PMU-Data: Data Traces Could be Distinguished

📅 2025-02-15
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work uncovers an overlooked data-dependent trace leakage in Performance Monitoring Units (PMUs): for the first time, it demonstrates that PMU event counts—particularly for DIV and MOV instructions—exhibit strong dependence on operand values. Leveraging this insight, we propose PMU-Data, a novel microarchitectural side-channel attack paradigm that infers sensitive operand values solely from PMU events, without relying on cache states or timing measurements. PMU-Data employs five control-flow-invariant data-encoding gadgets to encode operand information into observable PMU counters. We empirically validate 40 exploitable PMU events across three mainstream processors, successfully achieving kernel data exfiltration, cross-privilege-level covert channel establishment, and secret extraction from trusted execution environments (TEEs). This work fundamentally expands the PMU threat model beyond traditional side channels, revealing a previously unaddressed class of hardware-assisted data leakage—and provides critical implications for the design of secure hardware-assisted mechanisms.

Technology Category

Data Mining & Knowledge Management: Data Stream MiningMachine Learning: Hardware-aware MLApplication Domains: Security

Application Category

Security and Privacy: Data transparency and provenanceUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsSystems and Infrastructure for Web, Mobile and WoT: Data management and stream processing for Web, mobile and wireless applications
📝 Abstract
Modern processors widely equip the Performance Monitoring Unit (PMU) to collect various architecture and microarchitecture events. Software developers often utilize the PMU to enhance program's performance, but the potential side effects that arise from its activation are often disregarded. In this paper, we find that the PMU can be employed to retrieve instruction operands. Based on this discovery, we introduce PMU-Data, a novel category of side-channel attacks aimed at leaking secret by identifying instruction operands with PMU. To achieve the PMU-Data attack, we develop five gadgets to encode the confidential data into distinct data-related traces while maintaining the control-flow unchanged. We then measure all documented PMU events on three physical machines with different processors while those gadgets are performing. We successfully identify two types of vulnerable gadgets caused by DIV and MOV instructions. Additionally, we discover 40 vulnerable PMU events that can be used to carry out the PMU-Data attack. We through real experiments to demonstrate the perniciousness of the PMU-Data attack by implementing three attack goals: (1) leaking the kernel data illegally combined with the transient execution vulnerabilities including Meltdown, Spectre, and Zombieload; (2) building a covert-channel to secretly transfer data; (3) extracting the secret data protected by the Trusted Execution Environment (TEE) combined with the Zombieload vulnerability.
Problem

Research questions and friction points this paper is trying to address.

PMU enables side-channel attacks
Identify instruction operands leakage
Exploit PMU for secret data extraction
Innovation

Methods, ideas, or system contributions that make the work stand out.

PMU-Data side-channel attacks
Encoding data with gadgets
Exploiting PMU event vulnerabilities
🔎 Similar Papers
No similar papers found.
Z
Zhouyang Li
Key Laboratory of Trustworthy Distributed Computing and Service (BUPT), Ministry of Education, Beijing, China; Zhongguancun Laboratory, Beijing, China
Pengfei Qiu
Pengfei Qiu
Beijing University of Posts and Telecommunications
Hardware Security
Y
Yu Qing
Zhongguancun Laboratory, Beijing, China
C
Chunlu Wang
Key Laboratory of Trustworthy Distributed Computing and Service (BUPT), Ministry of Education, Beijing, China
D
Dongsheng Wang
Zhongguancun Laboratory, Beijing, China; Tsinghua University, Beijing, China
X
Xiao Zhang
Beijing University of Technology
Gang Qu
Gang Qu
University of Maryland
low powerembedded systemwireless sensor networksecurityinformation hiding