Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and Profit
Chang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu, Yu Jin, Zhuoyuan Lu, Yinqian Zhang, Gang Qu
摘要
This paper presents a comprehensive investigation into the security vulnerabilities associated with speculative memory access on AMD processors. Firstly, employing novel reverse engineering techniques, our study uncovers two key predictors, namely the Predictive Store Forwarding Predictor (PSFP) and the Speculative Store Bypass Predictor (SSBP), along with elucidating their internal structures and state machine designs. Secondly, our research empirically confirms that these predictors can be deliberately manipulated and altered during transient execution, resulting in secret leakage across security domains. Leveraging these discoveries, we propose innovative attacks targeting these predictors, including an out-of-place variant of Spectre-STL and an entirely new form of Spectre attack named Spectre-CTL. Finally, we establish experimentally that enabling Speculative Store Bypass Disable alleviates the vulnerabilities. However, this comes at the expense of significant performance degradation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- MDPeek: Breaking Balanced Branches in SGX with Memory Disambiguation Unit Side ChannelsChang Liu, Shuaihu Feng, Yuan Li, Dongsheng Wang 等ASPLOS 2025 · 被引用 7 次
- SSBench: Automated Characterization of Memory Dependence Predictors on Modern CPUsChang Liu, Yu Jin, Yuchen Fan, Tianrui Xiao 等ISCA 2026 · 被引用 1 次
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
- Exploiting Hidden Resource Contention in Selective Speculation DefensesXiaoyu Cheng, Fei Tong, Zhenyu Lei, Fang Jiang 等USENIX Security 2026
它引用的顶会 Paper27
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- SSBleed: Non-Speculative Side-Channel Attacks via Speculative Store Bypass on Armv9 CPUsChang Liu, Hongpei Zheng, Xin Zhang, Dapeng Ju 等HPCA 2026 · 被引用 1 次
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op CachesXida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan 等ISCA 2021 · 被引用 59 次
- Breaking the Barrier: Post-Barrier Spectre AttacksJohannes Wikner, Kaveh RazaviS&P 2025
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFIDaniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia YanS&P 2026 · 被引用 1 次
