SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for Security
Sanjeev Das, Jan Werner, Manos Antonakakis, Michalis Polychronakis, Fabian Monrose
Abstract
Hardware Performance Counters (HPCs) have been available in processors for more than a decade. These counters can be used to monitor and measure events that occur at the CPU level. Modern processors provide hundreds of hardware events that can be monitored, and with each new processor architecture more are added. Yet, there has been little in the way of systematic studies on how performance counters can best be utilized to accurately monitor events in real-world settings. Especially when it comes to the use of HPCs for security applications, measurement imprecisions or incorrect assumptions regarding the measured values can undermine the offered protection. To shed light on this issue, we embarked on a year-long effort to (i) study the best practices for obtaining accurate measurement of events using performance counters, (ii) understand the challenges and pitfalls of using HPCs in various settings, and (iii) explore ways to obtain consistent and accurate measurements across different settings and architectures. Additionally, we then empirically evaluated the way HPCs have been used throughout a wide variety of papers. Not wanting to stop there, we explored whether these widely used techniques are in fact obtaining performance counter data correctly. As part of that assessment, we (iv) extended the seminal work of Weaver and McKee from almost 10 years ago on non-determinism in HPCs, and applied our findings to 56 papers across various application domains. In that follow-up study, we found the acceptance of HPCs in security applications is in stark contrast to other application areas - especially in the last five years. Given that, we studied an additional representative set of 41 works from the security literature that rely on HPCs, to better elucidate how the intricacies we discovered can impact the soundness and correctness of their approaches and conclusions. Toward that goal, we (i) empirically evaluated how failure to accommodate for various subtleties in the use of HPCs can undermine the effectiveness of security applications, specifically in the case of exploit prevention and malware detection. Lastly, we showed how (ii) an adversary can manipulate HPCs to bypass certain security defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers18
- Understanding the Security of ARM Debugging FeaturesZhenyu Ning, Fengwei ZhangS&P 2019 · 41 citations
- A Benchmark Suite for Evaluating Caches' Vulnerability to Timing AttacksShuwen Deng, Wenjie Xiong, Jakub SzeferASPLOS 2020 · 20 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service PlatformsZhi Li, Weijie Liu, Hongbo Chen, XiaoFeng Wang et al.S&P 2022 · 19 citations
- BayesPerf: minimizing performance monitoring errors using Bayesian statisticsSubho S. Banerjee, Saurabh Jha, Zbigniew Kalbarczyk, Ravishankar K. IyerASPLOS 2021 · 14 citations
Related papers
- On the Feasibility of Malware Unpacking via Hardware-assisted Loop ProfilingBinlin Cheng, Erika A. Leal, Haotian Zhang, Jiang MingUSENIX Security 2023
- Tintin: A Unified Hardware Performance Profiling Infrastructure to Uncover and Manage UncertaintyAo Li, Marion Sudvarg, Zihan Li, Sanjoy K. Baruah et al.OSDI 2025 · 2 citations
- PerSpectron: Detecting Invariant Footprints of Microarchitectural Attacks with PerceptronSamira Mirbagher Ajorpaz, Gilles Pokam, Esmaeil Mohammadian Koruyeh, Elba Garza et al.MICRO 2020 · 23 citations
- VESTA: Power Modeling with Language Runtime EventsJoseph Raskind, Timur Babakol, Khaled Mahmoud, Yu David LiuPLDI 2024 · 5 citations
- SMaCk: Efficient Instruction Cache Attacks via Self-Modifying Code ConflictsSeonghun Son, Daniel Moghimi, Berk GülmezogluASPLOS 2025 · 1 citation
