The rapid adoption of the open and extensible RISC-V instruction set architecture across diverse computing domains requires a thorough understanding of its security posture, particularly against hardware threats. While performance optimizations like speculative and out-of-order execution enhance throughput, they concurrently introduce vulnerabilities to Transient Execution Attacks (TEAs), which can bypass traditional security mechanisms. The inherent flexibility of RISC-V leads to significant microarchitectural variation among implementations, suggesting that susceptibility to TEAs is not uniform. However, systematic comparative assessments across prominent processors are still lacking. This paper addresses this gap by presenting a comparative vulnerability analysis of three widely used open-source RISC-V cores: the high performance BOOM, the reliability-oriented NOEL-V, and CVA6. We ported and evaluated a set of TEAs, including variants of Spectre and Meltdown and the most recent attacks, such as Speculative Code Store Bypass (SCSB) and Indirector. Our experiments demonstrate the successful execution of different attack subsets on each processor, revealing distinct vulnerability profiles tied to their underlying microarchitectures, offering valuable vulnerability data and practical insights that may be crucial for guiding the design of more secure processors. One of the key insights of our analysis is that, contrary to the popular belief, in-order processors are vulnerable against TEAs.

Assessing the Vulnerability of Open-Source RISC-V Processors to Transient Execution Attacks

Lazzeri, Elia;Cassano, Luca
2026-01-01

Abstract

The rapid adoption of the open and extensible RISC-V instruction set architecture across diverse computing domains requires a thorough understanding of its security posture, particularly against hardware threats. While performance optimizations like speculative and out-of-order execution enhance throughput, they concurrently introduce vulnerabilities to Transient Execution Attacks (TEAs), which can bypass traditional security mechanisms. The inherent flexibility of RISC-V leads to significant microarchitectural variation among implementations, suggesting that susceptibility to TEAs is not uniform. However, systematic comparative assessments across prominent processors are still lacking. This paper addresses this gap by presenting a comparative vulnerability analysis of three widely used open-source RISC-V cores: the high performance BOOM, the reliability-oriented NOEL-V, and CVA6. We ported and evaluated a set of TEAs, including variants of Spectre and Meltdown and the most recent attacks, such as Speculative Code Store Bypass (SCSB) and Indirector. Our experiments demonstrate the successful execution of different attack subsets on each processor, revealing distinct vulnerability profiles tied to their underlying microarchitectures, offering valuable vulnerability data and practical insights that may be crucial for guiding the design of more secure processors. One of the key insights of our analysis is that, contrary to the popular belief, in-order processors are vulnerable against TEAs.
2026
2026 IEEE 29th International Symposium on Design and Diagnostics of Electronic Circuits and Systems, DDECS 2026
Hardware Security
Microprocessors
RISC-V
Security Benchmarking
Transient Execution Attacks
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11311/1323930
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact