Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection
Mohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen, Pouya Mahmoody, Jeyavijayan Rajendran, Ahmad-Reza Sadeghi
Abstract
Microarchitectural attacks represent a challenging and persistent threat to modern processors, exploiting inherent design vulnerabilities in processors to leak sensitive information or compromise systems. Of particular concern is the susceptibility of Speculative Execution, a fundamental part of performance enhancement, to such attacks. We introduce Specure, a novel pre-silicon verification method composing hardware fuzzing with Information Flow Tracking (IFT) to address speculative execution leakages. Integrating IFT enables two significant and non-trivial enhancements over the existing fuzzing approaches: i) automatic detection of microarchitectural information leakages vulnerabilities without golden model and ii) a novel Leakage Path coverage metric for efficient vulnerability detection. Specure identifies previously overlooked speculative execution vulnerabilities on the RISC-V BOOM processor and explores the vulnerability search space 6.45× faster than existing fuzzing techniques. Moreover, Specure detected known vulnerabilities 20× faster.
• Security and privacy → Security in hardware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 87d31ccf-c032-4548-ba0d-66e8089883f7Cited by top-tier papers5
- ReFuzz: Reusing Tests for Processor Fuzzing with Contextual BanditsChen Chen, Zaiyan Xu, Mohamadreza Rostami, David Liu et al.NDSS 2026 · 4 citations
- GoldenFuzz: Generative Golden Reference Hardware FuzzingLichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh et al.NDSS 2026 · 3 citations
- Fuzzilicon: A Post-Silicon Microcode-Guided x86 CPU FuzzerJohannes Lenzen, Mohamadreza Rostami, Lichao Wu, Ahmad-Reza SadeghiNDSS 2026 · 2 citations
- GenHuzz: An Efficient Generative Hardware FuzzerLichao Wu, Mohamadreza Rostami, Huimin Li, Jeyavijayan Rajendran et al.USENIX Security 2025
- MileSan: Detecting Exploitable Microarchitectural Leakage via Differential Hardware-Software Taint TrackingTobias Kovats, Flavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviCCS 2025
Builds on11
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- HardFails: Insights into Software-Exploitable Hardware BugsGhada Dessouky, David Gens, Patrick Haney, Garrett Persyn et al.USENIX Security 2019 · 149 citations
- INTROSPECTRE: A Pre-Silicon Framework for Discovery and Analysis of Transient Execution VulnerabilitiesMoein Ghaniyoun, Kristin Barber, Yinqian Zhang, Radu TeodorescuISCA 2021 · 23 citations
- SpecDoctor: Differential Fuzz Testing to Find Transient Execution VulnerabilitiesJaewon Hur, Suhwan Song, Sunwoo Kim, Byoungyoung LeeCCS 2022 · 19 citations
Related papers
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida et al.USENIX Security 2025
- DejaVuzz: Disclosing Transient Execution Bugs with Dynamic Swappable Memory and Differential Information Flow Tracking Assisted Processor FuzzingJinyan Xu, Yangye Zhou, Xingzhi Zhang, Yinshuai Li et al.ASPLOS 2025 · 4 citations
- CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTLFlavien Solt, Ben Gras, Kaveh RazaviUSENIX Security 2022
- Speculative Privacy Tracking (SPT): Leaking Information From Speculative Execution Without Compromising PrivacyRutvik Choudhary, Jiyong Yu, Christopher W. Fletcher, Adam MorrisonMICRO 2021 · 33 citations
- ProSpeCT: Provably Secure Speculation for the Constant-Time PolicyLesly-Ann Daniel, Marton Bognar, Job Noorman, Sébastien Bardin et al.USENIX Security 2023
