EAAI Journal 2026 Journal Article
Sample augmentation-based adversarial training method to counter evasive spectre attacks
- Zhongkai Tong
- Jian Gao
- Deyu Yuan
- Gang Liu
Microarchitectural attacks exploit subtle processor-level vulnerabilities to extract sensitive data, posing persistent challenges to modern hardware security. Although artificial intelligence (AI)–assisted detection using hardware performance counters (HPCs) provides a low-overhead defense, its reliability remains limited when facing evasive variants that deliberately mask their microarchitectural footprints. In this work, we present Evasive Spectre. This novel Spectre variant incorporates controlled delay operations to bypass state-of-the-art HPC-based AI detectors, thereby exposing inherent weaknesses in existing detection systems. To mitigate these limitations, we propose a sample-augmentation-based adversarial training framework that improves model robustness by periodically injecting adversarial samples and leveraging combined HPC feature representations. Experiments on Intel Corporation (Intel) i7-7700 and Advanced Micro Devices (AMD) Ryzen 7-4800H platforms demonstrate over 99% detection accuracy against both Spectre and the proposed Evasive Spectre, with a maximum runtime overhead of only 1. 7%. These results underscore a lightweight, scalable, and robust defense paradigm that advances the application of adversarial learning to intelligent hardware security in the AI-driven era.