CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel".
Elias: The gist The CPU-Auth mechanism leverages unique variations in Dynamic Voltage and Frequency Scaling (DVFS) behavior measured remotely from within a browser to establish a hardware-based device fingerprint for Multi-Factor…
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So we're looking at this paper today, "CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel." It’s about using the unique way a CPU scales its voltage and frequency as a way to create a hardware fingerprint for Multi-Factor Authentication.
Elias: Right, it’s about leveraging those minute variations in Dynamic Voltage and Frequency Scaling, or DVFS behavior, to build something that identifies the physical device remotely from within a web browser. It’s positioning itself against things like SMS codes or tokens which we already know have their own weaknesses.
Priya: From a privacy standpoint, it’s interesting because the authors are focusing on hardware properties rather than collecting personal data about the user's browsing habits, which is what software fingerprints often do five <ref:2610.10766#pg3>.
Nadia: Exactly. The core idea here is establishing a hardware-based device fingerprint that stays stable over time and resists external changes or cloning attempts ten <ref:2610.10766#pg1,a hardware-based device fingerprint>. They’re saying this hardware basis is far more robust against relay attacks than typical software-based methods.
Elias: And they do it by forcing the CPU to scale its frequency using a power virus that simulates an intense workload and then periods of sleep, which helps capture those DVFS details three. It’s a way to access information that isn't usually exposed remotely.
Priya: What I want to ask is what this actually means for the average user who just wants to log into their bank or an online service securely. Is this something they can use without needing special permissions on their computer?
Nadia: That’s a big part of it, Priya. The paper specifically mentions that CPU-Auth is designed to quickly verify identity without needing elevated permissions, meaning it works within the sandbox environment of a web browser two <ref:2610.10766#pg2,within the sandbox environment of a web browser>. It positions itself as a tool for authentication that doesn't require physical access to the device or sudo rights.
Elias: That’s a key distinction they make because they are careful not to confuse this with a standard browser fingerprint, which is what collects data about the user's browsing activity eight <ref:2610.10766#pg2>. They are focused on the underlying hardware characteristic.
Priya: So, if we look at what the paper actually collected in their experiments, what kind of data were they tracking and how did they measure it? I want to know what’s actually happening there.
Title and authors: Nadia: They measure elapsed time of computation as a proxy for DVFS behavior because measuring direct DVFS data is proving difficult three. They record the time between the start and end of a standardized computation, collecting these timing values into an array.
Elias: And they collected over fifty thousand data traces from what they call an in-the-wild deployment to see how reliable this timing mechanism is in real conditions <ref:2610.10766#pg1>. That’s a decent sample size for empirical testing of their method.
Priya: So, the next step seems to be how they use these collected traces to actually determine if two devices are the same or different. What kind of classification task is this?
Nadia: It’s framed as a binary classification task, determining if two fingerprints belong to the same device or different devices two <ref:2610.10766#pg2>. They use metrics like Dynamic Time Warping, or DTW, to handle those variable length time series when comparing similarity.
Elias: And for the deep learning side of things, they use a Siamese network architecture where each trace goes through the model separately before they are combined for classification <ref:2610.10766#pg2>. It’s a standard setup for comparing two inputs to see how close they are in feature space.
Priya: What did the results show when they tested their different models, like the MLP and ResNet, against each other? Which one performed best in classifying those traces?
Nadia: The results indicated that the MLP was actually the most successful classifier across every single category they tested, with FCN coming not too far behind <ref:2610.10766#pg2>. They showed that implementations using either the MLP or FCN could achieve over ninety-two percent accuracy in device-based authentication.
Elias: That level of accuracy is substantial for a side-channel measurement approach, but I’m interested in the comparison between the DTW metric and those deep learning models. Did DTW perform as expected?
Priya: They found that Dynamic Time Warping produced a small difference between precision and recall, which suggests it’s a reasonably good similarity measure for their data <ref:2610.10766#pg3>. However, the ResNet model showed the largest gap between its precision and recall.
Nadia: So, while they found high overall accuracy with MLP or FCN models reaching over ninety-two percent, they also found that the ResNet model had a larger discrepancy in its performance metrics compared to DTW <ref:2610.10766#pg3>.
Title and authors: Elias: And looking at the appendix details, their MLP embedding extractor is a four-layer network that takes input traces of length two thousand with output dimensions of five hundred twelve one thousand twenty-four five hundred twelve and one hundred twenty-eight Appendix Details. That shows the complexity involved in creating that hardware fingerprint.
Priya: It sounds like they are trying to build something very specific for authentication. What are the next steps they identified for making this system even more robust? What are their limitations?
Nadia: They pointed out a few things they need to tackle first. They noted that discriminating between two devices of the exact same type is harder than comparing different types Future Work. That means improving accuracy when the devices look almost identical.
Elias: And they also mentioned that building a more robust system model resistant to replay attacks is necessary Future Work. We need to make sure someone can't just re-record and reuse those timing traces later.
Priya: They also suggested that understanding external factors, like how long it’s been since the device was registered or even ambient temperature, might contribute to a more reliable authentication pipeline Future Work. That adds another layer of environmental context to the fingerprint.
Nadia: So, CPU-Auth is this novel mechanism based on DVFS side-channel measurement that establishes a hardware fingerprint for MFA by analyzing timing discrepancies in computation within a browser sandbox. It seems like it offers remote, low-permission identity verification at over ninety-two percent accuracy with MLP or FCN classifiers.
Elias: It’s a solid demonstration of using subtle physical phenomena to create authentication factors where traditional methods fall short one <ref:2610.10766#pg1>. But we have to keep an eye on those replay attack vulnerabilities they mentioned in their future work.
Priya: For me, the main implication is that if this holds up under real-world stress, it opens up a new way for AI systems to verify device legitimacy without relying on user credentials or physical access two <ref:2610.10766#pg2>. It’s about building trust into the hardware itself.
Nadia: Exactly. So, we’re looking at how we can integrate these kinds of hardware characteristics into existing security protocols to make authentication checks more resilient against the latest attack vectors. We'll be back after the break with another look at some LLM security research that might be relevant to this kind of fingerprinting work.
The paper's summary: Nadia: So, putting it all together, CPU-Auth uses those tiny fluctuations in how a CPU scales its power and speed—the DVFS behavior—to create a hardware fingerprint that works inside your browser.
Elias: Right, it’s about turning those physical timing differences into a unique ID for MFA. It’s not just looking at what the software is doing, but how the physical chip reacts to that workload.
Priya: What this means in plain English is they're using the hardware's own quirks as a signature, something that stays consistent over time even if you change your settings or use different browser extensions.
Nadia: Exactly. They force the CPU into specific states, like intense work followed by sleep, and measure the exact timing of those transitions. That timing data is what they use to build this fingerprint.
Elias: The core method is treating that computation time as a proxy for DVFS behavior because getting direct measurements from the hardware itself is really tricky to do remotely.
Priya: And then they take those thousands of collected timing traces and feed them into deep learning models, specifically architectures like a Siamese network, to figure out if two sets of traces match.
Nadia: They’re essentially training an AI to recognize the pattern of a specific device's hardware response signature across different computation workloads.
Elias: The results show that models like the MLP are actually quite effective at separating those device signatures, hitting over ninety-two percent accuracy in their tests.
Priya: But it’s important to remember they used Dynamic Time Warping to compare the traces because the timing sequences aren't always perfectly aligned. That metric helps bridge those gaps when comparing two different devices.
Nadia: That’s the nuance there, Priya; they found that DTW gave them a pretty good measure of similarity, keeping precision and recall fairly balanced in their classification task.
Elias: However, they also noted that other models like ResNet showed a bigger gap between precision and recall compared to DTW. It suggests different approaches have different strengths when analyzing these time series data.
Priya: So the practical implication is that this moves authentication away from just passwords or tokens and toward verifying the physical device's unique hardware characteristics without needing deep access to the operating system.
Nadia: That’s right, it opens a door for AI systems to verify device legitimacy remotely, even in a secure sandbox environment, which is a big step for online security.
Elias: But we have to keep an eye on the replay attack vulnerability they mentioned in their future work; if someone can just record and replay those timing traces later, the whole thing falls apart.
Priya: And looking ahead, they are focused on making it easier to tell two devices apart when they look almost identical, like comparing two different models of the same phone.
Nadia: That’s what makes it interesting; as devices get more similar, the challenge becomes harder for this kind of physical fingerprinting method.
Elias: We also need a better way to build these models that can resist those replay attacks they flagged, which is a big technical hurdle in making this practical.
The paper's improvements: Tom: So, we're looking at how these researchers plan to take this CPU-Auth concept and make it even stronger for real-world use.
Nadia: They’ve identified a few key areas they need to work on next, starting with distinguishing between two devices that are almost identical types.
Elias: That makes sense; comparing two iPhones is much easier than comparing an iPhone to a completely different device, and they need a way to handle that high density of similar inputs.
Priya: And then there’s the replay attack issue, which means building a system model that can resist someone just re-recording those timing traces later for malicious purposes.
Nadia: They also mentioned looking at external factors like how long it’s been since the device was registered or even the ambient temperature, thinking those might add another layer of robustness to the fingerprint.
Elias: That brings us back to making sure the underlying system model itself is tough enough so that these environmental changes don't completely break the authentication process.
Priya: It sounds like they’re aiming for a system where the authentication isn't just about one measurement, but a combination of multiple factors to really lock down the identity.
Nadia: Exactly; they want to move beyond just comparing two traces and build something more complex that accounts for those subtle real-world shifts.
Elias: The goal there is creating a system that’s resistant to those replay attacks, which is a big technical challenge because you have to secure the entire process, not just the measurement itself.
Priya: So what this changes for us listening right now is that it points toward a future where verifying device legitimacy doesn't rely solely on user credentials or simple software checks.
Nadia: That’s right; it suggests AI systems could start verifying device identity remotely, securely, and without needing root access on the end-user's machine.
Elias: The challenge is making that verification robust enough so that it can handle those subtle environmental shifts they mentioned, which requires a much more sophisticated system model than what they currently have.
Conclusion: Nadia: So, to wrap up, CPU-Auth is this paper’s method for building a hardware fingerprint using DVFS side channels measured from inside a browser sandbox for Multi-Factor Authentication.
Elias: It shows that we can use those power and frequency scaling variations as a stable way to identify the physical device.
Priya: The main result is that deep learning models, specifically the MLP, are highly accurate at distinguishing between identical and different devices in these traces.
Nadia: That accuracy level is solid for a side-channel approach, but they did flag that making this robust against replay attacks and handling very similar device types are the next big challenges.
Elias: Yeah, building a model that resists those replay attacks is a big technical hurdle because you have to secure the entire process from start to finish.
Priya: And since these results come from in-the-wild deployments with over fifty thousand traces, it gives us some real evidence that this method works outside of a controlled lab setting.
Nadia: It means we’re moving toward authentication factors that rely on the actual physical characteristics of the CPU, rather than just software credentials.
Elias: It opens up a new way for AI systems to verify device legitimacy remotely, which is important when we’re thinking about secure interactions with web applications.
Priya: I think the real world implication is that this kind of hardware-based verification could be integrated into security protocols to create a much stronger layer of trust.
Nadia: We’re definitely looking at how these kinds of hardware characteristics fit into existing security frameworks for MFA and device verification.
Elias: Next up, we’ll be looking at how these side-channel attacks relate to the vulnerabilities in larger AI models, like the ones we discussed earlier in the show.
Ryan Swift
University of California, Davis
cs.CR, cs.LG
Submitted: 2026-10-07
Updated: 2026-10-07
Comments: 13 pages
License: http://creativecommons.org/licenses/by/4.0/
The gist: The gist The CPU-Auth mechanism leverages unique variations in Dynamic Voltage and Frequency Scaling (DVFS) behavior measured remotely from within a browser to establish a hardware-based device
Key concepts
- Fingerprinting
- Establishing a unique signature for an entity. The paper focuses on hardware fingerprinting, which captures stable physical properties of a device that are unique enough to identify it in a specific environment while remaining consistent over time and under external changes.
- Dynamic Voltage and Frequency Scaling (DVFS)
- A CPU technique where the processor adjusts its operating voltage and clock speed based on the current workload. This scaling is managed by governors like Performance or Powersave, which causes measurable fluctuations in how the CPU operates under different tasks.
- CPU-Auth Mechanism
- A method that captures subtle hardware discrepancies from within a browser's secure environment. It uses a power virus to simulate intense workloads and sleep periods to intentionally trigger DVFS changes, allowing the system to record timing data reflecting these scaling events.
Terminology
Summary
The gist The CPU-Auth mechanism leverages unique variations in Dynamic Voltage and Frequency Scaling (DVFS) behavior measured remotely from within a browser to establish a hardware-based device fingerprint for Multi-Factor Authentication (MFA) purposes.
Background
Fingerprinting is defined as the establishment of a signature for a given entity which makes that entity uniquely identifiable The paper distinguishes between software-based and hardware-based fingerprinting methods. Hardware fingerprints are constructed by capturing some physical property of a device which contains enough entropy to be uniquely identifiable in the target environment, and is also stable over time and in the presence of external variations and perturbations.
Dynamic Voltage and Frequency Scaling (DVFS)
Modern CPUs utilize DVFS to operate at different voltage configurations and clock frequencies depending on the system processing load The mechanism adjusting performance states is called Dynamic Voltage and Frequency Scaling (DVFS), which uses scaling governors like Performance, Powersave, or Ondemand
CPU-Auth Mechanism
CPU-Auth captures minute details and discrepancies in hardware from within the sandbox environment of a web browser. To facilitate capturing DVFS information, CPU-Auth employs a power virus that uses a crafted, intense simulated workload and periods of sleep to force CPU frequency scaling.
Data Collection and Analysis
CPU-Auth measures elapsed time of computation as a proxy for DVFS behavior because measuring direct DVFS data is difficult. The timing mechanism records the elapsed time between the start and end of a standardized computation. Data collection involves running this clock concurrently with the power virus to collect timing values into an array. Over 50,000 data traces were collected from an in-the-wild deployment.
Authentication and Classification
The authentication problem is formulated as a binary classification task: determining if two fingerprints are from the same device or different devices To determine similarity, CPU-Auth uses metrics like Dynamic Time Warping (DTW) to handle variable length time series. For deep learning models, the architecture involves a Siamese network where each trace passes through the model separately before concatenation.
Results and Discussion
The results indicate that the MLP is the most successful classifier in every category, with the FCN being not too far behind. DTW produced a small difference between precision and recall, while ResNet possessed the largest difference. Implementations of CPU-Auth with either the MLP or FCN have been demonstrated as over 92% accurate in device-based authentication. Future work should ensure that accuracy remains sufficiently high as devices being compared become more and more similar.
Future Work
Three tasks remain for future work: first, discriminating between devices of the exact same type is harder than comparing different types. Second, a more robust system model resistant to replay attacks should be constructed. Finally, understanding the effects of factors such as time since registration and ambient temperature may contribute to a more robust authentication pipeline.
Appendix Details
The DTW threshold learned from the Train split and used to achieve the results in Validation for classification based on DTW was 71200.0 The MLP embedding extractor is a 4-layer MLP which takes input traces of length 2000. The output dimensions of the 4 layers are 512, 1024, 512, and 128. The ResNet embedding extractor is made up of three blocks with three convolutional layers. With one input channel, the output channels in each block are 16, 32, and 32. The binary classifier is a three-layer perceptron. This result is rounded to perform classification and analysis.
References
[1] Zhongjie Ba, Sixu Piao, Xinwen Fu, Dimitrios Koutsonikolas, Aziz Mohaisen, and Kui Ren. ABC: Enabling smartphone authentication with built-in camera. In Proceedings 2018 Network and Distributed System Security Symposium, San Diego, CA, 2018.
[3] Debopriya Roy Dipta and Berk Gulmezoglu. DF-SCA: Dynamic frequency side channel attacks are practical. In Proceedings of the 38th Annual Computer Security Applications Conference, pages 841–853, 2022 <ref:2610.10766#pg4>.
[4] Hassan Ismail Fawaz, Germain Forestier, Jonathan Weber, Lhassane Idoumghar, and Pierre-Alain Muller. Deep learning for time series classification: A review. Data Mining and Knowledge Discovery, 33(4):917–963, 2019 <ref:2610.10766#pg5>.
[8] Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre Laperdrix, Clémentine Maurice, Yossi Oren, Romain Rouvoy, Walter Rudametkin, and Yuval Yarom. DRAWNAPART: A device identification technique based on remote GPU fingerprinting.
Improvements for AI systems
-
CPU-Auth is intended to be used as an additional factor within a MFA (Multi-Factor Authentication) scheme.
This allows AI systems to integrate hardware-based device fingerprinting directly into existing security protocols, mitigating flaws in SMS or token-based factors by requiring a CPU characteristic check alongside traditional credentials. -
The system can
quickly verify identity without having physical access to the device, and without requiring elevated (i.e. sudo) permissions.
This enables remote authentication checks within asandbox environment of a web browser,
meaning AI applications can securely verify device legitimacy for sensitive tasks like online purchases or accessing protected information without needing root access on the end-user's machine. -
CPU-Auth can be used to
detect the high similarity between the registered fingerprint and query fingerprint and approve the transaction
in a fraud prevention system, specifically by denying transactions whenthe query fingerprint is excessively different from Alice’s registered phone fingerprint.
This allows AI to build a dynamic risk assessment model where transaction approval is contingent on a calculated similarity metric (like DTW distance) exceeding a learned threshold. -
The deep learning models can be adapted so that
the top level of the networks learn to extract a lower dimensional embedding, which is then fed through a binary classifier multilayer perceptron (MLP).
This enables the AI to performsimilarity learning
between two time series traces, allowing it to distinguish between traces from thesame device and from different devices.
-
The system can be trained on data where "positive pairs are formed by creating positive and negative lists of traces for each device by determining the number of traces collected for a given device, selecting a random sample of traces from any other device in the dataset that is equal in number to the traces from that device.
This structured data preparation allows AI systems to be trained on large-scale datasets (
over 50,000 data traces) to achieve high accuracy (
up to 95% accuracy discriminating between fingerprints extracted from the same and from different devices"). -
Future work should focus on
making the distinction between two devices is easiest at the highest level of granularity, where all devices are equally likely to be compared against each other,
enabling AI systems to handle increasingly similar device types (e.g., two iPhone 15’s) by improving discrimination capabilities in a high-density classification space.
Abstract
Lack of effective authentication has resulted in numerous security and privacy breaches, including unauthorized access to protected information, identity theft, and fraud. One approach to mitigating such attacks is Multi-Factor Authentication (MFA), in which users must provide multiple pieces of information for authentication. Some secondary authentication factors include SMS text verification codes, biometrics, and tokens. Each contains at least one notable flaw: SMS is notoriously insecure; biometrics rely upon access to sensitive personal data; and tokens require dependence on third-party providers (e.g. OAuth providers). This work explores CPU-Auth, a novel authentication mechanism based on unique variations in the physical characteristics of the CPU of a computing device. By measuring the behavior of the Dynamic Voltage and Frequency Scaling (DVFS) governor remotely from within a browser, unique properties of the CPU can be leveraged to establish a hardware-based device fingerprint for use in CPU-Auth. The performance of CPU-Auth is evaluated on over 50,000 data traces using distance-based and deep learning methods. CPU-Auth is part of a larger research project, and the results provided in this report reflect only the contributions made to the project by members of this group.
Sources
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs