USENIX Security2026Top-tier venue
PROBE+DETECT+MITIGATE (PDM): Enabling Cloud Tenants to Self-Defend against Microarchitectural Attacks
Arash Daneshmand, Hugo Kermabon-Bobinnec, Lingyu Wang, Makan Pourzandi, Suryadipta Majumdar, Yosr Jarraya
Abstract
Microarchitectural attacks represent a critical security concern in public cloud environments, as they can cause information leakage between cloud tenants with conflicting interests. Existing solutions usually require provider-level resources, such as hardware performance counters or host processes, which may be inaccessible to cloud tenants. The lack of awareness among cloud tenants may persuade cloud providers to postpone the deployment of vendor patches, as evidenced by patched-yet-active threats, such as PRIME+PROBE and Spectre variants. In this paper, we propose PDM, a solution that enables cloud tenants to independently detect and mitigate microarchitectural attacks without providers' help. First, PDM introduces tenant-based detection based on an interesting observation, i.e., probing the memory space of victim applications using the popular FLUSH+RELOAD attack technique can actually enable detection. Second, PDM achieves efficient tenant-based mitigation by selectively triggering obfuscation and in-memory encryption techniques upon detection. Third, we tackle several key challenges including (i) attacks not involving evictions (e.g., Spectre), (ii) the need for source code or binary instrumentation, (iii) benign noises from the victim or co-resident tenants, and (iv) the tradeoff between accuracy, delay, and overhead. Our experiments show that PDM allows tenants to detect and mitigate various microarchitectural attacks, including PRIME+PROBE and Spectre, in an accurate (e.g., ≥99.72% TPR and ≤0.13% FPR on our testbed, and ≥98.63% TPR and ≤0.83% FPR on AWS Fargate), timely (e.g., 7ms lead time for triggering mitigation), efficient (e.g., ≤2.47% overhead on SPEC CPU 2017), and robust (against both noises and evasive attacks) manner.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ce2fff87-bb91-407c-96c2-25ba5981a5d8Builds on26
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 155 citations
- VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud EnvironmentsJean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, Kaveh RazaviS&P 2026 · 4 citations
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 19 citations
- SpecTaint: Speculative Taint Analysis for Discovering Spectre GadgetsZhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan et al.NDSS 2021
- A Systematic Evaluation of Novel and Existing Cache Side ChannelsFabian Rauscher, Carina Fiedler, Andreas Kogler, Daniel GrussNDSS 2025
