TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
Tristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz, Ruiyi Zhang
Abstract
Confidential computing with VM-based trusted execution environments (TEEs) promises to protect code and data from a privileged cloud operator, enabling privacy-preserving workloads ranging from medical analytics to AI inference. However, most deployments exclude microarchitectural side channels from their threat model, shifting the burden to application developers who lack practical, general-purpose tools to assess (let alone mitigate) leakage. In particular, it remains unclear which host-observable signals persist under TDX's strict isolation and whether these signals can reveal sensitive information about confidential workloads.
In this paper, we systematically investigate the side-channel attack surface in Intel TDX. We identify four new side-channel primitives: SEPTrace, Load+Probe, TSX-Probe, and MWAIT-Probe. Together, they expose page-level and cache-level activity with varying temporal precision. By combining these primitives, we construct TDXRay, a host-side measurement framework that produces highly accurate, cache-line-granular memory access traces of unmodified confidential VMs. Using TDXRay, we build two case studies: (1) a classic AES T-table attack in which a malicious hypervisor recovers the secret key from access-pattern leakage, and (2) an attack against large language models in which the host infers user prompts by monitoring memory accesses during tokenization. Our evaluation demonstrates that TDXRay can reliably recover user prompts from a single memory access trace, thus posing a severe threat to private LLM inference.
Finally, we investigate and discuss mitigation strategies at system and application level. While effective countermeasures based on ORAM can be a short-term solution, our results highlight the need for long-term investment in improving Intel TDX and similar architectures against this class of attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ccee3533-b8cb-4940-9b32-9a3652ec888fCited by top-tier papers1
Ask how each one uses itBuilds on23
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz et al.S&P 2021 · 242 citations
Related papers
- TDXdown: Single-Stepping and Instruction Counting Attacks against Intel TDXLuca Wilke, Florian Sieck, Thomas EisenbarthCCS 2024 · 9 citations
- TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDXFabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth et al.USENIX Security 2025
- SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMsRuiyi Zhang, Albert Cheu, Adrià Gascón, Daniel Moghimi et al.NDSS 2026 · 7 citations
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik et al.S&P 2026 · 29 citations
- CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNPStefan Gast, Hannes Weissteiner, Robin Leander Schröder, Daniel GrussNDSS 2025
