Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an Eye
Bradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik, Chitchanok Chuengsatiansup, Daniel Genkin, Olaf Maennel, Paul Montague, Eyal Ronen, Yuval Yarom
Abstract
An essential step for mounting cache attacks is finding eviction sets, collections of memory locations that contend on cache space. On Intel processors, one of the main challenges for identifying contending addresses is the sliced cache design, where the processor hashes the physical address to determine where in the cache a memory location is stored. While past works have demonstrated that the hash function can be reversed, they also showed that it depends on physical address bits that the adversary does not know. In this work, we make three main contributions to the art of finding eviction sets. We first exploit microarchitectural races to compare memory access times and identify the cache slice to which an address maps. We then use the known hash function to both reduce the error rate in our slice identification method and to reduce the work by extrapolating slice mappings to untested memory addresses. Finally, we show how to propagate information on eviction sets across different page offsets for the hitherto unexplored case of non-linear hash functions. Our contributions allow for entire LLC eviction set generation in 0.7 seconds on the Intel i7-9850H and 1.6 seconds on the i9-10900K, both using non-linear functions. This represents a significant improvement compared to state-of-the-art techniques taking 9× and 10× longer, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c2ea4a5a-7f78-4db9-ad25-ca673fe952e2Cited by top-tier papers3
- Transient Architectural Execution: From Weird Gates to Weird ProgramsPing-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen et al.S&P 2026
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu et al.CCS 2026
- SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple SiliconTianhong Xu, Saion Kumar Roy, Ruyi Ding, A. Adam Ding et al.CCS 2026
Builds on22
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
- Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldMengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher et al.S&P 2019 · 201 citations
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 186 citations
Related papers
- Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageMikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz et al.S&P 2025
- Efficient and Generic Microarchitectural Hash-Function RecoveryLukas Gerlach, Simon Schwarz, Nicolas Faroß, Michael SchwarzS&P 2024 · 14 citations
- Prune+PlumTree - Finding Eviction Sets at ScaleTom Kessous, Niv GilboaS&P 2024 · 7 citations
- Double Trouble: Combined Heterogeneous Attacks on Non-Inclusive Cache HierarchiesAntoon Purnal, Furkan Turan, Ingrid VerbauwhedeUSENIX Security 2022
- ZenLeak: Practical Last-Level Cache Side-Channel Attacks on AMD Zen ProcessorsHan Wang, Ming Tang, Quancheng Wang, Ke Xu et al.DAC 2025 · 2 citations
