Pith. sign in

REVIEW 4 major objections 7 minor 183 references

SoK: A Systems Perspective on Compound AI Threats and Countermeasures

T0 review · 4 major / 7 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read This SoK argues that attack techniques from the application, software, and hardware layers can be sequenced into end-to-end attacks on compound AI systems, often with weaker attacker assumptions than any single component attack requires.

desk verdict Useful SoK on compound-AI system threats, but its biggest claim about composable cross-layer attacks is asserted rather than demonstrated. read the letter →

arxiv 2411.13459 v1 pith:EEFAHCPI submitted 2024-11-20 cs.CR cs.AIcs.LG

classification cs.CRcs.AIcs.LG
keywords compoundAIsystemsLLMsecuritycross-layerattacksattackwidgetsMITREATT&CKhardwaresidechannelssoftwaresupplychainthreatmodeling
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper systematizes attacks on compound AI systems—pipelines that combine multiple LLMs, vector databases, tools, and heterogeneous hardware. Its central claim is that individual attack techniques, which prior work studies in isolation, can be composed across the application, software, and hardware layers to produce end-to-end attacks requiring fewer threat-model assumptions than any isolated attack. The authors map these attack "widgets" onto the MITRE ATT&CK framework and present case studies, for example a hardware side-channel that reveals a model's architecture and enables model extraction, or an SQL injection into a RAG database that enables misinformation. If the claim holds, security evaluation of compound AI must consider composable cross-layer attack paths, and defenses must be deployed at every layer rather than in isolated components.

What carries the argument

The central object is the compound AI pipeline—query pre-processing, retrieval, generation, and query post-processing—decomposed into application, software, and hardware layers. The mechanism that carries the argument is the notion of an "attack widget": a discrete attack technique with an attached attacker capability and asset target. The paper's primary analytical tool is a mapping of these widgets onto the MITRE ATT&CK framework, which lets the authors show how reconnaissance, initial access, privilege escalation, and exfiltration steps in different layers can be chained. The case studies, such as hardware timing side-channel plus shadow-model training for extraction, and SQL injection plus ConfusedPilot for RAG misinformation, demonstrate the sequencing logic.

What would settle it

A concrete test would be to implement one of the Section 6.2 chains—say, a memory-safety bug to redirect a function call, a malicious grounding block, and a rowhammer bit flip—against a deployed RAG/MoE service and observe whether the attacker can produce a degraded or private-data-leaking response that passes fact-checking. If the chain fails at any step (for example, the bit flip is corrected, the grounding block rejects the output, or the malicious package is caught), the strongest claim would need revision.

Watch

Extended reading notes

Core claim

The paper's central claim is that "combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model." Concretely, an attacker can treat each published vulnerability, side channel, or algorithmic attack as a "widget": a building block with a specific capability and a specific cost. By sequencing widgets from different layers—an OOB write to redirect a function call, a supply-chain package to create a covert timing channel, a rowhammer bit flip to corrupt a MoE router—the attacker can satisfy the preconditions of each step using a weaker overall threat model than any isolated attack requires. The paper supports this by cataloging software CVEs and hardware side-channel and fault attacks, aligning them with MITRE ATT&CK, and describing four existing cross-layer attack case studies plus qualitative emerging attack chains on compound AI systems.

Load-bearing premise

The load-bearing premise is that the attacks from different layers can actually be stitched into the described end-to-end chains on a real compound AI system without the steps interfering with each other or being detected.

Editorial extensions

If this is right

  • Security evaluations of compound AI systems should treat attacks as composable paths across application, software, and hardware layers, not as isolated algorithmic threats.
  • The MITRE ATT&CK mapping gives system designers a common language to position attack steps by threat model, asset, and impact, and to select layer-appropriate defenses.
  • Cross-layer composition can lower the bar for existing attacks: a hardware side channel can turn a black-box model-extraction attempt into a white-box one, and an SQL injection can remove the need for direct write access to a RAG knowledge database.
  • Defenses must be holistic: software supply-chain and memory-safety controls, hardware TEE and link-encryption and reliable-storage templates, and cross-layer information-flow control, rather than single-layer fixes.
  • Critical targets in compound AI—knowledge databases, grounding blocks, MoE router bits, and the LLM agent—should receive prioritized protection.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If widget sequencing is as general as the paper argues, a practical next step is to build a public benchmark of compound AI attack chains, measuring success rates and interference between steps; that would test the composability assumption directly.
  • The same mapping could be turned into a red-team playbook: enterprise security teams could deliberately chain known CVEs and side channels against their own RAG and agent deployments before adversaries do.
  • The paper's call for severity scoring suggests that isolated-attack severity scores should be reweighted by how well an attack serves as reconnaissance or initial access for another layer, which current scoring does not capture.
  • Extending the argument, reusable attack chains may become packaged "exploit kits" for standardized compound AI stacks; the paper's framework could help anticipate which components those kits would target.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. This SoK paper categorizes security threats to compound AI systems across application, software, and hardware layers. It compiles software CVEs for frameworks/packages/libraries, surveys hardware attacks on memory/interconnect/compute, maps attacks onto the MITRE ATT&CK framework, and identifies four existing and four emerging cross-layer attack chains. The central thesis, stated in the abstract and reiterated in Section 7.1, is that individual attack 'widgets' can be sequenced into powerful end-to-end attacks against compound AI systems while reducing or minimizing threat-model assumptions. The paper also surveys defenses and lists open research challenges for holistic secure-by-design compound AI platforms.

Significance. If the central composition claim were established, the paper would broaden security evaluation for compound AI from isolated algorithmic attacks to composable cross-layer system attacks. The paper's organizational value is real: it brings together a wide range of software CVEs and hardware attacks, defines a clear asset/threat-model/trust-entity taxonomy, and attempts a MITRE-style mapping for AI-specific attacks. It does not provide machine-checked proofs, reproducible code, or experimental demonstrations; its value is primarily taxonomic and hypothesis-generating. The strongest contributions are the layered model in Figure 2/3 and the assembled catalogues in Tables 1 and 2. The weakest point is that the central 'minimal threat model assumptions' claim rests entirely on qualitative chains in Section 6.2, none of which is demonstrated or analyzed for composability, so the paper currently reads as a promising framework rather than a validated systematization of cross-layer attacks.

major comments (4)
  1. [Abstract, §6.2, §7.1 Takeaway 1] The central claim that attack widgets 'can be sequenced to launch an end-to-end attack on a compound AI system with minimal threat model assumptions' is not supported by the evidence in the paper. Section 6.2 explicitly labels the new cross-layer attacks as qualitative, and the described chains require heterogeneous capabilities at different trust boundaries. For example, 'Generation accuracy degradation' requires (i) a memory-safety vulnerability or boot attack to learn the physical address of the MoE router multiplexer, (ii) installation of a malicious grounding block, and (iii) a Rowhammer attack during live inference. These are not minimal assumptions; they are the union of a memory-corruption exploit, a software supply-chain or privileged-software compromise, and physical or near-physical fault injection. The paper does not demonstrate any single end-to-end chain, nor does it argue why the stages compose without interference or detection. This load-bearing premise needs either a concrete demonstration, an explicit composability analysis, or a reframing of the contribution as an open hypothesis with the actual capability requirements stated.
  2. [§4.1, Table 1] The CVE corpus in Table 1 is not validated systematically and contains internal inconsistencies. CVE-2024-42479 is listed for both 'LLama-OOB Write' and 'LLama-Heap Ovf.', and CVE-2023-31035 appears three times under different categories (vGPU OOB Write, Firmware Config Error, and vGPU OOB Write again). The text does not describe the CVE search protocol, inclusion criteria, or how each CVE was mapped to a specific attack category and threat model. Since the software vulnerability taxonomy is a core contribution of the SoK, these entries need to be audited, deduplicated, and accompanied by a transparent methodology; otherwise the table cannot serve as a reliable reference.
  3. [§6.1.1] The claimed benefit of cross-layer composition is confused in the model-extraction example. The text says that hardware attacks 'transform weaker threat model assumptions of algorithmic attacks into a more realistic threat model,' but the example starts with cold-boot attacks (physical access) or Deepsniffer-style digital side-channel monitoring, which are stronger capabilities than the remote query access already assumed by black-box model extraction. If the intended point is that side-channel information supplies the white-box knowledge that the algorithmic attack would otherwise lack, the paper should state this directly. As written, the direction of threat-model relaxation is reversed, which undermines the argument that cross-layer sequencing reduces assumptions.
  4. [§5.1, Table 2] The hardware attack catalogue is presented as a systematization, but the selection criteria are not stated and several entries are asserted rather than demonstrated in a compound AI context. For instance, Table 2 lists 'Sesame [11]' as a compute attack, yet the cited work is a design proposal for secure multi-tenant inference accelerators rather than a demonstrated attack on a deployed compound AI system. Similarly, the 'emerging cross-layer attacks' in Section 6.2 rely on capabilities such as inserting a hardware Trojan into an FPGA accelerator or modifying function-call addresses via an OOB write, with no evidence that these stages can be achieved by the same adversary under a single threat model. The paper should either provide systematic inclusion criteria for Table 2 or explicitly mark which entries are demonstrated attacks and which are hypothetical or extrapolated.
minor comments (7)
  1. [Figure 4 caption] The caption says 'Three attack cases' while Section 6.1 presents four cases; the caption or the enumeration should be corrected.
  2. [§3.1] There is a grammatical slip: 'as as techniques' should read 'as techniques'.
  3. [§4.2] The phrase 'address-space-linear randomization' should be 'address space layout randomization (ASLR)'.
  4. [Table 1 legend] The black/white square legend is ambiguous in grayscale printing; distinct symbols or textual labels should be used.
  5. [Throughout] The citation to MITRE appears variously as 'M itre', 'Mitre', and 'MITRE'; please standardize to 'MITRE ATT&CK' with a single canonical reference.
  6. [§5.1] The text mentions 'Rowpress [117]' in the memory attacks discussion, but Table 2 lists only Rowhammer-class bitflip attacks; either add Rowpress to the table or align the narrative with the table.
  7. [§3.2] The four threat models are presented as an ordered severity ladder, but 'Privileged software access' and 'Digital hardware access' can overlap (e.g., a hypervisor admin with access to performance counters); a sentence clarifying the intended disjointness or overlap would help.

Circularity Check

0 steps flagged · score 2.0 of 10

No load-bearing circularity: self-citations are illustrative only, and the MITRE mapping and cross-layer cases rest mainly on external CVEs and third-party attacks.

full rationale

This paper is a systematization rather than a formal derivation, so the usual circularity patterns (fitted input called prediction, uniqueness theorem imported from authors, ansatz smuggled via citation, equation-level self-definition) do not apply. The central claim that attack widgets can be sequenced into end-to-end attacks is supported by the four Section 6.1 cases, which combine external CVEs (e.g., Langchain CVE-2023-36189, vGPU CVE-2023-31035) and third-party research (DeepSniffer, Deephammer, Cache Telepathy, Rowhammer, Rambleed) with a small number of same-author results. ConfusedPilot is used as one component in case 6.1.4 ('After tampering the database, the ConfusedPilot algorithmic attack can be deployed'), but the cross-layer step that removes the database-admin assumption is supplied by an external SQL-injection CVE, not by ConfusedPilot itself. Similarly, Sesame, Triton, Obsidian, and the bandwidth side-channel are cited as examples in surveys of existing attacks and defenses; no load-bearing inference depends on accepting these same-author works as proof. The Section 6.2 'emerging' chains are explicitly qualitative discussions, not demonstrated end-to-end attacks; that is an evidentiary weakness about composability and feasibility, not circularity, because the paper does not define the claimed attack outcomes in terms of its own inputs or fitted parameters. The MITRE mapping and the proposed cross-layer arrangements are independent content. The score of 2 reflects the unusually high number of same-author citations in the paper while noting that none of them is load-bearing in a circular sense.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The paper relies on domain assumptions about the suitability of MITRE ATT&CK for AI attacks, the completeness of the threat model tiers, and the accuracy of the cited CVE entries. It does not introduce free parameters or invented entities.

assumptions (4)
  • domain assumption MITRE ATT&CK is a suitable framework for categorizing AI system attacks.
    The paper maps attacks to MITRE ATT&CK (Section 3.1) without justifying why this framework is appropriate for novel AI-specific attacks.
  • domain assumption The threat model categories (remote software, privileged software, digital hardware, physical hardware) cover the relevant adversaries.
    Section 3.2 defines these categories but does not provide evidence that they are exhaustive or that attacks fit cleanly into them.
  • domain assumption CVE entries selected in Table 1 are accurate and applicable to compound AI systems.
    The paper references CVEs but does not describe a systematic selection process or verify their exploitability in AI pipelines; some entries appear to duplicate CVE numbers.
  • domain assumption Prior attacks cited in Tables 1 and 2 are valid and generalizable to compound AI deployments.
    The paper relies on the correctness and applicability of numerous prior attack papers, many of which are not originally demonstrated on compound AI pipelines.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: A Systems Perspective on Compound AI Threats and Countermeasures." pith.science (2026). https://pith.science/paper/EEFAHCPI

@misc{pith2026241113459,
  author       = {Pith},
  title        = {Pith review of: SoK: A Systems Perspective on Compound AI Threats and Countermeasures},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/EEFAHCPI}},
  note         = {Machine review of arXiv:2411.13459}
}
read the original abstract

Large language models (LLMs) used across enterprises often use proprietary models and operate on sensitive inputs and data. The wide range of attack vectors identified in prior research - targeting various software and hardware components used in training and inference - makes it extremely challenging to enforce confidentiality and integrity policies. As we advance towards constructing compound AI inference pipelines that integrate multiple large language models (LLMs), the attack surfaces expand significantly. Attackers now focus on the AI algorithms as well as the software and hardware components associated with these systems. While current research often examines these elements in isolation, we find that combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model. Given, the sheer number of existing attacks at each layer, we need a holistic and systemized understanding of different attack vectors at each layer. This SoK discusses different software and hardware attacks applicable to compound AI systems and demonstrates how combining multiple attack mechanisms can reduce the threat model assumptions required for an isolated attack. Next, we systematize the ML attacks in lines with the Mitre Att&ck framework to better position each attack based on the threat model. Finally, we outline the existing countermeasures for both software and hardware layers and discuss the necessity of a comprehensive defense strategy to enable the secure and high-performance deployment of compound AI systems.

Figures

Figures reproduced from arXiv: 2411.13459 by the authors.

Figure 1
Figure 1. Application, software and hardware layers for compound AI. Example shows cross-layer components can be exploited to leak data. but many focus individually on algorithms or platforms, ignoring the complex interactions in modern AI systems. A recent study [16] also highlighted that privacy-preserving models can leak data when deployed alongside other soft￾ware components, challenging existing security guarantees. Emer… view at source ↗
Figure 2
Figure 2. A Compound AI Pipeline begins with Query pre-processing to refine the input query and feed to an LLM agent. The agent extracts knowledge in the Retrieval stage, generates a draft response, and fills information generated from MoE experts in the Generation step. This response goes through compliance and fact checks Query post-processing step to finally generate a multi-modal output. digital and physical side-channel … view at source ↗
Figure 3
Figure 3. Positioning each attack widget in the Mitre Attack framework. The different colors specify the attacker capability ranging from remote access (weakest adversary) to physical access (strongest adversary). The attack steps through different steps. The impact denotes the security policy violation [C = Confidentiality, I = Integrity, A = Availability] facts may be retrieved using a Retrieval Augmented Gener￾ator (RAG) [… view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: Three attack cases which leverages cross-stack vulnerabilities to mount powerful attacks. We map different attack techniques to the MITRE framework. hardware vulnerabilities to achieve higher efficacy. Many system attacks, especially those targeting hardware physical a…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

183 extracted references · 74 canonical work pages

  1. [11]

    SESAME: Software defined Enclaves to Secure Inference Accelerators with Multi-tenant Execution

    S. Banerjee, P. Ramrakhyani, S. Wei, and M. Tiwari, “Sesame: Software defined enclaves to secure inference accelerators with multi-tenant execution,” arXiv preprint arXiv:2007.06751 , 2020

  2. [1]

    Chatgpt

    ChatGPT, “Chatgpt.” https://chatgpt.com/

  3. [2]

    Gemini, “Gemini.” https://gemini.google.com/app

  4. [3]

    Copilot

    Copilot, “Copilot.” https://copilot.microsoft.com/

  5. [4]

    Autopilot and full self-driving (supervised) — tesla support

    Tesla, “Autopilot and full self-driving (supervised) — tesla support.” https://www.tesla.com/support/autopilot

  6. [5]

    Ocr software, data extraction tool - amazon textract - aws

    Textract, “Ocr software, data extraction tool - amazon textract - aws.” https://aws.amazon.com/textract/

  7. [6]

    Membership inference attacks against machine learning models,

    R. Shokri, M. Stronati, C. Song, and V . Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP) , pp. 3–18, IEEE, 2017

  8. [7]

    Stealing machine learning models via prediction {APIs},

    F. Tram `er, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction {APIs},” in 25th USENIX security symposium (USENIX Security 16) , pp. 601–618, 2016

Show all 183 references
  1. [8]

    Model recon- struction from model explanations,

    S. Milli, L. Schmidt, A. D. Dragan, and M. Hardt, “Model recon- struction from model explanations,” in Proceedings of the Confer- ence on Fairness, Accountability, and Transparency , pp. 1–9, 2019

  2. [9]

    A comprehensive survey on poisoning attacks and countermeasures in machine learning,

    Z. Tian, L. Cui, J. Liang, and S. Yu, “A comprehensive survey on poisoning attacks and countermeasures in machine learning,” ACM Computing Surveys, vol. 55, no. 8, pp. 1–35, 2022

  3. [10]

    Dnn model theft through trojan side-channel on edge fpga accelerator,

    S. Chandrasekar, S.-K. Lam, and S. Thambipillai, “Dnn model theft through trojan side-channel on edge fpga accelerator,” in Interna- tional Symposium on Applied Reconfigurable Computing , pp. 146– 158, Springer, 2023

  4. [12]

    Triton: Software-defined threat model for secure multi-tenant ml inference accelerators,

    S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Triton: Software-defined threat model for secure multi-tenant ml inference accelerators,” in Proceedings of the 12th International Workshop on Hardware and Architectural Support for Security and Privacy , pp. 19–28, 2023

  5. [13]

    Prada: protecting against dnn model stealing attacks,

    M. Juuti, S. Szyller, S. Marchal, and N. Asokan, “Prada: protecting against dnn model stealing attacks,” in 2019 IEEE European Sym- posium on Security and Privacy (EuroS&P) , pp. 512–527, IEEE, 2019

  6. [14]

    Machine un- learning,

    L. Bourtoule, V . Chandrasekaran, C. A. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot, “Machine un- learning,” in 2021 IEEE Symposium on Security and Privacy (SP) , pp. 141–159, IEEE, 2021

  7. [15]

    Strong data augmenta- tion sanitizes poisoning and backdoor attacks without an accuracy tradeoff,

    E. Borgnia, V . Cherepanova, L. Fowl, A. Ghiasi, J. Geiping, M. Goldblum, T. Goldstein, and A. Gupta, “Strong data augmenta- tion sanitizes poisoning and backdoor attacks without an accuracy tradeoff,” in ICASSP 2021-2021 IEEE International Conference on Acoustics, Speech and ...

  8. [16]

    Privacy side channels in machine learning systems,

    E. Debenedetti, G. Severi, N. Carlini, C. A. Choquette-Choo, M. Jagielski, M. Nasr, E. Wallace, and F. Tram `er, “Privacy side channels in machine learning systems,” in 33rd USENIX Security Symposium (USENIX Security 24) , pp. 6861–6848, 2024

  9. [17]

    The shift from models to compound ai systems

    M. Zaharia, O. Khattab, L. Chen, J. Q. Davis, H. Miller, C. Potts, J. Zou, M. Carbin, J. Frankle, N. Rao, and A. Ghodsi, “The shift from models to compound ai systems.” https://bair.berkeley.edu/bl og/2024/02/18/compound-ai-systems/, 2024

  10. [18]

    Langchain framework

    Langchain, “Langchain framework.” https://www.langchain.com/

  11. [19]

    Pytorch

    pyTorch, “Pytorch.” https://pytorch.org/

  12. [20]

    Cuda® deep neural network library

    Nvidia, “Cuda® deep neural network library.” https://developer.nv idia.com/cudnn

  13. [21]

    Rowhammer: A retrospective,

    O. Mutlu and J. S. Kim, “Rowhammer: A retrospective,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 8, pp. 1555–1571, 2019

  14. [22]

    Sok: Memorization in general-purpose large language models,

    V . Hartmann, A. Suri, V . Bindschaedler, D. Evans, S. Tople, and R. West, “Sok: Memorization in general-purpose large language models,” arXiv preprint arXiv:2310.18362 , 2023

  15. [23]

    Sok: Security and privacy in machine learning,

    N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, “Sok: Security and privacy in machine learning,” in 2018 IEEE European symposium on security and privacy (EuroS&P) , pp. 399–414, IEEE, 2018

  16. [24]

    Sok: Membership inference is harder than previously thought,

    A. Dionysiou and E. Athanasopoulos, “Sok: Membership inference is harder than previously thought,” Proceedings on Privacy Enhanc- ing Technologies, 2023

  17. [25]

    Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap,

    S. V . Dibbo, “Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap,” in 2023 IEEE 36th Computer Security Foundations Symposium (CSF) , pp. 439–456, IEEE, 2023

  18. [26]

    Mitre attack framework

    Mitre, “Mitre attack framework.” https://attack.mitre.org/

  19. [27]

    In-datacenter performance analysis of a tensor processing unit,

    N. P. Jouppi, C. Young, N. Patil, D. Patterson, G. Agrawal, R. Bajwa, S. Bates, S. Bhatia, N. Boden, A. Borchers, et al. , “In-datacenter performance analysis of a tensor processing unit,” in Proceedings of the 44th annual international symposium on computer architecture , pp....

  20. [28]

    Github copilot

    Github, “Github copilot.” https://github.com/features/copilot

  21. [29]

    Amazon q developer

    Amazon, “Amazon q developer.” https://aws.amazon.com/q/develop er/

  22. [30]

    Mistral ai

    Mistral, “Mistral ai.” https://mistral.ai/news/mixtral-of-experts/

  23. [31]

    Clip-decoder: Zeroshot multilabel classifica- tion using multimodal clip aligned representations,

    M. Ali and S. Khan, “Clip-decoder: Zeroshot multilabel classifica- tion using multimodal clip aligned representations,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , pp. 4675–4679, 2023

  24. [32]

    Mitre att&ck: Design and philosophy,

    B. E. Strom, A. Applebaum, D. P. Miller, K. C. Nickels, A. G. Pen- nington, and C. B. Thomas, “Mitre att&ck: Design and philosophy,” in Technical report, The MITRE Corporation, 2018

  25. [33]

    Ev- erywhere all at once: Co-location attacks on public cloud faas,

    Z. N. Zhao, A. Morrison, C. W. Fletcher, and J. Torrellas, “Ev- erywhere all at once: Co-location attacks on public cloud faas,” in Proceedings of the 29th ACM International Conference on Architec- tural Support for Programming Languages and Operating Systems, Volume 1, ASPLOS...

  26. [34]

    Theory and practice of finding eviction sets,

    P. Vila, B. K ¨opf, and J. F. Morales, “Theory and practice of finding eviction sets,” in 2019 IEEE Symposium on Security and Privacy (SP), pp. 39–54, IEEE, 2019

  27. [35]

    Flush+ reload: A high resolution, low noise, l3 cache side-channel attack,

    Y . Yarom and K. Falkner, “Flush+ reload: A high resolution, low noise, l3 cache side-channel attack,” in 23rd USENIX security sym- posium (USENIX security 14) , pp. 719–732, 2014

  28. [36]

    Cache missing for fun and profit,

    C. Percival, “Cache missing for fun and profit,” 2005

  29. [37]

    Confusedpilot: Confused deputy risks in rag-based llms,

    A. RoyChowdhury, M. Luo, P. Sahu, S. Banerjee, and M. Tiwari, “Confusedpilot: Confused deputy risks in rag-based llms,” 2024

  30. [39]

    Cache telepathy: Lever- aging shared resource attacks to learn dnn architectures,

    M. Yan, C. W. Fletcher, and J. Torrellas, “Cache telepathy: Lever- aging shared resource attacks to learn dnn architectures,” in 29th USENIX Security Symposium (USENIX Security 20), pp. 2003–2020, 2020

  31. [40]

    Hugging face

    Huggingface, “Hugging face.” https://huggingface.co/

  32. [41]

    Google tensorflow

    Google, “Google tensorflow.” https://www.tensorflow.org/

  33. [42]

    Apache spark

    Apache, “Apache spark.” https://spark.apache.org/

  34. [43]

    Apache hadoop

    Apache, “Apache hadoop.” https://hadoop.apache.org/

  35. [44]

    Snowflake

    Snowflake, “Snowflake.” https://www.snowflake.com/en/

  36. [45]

    Bentoml

    BentoML, “Bentoml.” https://www.bentoml.com/

  37. [46]

    Kubernetes

    Kubernetes, “Kubernetes.” https://kubernetes.io/

  38. [47]

    Pyyaml package

    Pyyaml, “Pyyaml package.” https://pypi.org/project/PyYAML/

  39. [48]

    Cve-2023-31035

    Mitre, “Cve-2023-31035.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2023-31035, 2023

  40. [49]

    Cve-2024-3095

    Mitre, “Cve-2024-3095.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-3095, 2024

  41. [50]

    Formal verification methods,

    O. Hasan and S. Tahar, “Formal verification methods,” in Encyclope- dia of Information Science and Technology, Third Edition, pp. 7162– 7170, IGI global, 2015

  42. [51]

    Hfl: Hybrid fuzzing on the linux kernel.,

    K. Kim, D. R. Jeong, C. H. Kim, Y . Jang, I. Shin, and B. Lee, “Hfl: Hybrid fuzzing on the linux kernel.,” in NDSS, 2020

  43. [52]

    Sok: A defense- oriented evaluation of software supply chain security,

    E. Abu Ishgair, M. S. Melara, and S. Torres-Arias, “Sok: A defense- oriented evaluation of software supply chain security,” arXiv e- prints, pp. arXiv–2405, 2024

  44. [53]

    Sok: Taxonomy of attacks on open-source software supply chains,

    P. Ladisa, H. Plate, M. Martinez, and O. Barais, “Sok: Taxonomy of attacks on open-source software supply chains,” in 2023 IEEE Symposium on Security and Privacy (SP) , pp. 1509–1526, IEEE, 2023

  45. [54]

    Practical automated detection of ma- licious npm packages,

    A. Sejfia and M. Sch ¨afer, “Practical automated detection of ma- licious npm packages,” in Proceedings of the 44th International Conference on Software Engineering , pp. 1681–1692, 2022

  46. [55]

    Immutability and encapsulation for sound oo information flow control,

    T. Runge, M. Servetto, A. Potanin, and I. Schaefer, “Immutability and encapsulation for sound oo information flow control,” ACM Transactions on Programming Languages and Systems , vol. 45, no. 1, pp. 1–35, 2023

  47. [56]

    Raksha: a flexible information flow architecture for software security,

    M. Dalton, H. Kannan, and C. Kozyrakis, “Raksha: a flexible information flow architecture for software security,” ACM SIGARCH Computer Architecture News, vol. 35, no. 2, pp. 482–493, 2007

  48. [57]

    Mod- ular information flow through ownership,

    W. Crichton, M. Patrignani, M. Agrawala, and P. Hanrahan, “Mod- ular information flow through ownership,” in Proceedings of the 43rd ACM SIGPLAN International Conference on Programming Language Design and Implementation , pp. 1–14, 2022

  49. [58]

    Rethinking privacy in machine learning pipelines from an information flow control perspective,

    L. Wutschitz, B. K ¨opf, A. Paverd, S. Rajmohan, A. Salem, S. Tople, S. Zanella-B ´eguelin, M. Xia, and V . R ¨uhle, “Rethinking privacy in machine learning pipelines from an information flow control perspective,” 2023

  50. [59]

    Rust ai engine

    “Rust ai engine.” https://rust-ml.github.io/book/

  51. [60]

    Rusty linux: Advances in rust for linux kernel development,

    S. K. Panter and N. U. Eisty, “Rusty linux: Advances in rust for linux kernel development,” arXiv preprint arXiv:2407.18431 , 2024

  52. [61]

    Erim: Secure, efficient in-process isolation with memory protection keys,

    A. Vahldiek-Oberwagner, E. Elnikety, N. O. Duarte, M. Samm- ler, P. Druschel, and D. Garg, “Erim: Secure, efficient in-process isolation with memory protection keys,” in 28th USENIX Security Symposium, 2019

  53. [62]

    Securecells: A secure compartmentalized architecture,

    A. Bhattacharyya, F. Hofhammer, Y . Li, S. Gupta, A. Sanchez, B. Falsafi, and M. Payer, “Securecells: A secure compartmentalized architecture,” in 2023 IEEE Symposium on Security and Privacy (SP), 2023

  54. [63]

    Retrofitting fine grain isola- tion in the firefox renderer,

    S. Narayan, C. Disselkoen, T. Garfinkel, N. Froyd, E. Rahm, S. Lerner, H. Shacham, and D. Stefan, “Retrofitting fine grain isola- tion in the firefox renderer,” in 29th USENIX Security Symposium , 2020

  55. [64]

    Going beyond the limits of sfi: Flexible and secure hardware-assisted in-process isolation with hfi,

    S. Narayan, T. Garfinkel, M. Taram, J. Rudek, D. Moghimi, E. John- son, C. Fallin, A. Vahldiek-Oberwagner, M. LeMay, R. Sahita, D. Tullsen, , and D. Stefan, “Going beyond the limits of sfi: Flexible and secure hardware-assisted in-process isolation with hfi,” in Proceedings of...

  56. [65]

    Cheri: A hybrid capability-system architecture for scalable software compart- mentalization,

    R. N. Watson, J. Woodruff, P. G. Neumann, S. W. Moore, J. An- derson, D. Chisnall, N. Dave, B. Davis, K. Gudka, B. Laurie, S. J. Murdoch, R. Norton, M. Roe, S. Son, and M. Vadera, “Cheri: A hybrid capability-system architecture for scalable software compart- mentalization,” in...

  57. [66]

    Morpheus: A vulnerability-tolerant secure architecture based on ensembles of moving target defenses with churn,

    M. Gallagher, L. Biernacki, S. Chen, Z. B. Aweke, S. F. Yitbarek, M. T. Aga, A. Harris, Z. Xu, B. Kasikci, V . Bertacco, S. Malik, M. Tiwari, and T. Austin, “Morpheus: A vulnerability-tolerant secure architecture based on ensembles of moving target defenses with churn,” in Pro...

  58. [67]

    Boosting microservice resilience: An evaluation of istio’s impact on kubernetes clusters under chaos,

    S. Singh, C. H. Muntean, and S. Gupta, “Boosting microservice resilience: An evaluation of istio’s impact on kubernetes clusters under chaos,” in 2024 9th International Conference on Fog and Mobile Edge Computing (FMEC) , pp. 245–252, IEEE, 2024

  59. [68]

    Rethinking system audit architectures for high event coverage and synchronous log availability,

    V . Gandhi, S. Banerjee, A. Agrawal, A. Ahmad, S. Lee, and M. Peinado, “Rethinking system audit architectures for high event coverage and synchronous log availability,” in 32nd USENIX Secu- rity Symposium (USENIX Security 23) , pp. 391–408, 2023

  60. [69]

    Nvidia bluefield dpu

    Nvidia, “Nvidia bluefield dpu.” https://www.nvidia.com/en-us/netw orking/products/data-processing-unit/

  61. [70]

    Practical cold boot attack on iot device-case study on raspberry pi,

    Y .-S. Won, J.-Y . Park, D.-G. Han, and S. Bhasin, “Practical cold boot attack on iot device-case study on raspberry pi,” in 2020 IEEE International Symposium on the Physical and Failure Analysis of Integrated Circuits (IPFA), pp. 1–4, IEEE, 2020

  62. [71]

    Warm-boot attack on modern drams,

    Y . Jiang, S. Wang, R. Figueiredo, and Y . Jin, “Warm-boot attack on modern drams,” in 2023 Design, Automation & Test in Europe Conference & Exhibition (DATE) , pp. 1–2, IEEE, 2023

  63. [72]

    Drama: Exploiting dram addressing for cross-cpu attacks,

    P. Pessl, D. Gruss, C. Maurice, M. Schwarz, and S. Mangard, “Drama: Exploiting dram addressing for cross-cpu attacks,” in 25th USENIX security symposium (USENIX security 16) , pp. 565–581, 2016

  64. [73]

    Dramaqueen: Revisiting side channels in dram,

    V . van der Veen and B. Gras, “Dramaqueen: Revisiting side channels in dram,” 2023

  65. [74]

    Nvleak:off-chip side-channel attacks via non-volatile mem- ory systems,

    Z. Wang, M. Taram, D. Moghimi, S. Swanson, D. Tullsen, and J. Zhao, “Nvleak:off-chip side-channel attacks via non-volatile mem- ory systems,” in 32nd USENIX Security Symposium (USENIX Secu- rity 23), pp. 6771–6788, 2023

  66. [75]

    Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips,

    F. Yao, A. S. Rakin, and D. Fan, “Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips,” in 29th USENIX Security Symposium (USENIX Security 20) , pp. 1463–1480, 2020

  67. [76]

    Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection,

    S. Li, X. Wang, M. Xue, H. Zhu, Z. Zhang, Y . Gao, W. Wu, and X. S. Shen, “Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection,” in Proceedings of the 33th USENIX Security Symposium , 2024

  68. [77]

    Bit-flip attack: Crushing neural net- work with progressive bit search,

    A. S. Rakin, Z. He, and D. Fan, “Bit-flip attack: Crushing neural net- work with progressive bit search,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 1211–1220, 2019

  69. [78]

    Rambleed: Reading bits in memory without accessing them,

    A. Kwong, D. Genkin, D. Gruss, and Y . Yarom, “Rambleed: Reading bits in memory without accessing them,” in 2020 IEEE Symposium on Security and Privacy (SP) , pp. 695–711, IEEE, 2020

  70. [79]

    Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,

    A. S. Rakin, M. H. I. Chowdhuryy, F. Yao, and D. Fan, “Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,” in 2022 IEEE symposium on security and privacy (SP) , pp. 1157–1174, IEEE, 2022

  71. [80]

    Side- channel attack analysis on in-memory computing architectures,

    Z. Wang, F.-h. Meng, Y . Park, J. K. Eshraghian, and W. D. Lu, “Side- channel attack analysis on in-memory computing architectures,” IEEE Transactions on Emerging Topics in Computing, vol. 12, no. 1, pp. 109–121, 2023

  72. [81]

    Powergan: A machine learning approach for power side-channel attack on compute-in-memory accelerators,

    Z. Wang, Y . Wu, Y . Park, S. Yoo, X. Wang, J. K. Eshraghian, and W. D. Lu, “Powergan: A machine learning approach for power side-channel attack on compute-in-memory accelerators,” Advanced Intelligent Systems, vol. 5, no. 12, p. 2300313, 2023

  73. [82]

    Amplifying main memory-based timing covert and side channels using processing-in-memory operations,

    K. Kanellopoulos, F. Bostanci, A. Olgun, A. G. Yaglikci, I. E. Yuksel, N. M. Ghiasi, Z. Bingol, M. Sadrosadati, and O. Mutlu, “Amplifying main memory-based timing covert and side channels using processing-in-memory operations,” arXiv preprint arXiv:2404.11284, 2024

  74. [84]

    Understanding error propagation in deep learning neural network (dnn) accelerators and applications,

    G. Li, S. K. S. Hari, M. Sullivan, T. Tsai, K. Pattabiraman, J. Emer, and S. W. Keckler, “Understanding error propagation in deep learning neural network (dnn) accelerators and applications,” in Proceedings of the International Conference for High Performance Computing, Networ...

  75. [85]

    Fault injection for tensorflow applications,

    N. Narayanan, Z. Chen, B. Fang, G. Li, K. Pattabiraman, and N. Debardeleben, “Fault injection for tensorflow applications,” IEEE Transactions on Dependable and Secure Computing , vol. 20, no. 4, pp. 2677–2695, 2022

  76. [86]

    pcileech

    ufrisk, “pcileech.” https://github.com/ufrisk/pcileech, 2017

  77. [87]

    Thunderclap: Exploring vulnerabilities in operating system iommu protection via dma from untrustworthy peripherals,

    A. T. Markettos, C. Rothwell, B. F. Gutstein, A. Pearce, P. G. Neumann, S. W. Moore, and R. N. M. Watson, “Thunderclap: Exploring vulnerabilities in operating system iommu protection via dma from untrustworthy peripherals,” in Proceedings 2019 Network and Distributed System Se...

  78. [88]

    New security challenges on machine learning inference engine: Chip cloning and model reverse engineering,

    S. Huang, X. Peng, H. Jiang, Y . Luo, and S. Yu, “New security challenges on machine learning inference engine: Chip cloning and model reverse engineering,” arXiv preprint arXiv:2003.09739, 2020

  79. [89]

    Reverse engineering convo- lutional neural networks through side-channel information leaks,

    W. Hua, Z. Zhang, and G. E. Suh, “Reverse engineering convo- lutional neural networks through side-channel information leaks,” in Proceedings of the 55th Annual Design Automation Conference , pp. 1–6, 2018

  80. [90]

    Bandwidth utilization side-channel on ml inference accelerators,

    S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Bandwidth utilization side-channel on ml inference accelerators,” arXiv preprint arXiv:2110.07157, 2021

  81. [91]

    Chen, “Hmtt.” https://asg.ict.ac.cn/hmtt/, 2019

    M. Chen, “Hmtt.” https://asg.ict.ac.cn/hmtt/, 2019

  82. [92]

    Hermes attack: Steal dnn models with lossless inference accuracy,

    Y . Zhu, Y . Cheng, H. Zhou, and Y . Lu, “Hermes attack: Steal dnn models with lossless inference accuracy,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021

  83. [93]

    Deepsniffer: A dnn model extraction framework based on learning architectural hints,

    X. Hu, L. Liang, S. Li, L. Deng, P. Zuo, Y . Ji, X. Xie, Y . Ding, C. Liu, T. Sherwood, et al. , “Deepsniffer: A dnn model extraction framework based on learning architectural hints,” in Proceedings of the Twenty-Fifth International Conference on Architectural Support for Prog...

  84. [94]

    Rendered insecure: Gpu side channel attacks are practical,

    H. Naghibijouybari, A. Neupane, Z. Qian, and N. Abu-Ghazaleh, “Rendered insecure: Gpu side channel attacks are practical,” in Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp. 2139–2153, 2018

  85. [95]

    Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel,

    J. Wei, Y . Zhang, Z. Zhou, Z. Li, and M. A. Al Faruque, “Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel,” in 2020 50th Annual IEEE/IFIP International Con- ference on Dependable Systems and Networks (DSN) , pp. 125–137, IEEE, 2020

  86. [96]

    Huffduff: Stealing pruned dnns from sparse accelerators,

    D. Yang, P. J. Nair, and M. Lis, “Huffduff: Stealing pruned dnns from sparse accelerators,” in Proceedings of the 28th ACM In- ternational Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2 , pp. 385–399, 2023

  87. [97]

    Sparsity turns adver- sarial: Energy and latency attacks on deep neural networks,

    S. Krithivasan, S. Sen, and A. Raghunathan, “Sparsity turns adver- sarial: Energy and latency attacks on deep neural networks,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 11, pp. 4129–4141, 2020

  88. [98]

    Beyond the bridge: Contention-based covert and side channel attacks on multi-gpu interconnect,

    Y . Zhang, R. Nazaraliyev, S. B. Dutta, N. Abu-Ghazaleh, A. Mar- quez, and K. Barker, “Beyond the bridge: Contention-based covert and side channel attacks on multi-gpu interconnect,” arXiv preprint arXiv:2404.03877, 2024

  89. [99]

    Invisible probe: Timing attacks with pcie congestion side-channel,

    M. Tan, J. Wan, Z. Zhou, and Z. Li, “Invisible probe: Timing attacks with pcie congestion side-channel,” in 2021 IEEE Symposium on Security and Privacy (SP) , pp. 322–338, IEEE, 2021

  90. [100]

    Steal- ing neural networks via timing side channels,

    V . Duddu, D. Samanta, D. V . Rao, and V . E. Balas, “Steal- ing neural networks via timing side channels,” arXiv preprint arXiv:1812.11720, 2018

  91. [101]

    Layer sequence extraction of optimized dnns using side-channel information leaks,

    Y . Sun, G. Jiang, X. Liu, P. He, and S.-K. Lam, “Layer sequence extraction of optimized dnns using side-channel information leaks,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024

  92. [102]

    Practical attacks on deep neural networks by memory trojaning,

    X. Hu, Y . Zhao, L. Deng, L. Liang, P. Zuo, J. Ye, Y . Lin, and Y . Xie, “Practical attacks on deep neural networks by memory trojaning,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 40, no. 6, pp. 1230–1243, 2020

  93. [103]

    Remote power attacks on the versatile tensor accelerator in multi-tenant fpgas,

    S. Tian, S. Moini, A. Wolnikowski, D. Holcomb, R. Tessier, and J. Szefer, “Remote power attacks on the versatile tensor accelerator in multi-tenant fpgas,” in 2021 IEEE 29th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM), pp. 242–246, IEEE, 2021

  94. [104]

    V oltage noise-based adversarial attacks on machine learning inference in multi-tenant fpga accelera- tors,

    S. Majumdar and R. Teodorescu, “V oltage noise-based adversarial attacks on machine learning inference in multi-tenant fpga accelera- tors,” in 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 80–85, IEEE, 2024

  95. [105]

    Mind control attack: Undermining deep learning with gpu memory exploitation,

    S.-O. Park, O. Kwon, Y . Kim, S. K. Cha, and H. Yoon, “Mind control attack: Undermining deep learning with gpu memory exploitation,” Computers & Security , vol. 102, p. 102115, 2021

  96. [106]

    Security analysis of deep neural networks operating in the presence of cache side-channel attacks,

    S. Hong, M. Davinroy, Y . Kaya, S. N. Locke, I. Rackow, K. Kulda, D. Dachman-Soled, and T. Dumitras ¸, “Security analysis of deep neural networks operating in the presence of cache side-channel attacks,” arXiv preprint arXiv:1810.03487 , 2018

  97. [107]

    Ganred: Gan-based reverse engineer- ing of dnns via cache side-channel,

    Y . Liu and A. Srivastava, “Ganred: Gan-based reverse engineer- ing of dnns via cache side-channel,” in Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop , pp. 41–52, 2020

  98. [108]

    Spy in the gpu-box: Covert and side channel attacks on multi-gpu systems,

    S. B. Dutta, H. Naghibijouybari, A. Gupta, N. Abu-Ghazaleh, A. Marquez, and K. Barker, “Spy in the gpu-box: Covert and side channel attacks on multi-gpu systems,” in Proceedings of the 50th Annual International Symposium on Computer Architecture , pp. 1– 13, 2023

  99. [109]

    Csinn: Reverse engi- neering of neural network architectures through electromagnetic side channel,

    L. Batina, S. Bhasin, D. Jap, and S. Picek, “Csinn: Reverse engi- neering of neural network architectures through electromagnetic side channel,” in 28th USENIX Security Symposium (USENIX Security 19), pp. 515–532, 2019

  100. [110]

    Simple electro- magnetic analysis against activation functions of deep neural net- works,

    G. Takatoi, T. Sugawara, K. Sakiyama, and Y . Li, “Simple electro- magnetic analysis against activation functions of deep neural net- works,” in Applied Cryptography and Network Security Workshops: ACNS 2020 Satellite Workshops, AIBlock, AIHWS, AIoTS, Cloud S&P , SCI, SecMT, a...

  101. [111]

    Barracuda: Bringing electromagnetic side channel into play to steal the weights of neural networks from nvidia gpus,

    P. Horvath, L. Chmielewski, L. Weissbart, L. Batina, and Y . Yarom, “Barracuda: Bringing electromagnetic side channel into play to steal the weights of neural networks from nvidia gpus,” arXiv preprint arXiv:2312.07783, 2023

  102. [112]

    Floating-point multiplication timing attack on deep neural network,

    G. Dong, P. Wang, P. Chen, R. Gu, and H. Hu, “Floating-point multiplication timing attack on deep neural network,” in 2019 IEEE International Conference on Smart Internet of Things (SmartIoT) , pp. 155–161, IEEE, 2019

  103. [113]

    Int-monitor: a model triggered hardware trojan in deep learning accelerators,

    P. Li and R. Hou, “Int-monitor: a model triggered hardware trojan in deep learning accelerators,” The Journal of Supercomputing, vol. 79, no. 3, pp. 3095–3111, 2023

  104. [114]

    Open dnn box by power side- channel attack,

    Y . Xiang, Z. Chen, Z. Chen, Z. Fang, H. Hao, J. Chen, Y . Liu, Z. Wu, Q. Xuan, and X. Yang, “Open dnn box by power side- channel attack,” IEEE Transactions on Circuits and Systems II: Express Briefs, vol. 67, no. 11, pp. 2717–2721, 2020

  105. [115]

    Physical side-channel attacks on embedded neural networks: A survey,

    M. M ´endez Real and R. Salvador, “Physical side-channel attacks on embedded neural networks: A survey,” Applied Sciences , vol. 11, no. 15, p. 6790, 2021

  106. [116]

    Fault injection attack on deep neural network,

    Y . Liu, L. Wei, B. Luo, and Q. Xu, “Fault injection attack on deep neural network,” in 2017 IEEE/ACM International Conference on Computer-Aided Design (ICCAD) , pp. 131–138, IEEE, 2017

  107. [117]

    Rowpress: Amplifying read disturbance in modern dram chips,

    H. Luo, A. Olgun, A. G. Ya ˘glıkc ¸ı, Y . C. Tu˘grul, S. Rhyner, M. B. Cavlak, J. Lindegger, M. Sadrosadati, and O. Mutlu, “Rowpress: Amplifying read disturbance in modern dram chips,” in Proceedings of the 50th Annual International Symposium on Computer Architec- ture, pp. 1–18, 2023

  108. [118]

    Aqua: Scalable rowhammer mitigation by quarantining aggressor rows at runtime,

    A. Saxena, G. Saileshwar, P. J. Nair, and M. Qureshi, “Aqua: Scalable rowhammer mitigation by quarantining aggressor rows at runtime,” in 2022 55th IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 108–123, IEEE, 2022

  109. [119]

    Intel trust domain extensions

    TDX, “Intel trust domain extensions.” https://www.intel.com/conten t/www/us/en/developer/tools/trust-domain-extensions/overview.htm l, 2021

  110. [120]

    Amd secure encrypted virtualizations

    AMD-SEV , “Amd secure encrypted virtualizations.” https://www. amd.com/en/developer/sev.html, 2018

  111. [121]

    Data integrity checking for iscsi with dm-verity,

    R. Zhou, Z. Ai, J. Hu, Q. Liu, Q. Zhou, X. Wang, H. Jiang, and K.-C. Li, “Data integrity checking for iscsi with dm-verity,” in Advanced Technologies, Embedded and Multimedia for Human-centric Com- puting: HumanCom and EMC 2013 , pp. 691–697, Springer, 2014

  112. [122]

    Intel sgx explained,

    V . Costan, “Intel sgx explained,” IACR Cryptol, EPrint Arch , 2016

  113. [123]

    Memory encryption for general-purpose processors,

    S. Gueron, “Memory encryption for general-purpose processors,” IEEE Security & Privacy , vol. 14, no. 6, pp. 54–62, 2016

  114. [124]

    Morphable counters: Enabling compact integrity trees for low-overhead secure memories,

    G. Saileshwar, P. J. Nair, P. Ramrakhyani, W. Elsasser, J. A. Joao, and M. K. Qureshi, “Morphable counters: Enabling compact integrity trees for low-overhead secure memories,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 416–427, IEEE, 2018

  115. [125]

    Mgx: Near-zero overhead memory protection for data-intensive accelerators,

    W. Hua, M. Umar, Z. Zhang, and G. E. Suh, “Mgx: Near-zero overhead memory protection for data-intensive accelerators,” in Pro- ceedings of the 49th Annual International Symposium on Computer Architecture, pp. 726–741, 2022

  116. [126]

    Aegis: Mitigating targeted bit-flip attacks against deep neural networks,

    J. Wang, Z. Zhang, M. Wang, H. Qiu, T. Zhang, Q. Li, Z. Li, T. Wei, and C. Zhang, “Aegis: Mitigating targeted bit-flip attacks against deep neural networks,” in 32nd USENIX Security Symposium (USENIX Security 23) , pp. 2329–2346, 2023

  117. [127]

    Hydra: En- abling low-overhead mitigation of row-hammer at ultra-low thresh- olds via hybrid tracking,

    M. Qureshi, A. Rohan, G. Saileshwar, and P. J. Nair, “Hydra: En- abling low-overhead mitigation of row-hammer at ultra-low thresh- olds via hybrid tracking,” in Proceedings of the 49th Annual Inter- national Symposium on Computer Architecture , pp. 699–710, 2022

  118. [128]

    Scalable and secure row- swap: Efficient and safe row hammer mitigation in memory sys- tems,

    J. Woo, G. Saileshwar, and P. J. Nair, “Scalable and secure row- swap: Efficient and safe row hammer mitigation in memory sys- tems,” in 2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA), pp. 374–389, IEEE, 2023

  119. [129]

    Timing channel protection for a shared memory controller,

    Y . Wang, A. Ferraiuolo, and G. E. Suh, “Timing channel protection for a shared memory controller,” in 2014 IEEE 20th International Symposium on High Performance Computer Architecture (HPCA) , pp. 225–236, IEEE, 2014

  120. [130]

    Lattice priority scheduling: Low-overhead timing-channel protec- tion for a shared memory controller,

    A. Ferraiuolo, Y . Wang, D. Zhang, A. C. Myers, and G. E. Suh, “Lattice priority scheduling: Low-overhead timing-channel protec- tion for a shared memory controller,” in 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA) , pp. 382–393, IEEE, 2016

  121. [131]

    Secndp: Secure near-data processing with untrusted memory,

    W. Xiong, L. Ke, D. Jankov, M. Kounavis, X. Wang, E. Northup, J. A. Yang, B. Acun, C.-J. Wu, P. T. P. Tang,et al., “Secndp: Secure near-data processing with untrusted memory,” in 2022 IEEE Inter- national Symposium on High-Performance Computer Architecture (HPCA), pp. 244–258,...

  122. [132]

    Avoiding information leakage in the memory controller with fixed service policies,

    A. Shafiee, A. Gundu, M. Shevgoor, R. Balasubramonian, and M. Tiwari, “Avoiding information leakage in the memory controller with fixed service policies,” in Proceedings of the 48th International Symposium on Microarchitecture, pp. 89–101, 2015

  123. [133]

    Power side-channel attacks and countermeasures on computation-in-memory architectures and technologies,

    B. Sapui, J. Krautter, M. Mayahinia, A. Jafari, D. Gnad, S. Meschkov, and M. B. Tahoori, “Power side-channel attacks and countermeasures on computation-in-memory architectures and technologies,” in 2023 IEEE European Test Symposium (ETS), pp. 1– 6, IEEE, 2023

  124. [134]

    {RL-Watchdog}: A fast and predictable {SSD} liveness watchdog on storage systems,

    J. Y . Ha, S. Lee, H. Y . Yeom, and Y . Son, “ {RL-Watchdog}: A fast and predictable {SSD} liveness watchdog on storage systems,” in 2024 USENIX Annual Technical Conference (USENIX ATC 24) , pp. 1083–1100, 2024

  125. [135]

    Security of nvme offloaded data in large-scale machine learning,

    T. Krauß, R. G ¨otz, and A. Dmitrienko, “Security of nvme offloaded data in large-scale machine learning,” in European Symposium on Research in Computer Security , pp. 143–163, Springer, 2023

  126. [136]

    Onion oram: A constant bandwidth blowup oblivious ram,

    S. Devadas, M. van Dijk, C. W. Fletcher, L. Ren, E. Shi, and D. Wichs, “Onion oram: A constant bandwidth blowup oblivious ram,” in Theory of Cryptography: 13th International Conference, TCC 2016-A, Tel Aviv, Israel, January 10-13, 2016, Proceedings, Part II 13, pp. 145–174, Sp...

  127. [137]

    Guardnn: secure accelerator architecture for privacy-preserving deep learning,

    W. Hua, M. Umar, Z. Zhang, and G. E. Suh, “Guardnn: secure accelerator architecture for privacy-preserving deep learning,” in Proceedings of the 59th ACM/IEEE Design Automation Conference , pp. 349–354, 2022

  128. [138]

    Intel iommu

    IOMMU, “Intel iommu.” https://www.intel.com/content/dam/develo p/external/us/en/documents/intel-whitepaper-using-iommu-for-dma -protection-in-uefi-820238.pdf, 2014

  129. [139]

    {sRDMA}– efficient {NIC-based} authentication and encryption for remote di- rect memory access,

    K. Taranov, B. Rothenberger, A. Perrig, and T. Hoefler, “{sRDMA}– efficient {NIC-based} authentication and encryption for remote di- rect memory access,” in 2020 USENIX Annual Technical Conference (USENIX ATC 20) , pp. 691–704, 2020

  130. [140]

    Nvidia trusted computing solutions

    T. Computing, “Nvidia trusted computing solutions.” https://docs.n vidia.com/nvtrust/index.html, 2021

  131. [141]

    Arm trustzone

    ARM, “Arm trustzone.” https://www.arm.com/technologies/trustzo ne-for-cortex-a, 2014

  132. [142]

    Structured sparsity in the nvidia ampere architecture

    Nvidia, “Structured sparsity in the nvidia ampere architecture.” https: //developer.nvidia.com/blog/structured-sparsity-in-the-nvidia-amper e-architecture-and-applications-in-search-engines/, 2023

  133. [143]

    Camouflage: Mem- ory traffic shaping to mitigate timing attacks,

    Y . Zhou, S. Wagh, P. Mittal, and D. Wentzlaff, “Camouflage: Mem- ory traffic shaping to mitigate timing attacks,” in 2017 IEEE Inter- national Symposium on High Performance Computer Architecture (HPCA), pp. 337–348, IEEE, 2017

  134. [144]

    Dagguise: mitigating memory timing side channels,

    P. W. Deutsch, Y . Yang, T. Bourgeat, J. Drean, J. S. Emer, and M. Yan, “Dagguise: mitigating memory timing side channels,” in Proceedings of the 27th ACM International Conference on Architec- tural Support for Programming Languages and Operating Systems , pp. 329–343, 2022

  135. [145]

    Obsidian: Cooperative state-space exploration for performant inference on secure ml accelerators,

    S. Banerjee, S. Wei, P. Ramrakhyani, and M. Tiwari, “Obsidian: Cooperative state-space exploration for performant inference on secure ml accelerators,” arXiv preprint arXiv:2409.02817 , 2024

  136. [146]

    Halak, Hardware supply chain security: Threat modelling, emerg- ing attacks and countermeasures

    B. Halak, Hardware supply chain security: Threat modelling, emerg- ing attacks and countermeasures . Springer Nature, 2021

  137. [147]

    {ScatterCache}: thwarting cache attacks via cache set randomization,

    M. Werner, T. Unterluggauer, L. Giner, M. Schwarz, D. Gruss, and S. Mangard, “ {ScatterCache}: thwarting cache attacks via cache set randomization,” in 28th USENIX Security Symposium (USENIX Security 19), pp. 675–692, 2019

  138. [148]

    Phantomcache: Obfuscating cache conflicts with localized randomization.,

    Q. Tan, Z. Zeng, K. Bu, and K. Ren, “Phantomcache: Obfuscating cache conflicts with localized randomization.,” in NDSS, 2020

  139. [149]

    New attacks and defense for encrypted-address cache,

    M. K. Qureshi, “New attacks and defense for encrypted-address cache,” in Proceedings of the 46th International Symposium on Computer Architecture, pp. 360–371, 2019

  140. [150]

    Dawg: A defense against cache timing attacks in speculative exe- cution processors,

    V . Kiriansky, I. Lebedev, S. Amarasinghe, S. Devadas, and J. Emer, “Dawg: A defense against cache timing attacks in speculative exe- cution processors,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO) , pp. 974–987, IEEE, 2018

  141. [151]

    Composable cachelets: Protecting enclaves from cache side-channel attacks,

    D. Townley, K. Arıkan, Y . D. Liu, D. Ponomarev, and O. Ergin, “Composable cachelets: Protecting enclaves from cache side-channel attacks,” in 31st USENIX Security Symposium (USENIX Security 22), pp. 2839–2856, 2022

  142. [152]

    Vantage: Scalable and efficient fine-grain cache partitioning,

    D. Sanchez and C. Kozyrakis, “Vantage: Scalable and efficient fine-grain cache partitioning,” in Proceedings of the 38th annual international symposium on Computer architecture, pp. 57–68, 2011

  143. [153]

    Maskednet: The first hardware inference engine aiming power side-channel protection,

    A. Dubey, R. Cammarota, and A. Aysu, “Maskednet: The first hardware inference engine aiming power side-channel protection,” in 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 197–208, IEEE, 2020

  144. [154]

    Bomanet: Boolean masking of an entire neural network,

    A. Dubey, R. Cammarota, and A. Aysu, “Bomanet: Boolean masking of an entire neural network,” inProceedings of the 39th International Conference on Computer-Aided Design , pp. 1–9, 2020

  145. [155]

    A quantitative defense framework against power attacks on multi-tenant fpga,

    Y . Luo and X. Xu, “A quantitative defense framework against power attacks on multi-tenant fpga,” in Proceedings of the 39th international conference on computer-aided design , pp. 1–9, 2020

  146. [156]

    Jamming and eavesdropping defense scheme based on deep reinforcement learning in autonomous vehicle networks,

    Y . Yao, J. Zhao, Z. Li, X. Cheng, and L. Wu, “Jamming and eavesdropping defense scheme based on deep reinforcement learning in autonomous vehicle networks,”IEEE Transactions on Information Forensics and Security, vol. 18, pp. 1211–1224, 2023

  147. [157]

    Deepem: Deep neural networks model recovery through em side-channel information leak- age,

    H. Yu, H. Ma, K. Yang, Y . Zhao, and Y . Jin, “Deepem: Deep neural networks model recovery through em side-channel information leak- age,” in 2020 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) , pp. 209–218, IEEE, 2020

  148. [158]

    Eliminating fine grained timers in xen,

    B. C. Vattikonda, S. Das, and H. Shacham, “Eliminating fine grained timers in xen,” in Proceedings of the 3rd ACM workshop on Cloud computing security workshop , pp. 41–46, 2011

  149. [159]

    Timewarp: Rethink- ing timekeeping and performance monitoring mechanisms to mit- igate side-channel attacks,

    R. Martin, J. Demme, and S. Sethumadhavan, “Timewarp: Rethink- ing timekeeping and performance monitoring mechanisms to mit- igate side-channel attacks,” ACM SIGARCH computer architecture news, vol. 40, no. 3, pp. 118–129, 2012

  150. [160]

    Iodine: Verifying constant-time execution of hardware,

    K. v. Gleissenthall, R. G. Kıcı, D. Stefan, and R. Jhala, “Iodine: Verifying constant-time execution of hardware,” in 28th USENIX Security Symposium (USENIX Security 19) , pp. 1411–1428, 2019

  151. [161]

    Small-footprint alu for public-key processors for per- vasive security,

    K. Sakiyama, L. Batina, N. Mentens, B. Preneel, and I. Ver- bauwhede, “Small-footprint alu for public-key processors for per- vasive security,” in Workshop on RFID Security , vol. 12, 2006

  152. [162]

    Aegis: Architecture for tamper-evident and tamper-resistant pro- cessing,

    G. E. Suh, D. Clarke, B. Gassend, M. Van Dijk, and S. Devadas, “Aegis: Architecture for tamper-evident and tamper-resistant pro- cessing,” in ACM International Conference on Supercomputing 25th Anniversary Volume, pp. 357–368, 2003

  153. [163]

    Data operand independent timing isa guidance

    “Data operand independent timing isa guidance.” https://www.intel. com/content/www/us/en/developer/articles/technical/software-secur ity-guidance/best-practices/data-operand-independent-timing-isa-g uidance.html

  154. [164]

    Arm architecture registers for future architecture technologies

    “Arm architecture registers for future architecture technologies.” ht tps://developer.arm.com/documentation/ddi0601/2020-12/AArch6 4-Registers/DIT--Data-Independent-Timing

  155. [165]

    Teesec: Pre-silicon vulnerability discovery for trusted execution environments,

    M. Ghaniyoun, K. Barber, Y . Xiao, Y . Zhang, and R. Teodorescu, “Teesec: Pre-silicon vulnerability discovery for trusted execution environments,” in Proceedings of the 50th Annual International Symposium on Computer Architecture , pp. 1–15, 2023

  156. [166]

    Zipchannel: Cache side-channel vulner- abilities in compression algorithms,

    M. Minkin and B. Kasikci, “Zipchannel: Cache side-channel vulner- abilities in compression algorithms,” in2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 223–237, IEEE, 2024

  157. [167]

    Secureloop: Design space exploration of secure dnn accelerators,

    K. Lee, M. Yan, J. Emer, and A. Chandrakasan, “Secureloop: Design space exploration of secure dnn accelerators,” in Proceedings of the 56th Annual IEEE/ACM International Symposium on Microarchitec- ture, pp. 194–208, 2023

  158. [168]

    Confidential computing deployment guide

    C. Computing, “Confidential computing deployment guide.” https: //docs.nvidia.com/cc-deployment-guide-tdx.pdf, 2024

  159. [169]

    Proflip: Targeted trojan attack with progressive bit flips,

    H. Chen, C. Fu, J. Zhao, and F. Koushanfar, “Proflip: Targeted trojan attack with progressive bit flips,” in Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 7718–7727, 2021

  160. [170]

    Tbt: Targeted neural network attack with bit trojan,

    A. S. Rakin, Z. He, and D. Fan, “Tbt: Targeted neural network attack with bit trojan,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , pp. 13198–13207, 2020

  161. [171]

    Cve-2023-36189

    Mitre, “Cve-2023-36189.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2023-36189, 2023

  162. [172]

    Timing black-box attacks: Crafting adversarial examples through timing leaks against dnns on embedded devices,

    T. Nakai, D. Suzuki, and T. Fujino, “Timing black-box attacks: Crafting adversarial examples through timing leaks against dnns on embedded devices,” IACR Transactions on Cryptographic Hardware and Embedded Systems , pp. 149–175, 2021

  163. [173]

    Cve-2024-7297

    Mitre, “Cve-2024-7297.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-7297, 2024

  164. [174]

    Cve-2024-28224

    Mitre, “Cve-2024-28224.” https://cve.mitre.org/cgi-bin/cvename.cgi ?name=CVE-2024-28224, 2024

  165. [175]

    Understanding contention-based channels and using them for defense,

    C. Hunger, M. Kazdagli, A. Rawat, A. Dimakis, S. Vishwanath, and M. Tiwari, “Understanding contention-based channels and using them for defense,” in 2015 IEEE 21st International Symposium on High Performance Computer Architecture (HPCA) , pp. 639–650, IEEE, 2015

  166. [176]

    Casa: End-to-end quantitative security analysis of randomly mapped caches,

    T. Bourgeat, J. Drean, Y . Yang, L. Tsai, J. Emer, and M. Yan, “Casa: End-to-end quantitative security analysis of randomly mapped caches,” in 2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), pp. 1110–1123, IEEE, 2020

  167. [177]

    Cwe - cwe/capec wgs & sigs

    “Cwe - cwe/capec wgs & sigs.” https://cwe.mitre.org/community/ working groups.html#ai wg

  168. [178]

    Differential privacy,

    C. Dwork, “Differential privacy,” in International colloquium on automata, languages, and programming , pp. 1–12, Springer, 2006

  169. [179]

    Have it your way: Individualized privacy assignment for dp-sgd,

    F. Boenisch, C. M ¨uhl, A. Dziedzic, R. Rinberg, and N. Papernot, “Have it your way: Individualized privacy assignment for dp-sgd,” Advances in Neural Information Processing Systems , vol. 36, 2024

  170. [180]

    Information flow control in machine learning through modular model architecture,

    T. Tiwari, S. Gururangan, C. Guo, W. Hua, S. Kariyappa, U. Gupta, W. Xiong, K. Maeng, H.-H. S. Lee, and G. E. Suh, “Information flow control in machine learning through modular model architecture,” in 33rd USENIX Security Symposium (USENIX Security 24), pp. 6921– 6938, 2024

  171. [181]

    Hyperflow: A processor architecture for nonmalleable, timing-safe information flow security,

    A. Ferraiuolo, M. Zhao, A. C. Myers, and G. E. Suh, “Hyperflow: A processor architecture for nonmalleable, timing-safe information flow security,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , pp. 1583–1600, 2018

  172. [182]

    Crafting a usable microkernel, processor, and i/o system with strict and provable information flow security,

    M. Tiwari, J. K. Oberg, X. Li, J. Valamehr, T. Levin, B. Hardekopf, R. Kastner, F. T. Chong, and T. Sherwood, “Crafting a usable microkernel, processor, and i/o system with strict and provable information flow security,” ACM SIGARCH Computer Architecture News, vol. 39, no. 3, ...

  173. [183]

    In- tegration verification across software and hardware for a simple embedded system,

    A. Erbsen, S. Gruetter, J. Choi, C. Wood, and A. Chlipala, “In- tegration verification across software and hardware for a simple embedded system,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation, pp. 604–619, 2021

  174. [184]

    Private cloud compute: A new frontier for ai privacy in the cloud

    Apple, “Private cloud compute: A new frontier for ai privacy in the cloud.” https://security.apple.com/blog/private-cloud-compute/

  175. [185]

    The confidential genai service

    Edgeless, “The confidential genai service.” https://www.edgeless.s ystems/products/continuum

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.