Janus: Compiler-Based Defense Against Transient Execution Attacks Using ARM Hardware Primitives

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ouyang, Ciyan, Li, Peinan, Huang, Yubiao, Meng, Dan, Hou, Rui
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917479849132032
author Ouyang, Ciyan
Li, Peinan
Huang, Yubiao
Meng, Dan
Hou, Rui
author_facet Ouyang, Ciyan
Li, Peinan
Huang, Yubiao
Meng, Dan
Hou, Rui
contents We present Janus, a compiler-based security framework that mitigates transient execution attacks like Spectre and control-flow hijacking on ARM64 platforms. Janus integrates speculative execution and control flow dependencies with PA modifiers, using PA and BTI microarchitectural features to prevent control-flow speculation attacks and secure both control flow and speculative execution through existing control-flow integrity mechanisms. To optimize performance, Janus minimizes overhead by merging defense operations across different defense layers (modifier fusion) and reusing registers of protected variables (carrier reuse), while maintaining strong security guarantees. Evaluation on SPEC CPU2017 shows an average performance overhead of 3.85%, with real-world applications exhibiting overheads ranging from 2.97% to 7.80%. Janus offers effective speculative execution security and low performance and code size overhead, making it a robust solution for ARM-based systems.
format Preprint
id arxiv_https___arxiv_org_abs_2605_10049
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Janus: Compiler-Based Defense Against Transient Execution Attacks Using ARM Hardware Primitives
Ouyang, Ciyan
Li, Peinan
Huang, Yubiao
Meng, Dan
Hou, Rui
Cryptography and Security
D.4.6; C.1.3; D.3.4
We present Janus, a compiler-based security framework that mitigates transient execution attacks like Spectre and control-flow hijacking on ARM64 platforms. Janus integrates speculative execution and control flow dependencies with PA modifiers, using PA and BTI microarchitectural features to prevent control-flow speculation attacks and secure both control flow and speculative execution through existing control-flow integrity mechanisms. To optimize performance, Janus minimizes overhead by merging defense operations across different defense layers (modifier fusion) and reusing registers of protected variables (carrier reuse), while maintaining strong security guarantees. Evaluation on SPEC CPU2017 shows an average performance overhead of 3.85%, with real-world applications exhibiting overheads ranging from 2.97% to 7.80%. Janus offers effective speculative execution security and low performance and code size overhead, making it a robust solution for ARM-based systems.
title Janus: Compiler-Based Defense Against Transient Execution Attacks Using ARM Hardware Primitives
topic Cryptography and Security
D.4.6; C.1.3; D.3.4
url https://arxiv.org/abs/2605.10049