RISC-V hardware attack detection using on-chip hardware performance counters

Abstract Hardware attacks exploit microarchitectural vulnerabilities at the CPU level, and RISC-V processors are no exception. These attacks induce anomalous behavior by stressing specific hardware components beyond the patterns observed in legitimate applications. Such deviations can be captured through internal monitoring units, namely Hardware Performance Counters (HPCs). This work analyzes a diverse set of hardware attacks on the RISC-V XuanTie C910 core and introduces a methodology that integrates HPC logging with Machine Learning (ML) techniques for automated attack detection. We present a reproducible dataset composed of 16 benign and 16 malicious applications, enabling systematic evaluation of classifiers such as Random Forest, Decision Trees, Support Vector Machines, and Naive Bayes. Feature-selection strategies, including mRMR and RFECV, are applied to identify the most informative counters. Experimental results show a detection precision of 99% for both benign and malicious samples, while classification performance for malicious samples remains around 95%. In zero-day scenarios, feature selection proves essential: mRMR achieves the best performance with Random Forest, whereas RFECV is more effective for Decision Trees. Overall, the study demonstrates that HPC-based monitoring combined with machine learning provides a hardware-centric and proactive defense mechanism against microarchitectural threats in RISC-V processors.

Authors

Institutions

Publication Details

Journal
Cybersecurity
Published
2026-09-24
DOI
https://doi.org/10.1186/s42400-026-00662-8
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

RISC-V hardware attack detection using on-chip hardware performance counters

R. Canal, Beatriz Otero, Albert Pou, Miguel Robledo et al.
Cybersecurity
Security and Verification in Computing
article

RISC-V hardware attack detection using on-chip hardware performance counters

R. Canal, Beatriz Otero, Albert Pou, Miguel Robledo, Alejandro Pajuelo
article en

Abstract

Abstract Hardware attacks exploit microarchitectural vulnerabilities at the CPU level, and RISC-V processors are no exception. These attacks induce anomalous behavior by stressing specific hardware components beyond the patterns observed in legitimate applications. Such deviations can be captured through internal monitoring units, namely Hardware Performance Counters (HPCs). This work analyzes a diverse set of hardware attacks on the RISC-V XuanTie C910 core and introduces a methodology that integrates HPC logging with Machine Learning (ML) techniques for automated attack detection. We present a reproducible dataset composed of 16 benign and 16 malicious applications, enabling systematic evaluation of classifiers such as Random Forest, Decision Trees, Support Vector Machines, and Naive Bayes. Feature-selection strategies, including mRMR and RFECV, are applied to identify the most informative counters. Experimental results show a detection precision of 99% for both benign and malicious samples, while classification performance for malicious samples remains around 95%. In zero-day scenarios, feature selection proves essential: mRMR achieves the best performance with Random Forest, whereas RFECV is more effective for Decision Trees. Overall, the study demonstrates that HPC-based monitoring combined with machine learning provides a hardware-centric and proactive defense mechanism against microarchitectural threats in RISC-V processors.

CybersecurityVol. 9(1)
Universitat Politècnica de Catalunya (ES)
Life in Land
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

RISC-V hardware attack detection using on-chip hardware performance counters — R. Canal, Beatriz Otero, et al. · Cybersecurity (2026) | TGRS Research Map | TGRS