A Low-Cost Secure Branch Predictor to Mitigate the Speculative Attacks by Disrupting Setup Phase
Runye Ding, Yuyang Liu, Yujie Chen, Yao Liu, Zhiyi Yu · IEEE Transactions on Very Large Scale Integration (VLSI) Systems · 2025
Many types of speculative attacks that exploit branch prediction bear a malicious training process on the branch predictor (BP) in the setup phase. Currently, defense mechanisms on the BP have been rarely studied, and the existing works are restricted to typical scenarios. In this article, we propose a low-cost secure BP to mitigate speculative attacks by monitoring suspicious branch prediction behaviors in all circumstances. We propose a secure mechanism to evaluate the risk level for every branch in the pattern history table. Additionally, we utilize a random number generator to randomly invert the prediction result so as to disrupt the training process, according to the risk level and the generated random number. The maximum inversion probability can be real-time configured during operation. Typically, we implement it on the BI-MODE BP in XuanTie-C910 RISC-V core with a minimal system on chip on field-programmable gate array (FPGA). The realistic hardware evaluation under SPEC2017 with Linux shows that, under the optimal tradeoff between security and performance with the maximum inversion probability of 20%, the hardware and performance overhead are less than 1%, and the speculative attacks including Spectre v1.x and Meltdown can be mitigated with the rates of 44%–88%.