Sigries Rowhammer Vulnerability & FiRM

Arxiv pdf 2026-08-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

This paper studies efficient and secure Rowhammer mitigation at the Memory-Controller (MC). Rowhammer mitigation faces a fundamental tradeoff between tracking storage and mitigation rate: precise trackers (such as Misra-Gries) avoid unnecessary mitigations but require large CAM structures, whereas sampling-based schemes (such as PARA) require no storage but incur frequent mitigations even when not under attack. Microsoft recently deployed Sigries, an MC-side Rowhammer defense that combines an under-provisioned Misra-Gries tracker with a rowsampling fallback, in its Azure Cobalt 200 SoC. Sigries observed that the tracker-to-sampling transition can be insecure, and claimed the reverse transition is always safe. Our analysis shows that this transition is also vulnerable, and that a Round-Robin Attack across sub-banks reduces the Mean-Time-To-Failure of Sigries to about one second, eight orders of magnitude below the 13 years with PARA. Sigries also suffers from CAM complexity and high storage overheads. Our goal is to develop a solution that is fully secure and minimizes the storage and complexity of Sigries, while matching its performance.

Loading executive summary...

LINK COPIED TO CLIPBOARD