@inproceedings{9746e59796fc4ac2bf2b173bf263e2ab,
title = "XcptProof: Formal Verification of CPU Exception Transient Execution Security via Leakage Contracts",
abstract = "Transient execution attacks triggered by CPU exceptions, such as Meltdown and MDS-type attacks, have compromised system security. Unfortunately, no prior work has conducted a formalized analysis of the CPU exception transient execution security. To bridge this gap, we propose a framework, XcptProof, which primarily consists of two components: (1) defining exception-related hardware-software contracts to model the CPU's leakage capabilities, and (2) utilizing a formal verification methods to exhaustively analyze the CPU's satisfiability of given contracts. We introduce a miter-circuit based detection model and further incorporate a frontend-backend decoupling approach to optimize efficiency. XcptProof successfully verifies 49 contracts on the BOOM processor and confirms the effectiveness of the frontend-backend decoupling optimization.",
keywords = "CPU exception, Microarchitectural security, formal hardware verification, leakage contract, transient execution attack",
author = "Shixuan Zhang and Yujia Zhang and Kexin Gong and Hongpeng Wang and Haixia Wang and Dongsheng Wang",
note = "Publisher Copyright: {\textcopyright} 2026 Copyright held by the owner/author(s).; 36th Great Lakes Symposium on VLSI, GLSVLSI 2026 ; Conference date: 22-06-2026 Through 24-06-2026",
year = "2026",
month = jun,
day = "22",
doi = "10.1145/3787109.3815242",
language = "英语",
series = "GLSVLSI 2026 - Proceedings of the Great Lakes Symposium on VLSI 2026",
publisher = "Association for Computing Machinery, Inc",
pages = "665--671",
editor = "Fan Chen and Peipei Zhou and Jie Gu and Trivedi, \{Amit R.\} and Xiaoxuan Yang",
booktitle = "GLSVLSI 2026 - Proceedings of the Great Lakes Symposium on VLSI 2026",
}