Skip to content
Review Open access

User Privacy Attacks through Self-Modifying Code Conflicts

Aug 2026 · ACM Transactions on Architecture and Code Optimization (TACO) · 0 citations · 71 references

TL;DR

This paper systematically analyze a set of x86 instructions that directly or indirectly invalidate instruction cache lines, revealing measurable timing asymmetries between cache hits and misses, and shows that these SMC-induced timing artifacts can be leveraged to mount high-resolution cache attacks that are both stealthier and more reliable than traditional techniques.

Abstract

Self-modifying code (SMC) is a specialized technique that alters program execution by modifying instructions in executable memory pages during runtime. While historically employed for performance tuning, dynamic optimization, and obfuscation, both x86 and RISC-V-based processors continue to support SMC as part of their architectural flexibility. However, the same capability that enables adaptive and high-performance execution also opens the door for novel microarchitectural exploitation. In particular, SMC allows attackers to induce distinctive instruction fetch and cache behaviors, thereby enabling precise monitoring of shared microarchitectural resources such as instruction caches. In this paper, we present the first in-depth security study of SMC on the latest Intel microarchitectures, including the latest hybrid CPU designs that balance performance and energy efficiency. We systematically analyze a set of x86 instructions that directly or indirectly invalidate instruction cache lines, revealing measurable timing asymmetries between cache hits and misses. Our results show that these SMC-induced timing artifacts can be leveraged to mount high-resolution cache attacks that are both stealthier and more reliable than traditional techniques. We demonstrate the power of our approach through two privacy-violating case studies: (1) recovering victim keystrokes with high accuracy in real time, and (2) performing website fingerprinting on hyper-threaded CPU cores, successfully targeting both the Google Chrome and Tor browsers. Beyond empirical results, we explore the architectural conditions that amplify SMC side effects, discuss the broader implications for multi-tenant and browser-based environments, and give an overview of possible hardware and software-level countermeasures.

Read PDF

Similar papers

Aug 2026

PMDangNull: Preventing use-After-Free for Persistent Memory Applications

Use-After-Free (UAF) remains one of the most critical security threats affecting C/C++ programs. Moreover, the cross-restart persistence semantics of persistent memory (PM) programming models significantly broaden the UAF attack surface. Existing DRAM-based protection schemes lack crash consistency guarantees, whereas...

Yuquan Chi, Yinjin Fu, Yong-Gang Hu et al. · 0 citations
Preprint Aug 2026

ANTMAN: An Efficient and Interpretable RTL-Level Run-Time Detection Framework for Stealthy Branch Predictor Attacks on BOOM

Runtime detection of microarchitectural side channel attacks remains significantly underexplored in RISCV compared with x86 and ARM ISAs, posing a serious threat to critical applications. State-of-the-art branch predictor attacks bypass traditional data and instruction caches by directly exploiting the state of interna...

Muhammad Hassan, Maria Mushtaq, J. Raik et al. · 0 citations
Preprint Sep 2026

Exploiting Software-level Abstractions To Support Practical Hardware Trojan Attacks

Hardware trojan (HT) attacks against CPUs typically assume threat scenarios where an attacker targeting a system with a trojanized CPU is able to execute arbitrary code (i.e. machine-level instructions) to reliably interact with the implanted trojan. On end-user devices (i.e., mobiles, laptops), achieving arbitrary cod...

Athanasios Moschos, Kevin Valakuzhy, G. Kokolakis et al. · 0 citations
Preprint Sep 2026

CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics

We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime cont...

N. Huỳnh, Minh Quang Luu, Ngoc Hong Tran · 0 citations
Open access Aug 2026

MixSan: Enhancing Address-Based Memory Sanitizers with Fused Metadata and Hybrid Detection

During software testing, memory errors in C/C++ can silently corrupt the program state. Address-based memory sanitizers, while offering practical performance and compatibility, are fundamentally unable to distinguish spatial errors that skip redzones or temporal errors that occur after memory reuse. Moreover, their reu...

Xiao-Yun Lu, Qiang Wei, Yun-Feng Wang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.