Spectre HPC Detection Variance

Arxiv other 2026-08-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Hardware attacks like Spectre exploit built-in processor vulnerabilities, leaving anomalous footprints in Hardware Performance Counter (HPC) metrics. While machine learning can detect these footprints in controlled settings, static models fail in the real world when confronted with background system noise, diverse attack variants, and adversarial traffic pacing. To close this gap, this paper characterizes the variance envelopethe full range of how attack signatures shiftacross Intel, ARM, and AMD architectures. We evaluate an extensive experimental matrix encompassing three attack variants, four pacing modes, and four background-noise conditions. Our analysis proves that HPC signatures are highly fragile and easily warped by their execution environment. Furthermore, we expose a critical microarchitectural bottleneck: the persistent, hardware-level failure of Prime+Probe attacks on the AMD Jaguar. Ultimately, this comprehensive characterization demonstrates the fundamental limits of static detection thresholds. By proving that signatures are deeply intertwined with underlying execution environments, this study establishes the empirical foundation required for future work in advanced adaptive modeling and hybrid detection architectures.

Loading executive summary...

LINK COPIED TO CLIPBOARD