{"id":"https://openalex.org/W7133520518","doi":"https://doi.org/10.1109/hpca68181.2026.11408465","title":"SSBleed: Non-Speculative Side-Channel Attacks via Speculative Store Bypass on Armv9 CPUs","display_name":"SSBleed: Non-Speculative Side-Channel Attacks via Speculative Store Bypass on Armv9 CPUs","publication_year":2026,"publication_date":"2026-01-31","ids":{"openalex":"https://openalex.org/W7133520518","doi":"https://doi.org/10.1109/hpca68181.2026.11408465"},"language":null,"primary_location":{"id":"doi:10.1109/hpca68181.2026.11408465","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpca68181.2026.11408465","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Symposium on High Performance Computer Architecture (HPCA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5128064050","display_name":"Chang Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Chang Liu","raw_affiliation_strings":["Tsinghua University"],"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Hongpei Zheng","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongpei Zheng","raw_affiliation_strings":["Tsinghua University"],"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100430876","display_name":"Xi Zhang","orcid":"https://orcid.org/0000-0003-3415-5345"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xin Zhang","raw_affiliation_strings":["Peking University"],"affiliations":[{"raw_affiliation_string":"Peking University","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128102480","display_name":"Dapeng Ju","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dapeng Ju","raw_affiliation_strings":["Tsinghua University"],"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128062875","display_name":"Dongsheng Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongsheng Wang","raw_affiliation_strings":["Tsinghua University"],"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070946957","display_name":"Yinqian Zhang","orcid":"https://orcid.org/0000-0002-7585-1075"},"institutions":[{"id":"https://openalex.org/I3045169105","display_name":"Southern University of Science and Technology","ror":"https://ror.org/049tv2d57","country_code":"CN","type":"education","lineage":["https://openalex.org/I3045169105"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinqian Zhang","raw_affiliation_strings":["Southern University of Science and Technology"],"affiliations":[{"raw_affiliation_string":"Southern University of Science and Technology","institution_ids":["https://openalex.org/I3045169105"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069683581","display_name":"Trevor E. Carlson","orcid":"https://orcid.org/0000-0001-8742-134X"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Trevor E. Carlson","raw_affiliation_strings":["National University of Singapore"],"affiliations":[{"raw_affiliation_string":"National University of Singapore","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5128064050"],"corresponding_institution_ids":["https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.46892268,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"15"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.7721999883651733,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.7721999883651733,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.20909999310970306,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.005400000140070915,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.27639999985694885},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2721000015735626},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.26350000500679016},{"id":"https://openalex.org/keywords/product","display_name":"Product (mathematics)","score":0.2248000055551529},{"id":"https://openalex.org/keywords/database-transaction","display_name":"Database transaction","score":0.2240000069141388}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.613099992275238},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3370000123977661},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.33500000834465027},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.2937999963760376},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.27639999985694885},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2721000015735626},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.26350000500679016},{"id":"https://openalex.org/C90673727","wikidata":"https://www.wikidata.org/wiki/Q901718","display_name":"Product (mathematics)","level":2,"score":0.2248000055551529},{"id":"https://openalex.org/C75949130","wikidata":"https://www.wikidata.org/wiki/Q848010","display_name":"Database transaction","level":2,"score":0.2240000069141388},{"id":"https://openalex.org/C147494362","wikidata":"https://www.wikidata.org/wiki/Q2078905","display_name":"Troubleshooting","level":2,"score":0.2215999960899353}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/hpca68181.2026.11408465","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpca68181.2026.11408465","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Symposium on High Performance Computer Architecture (HPCA)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6378448009490967,"display_name":"Affordable and clean energy","id":"https://metadata.un.org/sdg/7"}],"awards":[{"id":"https://openalex.org/G6460557096","display_name":null,"funder_award_id":"202406210249","funder_id":"https://openalex.org/F4320322725","funder_display_name":"China Scholarship Council"}],"funders":[{"id":"https://openalex.org/F4320322725","display_name":"China Scholarship Council","ror":"https://ror.org/04atp4p48"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":58,"referenced_works":["https://openalex.org/W1934458198","https://openalex.org/W2050143636","https://openalex.org/W2095872092","https://openalex.org/W2145483435","https://openalex.org/W2163015177","https://openalex.org/W2337480911","https://openalex.org/W2507765405","https://openalex.org/W2791034507","https://openalex.org/W2792446256","https://openalex.org/W2803900647","https://openalex.org/W2891854691","https://openalex.org/W2897302968","https://openalex.org/W2905418916","https://openalex.org/W2954241526","https://openalex.org/W2963311060","https://openalex.org/W2976763854","https://openalex.org/W2982848142","https://openalex.org/W3096372727","https://openalex.org/W3097783227","https://openalex.org/W3153564332","https://openalex.org/W3190597741","https://openalex.org/W3197795418","https://openalex.org/W4232120412","https://openalex.org/W4233531165","https://openalex.org/W4244227015","https://openalex.org/W4246977929","https://openalex.org/W4253546582","https://openalex.org/W4281779787","https://openalex.org/W4285236231","https://openalex.org/W4288057698","https://openalex.org/W4288086178","https://openalex.org/W4318541606","https://openalex.org/W4380881061","https://openalex.org/W4384948650","https://openalex.org/W4385080289","https://openalex.org/W4385245129","https://openalex.org/W4386764061","https://openalex.org/W4388857078","https://openalex.org/W4389476379","https://openalex.org/W4390742688","https://openalex.org/W4391725337","https://openalex.org/W4393406863","https://openalex.org/W4393406905","https://openalex.org/W4393406988","https://openalex.org/W4393407237","https://openalex.org/W4395106389","https://openalex.org/W4401568100","https://openalex.org/W4405181326","https://openalex.org/W4405182895","https://openalex.org/W4406047350","https://openalex.org/W4408749954","https://openalex.org/W4408894479","https://openalex.org/W4408895087","https://openalex.org/W4408902871","https://openalex.org/W4409248737","https://openalex.org/W4411337826","https://openalex.org/W4411337888","https://openalex.org/W4414198751"],"related_works":[],"abstract_inverted_index":{"Modern":[0],"CPUs":[1,45],"employ":[2],"Speculative":[3],"Store":[4],"Bypass":[5],"(SSB)":[6],"to":[7,16,28,98],"reduce":[8],"load":[9],"latency":[10],"and":[11,81,131,141,145],"improve":[12],"performance.":[13],"In":[14,35],"response":[15],"transient":[17,151],"attacks":[18,134],"such":[19,93],"as":[20,94],"Spectre,":[21],"CPU":[22],"vendors":[23],"have":[24],"also":[25],"introduced":[26],"mitigations":[27,92],"prevent":[29,99],"incorrect":[30],"speculation":[31],"from":[32],"leaking":[33],"data.":[34],"this":[36,79],"work,":[37],"we":[38,56,74,104,154],"show":[39,82],"that":[40,58,83],"the":[41,59,76,107,119,136],"SSB":[42,60,113],"on":[43,61,102,114,135],"Armv9":[44,62,115],"introduces":[46],"a":[47,156,160],"previously":[48],"unexplored":[49],"form":[50],"of":[51,78,121,139,169],"non-speculative":[52,109],"data":[53,147],"leakage.":[54],"Specifically,":[55],"find":[57],"performance":[63,167],"cores":[64],"is":[65],"governed":[66],"by":[67],"an":[68,165],"undocumented":[69],"predictor.":[70],"Through":[71],"reverse":[72],"engineering,":[73],"uncover":[75],"design":[77],"predictor":[80],"it":[84],"lacks":[85],"isolation":[86],"across":[87],"security":[88],"domains.":[89],"Furthermore,":[90],"existing":[91],"SSBS":[95],"are":[96],"insufficient":[97],"leaks.":[100],"Based":[101],"this,":[103],"present":[105],"SSBleed,":[106],"first":[108],"side-channel":[110],"attack":[111],"via":[112],"CPUs.":[116],"We":[117],"validate":[118],"practicality":[120],"SSBleed":[122],"through":[123,159],"five":[124],"case":[125],"studies,":[126],"including":[127],"crossprocess":[128],"RSA":[129],"signature":[130],"key":[132],"generation":[133],"latest":[137],"version":[138],"MbedTLS":[140],"WolfSSL,":[142],"interrupt":[143],"detection,":[144],"improved":[146],"transmission":[148],"in":[149],"two":[150],"attacks.":[152],"Finally,":[153],"propose":[155],"flush-based":[157],"mitigation":[158],"kernel":[161],"patch,":[162],"which":[163],"incurs":[164],"average":[166],"overhead":[168],"0.46":[170],"%.":[171]},"counts_by_year":[],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2026-03-05T00:00:00"}
