PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 28, 2026Entropy0 citationsOpen Access

Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event

JJJiajia JiaoQZQuan ZhouYLYulian Li

Key Points

  • This research aims to improve detection accuracy of Spectre attacks during web-based LLM workloads by addressing inherent noise issues.
  • Developed a dataset using multiple web-accessible LLMs alongside Spectre attacks.
  • Analyzed the performance of traditional hardware performance counter detectors against LLM workload interference.
  • Proposed Spec-LAMP, adding L1D Miss Pending event to enhance detection capabilities.
  • Conducted comparative statistical analysis to gauge performance improvements.
  • Discovery of significant accuracy drops in traditional HPC-based detectors due to LLM-induced noise.
  • Spec-LAMP improved detection accuracy from 85.15% to 98.43%.
  • Demonstrated superior robustness in distinguishing malicious from benign executions compared to traditional methods.

Abstract

As Large Language Models (LLMs) become increasingly integrated into web environments, they introduce complex microarchitectural noise that challenges existing hardware security mechanisms. This paper investigates the impact of concurrent web-based LLM workloads on the detection accuracy of Spectre attacks. Firstly, we constructed a representative dataset by executing multiple web-accessible LLMs (e.g., DeepSeek, Kimi, Doubao and Qwen) alongside Spectre attacks, capturing the specific interference patterns introduced by these AI workloads. Experimental analysis reveals that traditional Hardware Performance Counter (HPC)-based detectors, relying primarily on branch prediction and Last-Level Cache (LLC) events, suffer significant accuracy degradation due to the masking effects of LLM-induced noise. To address this limitation, we then propose a novel Spectre attack detector Spec-LAMP via augmenting conventional HPC feature sets with the L1D Miss Pending event. This new metric specifically captures unresolved speculative memory dependencies, a distinctive characteristic of Spectre attacks that remains discernible even under web-accessible LLM interference. Comparative statistical analysis demonstrates that incorporating this event significantly enhances the separability between malicious and benign executions. Finally, experimental results show that our proposed feature augmentation effectively restores detection performance, increasing average accuracy from 85.15% to 98.43% and demonstrating superior robustness compared to traditional approaches in realistic web-based LLM scenarios.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Jiao et al. (2026) studied this question.

synapsesocial.com/papers/69a287240a974eb0d3c02a83https://doi.org/10.3390/e28030254
Ask AI
Helpful
Bookmark
Share
View Full Paper