arXiv · 2607.15118
Automated Template-free Synthesis of Instruction-Centric Leakage Contracts for Black-Box CPUs
Abstract
Side-channel attacks pose a significant security threat for modern computing platforms, because they exploit subtle discrepancies in CPU behaviors to leak sensitive information. To model the information leaked by a CPU via microarchitectural side-channels, recent work proposed leakage contracts: an ISA-level security abstraction that provides the foundations for secure CPU programming. Unfortunately, due to the complexity of current microarchitectures, devising a leakage contract for a CPU requires extensive manual effort and thus modern CPUs lack dedicated leakage contracts. We present a methodology to extract instruction-centric leakage contracts for major CPU architectures with minimal manual intervention. We implemented this technique in malcos, the first template-free tool that automates the synthesis of leakage contracts for black-box CPUs. We evaluate malcos on x86 and ARM CPUs, and show that the contracts it synthesizes are precise and sound with respect to all leaks observed during synthesis. Our results demonstrate that learning leakage contracts from black-box CPUs is feasible.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Elvira Moreno, Tiziano Marinaro, Ryan Williams, Marco Patrignani, Roberto Guanciale, Hamed Nemati, Marco Guarnieri. 2026-07-16. Automated Template-free Synthesis of Instruction-Centric Leakage Contracts for Black-Box CPUs. https://arxiv.org/abs/2607.15118
Cite the original work for its findings. Save a collection to share your selection of sources.