Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution Vulnerabilities
Daniel Weber, Fabian Thomas, Leon Trampert, Ruiyi Zhang, Michael Schwarz
Abstract
Transient execution attacks continue to pose serious security risks, even years after their initial discovery in the form of Meltdown and Spectre. Despite growing awareness and research, most attacks have been discovered manually. Existing automated approaches only focus on variants of known attacks or make strict assumptions, such as access to the CPU's RTL, a given leakage contract, or an ISA emulator. These limitations hinder broader and more generic detection, especially in postsilicon environments. In this paper, we present TREVEX, a post-silicon black-box detection framework designed to discover data-flow transient execution vulnerabilities automatically. TREVEX does not rely on RTL access or semantics of the ISA. Instead, TREVEX detects any unexpected transient data flow between different execution contexts by employing novel techniques informed by insights from prior transient execution attacks. We evaluate TREVEX across 20 microarchitectures from Intel, AMD, and Zhaoxin. Hereby, TREVEX discovers Floating Point Divider State Sampling (FP-DSS), a novel transient execution attack affecting AMD CPUs. We show that FP-DSS allows an unprivileged attacker and even a malicious website to leak data from different security domains, including the operating system. TREVEX further discovers a new variant of FPVI on AMD CPUs and that Zhaoxin CPUs are affected by FPVI. Our study shows that TREVEX reliably discovers known vulnerabilities on affected machines. Our study shows that TREVEX detects known vulnerabilities on affected CPUs, while also closing gaps in existing vendor documentation. Our findings highlight the urgent need for more diverse automated tools and demonstrate that TREVEX fills an important gap in current CPU vulnerability research.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8ffb05b3-5b96-4db3-983e-1fd055c1695dRelated papers
- Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU ExceptionsJana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf et al.USENIX Security 2023
- Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel ProcessorsAnirban Chakraborty, Nimish Mishra, Debdeep MukhopadhyayUSENIX Security 2024 · 3 citations
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 76 citations
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida et al.USENIX Security 2025
- Revizor: testing black-box CPUs against speculation contractsOleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark SilbersteinASPLOS 2022 · 36 citations
