RISC-V hardware attack detection using on-chip hardware performance counters
Abstract Hardware attacks exploit microarchitectural vulnerabilities at the CPU level, and RISC-V processors are no exception. These attacks induce anomalous behavior by stressing specific hardware components beyond the patterns observed in legitimate applications. Such deviations can be captured through internal monitoring units, namely Hardware Performance Counters (HPCs). This work analyzes a diverse set of hardware attacks on the RISC-V XuanTie C910 core and introduces a methodology that integrates HPC logging with Machine Learning (ML) techniques for automated attack detection. We present a reproducible dataset composed of 16 benign and 16 malicious applications, enabling systematic evaluation of classifiers such as Random Forest, Decision Trees, Support Vector Machines, and Naive Bayes. Feature-selection strategies, including mRMR and RFECV, are applied to identify the most informative counters. Experimental results show a detection precision of 99% for both benign and malicious samples, while classification performance for malicious samples remains around 95%. In zero-day scenarios, feature selection proves essential: mRMR achieves the best performance with Random Forest, whereas RFECV is more effective for Decision Trees. Overall, the study demonstrates that HPC-based monitoring combined with machine learning provides a hardware-centric and proactive defense mechanism against microarchitectural threats in RISC-V processors.
Authors
- R. Canal (ORCID: https://orcid.org/0000-0002-0465-2829)
- Beatriz Otero (ORCID: https://orcid.org/0000-0002-9194-559X)
- Albert Pou
- Miguel Robledo
- Alejandro Pajuelo
Institutions
- Universitat Politècnica de Catalunya (ES)
Publication Details
- Journal
- Cybersecurity
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1186/s42400-026-00662-8
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00