Pentimento: Data Remanence in Cloud FPGAs
Colin Drewes, Olivia Weng, Andres Meza, Alric Althoff, David Kohlbrenner, Ryan Kastner, Dustin Richmond
Abstract
Remote attackers can recover "FPGA pentimento" -longremoved data belonging to a prior user or proprietary design image on a cloud FPGA. Just as a pentimento of a painting can be exposed by infrared imaging, FPGA pentimentos can be exposed by signal timing sensors. The data constituting an FPGA pentimento is imprinted on the device through bias temperature instability effects on the underlying transistors. Measuring this degradation using a time-to-digital converter allows an attacker to (1) extract proprietary details or keys from an encrypted FPGA design image available on the AWS marketplace and (2) recover information from a previous user of a cloud-FPGA. These threat models are validated on AWS F1, with successful AES key recovery under one model.
• Security and privacy → Side-channel analysis and countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e19db221-5303-4a1a-8e22-96abfc31f9baCited by top-tier papers2
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru et al.S&P 2026 · 1 citation
- PhasePrint: Exposing Cloud FPGA Fingerprints by Inducing Timing Faults at RuntimeJubayer Mahmod, Matthew HicksASPLOS 2025
Builds on5
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 301 citations
- C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit LeakageIlias Giechaskiel, Kasper Bonne Rasmussen, Jakub SzeferS&P 2020 · 74 citations
- Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGAAdnan Siraj Rakin, Yukui Luo, Xiaolin Xu, Deliang FanUSENIX Security 2021 · 64 citations
- DeepStrike: Remotely-Guided Fault Injection Attacks on DNN Accelerator in Cloud-FPGAYukui Luo, Cheng Gongye, Yunsi Fei, Xiaolin XuDAC 2021 · 42 citations
- Classifying Computations on Multi-Tenant FPGAsMustafa S. Gobulukoglu, Colin Drewes, William Hunter, Ryan Kastner et al.DAC 2021 · 13 citations
Related papers
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou et al.CCS 2023 · 4 citations
- A Novel Covert Timing Channel for Cloud FPGAsBrian Udugama, Darshana Jayasinghe, Hassaan Saadat, Aleksandar Ignjatovic et al.DAC 2025
- Silicon Heist: (Ransom) Attacks for Cloud FPGAs via Privilege EscalationSimon Klix, Felix Hahn, Maik Ender, Nils Albartus et al.USENIX Security 2026
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang et al.DAC 2022 · 8 citations
- FuncTeller: How Well Does eFPGA Hide Functionality?Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab et al.USENIX Security 2023
