USENIX Security2026Top-tier venue
Exploiting Hidden Resource Contention in Selective Speculation Defenses
Xiaoyu Cheng, Fei Tong, Zhenyu Lei, Fang Jiang, Zhe Zhou, Guang Cheng, Trevor E. Carlson
Abstract
Transient execution attacks continue to evolve beyond cache-centric channels, motivating selective speculation defenses that aim to provide comprehensive protection with low overhead by delaying only transmit instructions. In this work, we show that several state-of-the-art selective-speculation defenses rest on shared assumptions that overlook important microarchitectural behaviors, leaving systematic blind spots that admit secret-dependent reservation-station (RS) contention. Our analysis identifies three limitations in optimized selective-speculation designs. First, existing transmit taxonomies emphasize post-issue execution effects and miss dispatch-phase channels, such as operand-dependent μop expansion in instructions (e.g., REP-prefixed string operations) that create operand-dependent RS occupancy before execution. Second, the delay-until-resolution strategy focuses on redirect-based control leakage, but predicated instructions (e.g., x86 CMOV and RISC-V Zicond) enable secret-dependent selection without branch resolution, allowing secrets to steer operand-dependent μop expansion (e.g., REP iteration counts). Finally, the older-μop-first allocation strategy assumes unsafe contention is prevented by prioritizing non-transient μops, yet undelayed arithmetic and cache-hit memory μops can still lead to secret-dependent RS pressure through latency-amplifying dependency chains. Guided by these findings, we construct Spectre-v1-style gadgets that bypass STT/DOLMA on x86 and RISC-V gem5 models. We further validate RS-contention effects on real CPUs, including a REP MOVSB- and REP STOSB-based proof-of-concept and a real-world RS-contention pattern identified by our LLVM pass, demonstrating realistic gadget structure and measurable signal. Finally, we propose strengthened STT mechanisms that close both existing and newly exposed gaps at moderate performance overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97e5e09a-ee43-49fb-90de-48677aad24d7Builds on24
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
Related papers
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu et al.DAC 2022 · 1 citation
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao et al.ISCA 2024 · 6 citations
- DOLMA: Securing Speculation with the Principle of Transient Non-ObservabilityKevin Loughlin, Ian Neal, Jiacheng Ma, Elisa Tsai et al.USENIX Security 2021 · 94 citations
- SPECRUN: The Danger of Speculative Runahead Execution in ProcessorsChaoqun Shen, Gang Qu, Jiliang ZhangDAC 2024 · 1 citation
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu et al.ASPLOS 2021 · 69 citations
