Towards Remote Attestation of Microarchitectural Attacks: The Case of Rowhammer

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Herrmann, Martin, Draissi, Oussama, Niesler, Christian, Sadeghi, Ahmad-Reza, Davi, Lucas
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914424220024832
author Herrmann, Martin
Draissi, Oussama
Niesler, Christian
Sadeghi, Ahmad-Reza
Davi, Lucas
author_facet Herrmann, Martin
Draissi, Oussama
Niesler, Christian
Sadeghi, Ahmad-Reza
Davi, Lucas
contents Microarchitectural vulnerabilities increasingly undermine the assumption that hardware can be treated as a reliable root of trust. Prevention mechanisms often lag behind evolving attack techniques, leaving deployed systems unable to assume continued trustworthiness. We propose a shift from prevention to detection through microarchitectural-aware remote attestation. As a first instantiation of this idea, we present HammerWatch, a Rowhammer-aware remote attestation protocol that enables an external verifier to assess whether a system exhibits hardware-induced disturbance behavior. HammerWatch leverages memory-level evidence available on commodity platforms, specifically Machine-Check Exceptions (MCEs) from ECC DRAM and counter-based indicators from Per-Row Activation Counting (PRAC), and protects these measurements against kernel-level adversaries using TPM-anchored hash chains. We implement HammerWatch on commodity hardware and evaluate it on 20000 simulated benign and malicious access patterns. Our results show that the verifier reliably distinguishes Rowhammer-like behavior from benign operation under conservative heuristics, demonstrating that detection-oriented attestation is feasible and can complement incomplete prevention mechanisms
format Preprint
id arxiv_https___arxiv_org_abs_2603_24172
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Towards Remote Attestation of Microarchitectural Attacks: The Case of Rowhammer
Herrmann, Martin
Draissi, Oussama
Niesler, Christian
Sadeghi, Ahmad-Reza
Davi, Lucas
Cryptography and Security
Microarchitectural vulnerabilities increasingly undermine the assumption that hardware can be treated as a reliable root of trust. Prevention mechanisms often lag behind evolving attack techniques, leaving deployed systems unable to assume continued trustworthiness. We propose a shift from prevention to detection through microarchitectural-aware remote attestation. As a first instantiation of this idea, we present HammerWatch, a Rowhammer-aware remote attestation protocol that enables an external verifier to assess whether a system exhibits hardware-induced disturbance behavior. HammerWatch leverages memory-level evidence available on commodity platforms, specifically Machine-Check Exceptions (MCEs) from ECC DRAM and counter-based indicators from Per-Row Activation Counting (PRAC), and protects these measurements against kernel-level adversaries using TPM-anchored hash chains. We implement HammerWatch on commodity hardware and evaluate it on 20000 simulated benign and malicious access patterns. Our results show that the verifier reliably distinguishes Rowhammer-like behavior from benign operation under conservative heuristics, demonstrating that detection-oriented attestation is feasible and can complement incomplete prevention mechanisms
title Towards Remote Attestation of Microarchitectural Attacks: The Case of Rowhammer
topic Cryptography and Security
url https://arxiv.org/abs/2603.24172