Citadel: Rethinking Memory Allocation to Safeguard Against Inter-Domain Rowhammer Exploits
Anish Saxena, Walter Wang, Alexandros Daglis
Abstract
Rowhammer is a hardware security vulnerability at the heart of every DRAM-based memory system.Despite its discovery a decade ago, comprehensive defenses in current systems remain elusive, while the probability of successful attacks grows with DRAM density.Hardware-based defenses have proven ineffective due to substantial cost, delays in commercial adoption, and repeated circumventions by attackers, while more flexible software-based solutions incur major performance and memory capacity overheads or offer only limited protection.Citadel is a new memory allocator design that prevents Rowhammer-initiated security exploits by addressing the vulnerability's root cause: physical adjacency of DRAM rows.It introduces flexible security domains and isolates them in physically disjoint memory regions, guaranteeing security by design.On a server system, Citadel supports thousands of security domains at a modest 7.2% average memory overhead and no performance loss, while remaining readily deployable across legacy, contemporary, and future platforms.In contrast, recent domain isolation schemes fail to support many workload scenarios due to excessive overhead and incur 4-6× higher overhead for supported scenarios.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b2d5e2de-f2a0-44ed-a3bd-4697589b59e6Cited by top-tier papers4
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
- PuDghost: Experimental Analysis of Computation Result Corruption in Processing-Using-Dram Operations on Real Dram Chips and Implications for Future SystemsDaichi Tokuda, Ismail Emir Yüksel, Tatsuya Kubo, Ataberk Olgun et al.ISCA 2026 · 4 citations
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 1 citation
- Loaded Dice: Solving the Non-Selection Problem for Scalable Probabilistic RowHammer DefenseJeonghyun Woo, Junsu Kim, Aamer Jaleel, Prashant J. NairISCA 2026 · 1 citation
Related papers
- CAn't Touch This: Software-only Mitigation against Rowhammer Attacks targeting Kernel MemoryFerdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen et al.USENIX Security 2017 · 146 citations
- PThammer: Cross-User-Kernel-Boundary Rowhammer through Implicit AccessesZhi Zhang, Yueqiang Cheng, Dongxi Liu, Surya Nepal et al.MICRO 2020 · 69 citations
- BreakHammer: Enhancing RowHammer Mitigations by Carefully Throttling Suspect ThreadsOguzhan Canpolat, A. Giray Yaglikçi, Ataberk Olgun, Ismail Emir Yuksel et al.MICRO 2024 · 19 citations
- RowArmor: Efficient and Comprehensive Protection Against DRAM Disturbance AttacksMinbok Wi, Yoonyul Yoo, Yoojin Kim, Jaeho Shin et al.ASPLOS 2026 · 3 citations
- Marionette: A RowHammer Attack via Row CouplingSeungmin Baek, Minbok Wi, Seonyong Park, Hwayong Nam et al.ASPLOS 2025 · 11 citations
