{"id":"https://openalex.org/W3015844221","doi":"https://doi.org/10.1109/sp40000.2020.00089","title":"LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection","display_name":"LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection","publication_year":2020,"publication_date":"2020-05-01","ids":{"openalex":"https://openalex.org/W3015844221","doi":"https://doi.org/10.1109/sp40000.2020.00089","mag":"3015844221"},"language":"en","primary_location":{"id":"doi:10.1109/sp40000.2020.00089","is_oa":true,"landing_page_url":"https://doi.org/10.1109/sp40000.2020.00089","pdf_url":"https://ieeexplore.ieee.org/ielx7/9144328/9152199/09152763.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/9144328/9152199/09152763.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072446627","display_name":"Jo Van Bulck","orcid":"https://orcid.org/0000-0002-5953-9196"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]},{"id":"https://openalex.org/I196972281","display_name":"Imec the Netherlands","ror":"https://ror.org/01ezq2j76","country_code":"NL","type":"facility","lineage":["https://openalex.org/I196972281"]}],"countries":["BE","NL"],"is_corresponding":true,"raw_author_name":"Jo Van Bulck","raw_affiliation_strings":["imec-DistriNet, KU Leuven"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"imec-DistriNet, KU Leuven","institution_ids":["https://openalex.org/I196972281","https://openalex.org/I99464096"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072406383","display_name":"Daniel Moghimi","orcid":"https://orcid.org/0000-0002-3123-5916"},"institutions":[{"id":"https://openalex.org/I107077323","display_name":"Worcester Polytechnic Institute","ror":"https://ror.org/05ejpqr48","country_code":"US","type":"education","lineage":["https://openalex.org/I107077323"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Daniel Moghimi","raw_affiliation_strings":["Worcester Polytechnic Institute"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Worcester Polytechnic Institute","institution_ids":["https://openalex.org/I107077323"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070469078","display_name":"Michael Schwarz","orcid":"https://orcid.org/0000-0001-6744-3410"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Michael Schwarz","raw_affiliation_strings":["Graz University of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5080034747","display_name":"Moritz Lippi","orcid":null},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Moritz Lippi","raw_affiliation_strings":["Graz University of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006198181","display_name":"Marina Minkin","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Marina Minkin","raw_affiliation_strings":["University of Michigan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029386182","display_name":"Daniel Genkin","orcid":"https://orcid.org/0000-0003-2720-9288"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Daniel Genkin","raw_affiliation_strings":["University of Michigan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056484605","display_name":"Yuval Yarom","orcid":"https://orcid.org/0000-0003-0401-4197"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]},{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Yuval Yarom","raw_affiliation_strings":["University of Adelaide and Data61"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Adelaide and Data61","institution_ids":["https://openalex.org/I5681781","https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066592325","display_name":"Berk Sunar","orcid":"https://orcid.org/0000-0001-5404-5368"},"institutions":[{"id":"https://openalex.org/I107077323","display_name":"Worcester Polytechnic Institute","ror":"https://ror.org/05ejpqr48","country_code":"US","type":"education","lineage":["https://openalex.org/I107077323"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Berk Sunar","raw_affiliation_strings":["Worcester Polytechnic Institute"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Worcester Polytechnic Institute","institution_ids":["https://openalex.org/I107077323"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066874310","display_name":"Daniel Gruss","orcid":"https://orcid.org/0000-0002-7977-3246"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Daniel Gruss","raw_affiliation_strings":["Graz University of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5008329832","display_name":"Frank Piessens","orcid":"https://orcid.org/0000-0001-5438-153X"},"institutions":[{"id":"https://openalex.org/I196972281","display_name":"Imec the Netherlands","ror":"https://ror.org/01ezq2j76","country_code":"NL","type":"facility","lineage":["https://openalex.org/I196972281"]},{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]}],"countries":["BE","NL"],"is_corresponding":false,"raw_author_name":"Frank Piessens","raw_affiliation_strings":["imec-DistriNet, KU Leuven"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"imec-DistriNet, KU Leuven","institution_ids":["https://openalex.org/I196972281","https://openalex.org/I99464096"]}]}],"institutions":[],"countries_distinct_count":5,"institutions_distinct_count":10,"corresponding_author_ids":["https://openalex.org/A5072446627"],"corresponding_institution_ids":["https://openalex.org/I196972281","https://openalex.org/I99464096"],"apc_list":null,"apc_paid":null,"fwci":17.8161,"has_fulltext":true,"cited_by_count":196,"citation_normalized_percentile":{"value":0.99397961,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"54","last_page":"72"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10478","display_name":"Diamond and Carbon-based Materials Research","score":0.9843999743461609,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9603999853134155,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8054187297821045},{"id":"https://openalex.org/keywords/microarchitecture","display_name":"Microarchitecture","score":0.7221404314041138},{"id":"https://openalex.org/keywords/x86","display_name":"x86","score":0.5777915716171265},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5484824180603027},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.5409795045852661},{"id":"https://openalex.org/keywords/compiler","display_name":"Compiler","score":0.5069213509559631},{"id":"https://openalex.org/keywords/microcode","display_name":"Microcode","score":0.4783689081668854},{"id":"https://openalex.org/keywords/control-flow","display_name":"Control flow","score":0.45727968215942383},{"id":"https://openalex.org/keywords/buffer-overflow","display_name":"Buffer overflow","score":0.4513789415359497},{"id":"https://openalex.org/keywords/instruction-prefetch","display_name":"Instruction prefetch","score":0.42359820008277893},{"id":"https://openalex.org/keywords/serialization","display_name":"Serialization","score":0.41999220848083496},{"id":"https://openalex.org/keywords/transient","display_name":"Transient (computer programming)","score":0.41487917304039},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.3864653706550598},{"id":"https://openalex.org/keywords/parallel-computing","display_name":"Parallel computing","score":0.3831685185432434},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.30270421504974365},{"id":"https://openalex.org/keywords/cache","display_name":"Cache","score":0.29083138704299927},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.1186981201171875},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.09956187009811401}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8054187297821045},{"id":"https://openalex.org/C107598950","wikidata":"https://www.wikidata.org/wiki/Q259864","display_name":"Microarchitecture","level":2,"score":0.7221404314041138},{"id":"https://openalex.org/C170723468","wikidata":"https://www.wikidata.org/wiki/Q182933","display_name":"x86","level":3,"score":0.5777915716171265},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5484824180603027},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5409795045852661},{"id":"https://openalex.org/C169590947","wikidata":"https://www.wikidata.org/wiki/Q47506","display_name":"Compiler","level":2,"score":0.5069213509559631},{"id":"https://openalex.org/C22174128","wikidata":"https://www.wikidata.org/wiki/Q175869","display_name":"Microcode","level":2,"score":0.4783689081668854},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.45727968215942383},{"id":"https://openalex.org/C40842320","wikidata":"https://www.wikidata.org/wiki/Q19423","display_name":"Buffer overflow","level":2,"score":0.4513789415359497},{"id":"https://openalex.org/C133588205","wikidata":"https://www.wikidata.org/wiki/Q28455645","display_name":"Instruction prefetch","level":3,"score":0.42359820008277893},{"id":"https://openalex.org/C52723943","wikidata":"https://www.wikidata.org/wiki/Q1127410","display_name":"Serialization","level":2,"score":0.41999220848083496},{"id":"https://openalex.org/C2780799671","wikidata":"https://www.wikidata.org/wiki/Q17087362","display_name":"Transient (computer programming)","level":2,"score":0.41487917304039},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.3864653706550598},{"id":"https://openalex.org/C173608175","wikidata":"https://www.wikidata.org/wiki/Q232661","display_name":"Parallel computing","level":1,"score":0.3831685185432434},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.30270421504974365},{"id":"https://openalex.org/C115537543","wikidata":"https://www.wikidata.org/wiki/Q165596","display_name":"Cache","level":2,"score":0.29083138704299927},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.1186981201171875},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.09956187009811401}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/sp40000.2020.00089","is_oa":true,"landing_page_url":"https://doi.org/10.1109/sp40000.2020.00089","pdf_url":"https://ieeexplore.ieee.org/ielx7/9144328/9152199/09152763.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},{"id":"pmh:oai:lirias2repo.kuleuven.be:123456789/664465","is_oa":false,"landing_page_url":"https://lirias.kuleuven.be/bitstream/123456789/664465/2/oakland20-lvi.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306401954","display_name":"Lirias (KU Leuven)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I99464096","host_organization_name":"KU Leuven","host_organization_lineage":["https://openalex.org/I99464096"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"41st IEEE Symposium on Security and Privacy (S&P\u201920), virtual, 18-21 May 2020","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"doi:10.1109/sp40000.2020.00089","is_oa":true,"landing_page_url":"https://doi.org/10.1109/sp40000.2020.00089","pdf_url":"https://ieeexplore.ieee.org/ielx7/9144328/9152199/09152763.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.7400000095367432}],"awards":[{"id":"https://openalex.org/G2491787769","display_name":null,"funder_award_id":"CNS-1814406","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3259117655","display_name":"SaTC: CORE: Small: Super-Human Cryptanalysis for Scalable Side-Channel Analysis","funder_award_id":"1814406","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4713059963","display_name":null,"funder_award_id":"FA8750","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G523495190","display_name":"Securing Software against Physical Attacks","funder_award_id":"681402","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G7842005466","display_name":null,"funder_award_id":"Horizon 2020","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320321730","display_name":"Fonds Wetenschappelijk Onderzoek","ror":"https://ror.org/03qtxy027"},{"id":"https://openalex.org/F4320321896","display_name":"Bundesministerium f\u00fcr Wissenschaft, Forschung und Wirtschaft","ror":"https://ror.org/02d229b24"},{"id":"https://openalex.org/F4320322308","display_name":"KU Leuven","ror":"https://ror.org/05f950310"},{"id":"https://openalex.org/F4320323031","display_name":"\u00d6sterreichische Forschungsf\u00f6rderungsgesellschaft","ror":"https://ror.org/028jc0449"},{"id":"https://openalex.org/F4320323033","display_name":"Bundesministerium f\u00fcr Verkehr, Innovation und Technologie","ror":"https://ror.org/04marky29"},{"id":"https://openalex.org/F4320327336","display_name":"Vlaamse regering","ror":null},{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"},{"id":"https://openalex.org/F4320332815","display_name":"Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3015844221.pdf","grobid_xml":"https://content.openalex.org/works/W3015844221.grobid-xml"},"referenced_works_count":80,"referenced_works":["https://openalex.org/W1496248132","https://openalex.org/W1969501726","https://openalex.org/W2038347389","https://openalex.org/W2056778557","https://openalex.org/W2095872092","https://openalex.org/W2112438883","https://openalex.org/W2150620897","https://openalex.org/W2157116240","https://openalex.org/W2162800072","https://openalex.org/W2397423248","https://openalex.org/W2550858797","https://openalex.org/W2562036180","https://openalex.org/W2593994116","https://openalex.org/W2594560662","https://openalex.org/W2604789199","https://openalex.org/W2664885055","https://openalex.org/W2726246108","https://openalex.org/W2750990141","https://openalex.org/W2769061097","https://openalex.org/W2791034507","https://openalex.org/W2807403537","https://openalex.org/W2809355808","https://openalex.org/W2868863044","https://openalex.org/W2883613460","https://openalex.org/W2884163605","https://openalex.org/W2884364581","https://openalex.org/W2888798936","https://openalex.org/W2890914193","https://openalex.org/W2900479912","https://openalex.org/W2903910116","https://openalex.org/W2904519778","https://openalex.org/W2906721525","https://openalex.org/W2911594609","https://openalex.org/W2914399017","https://openalex.org/W2920016180","https://openalex.org/W2929833400","https://openalex.org/W2945638899","https://openalex.org/W2946300689","https://openalex.org/W2947949043","https://openalex.org/W2950168363","https://openalex.org/W2954241526","https://openalex.org/W2962986039","https://openalex.org/W2963311060","https://openalex.org/W2964590009","https://openalex.org/W2969173255","https://openalex.org/W2976763854","https://openalex.org/W2981343730","https://openalex.org/W2982827547","https://openalex.org/W2982848142","https://openalex.org/W2984643661","https://openalex.org/W2996753292","https://openalex.org/W3015291177","https://openalex.org/W3015806656","https://openalex.org/W3028668932","https://openalex.org/W3097990693","https://openalex.org/W3100164250","https://openalex.org/W4245117427","https://openalex.org/W4246977929","https://openalex.org/W4247080994","https://openalex.org/W4288086178","https://openalex.org/W4295815396","https://openalex.org/W6712237015","https://openalex.org/W6729667700","https://openalex.org/W6730881097","https://openalex.org/W6734345789","https://openalex.org/W6743496458","https://openalex.org/W6752410075","https://openalex.org/W6753251892","https://openalex.org/W6753443810","https://openalex.org/W6753807672","https://openalex.org/W6756740455","https://openalex.org/W6757585884","https://openalex.org/W6760517015","https://openalex.org/W6762378864","https://openalex.org/W6763353043","https://openalex.org/W6769288218","https://openalex.org/W6772375945","https://openalex.org/W6775608723","https://openalex.org/W6775654324","https://openalex.org/W6891923490"],"related_works":["https://openalex.org/W2140324148","https://openalex.org/W2121199344","https://openalex.org/W4293104654","https://openalex.org/W4311370984","https://openalex.org/W4287727071","https://openalex.org/W3041606120","https://openalex.org/W2889624678","https://openalex.org/W2467393770","https://openalex.org/W3033191713","https://openalex.org/W3208781723"],"abstract_inverted_index":{"The":[0],"recent":[1],"Spectre":[2,134],"attack":[3],"first":[4],"showed":[5],"how":[6,95],"to":[7,29,54,99,144,180,186,210,230],"inject":[8],"incorrect":[9,155],"branch":[10,19],"targets":[11],"into":[12,39],"a":[13,40,70],"victim":[14,72,101],"domain":[15],"by":[16,33,69,90],"poisoning":[17],"microarchitectural":[18,58,84],"prediction":[20],"history.":[21],"In":[22],"this":[23],"paper,":[24],"we":[25,121,223],"generalize":[26],"injection-based":[27],"methodologies":[28],"the":[30,91,152,164,190,218,236],"memory":[31,173],"hierarchy":[32],"directly":[34],"injecting":[35],"incorrect,":[36],"attacker-controlled":[37],"values":[38,78],"victim's":[41],"transient":[42,105,156],"execution.":[43],"We":[44,93,108],"propose":[45],"Load":[46],"Value":[47],"Injection":[48],"(LVI)":[49],"as":[50],"an":[51],"innovative":[52],"technique":[53],"reversely":[55],"exploit":[56],"Meltdown-type":[57],"data":[59,81],"leakage.":[60],"LVI":[61,96,111,147,149],"abuses":[62],"that":[63,202],"faulting":[64],"or":[65,79],"assisted":[66],"loads,":[67,182],"executed":[68],"legitimate":[71],"program,":[73],"may":[74],"transiently":[75],"use":[76],"dummy":[77],"poisoned":[80],"from":[82],"various":[83],"buffers,":[85],"before":[86],"eventually":[87],"being":[88],"re-issued":[89],"processor.":[92],"show":[94],"gadgets":[97],"allow":[98,204],"expose":[100],"secrets":[102],"and":[103,120,128,133,139,176,198,220],"hijack":[104],"control":[106],"flow.":[107],"practically":[109],"demonstrate":[110],"in":[112],"several":[113],"proof-of-concept":[114],"attacks":[115,161],"against":[116],"Intel":[117,195],"SGX":[118,207],"enclaves,":[119],"discuss":[122],"implications":[123],"for":[124,232],"traditional":[125],"user":[126],"process":[127],"kernel":[129],"isolation.":[130],"State-of-the-art":[131],"Meltdown":[132],"defenses,":[135],"including":[136,189],"widespread":[137],"silicon-level":[138],"microcode":[140],"mitigations,":[141],"are":[142],"orthogonal":[143],"our":[145,160],"novel":[146],"techniques.":[148],"drastically":[150],"widens":[151],"spectrum":[153],"of":[154,227,235],"paths.":[157],"Fully":[158],"mitigating":[159],"requires":[162],"serializing":[163],"processor":[165],"pipeline":[166],"with":[167],"lfence":[168],"instructions":[169,184],"after":[170],"possibly":[171],"every":[172],"load.":[174],"Additionally":[175],"even":[177],"worse,":[178],"due":[179],"implicit":[181],"certain":[183],"have":[185],"be":[187],"blacklisted,":[188],"ubiquitous":[191],"x86":[192],"ret":[193],"instruction.":[194],"plans":[196],"compiler":[197],"assembler-based":[199],"full":[200,237],"mitigations":[201],"will":[203],"at":[205],"least":[206],"enclave":[208],"programs":[209],"remain":[211],"secure":[212],"on":[213,217],"LVI-vulnerable":[214],"systems.":[215],"Depending":[216],"application":[219],"optimization":[221],"strategy,":[222],"observe":[224],"extensive":[225],"overheads":[226],"factor":[228],"2":[229],"19":[231],"prototype":[233],"implementations":[234],"mitigation.":[238]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":33},{"year":2024,"cited_by_count":28},{"year":2023,"cited_by_count":28},{"year":2022,"cited_by_count":35},{"year":2021,"cited_by_count":39},{"year":2020,"cited_by_count":29}],"updated_date":"2026-05-15T08:27:34.491423","created_date":"2025-10-10T00:00:00"}
