Performance of microarchitectural attacks in realistic environments

Characterize how microarchitectural side-channel attacks perform in realistic environments rather than only in highly controlled or simplified systems, including under practical noise, privilege, configuration, and workload conditions.

Background

The survey identifies evaluations that rely on fixed CPU frequencies, isolated cores, disabled operating-system services, disabled prefetchers, privileged access, specially instrumented victims, or trivial payloads. Such conditions may demonstrate feasibility while failing to reflect the threat model or deployment conditions relevant to an actual attack.

The authors explicitly state that, for attacks evaluated only in these constrained settings, their behavior in realistic environments is unresolved. This motivates the paper’s recommendation that future evaluations vary system configurations, noise levels, access privileges, and workloads.

References

Due to all those aspects, it is unclear how the attacks would perform in realistic environments.

Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel Attacks  (2609.03893 - Fayolle et al., 3 Sep 2026) in Section 6, subsection “B4 Benchmarks only on highly controlled/simplified systems”