SALT: Track-and-Mitigate Subarrays, Not Rows, for Blast-Radius-Free Rowhammer Defense
Moinuddin K. Qureshi
摘要
Typical in-DRAM Rowhammer mitigation operates by identifying aggressor rows and refreshing a limited number of victim rows on either side of the aggressor row. The number of victim rows is specified by the Blast Radius. JEDEC recently introduced state-of-the-art Rowhammer defense, which includes Per-Row-Activation-Counting (PRAC) to identify aggressor rows and Alert-Back-Off (ABO) to allow the DRAM chip to obtain time to refresh two victim rows on either side of the aggressor row. The implicit assumption in PRAC is that charge loss beyond the two victim rows is negligibly small and does not represent a threat to the security of PRAC. In this paper, we develop Ripple Attack that can amplify even a small amount of leakage in distant rows to cause charge loss equivalent tothe activations tolerated by PRAC for the given threshold. The goal of our paper is to develop an in-DRAM mitigation that tolerates Rowhammer without relying on a pre-defined Blast Radius. We observe that as subarrays are spatially isolated from each other, activity in one subarray does not cause charge leakage in rows of another subarray. To develop Blast-RadiusFree Rowhammer mitigation, we propose SALT (Subarray-Level Tracking and Mitigation). SALT tracks activation counts per subarray, and when the count exceeds a specified value, it triggers ABO to obtain time for refreshing a portion of the subarray. SALT bounds the maximum number of activations to the subarray before all rows are guaranteed to be refreshed, thus providing Blast-Radius-Free Rowhammer mitigation. To reduce the slowdown from ABO, SALT-C coordinates the demand refresh operations such that ABO is not required if the activations to the subarray are below what can be handled by the demand refresh, thus reducing ABO by 48x. SALT-C not only provides stronger security guarantees than PRAC due to Blast-RadiusFreedom, but also has 38x lower storage overhead than PRAC, and incurs lower slowdown (0.3 % vs 1.7 %) than PRAC.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper4
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi 等ISCA 2026 · 被引用 5 次
- PuDghost: Experimental Analysis of Computation Result Corruption in Processing-Using-Dram Operations on Real Dram Chips and Implications for Future SystemsDaichi Tokuda, Ismail Emir Yüksel, Tatsuya Kubo, Ataberk Olgun 等ISCA 2026 · 被引用 4 次
- Loaded Dice: Solving the Non-Selection Problem for Scalable Probabilistic RowHammer DefenseJeonghyun Woo, Junsu Kim, Aamer Jaleel, Prashant J. NairISCA 2026 · 被引用 1 次
- ColumnKeeper: Efficient Solutions to the Columndisturb Vulnerability in Dram-Based SystemsAndreas Kosmas Kakolyris, F. Nisa Bostanci, Ataberk Olgun, Ismail Emir Yüksel 等ISCA 2026 · 被引用 1 次
相关 Paper
- MIRZA: Efficiently Mitigating Rowhammer with Randomization and ALERTHritvik Taneja, Ali Hajiabadi, Michele Marazzi, Kaveh Razavi 等HPCA 2026 · 被引用 6 次
- QPRAC: Towards Secure and Practical PRAC-based Rowhammer Mitigation using Priority QueuesJeonghyun Woo, Shaopeng Chris Lin, Prashant J. Nair, Aamer Jaleel 等HPCA 2025 · 被引用 20 次
- MINT: Securely Mitigating Rowhammer with a Minimalist in-DRAM TrackerMoinuddin Qureshi, Salman Qazi, Aamer JaleelMICRO 2024 · 被引用 28 次
- When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer MitigationsJeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Prashant Jayaprakash NairISCA 2025 · 被引用 6 次
- ABACuS: All-Bank Activation Counters for Scalable and Low Overhead RowHammer MitigationAtaberk Olgun, Yahya Can Tugrul, Nisa Bostanci, Ismail Emir Yuksel 等USENIX Security 2024 · 被引用 29 次
