Validation of Side-Channel Models via Observation Refinement
Pablo Buiras, Hamed Nemati, Andreas Lindner, Roberto Guanciale
Abstract
Observational models enable the analysis of information flow properties against side channels. Relational testing has been used to validate the soundness of these models by measuring the side channel on states that the model considers indistinguishable. However, unguided search can generate test states that are too similar to each other to invalidate the model. To address this we introduce observation refinement, a technique to guide the exploration of the state space to focus on hardware features of interest. We refine observational models to include fine-grained observations that characterize behavior that we want to exclude. States that yield equivalent refined observations are then ruled out, reducing the size of the space. We have extended an existing model validation framework, Scam-V, to support refinement. We have evaluated the usefulness of refinement for search guidance by analyzing cache coloring and speculative leakage in the ARMv8-A architecture. As a surprising result, we have exposed SiSCLoak, a new vulnerability linked to speculative execution in Cortex-A53.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers9
- Specification and Verification of Side-channel Security for Open-source Processors via Leakage ContractsZilong Wang, Gideon Mohr, Klaus von Gleissenthall, Jan Reineke et al.CCS 2023 · 20 citations
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup et al.CCS 2024 · 6 citations
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann et al.S&P 2026 · 4 citations
- Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel ProcessorsAnirban Chakraborty, Nimish Mishra, Debdeep MukhopadhyayUSENIX Security 2024 · 3 citations
- AutoCAT: Reinforcement Learning for Automated Exploration of Cache-Timing AttacksMulong Luo, Wenjie Xiong, Geunbae Lee, Yueying Li et al.HPCA 2023 · 3 citations
Related papers
- Validation of Abstract Side-Channel Models for Computer ArchitecturesHamed Nemati, Pablo Buiras, Andreas Lindner, Roberto Guanciale et al.CAV 2020 · 18 citations
- Compass: Navigating the Design Space of Taint Schemes for RTL Security VerificationYuheng Yang, Qinhan Tan, Thomas Bourgeat, Sharad Malik et al.ASPLOS 2026 · 1 citation
- Revizor: testing black-box CPUs against speculation contractsOleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark SilbersteinASPLOS 2022 · 36 citations
- Generalized Security-Preserving Refinement for Concurrent SystemsHuan Sun, David Sanán, Jingyi Wang, Yongwang Zhao et al.CCS 2025
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida et al.USENIX Security 2025
