Scheduled Disclosure: Turning Power into Timing Without Frequency Scaling
Inwhan Chun, Isabella Siu, Riccardo Paccagnella
Abstract
Power side-channel attacks are seeing a resurgence of interest in computer security research. An emerging class of these attacks exploits remote methods to monitor power consumption-most notably by observing power-dependent CPU frequency variations. However, existing methods have only been demonstrated on (older) x86 CPU architectures where frequency scaling is the primary-if not only-mechanism utilized to keep the system within safe operating conditions. It remains unclear whether remote power side-channel attacks are still feasible on modern x86 CPU architectures with additional, more sophisticated such mechanisms. We demonstrate that not only do remote power-side channel attacks remain feasible on modern x86 CPU architectures, but that they are also more effective and work even in the absence of frequency side-channel leakage. Our attacks take advantage of Thread Director, a hardware optimization that provides scheduling “hints” to enhance performance and energy efficiency on modern Intel processors. We demonstrate that these hints depend on the processor's power consumption, leading to power-dependent scheduling behaviors-such as variations in the number of active cores-that can be observed purely from software and even via remote-timing analysis. We show the efficacy of our attacks by leaking keys from constant-time cryptographic code (5 x faster than prior attacks on older x86 CPUs) and mounting cross-origin pixel stealing attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Towards Practical Interrupt Side-Channel Attacks on macOS for Apple SiliconXin Zhang, Chang Liu, Jiajun Zou, Yi Yang et al.ISCA 2026 · 1 citation
- Pixnapping: Bringing Pixel Stealing out of the Stone AgeAlan Wang, Pranav Gopalkrishnan, Yingchen Wang, Christopher W. Fletcher et al.CCS 2025 · 1 citation
- Transient Architectural Execution: From Weird Gates to Weird ProgramsPing-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen et al.S&P 2026
Builds on15
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 301 citations
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz et al.S&P 2021 · 242 citations
- Breaking SIDH in Polynomial TimeDamien RobertEUROCRYPT 2023 · 158 citations
- On the effectiveness of mitigations against floating-point timing channelsDavid Kohlbrenner, Hovav ShachamUSENIX Security 2017 · 40 citations
Related papers
- Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham et al.USENIX Security 2022
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin et al.USENIX Security 2022
- Frequency Throttling Side-Channel AttackChen Liu, Abhishek Chakraborty, Nikhil Chawla, Neer RoggelCCS 2022 · 33 citations
- PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksYun Chen, Ali Hajiabadi, Lingfeng Pei, Trevor E. CarlsonHPCA 2024 · 15 citations
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu et al.ISCA 2026 · 1 citation
