REVIEW 5 major objections 5 minor 112 references
When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer Mitigations
T0 review · 5 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read PRAC's RowHammer mitigation creates a timing channel that leaks AES key bits.
desk verdict Solid new timing-channel finding on PRAC's ABO/RFM, but the defense's headline 3.4% overhead is tied to an NBO inconsistent with the attack demo and possibly unsafe at NRH=1024. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is the Alert Back-Off (ABO) protocol: each DRAM row has an activation counter, and when the counter reaches the back-off threshold $N_{BO}$, the DRAM asserts an Alert, prompting the memory controller to issue an RFM All Bank (RFMab) command that stalls the entire channel for 350 ns. This converts per-row activation counts into globally observable latency. The attack part of the paper is carried by the activation-count-based side channel: shared-row activation counts are probed by counting how many attacker activations are needed to complete an ABO. The defense part is carried by TPRAC's Timing-Based RFM (TB-RFM), issued on a fixed timer independent of memory activity, together with a single-entry frequency-based mitigation queue per bank that identifies the most-activated row to refresh during each TB-RFM.
What would settle it
Run a real PRAC-enabled DDR5 module with one core repeatedly activating a row to the back-off threshold while another core measures memory latency on the same channel; if no reproducible system-wide latency spike appears, or the spike's timing is not tied to the activation count, the proposed channel is not exploitable as described. The paper's evidence is simulation-only on this point.
Extended reading notes
Core claim
The central discovery is that the Alert Back-Off (ABO) protocol and Refresh Management (RFM) commands in PRAC turn a security mechanism into an information channel. Each ABO event produces an RFM All Bank (RFMab) command that blocks all requests to the DRAM channel for $t_{RFMab}=350$ ns, and the number of activations needed to reach the back-off threshold $N_{BO}$ is exactly controllable. In an activation-count-based channel, a sender and receiver sharing one physical DRAM row encode a value by leaving $k$ activations in the row counter; the receiver activates the same row and observes after $N_{BO}-k$ activations when the ABO latency spike fires, recovering the sender's value $k$. Because $k$ can range up to $N_{BO}$, each transmission carries several bits. The same mechanism leaks a victim's row-activation pattern: in a chosen-plaintext AES T-table implementation, the DRAM row corresponding to the secret-dependent T-table entry gets the most activations, and the row that first triggers an ABO during probing reveals the top four bits of each key byte, 64 of 128 bits total. The paper's defense, TPRAC, issues Timing-Based RFMs at fixed intervals and mitigates the most-activated row per bank from a single-entry queue, so no row can reach $N_{BO}$ and no attacker-triggerable ABO latency exists.
Load-bearing premise
The attack and the defense both assume that every RFM All Bank command produces a fixed, system-wide 350 nanosecond stall that any process can measure; if real memory controllers hide, localize, or randomize that delay, the channel weakens or disappears.
Editorial extensions
If this is right
- Any PRAC-style mitigation that issues activation-dependent RFMs, whether Alert Back-Off or activation-based proactive RFMs, carries a timing channel because the latency depends on row access counts.
- A user-level attacker sharing a DRAM module with a vulnerable T-table AES victim can recover 64 of 128 key bits in fewer than 200 encryptions; constant-time AES or other table-free implementations avoid this specific leak.
- TPRAC closes the channel without changing DRAM chips or the JEDEC interface: one register stores the RFM interval and one mitigation-queue entry per bank is enough.
- At a RowHammer threshold of 1024, TPRAC's average performance cost is 3.4%, and co-design with targeted refreshes can reduce or eliminate that cost.
- At lower RowHammer thresholds the required TB-RFM frequency grows, with slowdown rising from 6.5% at a threshold of 512 to 22.6% at 128, so very-low-threshold systems face a performance-security trade-off.
Reading between the lines
- The leak is a general instance of security metadata creating a timing channel: any future DRAM feature that counts per-row activity and signals the controller with a fixed, globally visible stall will likely suffer a similar channel.
- If real controllers implement TB-RFM with timing jitter or hide the 350 ns stall by overlapping it with other work, the residual leakage would be far smaller than the simulated worst case; measuring the real latency distribution on PRAC hardware would calibrate the required interval.
- The AES attack's structure, making one secret-dependent row the most-activated and then probing which row trips the counter, should generalize to other table-driven cryptographic implementations with attacker-controllable inputs and shared rows.
- A testable extension is an adaptive TB-RFM interval that responds to observed activation rates; the paper analyzes fixed intervals, and an adaptive schedule could lower the performance cost at small RowHammer thresholds.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper studies timing channels introduced by the JEDEC PRAC RowHammer mitigation framework. It proposes PRACLeak, a set of covert- and side-channel attacks that exploit the Alert Back-Off (ABO) protocol and the Refresh Management (RFM) commands: when a row's activation counter reaches the back-off threshold NBO, the DRAM asserts Alert and the memory controller issues RFMab commands that block the channel for about 350 ns, creating a system-visible latency spike. The paper demonstrates activity-based and activation-count-based covert channels in simulation, and an AES T-table side channel that recovers 4 bits of each key byte (50% of a 128-bit key) in fewer than 200 encryptions. To close the channel, the paper proposes Timing-Safe PRAC (TPRAC), which replaces activity-dependent ABO/ACB RFMs with periodic, activity-independent Timing-Based RFMs (TB-RFMs) configured so that no row reaches NBO under the Feinting/Wave worst-case attack. TPRAC is evaluated in ChampSim-Ramulator2 simulations and reported to close the channel with an average 3.4% performance overhead at an RH threshold of 1024, using a single-entry per-bank mitigation queue.
Significance. If the central claims hold, this is a timely and important result: PRAC is the industry's standard direction for DDR5 RowHammer mitigation, and the observation that its mitigation machinery itself creates a precise, cross-process timing channel is novel and security-relevant. The paper also ships a substantial artifact: the Ramulator2 modifications, trace generators, ChampSim-Ramulator2 integration, and plotting scripts are all archived, which strengthens reproducibility. The proposed TPRAC defense is standards-compatible, does not require DRAM modifications, and the idea of decoupling RFM issuance from activation counts is a clean conceptual fix. The performance evaluation covers 50 workloads, multiple NRH values, PRAC levels, targeted refresh co-design, and counter-reset policies, and the reported energy and storage overheads are explicitly quantified.
major comments (5)
- [Section 6.2 vs. Section 3.3 and Table 2] The headline overhead claim is disconnected from the demonstrated attack configuration. The AES side channel in Section 3.3 is explicitly demonstrated with NBO=256 (Figure 4 and the accompanying text), and the covert-channel evaluation in Table 2 spans NBO=256 to 1024. The TPRAC performance evaluation in Section 6.2, however, claims that at NRH=1024, issuing one TB-RFM every 1.6 tREFI suffices, which corresponds to NBO=1024 in Figure 7 (TMAX≈900 < NBO). Under the paper's own Equation (1) and Figure 7, NBO=256 requires a TB-Window near 0.25 tREFI, and Figure 13 reports a 14.1% slowdown at NRH=256. Thus the 3.4% figure does not apply to the configuration in which the key-leak channel is actually demonstrated. The paper should either demonstrate the side channel at NBO=1024 or report the defense overhead at NBO=256 as the cost of closing the demonstrated channel.
- [Section 4.2.2, Eq. (1), and Table 1] The security condition TACT < NBO ignores the ABOACT slack in the paper's own PRAC model. Table 1 states that after a row crosses NBO, the DRAM permits up to ABOACT=3 additional activations before the RFM is issued. If NBO is set equal to NRH (as the evaluation appears to do, since TPRAC's overhead is reported 'at the RH threshold of 1024' with NBO=1024), a baseline PRAC system without TPRAC would allow a row to reach NBO+ABOACT=1027 activations before mitigation, exceeding NRH. The paper should either justify that NBO is always chosen at least ABOACT below NRH in all experiments, or explain explicitly why the ABOACT slack does not affect the claimed RH efficacy of the evaluated configuration.
- [Section 3.1 and Section 5] The attack's central premise that every RFMab produces a deterministic, system-wide 350 ns stall observable to all cores is not validated on any real memory controller or DRAM implementation. All PRACLeak and TPRAC results are produced with Ramulator2/ChampSim using JEDEC-derived timing parameters; real controllers may buffer or coalesce requests, hide RFM latency under queued traffic, or implement the ABO protocol differently from the UPRAC/QPRAC model used here. The paper should either provide a real-system validation of the global 350 ns observability assumption or add a sensitivity analysis (e.g., to scheduling policy, request queue depth, and RFM-to-request overlap) and temper the abstract's 'demonstrate' wording to reflect simulation-only evidence.
- [Section 4.2 and Section 5] The mechanism by which TPRAC eliminates Activation-Based RFMs (ACB-RFMs) is not specified. Section 4.2 states that the goal is to eliminate ABO-RFMs 'and consequently' ACB-RFMs, but the design description in Section 4 only disables RFM postponing and introduces TB-RFMs; it does not state that ACB-RFMs are disabled or that the Bank Activation Threshold is set to infinity. Since any remaining ACB-RFM is itself activity-dependent and exploitable as a timing channel (as the paper argues in Section 2.6 and Figure 2(b)), the paper must state explicitly how TPRAC prevents ACB-RFMs in the evaluated configuration.
- [Section 4.2.3] The claim that a single-entry, frequency-based mitigation queue achieves security equivalent to the idealized UPRAC design is supported only by three informal scenarios and one illustrative example, not by a proof or a formal invariant. Given that the TB-Window calculation in Section 4.2 is the security foundation for TPRAC, the paper should either provide a rigorous argument that the single-entry queue always mitigates the row that would otherwise reach NBO first, or state the exact replacement rule and timing model and prove that TMAX remains below NBO under that rule.
minor comments (5)
- [Section 6.6] The sentence 'TPRAC without counter reset incurs a 73.9% slowdown, compared to 77.4% with reset, resulting in a 3.4% performance improvement' appears to have the two conditions reversed. Since counter resets reduce TMAX in Figure 7 and should allow a longer TB-Window, the text should be checked for consistency with Figure 14.
- [Table 4] The workload categorization table lists several benchmark names twice within the same category (e.g., 470.lbm, 483.xalancbmk, 471.omnetpp, 456.hmmer, 464.h264ref, 481.wrf); please deduplicate the list.
- [Section 3.1 and Table 1] The paper uses both 'tRFM' and 'tRFMab' for the RFM-all-bank blocking duration; please use one consistent symbol throughout, and state whether the 350 ns value is tRFMab or tRFM.
- [Abstract and Section 3.3] The abstract says the AES key is leaked in 'fewer than 200 encryptions,' while Figure 5 is described as running '200 encryptions.' Please clarify whether the attack succeeds before or after 200 encryptions and make the wording uniform.
- [Section 4.2.2, Eq. (3)] Equation (3) uses Ri without defining how the row-pool size evolves after each round, and the floor-bracket notation is not typeset clearly. Please define Ri for each round and rewrite the equation with standard floor notation.
Circularity Check
No significant circularity; attack bitrates are formula-derived and TPRAC's TB-Window is set by an external worst-case analysis, with only non-load-bearing self-citation.
full rationale
The paper's central claims are self-contained. PRACLeak is demonstrated in Ramulator2 using the external UPRAC implementation, and its bitrates follow directly from the transmission-period formulas (NBO*tRC + tRFM for activity-based, ~2*NBO*tRC + tRFM for activation-count-based), so no fitted parameter is relabeled as a prediction. TPRAC's TB-Window is set by the worst-case Feinting analysis (Eqs. 1-5) whose worst-case premise is cited to external prior work (ProTRR [61], Wave [111]); the condition TACT < NBO is a design constraint from the PRAC/JEDEC model, not a fit to the paper's own performance results. The 3.4% overhead at NRH=1024 is a ChampSim+Ramulator2 simulation output, and the Figure 9 security validation is a direct consequence of eliminating ABO-RFMs rather than a circular reinport of the attack. The only self-citations (QPRAC [102] used as the underlying/baseline PRAC implementation, and an RFMpb footnote) are compatibility and baseline references; they do not carry the timing-channel argument, which rests on JEDEC behavior and external UPRAC/ProTRR work. The reviewer's NBO-256 attack vs. NRH-1024 defense concern is a parameter-consistency/correctness issue, not a circular reduction, since the security condition is expressed in terms of NBO and Figure 7 provides the TMAX curve for any NBO.
Assumptions & free parameters
free parameters (2)
- TB-Window =
1.6 tREFI (6.2 us) at NRH=1024; 0.25 to 4 tREFI across sensitivity
- Bank Activation Threshold (BAT) =
Configured per NRH for the insecure ABO+ACB-RFM baseline
assumptions (4)
- domain assumption PRAC's per-row counters, Alert Back-Off protocol, and RFMab commands behave as modeled: a row crossing NBO triggers an Alert, and each RFMab blocks all memory requests on the channel for 350 ns.
- domain assumption The Feinting (Wave) attack is the worst-case activation pattern for RFM-based mitigations and bounds the target-row activations in TPRAC.
- domain assumption Attacker and victim can share a single physical DRAM row, because the row is larger than the page or because address mapping stripes pages across banks, for the activation-count channel and the AES side channel.
- domain assumption The ChampSim and Ramulator2 simulation models a 4-core out-of-order processor and DDR5-8000B timing faithfully.
Cite this review
Pith. "Pith review of When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer Mitigations." pith.science (2026). https://pith.science/paper/ACVACV53
@misc{pith2026250510111,
author = {Pith},
title = {Pith review of: When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer Mitigations},
year = {2026},
howpublished = {\url{https://pith.science/paper/ACVACV53}},
note = {Machine review of arXiv:2505.10111}
}
read the original abstract
Per Row Activation Counting (PRAC) has emerged as a robust framework for mitigating RowHammer (RH) vulnerabilities in modern DRAM systems. However, we uncover a critical vulnerability: a timing channel introduced by the Alert Back-Off (ABO) protocol and Refresh Management (RFM) commands. We present PRACLeak, a novel attack that exploits these timing differences to leak sensitive information, such as secret keys from vulnerable AES implementations, by monitoring memory access latencies. To counter this, we propose Timing-Safe PRAC (TPRAC), a defense that eliminates PRAC-induced timing channels without compromising RH mitigation efficacy. TPRAC uses Timing-Based RFMs, issued periodically and independent of memory activity. It requires only a single-entry in-DRAM mitigation queue per DRAM bank and is compatible with existing DRAM standards. Our evaluations demonstrate that TPRAC closes timing channels while incurring only 3.4% performance overhead at the RH threshold of 1024.
Figures
Figures from the paper (9 more)
Reference graph
Works this paper leans on
-
[1]
[n. d.]. UBC Advanced Research Computing, "UBC ARC Sockeye. " UBC Ad- vanced Research Computing, 2019, doi: 10.14288/SOCKEYE. ([n. d.])
doi:10.14288/sockeye 2019
-
[2]
Ali Asgari Khoshouyeh, Florian Geissler, Syed Qutub, Michael Paulitsch, Prashant Nair, and Karthik Pattabiraman. 2023. Structural Coding: A Low- Cost Scheme to Protect CNNs from Large-Granularity Memory Faults. In Proceedings of the International Conference for High Performance Comput- ing, Networking, Storage and Analysis (Denver, CO, USA) (SC ’23) . Ass...
arXiv 2023
-
[3]
Bernstein
Daniel J. Bernstein. 2005. Cache-timing attacks on AES . Technical Report
2005
-
[5]
Joseph Bonneau and Ilya Mironov. 2006. Cache-collision timing attacks against AES. In CHES
2006
-
[7]
Kunbei Cai, Md Hafizul Islam Chowdhuryy, Zhenkai Zhang, and Fan Yao
-
[8]
Oğuzhan Canpolat, A Giray Yağlıkçı, Geraldo F Oliveira, Ataberk Olgun, Oğuz Ergin, and Onur Mutlu. 2024. Understanding the Security Benefits and Over- heads of Emerging Industry Solutions to DRAM Read Disturbance. InWorkshop on DRAM Security (DRAMSec)
2024
-
[9]
Giray Yağlıkçı, Ataberk Olgun, Ismail Emir Yuksel, Yahya Can Tuğrul, Konstantinos Kanellopoulos, Oğuz Ergin, and Onur Mutlu
Oğuzhan Canpolat, A. Giray Yağlıkçı, Ataberk Olgun, Ismail Emir Yuksel, Yahya Can Tuğrul, Konstantinos Kanellopoulos, Oğuz Ergin, and Onur Mutlu
-
[12]
Boru Chen, Yingchen Wang, Pradyumna Shome, Christopher Fletcher, David Kohlbrenner, Riccardo Paccagnella, and Daniel Genkin. 2024. GoFetch: Break- ing Constant-Time Cryptographic Implementations Using Data Memory- Dependent Prefetchers. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 1117–1134. https://www.use...
2024
Show all 112 references
-
[13]
Chang, Prashant J
Kevin K. Chang, Prashant J. Nair, Donghyuk Lee, Saugata Ghose, Moinuddin K. Qureshi, and Onur Mutlu. 2016. Low-Cost Inter-Linked Subarrays (LISA): Enabling fast inter-subarray data movement in DRAM. In2016 IEEE International Symposium on High Performance Computer Architecture ...
2016
-
[14]
Md Hafizul Islam Chowdhuryy, Hao Zheng, and Fan Yao. 2024. MetaLeak: Uncovering Side Channels in Secure Processor Architectures Exploiting Meta- data. In 2024 ACM/IEEE 51st Annual International Symposium on Computer Architecture (ISCA). 693–707. https://doi.org/10.1109/ISCA590...
2024
-
[15]
Yun Chen, Lingfeng Pei, and Trevor E. Carlson. 2023. AfterImage: Leaking Control Flow Data and Tracking Load Operations via the Hardware Prefetcher. In Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems...
2023
-
[16]
Lucian Cojocar, Kaveh Razavi, Cristiano Giuffrida, and Herbert Bos. 2019. Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer Attacks. In 2019 IEEE Symposium on Security and Privacy (SP) . 55–71. https://doi.org/10.1109/SP.2019.00089
2019
-
[17]
Zachary Coalson, Jeonghyun Woo, Shiyang Chen, Yu Sun, Lishan Yang, Prashant Nair, Bo Fang, and Sanghyun Hong. 2024. PrisonBreak: Jailbreak- ing Large Language Models with Fewer Than Twenty-Five Targeted Bit-flips. arXiv:2412.07192 [cs.CR] https://arxiv.org/abs/2412.07192
2024
-
[19]
Standard Performance Evaluation Corporation. 2006. SPEC CPU2006 Bench- mark Suite. http://www.spec.org/cpu2006/
2006
-
[20]
Patt, Prashant J
Ali Fakhrzadehgan, Yale N. Patt, Prashant J. Nair, and Moinuddin K. Qureshi
-
[21]
Dmitry Evtyushkin, Ryan Riley, Nael CSE Abu-Ghazaleh, ECE, and Dmitry Ponomarev. 2018. BranchScope: A New Side-Channel Attack on Directional Branch Predictor. In Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages and Ope...
2018
-
[22]
Pietro Frigo, Emanuele Vannacc, Hasan Hassan, Victor van der Veen, Onur Mutlu, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2020. TRRespass: Exploiting the Many Sides of Target Row Refresh. In 2020 IEEE Symposium on Security and Privacy (SP) . 747–762. https://doi.org/1...
2020
-
[24]
Michael Ferdman, Almutaz Adileh, Onur Kocberber, Stavros Volos, Mohammad Alisafaee, Djordje Jevdjic, Cansu Kaynak, Adrian Daniel Popescu, Anastasia Ailamaki, and Babak Falsafi. 2012. Clearing the clouds: a study of emerging scale-out workloads on modern hardware. In Proceeding...
2012
-
[25]
Daniel Gruss, Julian Lettner, Felix Schuster, Olya Ohrimenko, Istvan Haller, and Manuel Costa. 2017. Strong and Efficient Cache Side-Channel Protection using Hardware Transactional Memory. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, B...
2017
-
[26]
Daniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin, Jonas Juffinger, Sioli O’Connell, Wolfgang Schoechl, and Yuval Yarom. 2018. Another Flip in the Wall of Rowhammer Defenses. In 2018 IEEE Symposium on Security and Privacy (SP). 245–261. https://doi.org/10.1109/SP.2018.00031
2018
-
[27]
Gratz, Daniel A
Nathan Gober, Gino Chacon, Lei Wang, Paul V. Gratz, Daniel A. Jimenez, Elvira Teran, Seth Pugsley, and Jinchun Kim. 2022. The Championship Simulator: Ar- chitectural Simulation for Education and Competition. arXiv:2210.14324 [cs.AR] https://arxiv.org/abs/2210.14324
2022 arXiv
-
[28]
Daniel Gruss, Clémentine Maurice, Klaus Wagner, and Stefan Mangard. 2016. Flush+Flush: A Fast and Stealthy Cache Attack. In Proceedings of the 13th Inter- national Conference on Detection of Intrusions and Malware, and Vulnerability Assessment - Volume 9721 (San Sebastián, Spa...
2016 doi
-
[30]
Daniel Gruss, Clémentine Maurice, and Stefan Mangard. 2016. Rowhammer.js: A Remote Software-Induced Fault Attack in JavaScript. In Proceedings of the 13th International Conference on Detection of Intrusions and Malware, and Vulner- ability Assessment - Volume 9721 (San Sebasti...
2016 doi
-
[31]
Sanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida, and Tudor Dumitras. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks. In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Associatio...
2019
-
[32]
Seungki Hong, Dongha Kim, Jaehyung Lee, Reum Oh, Changsik Yoo, Sangjoon Hwang, and Jooyoung Lee. 2023. Dsac: Low-cost rowhammer mitigation using in-dram stochastic and approximate counting algorithm. arXiv:2302.03591 (2023)
2023 arXiv
-
[33]
Kim, Victor van der Veen, Kaveh Razavi, and Onur Mutlu
Hasan Hassan, Yahya Can Tugrul, Jeremie S. Kim, Victor van der Veen, Kaveh Razavi, and Onur Mutlu. 2021. Uncovering In-DRAM RowHammer Protec- tion Mechanisms:A New Methodology, Custom RowHammer Patterns, and Implications. In MICRO-54: 54th Annual IEEE/ACM International Symposi...
2021
-
[34]
Keckler, and Gururaj Saileshwar
Aamer Jaleel, Stephen W. Keckler, and Gururaj Saileshwar. 2024. Probabilistic Tracker Management Policies for Low-Cost and Scalable Rowhammer Mitiga- tion. arXiv:2404.16256 (2024)
2024 arXiv
-
[35]
Keckler, and Moinuddin Qureshi
Aamer Jaleel, Gururaj Saileshwar, Stephen W. Keckler, and Moinuddin Qureshi
-
[36]
Theobald, Simon C
Aamer Jaleel, Kevin B. Theobald, Simon C. Steely, and Joel Emer. 2010. High performance cache replacement using re-reference interval prediction (RRIP). In Proceedings of the 37th Annual International Symposium on Computer Archi- tecture (Saint-Malo, France) (ISCA ’10). Associ...
2010
-
[37]
Intel. 2022. What does SGX 2.0 (scalable SGX) sacrifice. Github. https: //github.com/intel/linux-sgx/issues/899
2022
-
[38]
Patrick Jattke, Victor Van Der Veen, Pietro Frigo, Stijn Gunter, and Kaveh Razavi
-
[39]
Patrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi, Matej Bölcskei, and Kaveh Razavi. 2024. ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms. In 33rd USENIX Security Symposium (USENIX Security 24) . USENIX Association, Philadelphia, PA, 1615–1633. https://www.use...
2024
-
[40]
In 2024 ACM/IEEE 51st Annual International Symposium on Computer Architecture (ISCA)
PrIDE: Achieving Secure Rowhammer Mitigation with Low-Cost In- DRAM Trackers. In 2024 ACM/IEEE 51st Annual International Symposium on Computer Architecture (ISCA). 1157–1172. https://doi.org/10.1109/ISCA59077. 2024.00087
2024
-
[41]
JEDEC. 2024. JESD79-5C. https://www.jedec.org/document_search?search_ api_views_fulltext=jesd79-5c
2024
-
[42]
Yeongjin Jang, Jaehyuk Lee, Sangho Lee, and Taesoo Kim. 2017. SGX-Bomb: Locking Down the Processor via Rowhammer Attack. In Proceedings of the 2nd Workshop on System Software for Trusted Execution (Shanghai, China) (Sys- TEX’17). Association for Computing Machinery, New York, ...
2017
-
[43]
Dimitris Kaseridis, Jeffrey Stuecheli, and Lizy Kurian John. 2011. Minimalist open-page: a DRAM page-mode scheduling policy for the many-core era. InPro- ceedings of the 44th Annual IEEE/ACM International Symposium on Microarchitec- ture (Porto Alegre, Brazil) (MICRO-44). Asso...
2011
-
[45]
Kim, Minesh Patel, A
Jeremie S. Kim, Minesh Patel, A. Giray Yağlıkçı, Hasan Hassan, Roknoddin Azizi, Lois Orosa, and Onur Mutlu. 2020. Revisiting RowHammer: an ex- perimental analysis of modern DRAM devices and mitigation techniques. In Proceedings of the ACM/IEEE 47th Annual International Symposi...
2020
-
[46]
JEDEC. 2017. DDR4 SDRAM standard (JESD79-4B). (2017)
2017
-
[47]
Lee, and Jung Ho Ahn
Michael Jaemin Kim, Jaehyun Park, Yeonhong Park, Wanju Doh, Namhoon Kim, Tae Jun Ham, Jae W. Lee, and Jung Ho Ahn. 2022. Mithril: Cooperative Row Hammer Protection on Commodity DRAM Leveraging Managed Refresh. In 2022 IEEE International Symposium on High-Performance Computer A...
2022
-
[48]
Jimenez and C
D.A. Jimenez and C. Lin. 2001. Dynamic branch prediction with perceptrons. In Proceedings HPCA Seventh International Symposium on High-Performance Computer Architecture. 197–206. https://doi.org/10.1109/HPCA.2001.903263
2001
-
[49]
Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu. 2014. Flipping bits in memory without accessing them: an experimental study of DRAM disturbance errors. SIGARCH Comput. Archit. News 42, 3 (June 2014), 361–...
2014
-
[50]
Nair, and Moinuddin K
Dae-Hyun Kim, Prashant J. Nair, and Moinuddin K. Qureshi. 2015. Architectural Support for Mitigating Row Hammering in DRAM Memories. IEEE Computer Architecture Letters 14, 1 (2015), 9–12. https://doi.org/10.1109/LCA.2014.2332177
2015
-
[51]
Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 2019 IEEE Symposium on Security and Privacy ...
2019
-
[52]
Kwangrae Kim, Jeonghyun Woo, Junsu Kim, and Ki-Seok Chung. 2021. Hammer- Filter: Robust Protection and Low Hardware Overhead Method for RowHammer. In 2021 IEEE 39th International Conference on Computer Design (ICCD) . 212–219. https://doi.org/10.1109/ICCD53106.2021.00043
2021
-
[53]
Andrew Kwong, Daniel Genkin, Daniel Gruss, and Yuval Yarom. 2020. RAM- Bleed: Reading Bits in Memory Without Accessing Them. In 2020 IEEE Sympo- sium on Security and Privacy (SP) . 695–711. https://doi.org/10.1109/SP40000. 2020.00020
2020
-
[54]
Woongrae Kim, Chulmoon Jung, Seongnyuh Yoo, Duckhwa Hong, Jeongjin Hwang, Jungmin Yoon, Ohyong Jung, Joonwoo Choi, Sanga Hyun, Mankeun Kang, Sangho Lee, Dohong Kim, Sanghyun Ku, Donhyun Choi, Nogeun Joo, Sangwoo Yoon, Junseok Noh, Byeongyong Go, Cheolhoe Kim, Sunil Hwang, Mihy...
2023
-
[55]
Moritz Lipp, Vedad Hadžić, Michael Schwarz, Arthur Perais, Clémentine Mau- rice, and Daniel Gruss. 2020. Take A Way: Exploring the Security Implica- tions of AMD’s Cache Way Predictors. In Proceedings of the 15th ACM Asia Conference on Computer and Communications Security (Tai...
2020
-
[56]
Yoongu Kim, Weikun Yang, and Onur Mutlu. 2016. Ramulator: A Fast and Extensible DRAM Simulator. IEEE Computer Architecture Letters 15, 1 (2016), 45–49. https://doi.org/10.1109/LCA.2015.2414456
2016
-
[57]
Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B. Lee. 2015. Last- Level Cache Side-Channel Attacks are Practical. In 2015 IEEE Symposium on Security and Privacy. 605–622. https://doi.org/10.1109/SP.2015.43
2015 doi
-
[58]
Andreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim, Moritz Lipp, Nicolas Boichat, Eric Shiu, Mattias Nissler, and Daniel Gruss. 2022. Half-Double: Ham- mering From the Next Row Over. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, ...
2022
-
[60]
Edward Suh, and Jung Ho Ahn
Eojin Lee, Ingab Kang, Sukhan Lee, G. Edward Suh, and Jung Ho Ahn. 2019. TWiCe: preventing row-hammering by exploiting time window counters. InPro- ceedings of the 46th International Symposium on Computer Architecture (Phoenix, Arizona) (ISCA ’19). Association for Computing Ma...
2019
-
[62]
Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Securit...
2018
-
[63]
Onur Mutlu and Thomas Moscibroda. 2007. Stall-Time Fair Memory Access Scheduling for Chip Multiprocessors. In 40th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO 2007) . 146–160. https://doi.org/10. 1109/MICRO.2007.21
2007
-
[64]
Kevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman, Dimitrios Skarlatos, and Baris Kasikci. 2023. Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM Rowhammer. In Proceedings of the 29th Symposium on Operating Systems Principles (Koblenz, Germany) (SOSP ’23)...
2023
-
[65]
Nair, Bahar Asgari, and Moinuddin K
Prashant J. Nair, Bahar Asgari, and Moinuddin K. Qureshi. 2019. SuDoku: Tolerating High-Rate of Transient Failures for Enabling Scalable STTRAM. In 2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and 17 Jeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Pra...
2019
-
[66]
Nisa Bostancı, Ataberk Olgun, A
Haocong Luo, Yahya Can Tuğrul, F. Nisa Bostancı, Ataberk Olgun, A. Giray Yağlıkçı, and Onur Mutlu. 2024. Ramulator 2.0: A Modern, Modular, and Ex- tensible DRAM Simulator. IEEE Comput. Archit. Lett. 23, 1 (Jan. 2024), 112–116. https://doi.org/10.1109/LCA.2023.3333759
2024
-
[67]
Nair, David A
Prashant J. Nair, David A. Roberts, and Moinuddin K. Qureshi. 2014. Citadel: Efficiently Protecting Stacked Memory from Large Granularity Failures. In 2014 47th Annual IEEE/ACM International Symposium on Microarchitecture . 51–62. https://doi.org/10.1109/MICRO.2014.57
2014 doi
-
[68]
Michele Marazzi, Flavien Solt, Patrick Jattke, Kubo Takashi, and Kaveh Razavi
-
[69]
Nair, David A
Prashant J. Nair, David A. Roberts, and Moinuddin K. Qureshi. 2016. Citadel: Efficiently Protecting Stacked Memory from TSV and Large Granularity Failures. ACM Trans. Archit. Code Optim. 12, 4, Article 49 (Jan. 2016), 24 pages. https: //doi.org/10.1145/2840807
2016 doi
-
[70]
Nair, Vilas Sridharan, and Moinuddin K
Prashant J. Nair, Vilas Sridharan, and Moinuddin K. Qureshi. 2016. XED: ex- posing on-die error detection information for strong memory reliability. In Proceedings of the 43rd International Symposium on Computer Architecture (Seoul, Republic of Korea) (ISCA ’16). IEEE Press, 3...
2016
-
[71]
Prashant Nair, Chia-Chen Chou, and Moinuddin K. Qureshi. 2013. A case for Refresh Pausing in DRAM memory systems. In 2013 IEEE 19th International Symposium on High Performance Computer Architecture (HPCA). 627–638. https: //doi.org/10.1109/HPCA.2013.6522355
2013
-
[72]
Giray Yağlıkçı, Yahya Can Tuğrul, Haocong Luo, Steve Rhyner, Behzad Salami, Juan Gomez Luna, and Onur Mutlu
Ataberk Olgun, Majd Osseiran, A. Giray Yağlıkçı, Yahya Can Tuğrul, Haocong Luo, Steve Rhyner, Behzad Salami, Juan Gomez Luna, and Onur Mutlu. 2024. Read Disturbance in High Bandwidth Memory: A Detailed Experimental Study on HBM2 DRAM Chips. In 2024 54th Annual IEEE/IFIP Intern...
2024
-
[73]
Nair, Dae-Hyun Kim, and Moinuddin K
Prashant J. Nair, Dae-Hyun Kim, and Moinuddin K. Qureshi. 2013. ArchShield: architectural framework for assisting DRAM scaling by tolerating high error rates. In Proceedings of the 40th Annual International Symposium on Computer Architecture (Tel-Aviv, Israel)(ISCA ’13). Assoc...
2013
-
[74]
Yeonhong Park, Woosuk Kwon, Eojin Lee, Tae Jun Ham, Jung Ho Ahn, and Jae W. Lee. 2020. Graphene: Strong yet Lightweight Row Hammer Protection. In 2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO). 1–13. https://doi.org/10.1109/MICRO50266.2020.00014
2020
-
[75]
Nair, David A
Prashant J. Nair, David A. Roberts, and Moinuddin K. Qureshi. 2015. FaultSim: A Fast, Configurable Memory-Reliability Simulator for Conventional and 3D- Stacked Systems. ACM Trans. Archit. Code Optim. 12, 4, Article 44 (Dec. 2015), 24 pages. https://doi.org/10.1145/2831234
2015 doi
-
[77]
Moinuddin Qureshi and Salman Qazi. 2025. MOAT: Securely Mitigating Rowhammer with Per-Row Activation Counters. In Proceedings of the 30th ACM International Conference on Architectural Support for Programming Lan- guages and Operating Systems, Volume 1 (Rotterdam, Netherlands) ...
2025
-
[79]
Moinuddin Qureshi, Aditya Rohan, Gururaj Saileshwar, and Prashant J. Nair
-
[80]
Oliveira, and Onur Mutlu
Ataberk Olgun, Yahya Can Tugrul, Nisa Bostanci, Ismail Emir Yuksel, Haocong Luo, Steve Rhyner, Abdullah Giray Yaglikci, Geraldo F. Oliveira, and Onur Mutlu
-
[81]
In 33rd USENIX Security Symposium (USENIX Security 24)
ABACuS: All-Bank Activation Counters for Scalable and Low Overhead RowHammer Mitigation. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 1579–1596. https://www.usenix. org/conference/usenixsecurity24/presentation/olgun
-
[82]
Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuffrida, and Herbert Bos. 2016. Flip Feng Shui: Hammering a Needle in the Software Stack. In 25th USENIX Security Symposium (USENIX Security 16) . USENIX Associa- tion, Austin, TX, 1–18. https://www.usenix.org/conf...
2016
-
[83]
Peter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. DRAMA: Exploiting DRAM Addressing for Cross-CPU Attacks. In 25th USENIX Security Symposium (USENIX Security 16) . USENIX Association, Austin, TX, 565–581. https://www.usenix.org/conferenc...
2016
-
[84]
Nair, Prakash Ramrakhyani, Wendy Elsasser, Jose A
Gururaj Saileshwar, Prashant J. Nair, Prakash Ramrakhyani, Wendy Elsasser, Jose A. Joao, and Moinuddin K. Qureshi. 2018. Morphable Counters: Enabling Compact Integrity Trees For Low-Overhead Secure Memories. In 2018 51st Annual IEEE/ACM International Symposium on Microarchitec...
2018
-
[85]
Nair, Prakash Ramrakhyani, Wendy Elsasser, and Moinuddin K
Gururaj Saileshwar, Prashant J. Nair, Prakash Ramrakhyani, Wendy Elsasser, and Moinuddin K. Qureshi. 2018. SYNERGY: Rethinking Secure-Memory Design for Error-Correcting Memories. In 2018 IEEE International Symposium on High Performance Computer Architecture (HPCA). 454–465. ht...
2018
-
[86]
Moinuddin Qureshi, Salman Qazi, and Aamer Jaleel. 2024. MINT: Securely Mitigating Rowhammer with a Minimalist in-DRAM Tracker. In 2024 57th IEEE/ACM International Symposium on Microarchitecture (MICRO) . 899–914. https://doi.org/10.1109/MICRO61859.2024.00071
2024
-
[87]
Anish Saxena, Saurav Mathur, and Moinuddin Qureshi. 2024. Rubix: Reducing the Overhead of Secure Rowhammer Mitigations via Randomized Line-to- Row Mapping. In Proceedings of the 29th ACM International Conference on Architectural Support for Programming Languages and Operating ...
2024
-
[88]
In Proceedings of the 49th Annual Inter- national Symposium on Computer Architecture (New York, New York) (ISCA ’22)
Hydra: enabling low-overhead mitigation of row-hammer at ultra- low thresholds via hybrid tracking. In Proceedings of the 49th Annual Inter- national Symposium on Computer Architecture (New York, New York) (ISCA ’22). Association for Computing Machinery, New York, NY, USA, 699...
-
[89]
Qureshi, Dae-Hyun Kim, Samira Khan, Prashant J
Moinuddin K. Qureshi, Dae-Hyun Kim, Samira Khan, Prashant J. Nair, and Onur Mutlu. 2015. AVATAR: A Variable-Retention-Time (VRT) Aware Refresh for DRAM Systems. In 2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks . 427–437. https://doi.org...
2015 doi
-
[90]
Adnan Siraj Rakin, Md Hafizul Islam Chowdhuryy, Fan Yao, and Deliang Fan
-
[92]
Ali Shafiee, Akhila Gundu, Manjunath Shevgoor, Rajeev Balasubramonian, and Mohit Tiwari. 2015. Avoiding information leakage in the memory controller with fixed service policies. InProceedings of the 48th International Symposium on Microarchitecture (Waikiki, Hawaii)(MICRO-48)....
2015
-
[93]
Rixner, W.J
S. Rixner, W.J. Dally, U.J. Kapasi, P. Mattson, and J.D. Owens. 2000. Memory access scheduling. In Proceedings of 27th International Symposium on Computer Architecture (IEEE Cat. No.RS00201). 128–138. https://doi.org/10.1145/339647. 339668
2000 doi
-
[94]
Mungyu Son, Hyunsun Park, Junwhan Ahn, and Sungjoo Yoo. 2017. Making DRAM stronger against row hammering. In 2017 54th ACM/EDAC/IEEE Design Automation Conference (DAC). 1–6. https://doi.org/10.1145/3061639.3062281
2017
-
[95]
SPEC2017 [n. d.]. SPEC CPU2017 Benchmark Suite. Standard Performance Evaluation Corporation. http://www.spec.org/cpu2017/
-
[96]
Victor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss, Clementine Maurice, Giovanni Vigna, Herbert Bos, Kaveh Razavi, and Cris- tiano Giuffrida. 2016. Drammer: Deterministic Rowhammer Attacks on Mobile Platforms. In Proceedings of the 2016 ACM SIGSAC Confere...
2016
-
[97]
Gururaj Saileshwar, Bolin Wang, Moinuddin Qureshi, and Prashant J. Nair
-
[98]
In Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (Lausanne, Switzerland) (ASPLOS ’22)
Randomized row-swap: mitigating Row Hammer by breaking spatial correlation between aggressor and victim rows. In Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (Lausanne, Switzerland) (ASPLOS ’22). ...
-
[99]
Edward Suh
Yao Wang, Andrew Ferraiuolo, and G. Edward Suh. 2014. Timing channel protection for a shared memory controller. In 2014 IEEE 20th International Symposium on High Performance Computer Architecture (HPCA). 225–236. https: //doi.org/10.1109/HPCA.2014.6835934
2014
-
[101]
Nair, and Moinuddin Qureshi
Anish Saxena, Gururaj Saileshwar, Prashant J. Nair, and Moinuddin Qureshi
-
[103]
Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM rowhammer bug to gain kernel privileges. Black Hat 15 (2015), 71
2015
-
[104]
Jones, and Rami Melhem
Seyed Mohammad Seyedzadeh, Alex K. Jones, and Rami Melhem. 2018. Mitigat- ing wordline crosstalk using adaptive trees of counters. InProceedings of the 45th Annual International Symposium on Computer Architecture (Los Angeles, Califor- nia) (ISCA ’18). IEEE Press, 612–623. htt...
2018
-
[105]
Giray Yağlikçi, Minesh Patel, Jeremie S
A. Giray Yağlikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi, Ataberk Olgun, Lois Orosa, Hasan Hassan, Jisung Park, Konstantinos Kanellopoulos, Taha Shahroodi, Saugata Ghose, and Onur Mutlu. 2021. BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Access...
2021
-
[106]
Youngjoo Shin, Hyung Chan Kim, Dokeun Kwon, Ji Hoon Jeong, and Jun- beom Hur. 2018. Unveiling Hardware-based Data Prefetcher, a Hidden Source of Information Leakage. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (Toronto, Canada) (CCS...
2018
-
[107]
Mengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher Fletcher, Roy Campbell, and Josep Torrellas. 2019. Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive World. In 2019 IEEE Symposium on Security and Privacy (SP). 888–904. https://doi.org/10.1109/S...
2019
-
[108]
Fan Yao, Adnan Siraj Rakin, and Deliang Fan. 2020. DeepHammer: Deplet- ing the Intelligence of Deep Neural Networks through Targeted Chain of Bit Flips. In 29th USENIX Security Symposium (USENIX Security 20) . USENIX As- sociation, 1463–1480. https://www.usenix.org/conference/...
2020
-
[109]
Yuval Yarom and Katrina Falkner. 2014. FLUSH+ RELOAD: A high resolution, low noise, l3 cache Side-Channel attack. In 23rd USENIX security symposium (USENIX Security). 719–732
2014
-
[110]
Fletcher, and David Kohlbrenner
Jose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman, Adam Morrison, Christopher W. Fletcher, and David Kohlbrenner. 2022. Augury: Using Data Memory-Dependent Prefetchers to Leak Data at Rest. In 2022 IEEE Symposium on Security and Priva...
2022
-
[111]
Minghua Wang, Zhi Zhang, Yueqiang Cheng, and Surya Nepal. 2020. DRAMDig: a knowledge-assisted tool to uncover DRAM address mapping. In Proceedings of the 57th ACM/EDAC/IEEE Design Automation Conference (Virtual Event, USA) (DAC ’20). IEEE Press, Article 89, 6 pages. 18 When Mi...
2020
-
[112]
Oliveira, İsmail Emir Yüksel, Ataberk Olgun, Haocong Luo, and Onur Mutlu
Abdullah Giray Yağlıkçı, Yahya Can Tuğrul, Geraldo F. Oliveira, İsmail Emir Yüksel, Ataberk Olgun, Haocong Luo, and Onur Mutlu. 2024. Spatial Variation- Aware Read Disturbance Defenses: Experimental Analysis of Real DRAM Chips and Implications on Future Solutions. In 2024 IEEE...
2024
-
[113]
Edward Suh
Yao Wang, Benjamin Wu, and G. Edward Suh. 2017. Secure Dynamic Mem- ory Scheduling Against Timing Channel Attacks. In 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA) . 301–312. https://doi.org/10.1109/HPCA.2017.27
2017 doi
-
[116]
Jeonghyun Woo and Prashant J. Nair. 2025. DAPPER: A Performance-Attack- Resilient Tracker for RowHammer Defense. In 2025 IEEE International Sympo- sium on High Performance Computer Architecture (HPCA) . 1005–1020. https: //doi.org/10.1109/HPCA61900.2025.00079
2025
-
[117]
Jeonghyun Woo, Gururaj Saileshwar, and Prashant J. Nair. 2023. Scalable and Se- cure Row-Swap: Efficient and Safe Row Hammer Mitigation in Memory Systems. In 2023 IEEE International Symposium on High-Performance Computer Architec- ture (HPCA). 374–389. https://doi.org/10.1109/...
2023
-
[119]
Englender, M
Chenyu Yan, D. Englender, M. Prvulovic, B. Rogers, and Yan Solihin. 2006. Improving Cost, Performance, and Security of Memory Encryption and Authen- tication. In 33rd International Symposium on Computer Architecture (ISCA’06) . 179–190. https://doi.org/10.1109/ISCA.2006.22
2006 doi
-
[123]
Giray Yağlikçi, Ataberk Olgun, Minesh Patel, Haocong Luo, Hasan Hassan, Lois Orosa, Oğuz Ergin, and Onur Mutlu
A. Giray Yağlikçi, Ataberk Olgun, Minesh Patel, Haocong Luo, Hasan Hassan, Lois Orosa, Oğuz Ergin, and Onur Mutlu. 2022. HiRA: Hidden Row Activation for Reducing Refresh Latency of Off-the-Shelf DRAM Chips. In2022 55th IEEE/ACM International Symposium on Microarchitecture (MIC...
2022
-
[124]
Kim, Fabrice Devaux, and Onur Mutlu
Abdullah Giray Yağlıkçı, Jeremie S. Kim, Fabrice Devaux, and Onur Mutlu. 2021. Security Analysis of the Silver Bullet Technique for RowHammer Prevention. arXiv:2106.07084 [cs.CR] https://arxiv.org/abs/2106.07084
2021 arXiv
-
[126]
Jung Min You and Joon-Sung Yang. 2019. MRLoc: Mitigating Row-hammering based on memory Locality. In2019 56th ACM/IEEE Design Automation Conference (DAC). 1–6
2019
-
[127]
Nair, and Moinuddin K
Vinson Young, Prashant J. Nair, and Moinuddin K. Qureshi. 2015. DEUCE: Write-Efficient Encryption for Non-Volatile Memories. In Proceedings of the Twentieth International Conference on Architectural Support for Programming Languages and Operating Systems (Istanbul, Turkey) (AS...
2015
-
[128]
Yanqi Zhou, Sameer Wagh, Prateek Mittal, and David Wentzlaff. 2017. Cam- ouflage: Memory Traffic Shaping to Mitigate Timing Attacks. In 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA) . 337–348. https://doi.org/10.1109/HPCA.2017.36
2017 doi
-
[129]
William K Zuravleff and Timothy Robinson. 1997. Controller for a synchronous DRAM that maximizes throughput by allowing memory requests and commands to be issued out of order. US Patent 5,630,096. 19
1997
-
[427]
https://doi.org/10.1109/MICRO.2018.00041
2018
-
[514]
https://www.usenix.org/conference/usenixsecurity19/presentation/hong
-
[2022]
In 2022 IEEE International Symposium on High-Performance Computer Architecture (HPCA)
SafeGuard: Reducing the Security Risk from Row-Hammer via Low-Cost Integrity Protection. In 2022 IEEE International Symposium on High-Performance Computer Architecture (HPCA). 373–386. https://doi.org/10.1109/HPCA53966. 2022.00035
2022
-
[2023]
In 2023 IEEE Symposium on Security and Privacy (SP)
REGA: Scalable Rowhammer Mitigation with Refresh-Generating Ac- tivations. In 2023 IEEE Symposium on Security and Privacy (SP) . 1684–1701. https://doi.org/10.1109/SP46215.2023.10179327
2023
-
[2024]
In 2024 IEEE Symposium on Security and Privacy (SP)
DeepVenom: Persistent DNN Backdoors Exploiting Transient Weight Perturbations in Memories. In 2024 IEEE Symposium on Security and Privacy (SP). 2067–2085. https://doi.org/10.1109/SP54263.2024.00223
2024
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.