{"id":"https://openalex.org/W7152083605","doi":"https://doi.org/10.1109/isdfs69419.2026.11459082","title":"Microarchitectural Espionage: FPGA-Based Security Analysis of Branch Prediction in RISC-V Out-of-Order Cores","display_name":"Microarchitectural Espionage: FPGA-Based Security Analysis of Branch Prediction in RISC-V Out-of-Order Cores","publication_year":2026,"publication_date":"2026-03-19","ids":{"openalex":"https://openalex.org/W7152083605","doi":"https://doi.org/10.1109/isdfs69419.2026.11459082"},"language":"en","primary_location":{"id":"doi:10.1109/isdfs69419.2026.11459082","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isdfs69419.2026.11459082","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 14th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://hal.science/hal-05479284/document","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5121681761","display_name":"Mahreen Khan","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Mahreen Khan","raw_affiliation_strings":["Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France","institution_ids":["https://openalex.org/I12356871"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133181238","display_name":"Muhammad Emir Bin Mohd Shahfie","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Muhammad Emir Bin Mohd Shahfie","raw_affiliation_strings":["Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France","institution_ids":["https://openalex.org/I12356871"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048830959","display_name":"Maria Mushtaq","orcid":"https://orcid.org/0000-0003-0046-2582"},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Maria Mushtaq","raw_affiliation_strings":["Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France","institution_ids":["https://openalex.org/I12356871"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133188259","display_name":"Renaud Pacalet","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Renaud Pacalet","raw_affiliation_strings":["Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France","institution_ids":["https://openalex.org/I12356871"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5133199095","display_name":"Ludovic Apvrille","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Ludovic Apvrille","raw_affiliation_strings":["Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telecom Paris, Institut Polytechnique de Paris,Palaiseau,France","institution_ids":["https://openalex.org/I12356871"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5121681761"],"corresponding_institution_ids":["https://openalex.org/I12356871"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.75947392,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.6061000227928162,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.6061000227928162,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.3215000033378601,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.029100000858306885,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/security-analysis","display_name":"Security analysis","score":0.3098999857902527},{"id":"https://openalex.org/keywords/time-series","display_name":"Time series","score":0.2874000072479248},{"id":"https://openalex.org/keywords/branch-predictor","display_name":"Branch predictor","score":0.2849000096321106},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.27880001068115234},{"id":"https://openalex.org/keywords/term","display_name":"Term (time)","score":0.25609999895095825}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5343999862670898},{"id":"https://openalex.org/C38369872","wikidata":"https://www.wikidata.org/wiki/Q7445009","display_name":"Security analysis","level":2,"score":0.3098999857902527},{"id":"https://openalex.org/C151406439","wikidata":"https://www.wikidata.org/wiki/Q186588","display_name":"Time series","level":2,"score":0.2874000072479248},{"id":"https://openalex.org/C168522837","wikidata":"https://www.wikidata.org/wiki/Q679552","display_name":"Branch predictor","level":2,"score":0.2849000096321106},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.27880001068115234},{"id":"https://openalex.org/C61797465","wikidata":"https://www.wikidata.org/wiki/Q1188986","display_name":"Term (time)","level":2,"score":0.25609999895095825},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.23980000615119934},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.23759999871253967},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.2361000031232834},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.23569999635219574}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/isdfs69419.2026.11459082","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isdfs69419.2026.11459082","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 14th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-05479284v1","is_oa":true,"landing_page_url":"https://hal.science/hal-05479284","pdf_url":"https://hal.science/hal-05479284/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"2026 14th International Symposium on Digital Forensics and Security (ISDFS), Mar 2026, BOSTON, Massachusetts, United States. pp.1-7, &#x27E8;10.1109/ISDFS69419.2026.11459082&#x27E9;","raw_type":"Conference papers"}],"best_oa_location":{"id":"pmh:oai:HAL:hal-05479284v1","is_oa":true,"landing_page_url":"https://hal.science/hal-05479284","pdf_url":"https://hal.science/hal-05479284/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"2026 14th International Symposium on Digital Forensics and Security (ISDFS), Mar 2026, BOSTON, Massachusetts, United States. pp.1-7, &#x27E8;10.1109/ISDFS69419.2026.11459082&#x27E9;","raw_type":"Conference papers"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W7152083605.pdf"},"referenced_works_count":10,"referenced_works":["https://openalex.org/W1613874182","https://openalex.org/W2562036180","https://openalex.org/W2613609759","https://openalex.org/W2761003783","https://openalex.org/W2803579379","https://openalex.org/W2899688953","https://openalex.org/W3027968530","https://openalex.org/W3029114445","https://openalex.org/W3036557299","https://openalex.org/W4384948664"],"related_works":[],"abstract_inverted_index":{"Modern":[0],"processor":[1],"microarchitectural":[2,156],"optimizations,":[3],"while":[4],"enhancing":[5],"performance,":[6],"inadvertently":[7],"introduce":[8],"side":[9],"channels":[10],"that":[11,95],"can":[12],"leak":[13],"sensitive":[14],"information":[15],"through":[16],"timing":[17,65,74,101],"variations.":[18],"This":[19,148],"paper":[20],"presents":[21],"an":[22,151],"FPGA-based":[23],"security":[24,157],"testbed":[25],"for":[26,51,115,154],"studying":[27],"branch":[28,57,142],"predictor":[29,58,143],"side-channel":[30],"vulnerabilities":[31],"in":[32],"open-source":[33,152],"RISC-V":[34,160],"out-of-order":[35],"cores.":[36],"We":[37,122],"demonstrate":[38,124],"a":[39,87,132],"configurable":[40],"platform":[41],"built":[42],"on":[43,145,159],"the":[44,129,139],"Berkeley":[45],"Out-of-Order":[46],"Machine":[47],"(BOOM)":[48],"core,":[49],"adapted":[50],"resource-constrained":[52],"FPGA":[53],"deployment":[54],"with":[55,112],"customizable":[56],"configurations.":[59],"Through":[60],"bare-metal":[61],"execution":[62],"and":[63,69,86,137,167],"cycle-accurate":[64],"measurements,":[66],"we":[67],"implement":[68],"evaluate":[70,138],"three":[71],"classes":[72],"of":[73,103,131,141,164],"attacks:":[75],"Conditional":[76],"Branch":[77,82],"Prediction":[78,83],"Attacks":[79,84],"(CBPA),":[80],"Indirect":[81],"(IBPA),":[85],"practical":[88,125],"smart-lock":[89,135],"application":[90],"attack.":[91],"Our":[92],"results":[93],"show":[94],"simplified":[96],"one-level":[97],"predictors":[98],"exhibit":[99],"deterministic":[100],"separations":[102],"9":[104],"to":[105],"17":[106],"cycles,":[107],"enabling":[108,162],"perfect":[109],"secret":[110],"recovery":[111],"100%":[113],"accuracy":[114],"16-bit":[116],"secrets":[117],"within":[118],"500":[119],"measurement":[120],"rounds.":[121],"further":[123],"attack":[126,146],"scenarios,":[127],"including":[128],"extraction":[130],"randomly-generated":[133],"4-digit":[134],"code,":[136],"impact":[140],"complexity":[144],"feasibility.":[147],"work":[149],"provides":[150],"framework":[153],"reproducible":[155],"research":[158],"platforms,":[161],"evaluation":[163],"both":[165],"attacks":[166],"countermeasures.":[168]},"counts_by_year":[],"updated_date":"2026-05-08T15:41:06.802602","created_date":"2026-04-09T00:00:00"}
