Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event
Abstract
1. Introduction
- A comprehensive dataset is constructed by combining multiple web-based LLM workloads with a wide range of Spectre attacks, enabling systematic analysis under realistic microarchitectural interference.
- The interaction between Spectre attack detection and concurrent web-based LLM execution is systematically investigated, providing new insights and research directions for attack detection in AI-intensive environments.
- A detailed statistical analysis of L1, L2, and L3 cache related HPC events is conducted to identify the most sensitive and robust indicators of Spectre attack behavior under LLM-induced noise.
- A novel Spectre attack detection method Spec-LAMP is proposed, significantly improving detection accuracy in the presence of web-based LLM workloads. The source code of Spec-LAMP is publicly available at: https://github.com/Hamster-K/Spec-LAMP (accessed on 17 January 2026).
2. Background
2.1. Web-Based LLMs
2.2. Spectre Attacks and Variants
- Spectre-PHT (Variant 1): This variant exploits the processor’s branch predictor, specifically the Pattern History Table (PHT), to mispredict conditional branches [7]. Attackers train the predictor to speculatively execute code that accesses secret data, which is then leaked through cache side channels.
- Spectre-BTB (Variant 2): This variant targets indirect branches by poisoning the Branch Target Buffer (BTB) [7,16]. By redirecting the speculative control flow to a gadget containing secret-dependent memory accesses, attackers can leak information based on the outcomes of this speculative execution.
- Meltdown (Variant 3): Meltdown, exploits delayed permission checks on speculative memory loads [17]. During speculative execution, unauthorized memory accesses may transiently succeed and populate cache lines before permission checks are enforced. Although Meltdown is sometimes categorized separately from Spectre, it shares the same fundamental principle of transient execution leakage.
- Spectre-SSB (Variant 4): This variant abuses memory disambiguation in speculative execution [16]. It allows a load instruction to speculatively bypass a previous store, potentially exposing stale or sensitive values that should have been overwritten, thereby leaking information across security boundaries.
2.3. HPC-Based Detection for Spectre Attack and Variants
3. Proposed Methodology
3.1. Motivation
3.2. Hybrid Statistical HPC Feature Ranking and Selection for Spec-LAMP
| Algorithm 1: Statistical Ranking of HPC Events under Web-based LLM Workloads |
![]() |
3.3. Overall Spec-LAMP Framework
3.3.1. Dataset Collection
3.3.2. Model Training with Selected HPC Events
3.3.3. Attack Detection and Evaluation
4. Results and Analysis
4.1. Experimental Setup and Dataset Construction
4.2. Spec-LAMP Detection Performance Under Spectre Variants and Web-LLM Interference
4.3. Spec-LAMP Robustness Under Web-LLM Interference
4.3.1. Impact of LLM Variations Within the Same Platform
4.3.2. Cross-Service Generalization Under Leave-One-Service-Out (LOSO) Evaluation
4.4. HPC Feature Importance Analysis of Spec-LAMP
4.5. Discussion
5. Related Work
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Liang, Z.; Xu, Y.; Hong, Y.; Shang, P.; Wang, Q.; Fu, Q.; Liu, K. A Survey of Multimodel Large Language Models. In Proceedings of the 3rd International Conference on Computer, Artificial Intelligence and Control Engineering; ACM: New York, NY, USA, 2024; pp. 405–409. [Google Scholar] [CrossRef] [Scilit]
- Liu, A.; Feng, B.; Xue, B.; Wang, B.; Wu, B.; Lu, C.; Zhao, C.; Deng, C.; Zhang, C.; Ruan, C.; et al. DeepSeek-V3 Technical Report. arXiv 2024, arXiv:2412.19437. [Google Scholar]
- Team, K.; Bai, Y.; Bao, Y.; Chen, G.; Chen, J.; Chen, N.; Chen, R.; Chen, Y.; Chen, Y.; Chen, Y.; et al. Kimi K2: Open Agentic Intelligence. arXiv 2025, arXiv:2507.20534. [Google Scholar] [CrossRef] [Scilit]
- Gong, L.; Hou, X.; Li, F.; Li, L.; Lian, X.; Liu, F.; Liu, L.; Liu, W.; Lu, W.; Shi, Y.; et al. Seedream 2.0: A Native Chinese–English Bilingual Image Generation Foundation Model. arXiv 2025, arXiv:2503.07703. [Google Scholar]
- Bai, J.; Bai, S.; Chu, Y.; Cui, Z.; Dang, K.; Deng, X.; Fan, Y.; Ge, W.; Han, Y.; Huang, F.; et al. Qwen Technical Report. arXiv 2023, arXiv:2309.16609. [Google Scholar] [CrossRef] [Scilit]
- Sayadi, H.; He, Z.; Makrani, H.M.; Homayoun, H. Intelligent Malware Detection Based on Hardware Performance Counters: A Comprehensive Survey. In Proceedings of the 25th International Symposium on Quality Electronic Design (ISQED); IEEE: New York, NY, USA, 2024; pp. 1–10. [Google Scholar] [CrossRef] [Scilit]
- Kocher, P.; Horn, J.; Fogh, A.; Genkin, D.; Gruss, D.; Haas, W.; Hamburg, M.; Lipp, M.; Mangard, S.; Prescher, T.; et al. Spectre Attacks: Exploiting Speculative Execution. Commun. ACM 2020, 63, 93–101. [Google Scholar] [CrossRef] [Scilit]
- Li, C.; Gaudiot, J.-L. Detecting Spectre Attacks Using Hardware Performance Counters. IEEE Trans. Comput. 2022, 71, 1320–1331. [Google Scholar] [CrossRef] [Scilit]
- Jiao, J.; Wen, R.; Li, Y. T-Smade: A Two-Stage Smart Detector for Evasive Spectre Attacks under Various Workloads. Electronics 2024, 13, 4090. [Google Scholar] [CrossRef] [Scilit]
- Polychronou, N.F.; Thevenon, P.-H.; Puys, M.; Beroulle, V. MaDMAN: Detection of Software Attacks Targeting Hardware Vulnerabilities. In Proceedings of the 24th Euromicro Conference on Digital System Design (DSD); IEEE: New York, NY, USA, 2021; pp. 355–362. [Google Scholar] [CrossRef] [Scilit]
- Wang, Q.; Jiang, S.; Chen, Z.; Cao, X.; Li, Y.; Li, A.; Ma, Y.; Cao, T.; Liu, X. Anatomizing Deep Learning Inference in Web Browsers. ACM Trans. Softw. Eng. Methodol. 2025, 34, 47. [Google Scholar] [CrossRef] [Scilit]
- Gulmezoglu, B.; Zankl, A.; Eisenbarth, T.; Sunar, B. PerfWeb: How to Violate Web Privacy with Hardware Performance Events. In Proceedings of the European Symposium on Research in Computer Security (ESORICS); Springer: Berlin/Heidelberg, Germany, 2017; pp. 80–97. [Google Scholar] [CrossRef] [Scilit]
- Jiao, J.; Jiang, L.; Zhou, Q.; Wen, R. Evaluating Large Language Model Application Impacts on Evasive Spectre Attack Detection. Electronics 2025, 14, 1384. [Google Scholar] [CrossRef] [Scilit]
- Wikner, J.; Giuffrida, C.; Bos, H.; Razavi, K. Spring: Spectre Returning in the Browser with Speculative Load Queuing and Deep Stacks. In Proceedings of the 16th IEEE Workshop on Offensive Technologies (WOOT 2022), San Francisco, CA, USA, 26 May 2022; IEEE: Piscataway, NJ, USA, 2022. [Google Scholar]
- Zhang, J.; Chen, C.; Cui, J.; Li, K. Timing Side-Channel Attacks and Countermeasures in CPU Microarchitectures. ACM Comput. Surv. 2024, 56, 178. [Google Scholar] [CrossRef] [Scilit]
- Canella, C.; Van Bulck, J.; Schwarz, M.; Lipp, M.; Von Berg, B.; Ortner, P.; Piessens, F.; Evtyushkin, D.; Gruss, D. A Systematic Evaluation of Transient Execution Attacks and Defenses. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19); ACM: New York, NY, USA, 2019; pp. 249–266. [Google Scholar]
- Lipp, M.; Schwarz, M.; Gruss, D.; Prescher, T.; Haas, W.; Mangard, S.; Kocher, P.; Genkin, D.; Yarom, Y.; Hamburg, M. Meltdown. arXiv 2018, arXiv:1801.01207. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Das, S.; Werner, J.; Antonakakis, M.; Polychronakis, M.; Monrose, F. SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for Security. In Proceedings of the IEEE Symposium on Security and Privacy (S&P); IEEE: New York, NY, USA, 2019; pp. 20–38. [Google Scholar] [CrossRef] [Scilit]
- Li, C.; Gaudiot, J.-L. Challenges in Detecting an “Evasive Spectre”. IEEE Comput. Archit. Lett. 2020, 19, 18–21. [Google Scholar] [CrossRef] [Scilit]
- Intel Corporation. Intel® 64 and IA-32 Architectures Software Developer’s Manual, Combined Volumes 1, 2A, 2B, 2C, 2D, 3A, 3B, 3C, 3D, and 4; Intel Corporation: Santa Clara, CA, USA, 2023; Available online: https://www.intel.com/content/www/us/en/developer/articles/technical/intel-sdm.html (accessed on 17 January 2026).
- Liu, Y.; Cheng, L.; Sun, L. A Feature Selection Method Based on the Kolmogorov–Smirnov Test and Neighborhood Rough Sets. J. Henan Norm. Univ. (Nat. Sci. Ed.) 2019, 47, 21–28. [Google Scholar] [CrossRef]
- Li, J.; Othman, M.S.; Hewan, C.; Yusuf, L.M. IoT Security: A Systematic Literature Review of Feature Selection Methods for Machine Learning-Based Attack Classification. Int. J. Electron. Secur. Digit. Forensics 2025, 17, 60–107. [Google Scholar] [CrossRef] [Scilit]
- Tong, Z.; Zhu, Z.; Zhang, Y.; Liu, Y.; Meng, D. Attack Detection Based on Machine Learning Algorithms for Different Variants of Spectre Attacks and Different Meltdown Attack Implementations. arXiv 2022, arXiv:2208.14062. [Google Scholar] [CrossRef] [Scilit]
- Ahmad, B.A. Real Time Detection of Spectre and Meltdown Attacks Using Machine Learning. arXiv 2020, arXiv:2006.01442. [Google Scholar] [CrossRef] [Scilit]
- Li, C.; Gaudiot, J.-L. Online Detection of Spectre Attacks Using Microarchitectural Traces from Performance Counters. In Proceedings of the 30th International Symposium on Computer Architecture and High Performance Computing (SBAC-PAD); IEEE: Lyon, France, 2018; pp. 25–28. [Google Scholar] [CrossRef] [Scilit]
- Wang, W.; Chen, G.; Cheng, Y.; Zhang, Y.; Lin, Z. Specularizer: Detecting speculative execution attacks via performance tracing. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA); Springer: Cham, Switzerland, 2021; pp. 151–172. [Google Scholar] [CrossRef] [Scilit]
- Hassan, M.; Mushtaq, M.; Raik, J.; Ghasempouri, T. DRsam: Detection of Fault-Based Microarchitectural Side-Channel Attacks in RISC-V Using Statistical Preprocessing and Association Rule Mining. arXiv 2025, arXiv:2510.18612. [Google Scholar] [CrossRef] [Scilit]
- Lou, X.; Chen, K.; Xu, G.; Qiu, H.; Guo, S.; Zhang, T. Protecting Confidential Virtual Machines from Hardware Performance Counter Side Channels. In Proceedings of the 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN); IEEE: Piscataway, NJ, USA, 2024; pp. 195–208. [Google Scholar] [CrossRef] [Scilit]
- Volos, S.; Fournet, C.; Hofmann, J.; Köpf, B.; Oleksenko, O. Principled Microarchitectural Isolation on Cloud CPUs. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS ’24); ACM: New York, NY, USA, 2024; pp. 183–197. [Google Scholar] [CrossRef] [Scilit]





| Event Name | Description | Programming Info |
|---|---|---|
| L1D_PEND_MISS.PENDING | Measures the cumulative duration of outstanding L1D demand load misses, reflecting the number of cycles with pending fill buffer entries. | EventSel = 48H UMask = 01H |
| L1D.REPLACEMENT | Counts L1D cache line replacements, including both opportunistic and stall-inducing replacements. | EventSel = 51H UMask = 01H |
| L2_RQSTS.MISS | Counts all requests that miss the L2 cache. | EventSel = 24H UMask = 3FH |
| L2_RQSTS.REFERENCES | Counts all requests to the L2 cache. | EventSel = 24H UMask = FFH |
| L2_RQSTS.ALL_DEMAND_MISS | Counts demand requests that miss the L2 cache. | EventSel = 24H UMask = 27H |
| L2_RQSTS.ALL_DEMAND_REFERENCES | Counts demand requests to the L2 cache. | EventSel = 24H UMask = E7H |
| LONGEST_LAT_CACHE.MISS | Counts core-originated cacheable requests that miss the LLC, including data/code reads, RFOs, speculative accesses, and hardware prefetches. | EventSel = 2EH UMask = 41H |
| LONGEST_LAT_CACHE.REFERENCE | Counts core-originated cacheable requests to the LLC, including data/code reads, RFOs, speculative accesses, and hardware prefetches. | EventSel = 2EH UMask = 4FH |
| Category | Configuration |
|---|---|
| Hardware Configuration | |
| Processor | Intel Xeon Silver 4210 (Cascade Lake) |
| CPU Cores/Frequency | 20 cores @ 2.20 GHz |
| Main Memory | 125.5 GiB |
| Software Configuration | |
| Operating System | Ubuntu 18.04.6 LTS (64-bit) |
| Linux Kernel | 5.4.0-146-generic |
| HPC Collection Tool | perf 5.4.229 |
| Programming Language | Python 3.10 |
| IDE | PyCharm Professional 2022.1.3 |
| Browser | Google Chrome 144.0.7559.133 |
| Browser Automation | Selenium |
| Spectre Attack Configuration | |
| Evaluated Attack Variants | Spectre-PHT, Spectre-BTB, Meltdown, Spectre-SSB |
| Attack Implementation | Publicly available PoC with minor adaptations |
| Execution Mode | Standalone process, fresh invocation per sample |
| Attack Duration | Variant-dependent, typically ms |
| HPC Monitoring Configuration | |
| Sampling Mode | Counting mode |
| Readout Interval | 500 ms |
| Monitored HPC Events | Branches, Branch Misses, LLC References, |
| LLC Misses, L1D Miss Pending | |
| Derived Features | Branch miss rate, LLC miss rate |
| Dataset Construction and Split | |
| Execution Environments | Pure execution; Web-based LLM interference |
| LLM Services | DeepSeek, Kimi, Doubao, Qwen |
| Samples per Condition | 600 attack + 600 benign |
| Conditions per Variant | 1 pure + 4 LLM-interfered |
| Total Samples per Variant | ∼6000 |
| Training Data | Pure execution environment only |
| Testing Data | Web-based LLM interference only |
| Split Strategy | Environment-level separation (no overlap) |
| Class Balance | Strictly balanced (1:1) |
| Method | Web-LLM | Attack Variants(%) |
Average (%) |
Overall Average (%) | |||
|---|---|---|---|---|---|---|---|
| Spectre-PHT | Spectre-BTB | Meltdown | Spectre-SSB | ||||
| baseline [8] | DeepSeek | 99.3 | 99.42 | 99.3 | 94.55 | 98.14 | 85.15 |
| Kimi | 93.74 | 86.43 | 87.59 | 81.82 | 87.4 | ||
| Doubao | 87.35 | 78.56 | 70.53 | 80.16 | 79.15 | ||
| Qwen | 70.42 | 80.71 | 77.65 | 74.76 | 75.89 | ||
| None | 99.73 | 99.73 | 99.91 | 100 | 99.84 | \ | |
| Spec-LAMP | DeepSeek | 99.65 | 99.46 | 99.88 | 100 | 99.75 | 98.5 |
| Kimi | 99.77 | 97.22 | 100 | 100 | 99.25 | ||
| Doubao | 97.8 | 98.38 | 99.65 | 98.96 | 98.7 | ||
| Qwen | 95.82 | 92.93 | 96.46 | 100 | 96.3 | ||
| None | 99.91 | 100.00 | 100 | 100 | 99.98 | \ | |
| Web-LLM | Attack Variants (%) | Average (%) | Overall Average(%) | |||
|---|---|---|---|---|---|---|
| Spectre-PHT | Spectre-BTB | Meltdown | Spectre-SSB | |||
| Deepseek | 99.19 | 99.65 | 99.54 | 96.52 | 98.73 | 96.89 |
| Kimi | 99.2 | 98.03 | 98.26 | 93.27 | 97.19 | |
| Doubao | 97.22 | 99.65 | 93.62 | 95.59 | 96.52 | |
| Qwen | 93.25 | 99.84 | 93.25 | 94.21 | 95.14 | |
| Event | KS | Score | Rank | |||
|---|---|---|---|---|---|---|
| L1D_PEND_MISS.PENDING | <1 × | <1 | 83.31 | 0.87 | 1 | 1 |
| LLC_MISS_RATE | <1 | <1 | 56.97 | 0.648 | 0.681 | 2 |
| LONGEST_LAT_CACHE.MISS | <1 | 41.24 | 0.464 | 0.456 | 3 | |
| L1D.REPLACEMENT | 28.86 | 0.354 | 0.303 | 4 | ||
| LONGEST_LAT_CACHE.REFERENCE | 28.52 | 0.332 | 0.286 | 5 | ||
| L2_RQSTS.MISS | 28.21 | 0.326 | 0.28 | 6 | ||
| L2_RQSTS.ALL_DEMAND_MISS | 28.03 | 0.321 | 0.276 | 7 | ||
| L2_RQSTS.REFERENCES | 20.85 | 0.263 | 0.19 | 8 | ||
| L2_RQSTS.ALL_DEMAND_REFERENCES | 17.8 | 0.244 | 0.158 | 9 | ||
| L2_MISS_RATE | 5.73 | 0.142 | 0.011 | 10 | ||
| L2_DEMAND_MISS_RATE | 6.64 | 0.125 | 0.006 | 11 |
| Name | Event Count | TP | FN | TN | FP | Precision | Recall | F1 | Accuracy (%) |
|---|---|---|---|---|---|---|---|---|---|
| Baseline | 4 | 0.9084 | 0.0916 | 0.7946 | 0.2054 | 0.8157 | 0.9084 | 0.8595 | 85.15 |
| L1D miss pending | 5 | 0.9939 | 0.0061 | 0.9748 | 0.0252 | 0.9752 | 0.9939 | 0.9845 | 98.43 |
| L1 replacement | 5 | 0.814 | 0.186 | 0.9075 | 0.0925 | 0.8979 | 0.814 | 0.8539 | 86.07 |
| L2 misses | 5 | 0.8696 | 0.1304 | 0.8921 | 0.1079 | 0.8896 | 0.8696 | 0.8795 | 88.08 |
| L2 references | 5 | 0.8818 | 0.1182 | 0.879 | 0.121 | 0.8793 | 0.8818 | 0.8805 | 88.04 |
| L2 demand misses | 5 | 0.9126 | 0.0874 | 0.8458 | 0.1542 | 0.8555 | 0.9126 | 0.8831 | 87.92 |
| L2 demand references | 5 | 0.857 | 0.143 | 0.943 | 0.057 | 0.9376 | 0.857 | 0.8955 | 90.00 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Jiao, J.; Zhou, Q.; Li, Y. Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event. Entropy 2026, 28, 254. https://doi.org/10.3390/e28030254
Jiao J, Zhou Q, Li Y. Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event. Entropy. 2026; 28(3):254. https://doi.org/10.3390/e28030254
Chicago/Turabian StyleJiao, Jiajia, Quan Zhou, and Yulian Li. 2026. "Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event" Entropy 28, no. 3: 254. https://doi.org/10.3390/e28030254
APA StyleJiao, J., Zhou, Q., & Li, Y. (2026). Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event. Entropy, 28(3), 254. https://doi.org/10.3390/e28030254


