Aug 2026· ACM Transactions on Architecture and Code Optimization (TACO)· 0 citations· 71 references
TL;DR
This paper systematically analyze a set of x86 instructions that directly or indirectly invalidate instruction cache lines, revealing measurable timing asymmetries between cache hits and misses, and shows that these SMC-induced timing artifacts can be leveraged to mount high-resolution cache attacks that are both stealthier and more reliable than traditional techniques.
Abstract
Self-modifying code (SMC) is a specialized technique that alters program execution by modifying instructions in executable memory pages during runtime. While historically employed for performance tuning, dynamic optimization, and obfuscation, both x86 and RISC-V-based processors continue to support SMC as part of their architectural flexibility. However, the same capability that enables adaptive and high-performance execution also opens the door for novel microarchitectural exploitation. In particular, SMC allows attackers to induce distinctive instruction fetch and cache behaviors, thereby enabling precise monitoring of shared microarchitectural resources such as instruction caches. In this paper, we present the first in-depth security study of SMC on the latest Intel microarchitectures, including the latest hybrid CPU designs that balance performance and energy efficiency. We systematically analyze a set of x86 instructions that directly or indirectly invalidate instruction cache lines, revealing measurable timing asymmetries between cache hits and misses. Our results show that these SMC-induced timing artifacts can be leveraged to mount high-resolution cache attacks that are both stealthier and more reliable than traditional techniques. We demonstrate the power of our approach through two privacy-violating case studies: (1) recovering victim keystrokes with high accuracy in real time, and (2) performing website fingerprinting on hyper-threaded CPU cores, successfully targeting both the Google Chrome and Tor browsers. Beyond empirical results, we explore the architectural conditions that amplify SMC side effects, discuss the broader implications for multi-tenant and browser-based environments, and give an overview of possible hardware and software-level countermeasures.
Runtime detection of microarchitectural side channel attacks remains significantly underexplored in RISCV compared with x86 and ARM ISAs, posing a serious threat to critical applications. State-of-the-art branch predictor attacks bypass traditional data and instruction caches by directly exploiting the state of interna...
Muhammad Hassan, Maria Mushtaq, J. Raik et al.· 0 citations
Hardware trojan (HT) attacks against CPUs typically assume threat scenarios where an attacker targeting a system with a trojanized CPU is able to execute arbitrary code (i.e. machine-level instructions) to reliably interact with the implanted trojan. On end-user devices (i.e., mobiles, laptops), achieving arbitrary cod...
Athanasios Moschos, Kevin Valakuzhy, G. Kokolakis et al.· 0 citations
We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime cont...
N. Huỳnh, Minh Quang Luu, Ngoc Hong Tran· 0 citations
During software testing, memory errors in C/C++ can silently corrupt the program state. Address-based memory sanitizers, while offering practical performance and compatibility, are fundamentally unable to distinguish spatial errors that skip redzones or temporal errors that occur after memory reuse. Moreover, their reu...
Xiao-Yun Lu, Qiang Wei, Yun-Feng Wang et al.· Applied Sciences· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.