Memory DisOrder: Memory Re-orderings as a Timerless Side-channel

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Siddens, Sean, Srivastava, Sanya, Levine, Reese, Dykstra, Josiah, Sorensen, Tyler
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911372440240128
author Siddens, Sean
Srivastava, Sanya
Levine, Reese
Dykstra, Josiah
Sorensen, Tyler
author_facet Siddens, Sean
Srivastava, Sanya
Levine, Reese
Dykstra, Josiah
Sorensen, Tyler
contents To improve efficiency, nearly all parallel processing units (CPUs and GPUs) implement relaxed memory models in which memory operations may be re-ordered, i.e., executed out-of-order. Prior testing work in this area found that memory re-orderings are observed more frequently when other cores are active, e.g., stressing the memory system, which likely triggers aggressive hardware optimizations. In this work, we present Memory DisOrder: a timerless side-channel that uses memory re-orderings to infer activity on other processes. We first perform a fuzzing campaign and show that many mainstream processors (X86/Arm/Apple CPUs, NVIDIA/AMD/Apple GPUs) are susceptible to cross-process signals. We then show how the vulnerability can be used to implement classic attacks, including a covert channel, achieving up to 16 bits/second with 95% accuracy on an Apple M3 GPU, and application fingerprinting, achieving reliable closed-world DNN architecture fingerprinting on several CPUs and an Apple M3 GPU. Finally, we explore how low-level system details can be exploited to increase re-orderings, showing the potential for a covert channel to achieve nearly 30K bits/second on X86 CPUs. More precise attacks can likely be developed as the vulnerability becomes better understood.
format Preprint
id arxiv_https___arxiv_org_abs_2601_08770
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Memory DisOrder: Memory Re-orderings as a Timerless Side-channel
Siddens, Sean
Srivastava, Sanya
Levine, Reese
Dykstra, Josiah
Sorensen, Tyler
Cryptography and Security
Hardware Architecture
To improve efficiency, nearly all parallel processing units (CPUs and GPUs) implement relaxed memory models in which memory operations may be re-ordered, i.e., executed out-of-order. Prior testing work in this area found that memory re-orderings are observed more frequently when other cores are active, e.g., stressing the memory system, which likely triggers aggressive hardware optimizations. In this work, we present Memory DisOrder: a timerless side-channel that uses memory re-orderings to infer activity on other processes. We first perform a fuzzing campaign and show that many mainstream processors (X86/Arm/Apple CPUs, NVIDIA/AMD/Apple GPUs) are susceptible to cross-process signals. We then show how the vulnerability can be used to implement classic attacks, including a covert channel, achieving up to 16 bits/second with 95% accuracy on an Apple M3 GPU, and application fingerprinting, achieving reliable closed-world DNN architecture fingerprinting on several CPUs and an Apple M3 GPU. Finally, we explore how low-level system details can be exploited to increase re-orderings, showing the potential for a covert channel to achieve nearly 30K bits/second on X86 CPUs. More precise attacks can likely be developed as the vulnerability becomes better understood.
title Memory DisOrder: Memory Re-orderings as a Timerless Side-channel
topic Cryptography and Security
Hardware Architecture
url https://arxiv.org/abs/2601.08770