Goldilocks and the Three P-States: Mitigating Hertzbleed with Formal Leakage Guarantees
Inwhan Chun, Christine Guo, Riccardo Paccagnella
Abstract
Hertzbleed is an emerging class of remote timing attacks that can leak secrets previously considered beyond the reach of timing analysis. The attack exploits how, when a processor exceeds power or thermal limits and starts throttling, CPU frequency—and thus, program runtime—becomes dependent on power consumption. In response to Hertzbleed, several software-level mitigations have been proposed, including masking, key refresh, noise injection, and disabling frequency boost. However, none of these mitigations achieves general software applicability, low overhead, and provable security. In this work, we introduce Goldilocks, a practical mitigation against Hertzbleed. Goldilocks treats Hertzbleed as an information-theoretic channel and limits how much information the channel can carry by constraining when and how throttling can occur. It can be deployed on existing processors with no changes to application software, maintains a CPU frequency level that is “just right” for each machine and workload, and provides formal leakage bounds that reduce worst-case leakage growth from linear in execution time to as little as logarithmic. Our evaluation across a variety of processors and workloads shows that Goldilocks effectively mitigates Hertzbleed attacks and incurs low overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- DVFS Frequently Leaks Secrets: Hertzbleed Attacks Beyond SIKE, Cryptography, and CPU-Only DataYingchen Wang, Riccardo Paccagnella, Alan Wandke, Zhao Gang et al.S&P 2023
- Frequency Throttling Side-Channel AttackChen Liu, Abhishek Chakraborty, Nikhil Chawla, Neer RoggelCCS 2022 · 33 citations
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu et al.ISCA 2026 · 1 citation
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- ClepsydraCache - Preventing Cache Attacks with Time-Based EvictionsJan Philipp Thoma, Christian Niesler, Dominic A. Funke, Gregor Leander et al.USENIX Security 2023
