Mechanism · Workload classification from telemetry and side channels
Software-read counters can be forged by a privileged operator
On this page
Rahman and Tajdari state that without hardware-enabled guarantees, an adversary with software privilege can return forged counter values. Their results assume a tamper-resistant read path and an authenticated telemetry channel 1. Gargiulo and Kulp note that on-chip counters are read by software under the operator's control, so values could be reported without being measured, or replayed from an authorized workload while a hidden one runs 2. Against an operator who controls the full stack, forgery defeats classification from software counters, the signal source that On-chip telemetry from timing, memory and performance counters covers. It does not affect the external-probe route, which Gargiulo and Kulp argue can in principle be observed without the operator's cooperation 2.