Pentimento: Data Remanence in Cloud FPGAs
Colin Drewes, Olivia Weng, Andres Meza, Alric Althoff, David Kohlbrenner, Ryan Kastner, Dustin Richmond
摘要
Remote attackers can recover "FPGA pentimento" -longremoved data belonging to a prior user or proprietary design image on a cloud FPGA. Just as a pentimento of a painting can be exposed by infrared imaging, FPGA pentimentos can be exposed by signal timing sensors. The data constituting an FPGA pentimento is imprinted on the device through bias temperature instability effects on the underlying transistors. Measuring this degradation using a time-to-digital converter allows an attacker to (1) extract proprietary details or keys from an encrypted FPGA design image available on the AWS marketplace and (2) recover information from a previous user of a cloud-FPGA. These threat models are validated on AWS F1, with successful AES key recovery under one model.
• Security and privacy → Side-channel analysis and countermeasures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru 等S&P 2026 · 被引用 1 次
- PhasePrint: Exposing Cloud FPGA Fingerprints by Inducing Timing Faults at RuntimeJubayer Mahmod, Matthew HicksASPLOS 2025
它引用的顶会 Paper5
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 被引用 301 次
- C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit LeakageIlias Giechaskiel, Kasper Bonne Rasmussen, Jakub SzeferS&P 2020 · 被引用 74 次
- Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGAAdnan Siraj Rakin, Yukui Luo, Xiaolin Xu, Deliang FanUSENIX Security 2021 · 被引用 64 次
- DeepStrike: Remotely-Guided Fault Injection Attacks on DNN Accelerator in Cloud-FPGAYukui Luo, Cheng Gongye, Yunsi Fei, Xiaolin XuDAC 2021 · 被引用 42 次
- Classifying Computations on Multi-Tenant FPGAsMustafa S. Gobulukoglu, Colin Drewes, William Hunter, Ryan Kastner 等DAC 2021 · 被引用 13 次
相关 Paper
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou 等CCS 2023 · 被引用 4 次
- A Novel Covert Timing Channel for Cloud FPGAsBrian Udugama, Darshana Jayasinghe, Hassaan Saadat, Aleksandar Ignjatovic 等DAC 2025
- Silicon Heist: (Ransom) Attacks for Cloud FPGAs via Privilege EscalationSimon Klix, Felix Hahn, Maik Ender, Nils Albartus 等USENIX Security 2026
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang 等DAC 2022 · 被引用 8 次
- FuncTeller: How Well Does eFPGA Hide Functionality?Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab 等USENIX Security 2023
