arrow
Return

Detecting Speculative Data Flow Vulnerabilities Using Weakest Precondition Reasoning

delete2026-01-01
delete0
PRE
AI
G
Graeme Smith *
DOI:10.1007/978-3-031-98208-8_19delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Speculative execution is a hardware optimisation technique where a processor, while waiting on the completion of a computation required for an instruction, continues to execute later instructions based on a predicted value of the pending computation. It came to the forefront of security research in 2018 with the disclosure of two related attacks, Spectre and Meltdown. Since then many similar attacks have been identified. While there has been much research on using formal methods to detect speculative execution vulnerabilities based on predicted control flow, there has been significantly less on vulnerabilities based on predicted data flow. In this paper, we introduce an approach for detecting the data flow vulnerabilities, Spectre-STL and Spectre-PSF, using weakest precondition reasoning. We validate our approach on a suite of litmus tests used to validate related approaches in the literature.
Keywords:
Speculative Execution
Data Flow Vulnerabilities
Weakest Precondition Reasoning
Spectre Attacks
Formal Methods

Journal

T
THEORETICAL ASPECTS OF SOFTWARE ENGINEERING, TASE 2025
IF:
0
Papers:
17
Citations:
0

Organization

D
defence science & technology
Scholars:
896
Papers: 938
Citations: 0