dorsal/arxiv
View SchemaMemory DisOrder: Memory Re-orderings as a Timerless Side-channel
| Authors | Sean Siddens, Sanya Srivastava, Reese Levine, Josiah Dykstra, Tyler Sorensen |
|---|---|
| Categories | |
| ArXiv ID | 2601.08770vv1 |
| URL | https://arxiv.org/abs/2601.08770 |
| License | http://creativecommons.org/licenses/by/4.0/ |
Abstract
To improve efficiency, nearly all parallel processing units (CPUs and GPUs) implement relaxed memory models in which memory operations may be re-ordered, i.e., executed out-of-order. Prior testing work in this area found that memory re-orderings are observed more frequently when other cores are active, e.g., stressing the memory system, which likely triggers aggressive hardware optimizations. In this work, we present Memory DisOrder: a timerless side-channel that uses memory re-orderings to infer activity on other processes. We first perform a fuzzing campaign and show that many mainstream processors (X86/Arm/Apple CPUs, NVIDIA/AMD/Apple GPUs) are susceptible to cross-process signals. We then show how the vulnerability can be used to implement classic attacks, including a covert channel, achieving up to 16 bits/second with 95% accuracy on an Apple M3 GPU, and application fingerprinting, achieving reliable closed-world DNN architecture fingerprinting on several CPUs and an Apple M3 GPU. Finally, we explore how low-level system details can be exploited to increase re-orderings, showing the potential for a covert channel to achieve nearly 30K bits/second on X86 CPUs. More precise attacks can likely be developed as the vulnerability becomes better understood.
{
"annotation_id": "4df85b1d-2197-468d-8d5d-c483bf61b309",
"date_created": "2026-02-17T05:53:16.087000Z",
"date_modified": "2026-02-17T05:53:16.087000Z",
"file_hash": "812643a262953cf26e31ae9d277cf0f55621a6501f58ffcbb3ee58afc545dc54",
"private": false,
"record": {
"abstract": "To improve efficiency, nearly all parallel processing units (CPUs and GPUs) implement relaxed memory models in which memory operations may be re-ordered, i.e., executed out-of-order. Prior testing work in this area found that memory re-orderings are observed more frequently when other cores are active, e.g., stressing the memory system, which likely triggers aggressive hardware optimizations.\n In this work, we present Memory DisOrder: a timerless side-channel that uses memory re-orderings to infer activity on other processes. We first perform a fuzzing campaign and show that many mainstream processors (X86/Arm/Apple CPUs, NVIDIA/AMD/Apple GPUs) are susceptible to cross-process signals. We then show how the vulnerability can be used to implement classic attacks, including a covert channel, achieving up to 16 bits/second with 95% accuracy on an Apple M3 GPU, and application fingerprinting, achieving reliable closed-world DNN architecture fingerprinting on several CPUs and an Apple M3 GPU. Finally, we explore how low-level system details can be exploited to increase re-orderings, showing the potential for a covert channel to achieve nearly 30K bits/second on X86 CPUs. More precise attacks can likely be developed as the vulnerability becomes better understood.",
"arxiv_id": "2601.08770",
"authors": [
"Sean Siddens",
"Sanya Srivastava",
"Reese Levine",
"Josiah Dykstra",
"Tyler Sorensen"
],
"categories": [
"cs.CR",
"cs.AR"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"title": "Memory DisOrder: Memory Re-orderings as a Timerless Side-channel",
"url": "https://arxiv.org/abs/2601.08770",
"version": "v1"
},
"schema_id": "dorsal/arxiv",
"source": {
"execution_id": "188b806f-e444-4ba3-b0e2-9a4977ce9871",
"id": "arXiv Dataset",
"type": "Model",
"variant": "snapshot-2026-01-17",
"version": "0.1.0"
},
"user_id": 1000002
}