HOMARD

IEEE Security & Privacy 2027

HOMARD

Hammering Off-chip Memory via Aggregate power Rail Disclosure

HOMARD leaks data moving through DRAM using onboard power sensors. We introduce two primitives: HOMARD-DATA to recover data, and HOMARD-RE to recover memory mappings. All from software.

Paper and code coming soon.

HOMARD lobster holding a hammer and a magnifying glass

> Main contribution

HOMARD-DATA

Recover secret data from DRAM power.

Power consumption depends on the values transferred from memory. HOMARD-DATA lets us recover the number of set bits in a memory block and leak secret byte values using software-accessible power measurements.

81.5%

Hamming-weight accuracy

Classifies nine Hamming-weight levels on Raspberry Pi 5. Hamming weight is the number of bits set to one.

Bytes

Recovered in minutes

Recovers secret byte values from DRAM power measurements on Raspberry Pi 5 in our evaluation.

Spectre

Speculative loads leak too

Demonstrated with architectural loads and a Spectre-RSB path, where the value is not architecturally read.

Results depend on the platform and the profiling and access assumptions described in the paper.

> Second primitive

HOMARD-RE

Recover the memory mapping.

HOMARD-RE recovers DRAM addressing functions from power measurements. It reveals how addresses map to the memory hierarchy, including on the Jetson TX2 where row-buffer timing methods fail.

AMD ZCU102Raspberry Pi 5NVIDIA Jetson TX2

> Paper & code

Read. Cite. Explore.

HOMARD: Hammering Off-chip Memory via Aggregate power Rail Disclosure

To appear at the IEEE Symposium on Security and Privacy, 2027.

01 / Paper

Read the research.

The public PDF will be linked here when released.

Paper PDF Coming soon ↗
02 / Code

Explore the artifacts.

The repository is planned at github.com/Koyiott/homard.

GitHub Coming soon ↗

> FAQ

Questions & answers

Which systems did you evaluate?

AMD ZCU102, Raspberry Pi 5, and NVIDIA Jetson TX2. The demonstrated results depend on the platform, sensor access, and experimental conditions. They do not establish that every Arm device is affected.

Does HOMARD need physical access?

The demonstrated measurement path uses onboard power sensors accessible from software. No external probe is needed. The paper details the access and profiling assumptions for each experiment.

What can reduce the risk?

Restricting unprivileged access to power-management telemetry removes the demonstrated unprivileged software measurement path. It does not eliminate the underlying physical leakage or protect against every privileged adversary.

Why HOMARD?

HOMARD stands for Hammering Off-chip Memory via Aggregate power Rail Disclosure. “Homard” is also French for lobster.

> The crew

Who is behind HOMARD?

  • Eliott Quéré1
  • Li-Chung Chiang2
  • Carina Fiedler2
  • Thomas Rokicki1
  • Maria Méndez Real3
  • Alessandro Palumbo1
  • Lilian Bossuet4
  • Rubén Salvador1
  • Daniel Gruss2
TU GrazUniversité de RennesCentraleSupélecIRISAInria
  1. CentraleSupélec, Univ. Rennes, Inria, CNRS, IRISA
  2. Graz University of Technology
  3. Univ. Bretagne-Sud, Lab-STICC, UMR 6285
  4. Univ. Lyon, UJM-Saint-Étienne, CNRS, Lab. Hubert Curien, UMR 5516

> BibTeX

Cite HOMARD.

Preliminary citation. Publication details will be updated when available.

BibTeX
@inproceedings{quere2027homard,
  title = {{HOMARD}: Hammering Off-chip Memory via
           Aggregate power Rail Disclosure},
  author = {Quéré, Eliott and Chiang, Li-Chung and
            Fiedler, Carina and Rokicki, Thomas and
            Méndez Real, Maria and Palumbo, Alessandro and
            Bossuet, Lilian and Salvador, Rubén and
            Gruss, Daniel},
  booktitle = {2027 IEEE Symposium on Security and Privacy (SP)},
  year = {2027},
  note = {To appear}
}

Acknowledgments

Work partially funded by the ANR within the framework of the PIA EUR CyberSchool project (ANR-18-EURE-0004).