Skip to main navigation Skip to search Skip to main content

Phantom Trails: Practical Pre-Silicon Discovery of Transient Data Leaks

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Transient execution vulnerabilities have affected CPUs for the better part of the decade, yet, we are still missing methods to efficiently uncover them at the design stage. Existing approaches try to find programs that leak explicitly defined secrets, sometimes including the transmission over a side-channel, which severely restricts the space of programs that can trigger detection. As a result, current fuzzers are forced to constrain the search space using templates of known vulnerabilities, which risks overfitting. What is missing is a general detection mechanism that (1) makes it easy for the fuzzer to trigger a violation and (2) catches vulnerabilities at their root cause - similarly to sanitizers in software. In this paper, we propose Phantom Trails, an efficient yet generic method for discovering transient execution vulnerabilities. Phantom Trails relies on a fuzzer-friendly detection model that can be applied without the need for templating. Our detector builds on two key design choices. First, it concentrates on finding microarchitectural data leaks independently of the covert channel, thereby focusing on the core of the attack. Second, it automatically infers all secret locations from the architectural behavior of a program, making it easier for the detector to find leaks. We evaluate Phantom Trails by fuzzing the BOOM RISC-V CPU, where it finds all known speculative vulnerabilities in 24-hours, starting from an empty seed and without pre-defined templates, as well as a new Spectre variant specific to BOOM - Spectre-LoopPredictor.

Original languageEnglish
Title of host publicationProceedings of the 34th USENIX Security Symposium
PublisherUSENIX Association
Pages2539-2556
Number of pages18
ISBN (Electronic)9781939133526
DOIs
Publication statusPublished - 2025
Event34th USENIX Security Symposium, USENIX Security 2025 - Seattle, United States
Duration: 13 Aug 202515 Aug 2025

Conference

Conference34th USENIX Security Symposium, USENIX Security 2025
Country/TerritoryUnited States
CitySeattle
Period13/08/2515/08/25

Bibliographical note

Publisher Copyright:
© 2025 by The USENIX Association All Rights Reserved.

Funding

The authors would like to thank the anonymous reviewers for their valuable feedback, and Nassim Corteggiani for his early feedback on the project. This work was supported by Intel Corporation through the “Allocamelus” project, by NWO (through project “INTERSECT”, the Gravitation “CiCS” project grant 024.006.037, and the Dutch Prize for ICT research), by the EU’s Horizon Europe programme (under grant No. 101120962, “Rescale”), and the European Research Council (through ERC Starting Grant no. 101115046 “SecuStack”, and ERC Advanced Grant no. 101141972 “Ghost-buster”).

FundersFunder number
Intel Corporation
Dutch Prize for ICT Research
Nederlandse Organisatie voor Wetenschappelijk Onderzoek024.006.037
HORIZON EUROPE Framework Programme101120962
European Research Council101115046, 101141972

    Fingerprint

    Dive into the research topics of 'Phantom Trails: Practical Pre-Silicon Discovery of Transient Data Leaks'. Together they form a unique fingerprint.

    Cite this