acceptodds
Under review as a conference paper at ICLR 2027

HammerEVO: LLM-Driven Evolution of RowHammer Performance-Isolation Defenses

Abstract

Modern DRAM is vulnerable to RowHammer: repeatedly activating a row can flip bits in nearby rows without ever writing them. Safety mitigations stop the flips, but their preventive work—migrations, copies, refreshes—occupies the shared memory-controller service path, and an adversary can trigger that work repeatedly to deny service to benign co-runners. This performance denial-of-service channel is severe yet largely unaddressed: BreakHammer, the existing countermeasure, was evaluated on fixed hammer patterns, not camouflaged ones; real attacks are diverse; and designing a defense demands deep knowledge of each mitigation's mechanism. We present HammerEVO, which applies expert-guided LLM evolution to this problem. The search must cope with a moving adversary, the limited visibility each mitigation exposes, and candidates judgeable only by measurement: domain experts approve hardware extensions and adjudicate measurements, while an LLM proposes attack strategies, probes, and policy code graded by a deterministic, fail-closed simulator campaign. Since evaluating a defense requires real attacks, the campaign evolves both sides. It discovered patterns that degrade benign cores by 13.8–49.1% mean IPC loss (75.6–90.5% worst-core) across multiple mitigation families, which BreakHammer fails to recover, and produced a working performance-isolation policy for each of the eight families: mean benign impact at or below 2.5% (worst-case 7.0%) with near-zero pure-benign overhead, outperforming BreakHammer wherever it engages (worst-core 32–99% reduced to at most 7%) and holding against six published attack families and eight 40-round adaptive red campaigns—for an estimated $50 of API spend and one workstation-week. We release the policies, per-iteration artifacts, and evaluation traces at https://anonymous.4open.science/r/hammerevo-artifact-EB58.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.