware delivery time of interrupts from user space and virtual machines. More specifically, we exploit that interrupts are delivered through a cross-core bus, leading to timing variations on the attacker's local IPIs. We present multiple case studies to compare the IPI side channel with the state of the art: First, we present an unprivileged cross-core covert channel with a native true capacity of 434.7 kbit/s (𝑛=100, 𝜎 x =0.03) and a cross-VM capacity of 3.45 kbit/s (𝑛=100, 𝜎 x =0.01). Second, we demonstrate a native inter-keystroke timing attack with an 𝐹 1 score of 97.9 %. Third, we present an open-world website fingerprinting attack on the top 100 websites, achieving an 𝐹 1 score of 89.0 % in a native scenario and an 𝐹 1 score of 71.0 % in a cross-VM (thin client) scenario. Furthermore, we discuss the broader context of the IPI side channels and categorize interrupt side channels and mitigations. CCS Concepts • Security and privacy → Side-channel analysis and countermeasures; Operating systems security; Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Keytar: Practical Keystroke Timing Attacks and Input ReconstructionMufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu et al.S&P 2026 · 2 citations
- Towards Practical Interrupt Side-Channel Attacks on macOS for Apple SiliconXin Zhang, Chang Liu, Jiajun Zou, Yi Yang et al.ISCA 2026 · 1 citation
- Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel AttacksIliana Fayolle, Antoine Geimer, Daniel De Almeida Braga, Clémentine MauriceCCS 2026
Builds on30
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
Related papers
- IdleLeak: Exploiting Idle State Side Effects for Information LeakageFabian Rauscher, Andreas Kogler, Jonas Juffinger, Daniel GrussNDSS 2024
- PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksYun Chen, Ali Hajiabadi, Lingfeng Pei, Trevor E. CarlsonHPCA 2024 · 15 citations
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin et al.USENIX Security 2022
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- DSAssassin: Cross-VM Side-Channel Attacks by Exploiting Intel Data Streaming AcceleratorBen Chen, Kunlin Li, Shuwen Deng, Dongsheng Wang et al.HPCA 2026 · 1 citation
