Independent reproduction and vendor review will determine whether SLAC’s Apple Silicon system-level-cache channel enables practical CPU-to-GPU data leakage requiring architectural or software mitigations.
state: expiredheat: lowuncertainty: highcontradictsscott: mediumapple-silicon side-channel-attacks local-inference-securityApple
What is this?
SLAC is a research paper reporting what it describes as the first fine-grained, access-driven Prime+Probe CPU-to-GPU cache side-channel on Apple Silicon. The researchers say they reverse-engineered the M1 system-level-cache indexing behavior and showed that an unprivileged CPU process can observe cache footprints left by sensitive GPU workloads, making the shared cache in Apple’s unified-memory architecture a cross-domain attack surface. The supplied snippets do not identify the authors or establish independent reproduction, practical leakage of specific model data, Apple’s review, or any vendor mitigation.
Why it matters to Scott
If reproduced with practical leakage, SLAC’s cross-domain cache channel would challenge the sufficiency of SiloOS and padded-cell software isolation on shared Apple Silicon hardware: an unprivileged process could observe a GPU workload despite nominal containment boundaries. The current evidence establishes cache-footprint observation, not model-data extraction or a deployable exploit, so this is a provisional architectural challenge rather than a demonstrated break requiring immediate redesign.
ip:framework.siloosip:concept.architectural-containmentdev:concept.padded-cell-agent-architecturedev:concept.hardware-aware-local-inferenceradar:concept.apple-siliconradar:concept.local-inferenceradar:concept.llm-securityradar:sparsety-sparse-serving-token-leak
queries asked of Scott's wikis
- local inference threat models for untrusted processes
- Apple Silicon unified-memory security assumptions
- GPU workload side channels and model-data leakage
- hardware isolation requirements for private local AI
- cache side-channel mitigations in heterogeneous CPU-GPU systems
- security tradeoffs of shared memory for local inference
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-15T04:24:47Z
The case has produced no independent reproduction, Apple response, or practical extraction evidence within its active horizon; the slight engagement increase is repetitive amplification, so it expires as an unvalidated research lead.
2026-08-13T03:33:05Z
No independent reproduction, vendor response, or practical leakage evidence has appeared; this is unchanged first-party research testimony rather than a developing security event.
2026-08-13T03:27:27Z
grounded: contradicts/medium — If reproduced with practical leakage, SLAC’s cross-domain cache channel would challenge the sufficiency of SiloOS and padded-cell software isolation on shared A
2026-08-13T03:24:38Z
origin walked (codex/luna, conf 0.99): anchor hn.story.49281360 -> echo.paper.9740681376 by Tianhong Xu, Saion K. Roy, Ruyi Ding, Aidong Adam Ding, and Yunsi Fei
2026-08-13T03:23:28Z
case created — The linked paper presents a concrete systems-security finding with potential implications for workload isolation on shared Apple Silicon hardware.
Decision trace
- 08-15 14:24expireThe case has produced no independent reproduction, Apple response, or practical extraction evidence within its active horizon; the slight engagement increase is repetitive amplification, so it expires
- 08-15 14:24alert_silentThe only delta is a trivial engagement increase with no new technical or vendor evidence. It can wait unless reproduction, Apple review, or demonstrated model-data leakage emerges.
- 08-15 14:24alert_routeThe only delta is a trivial engagement increase with no new technical or vendor evidence. It can wait unless reproduction, Apple review, or demonstrated model-data leakage emerges.
- 08-13 13:33repriceNo independent reproduction, vendor response, or practical leakage evidence has appeared; this is unchanged first-party research testimony rather than a developing security event.
- 08-13 13:33alert_silentThe paper and its implications were already assessed, and the new delta is only an unchanged reobservation. It can wait for independent validation, an Apple response, or a demonstrated extraction atta
- 08-13 13:33alert_routeThe paper and its implications were already assessed, and the new delta is only an unchanged reobservation. It can wait for independent validation, an Apple response, or a demonstrated extraction atta
- 08-13 13:32alert_shadowThe original paper reports fine-grained Prime+Probe attacks through Apple Silicon’s shared system-level cache, including observable GPU memory-access footprints and GNN/LLM privacy demonstrations. Tha
- 08-13 13:32alert_routeThe original paper reports fine-grained Prime+Probe attacks through Apple Silicon’s shared system-level cache, including observable GPU memory-access footprints and GNN/LLM privacy demonstrations. Tha
- 08-13 13:27groundIf reproduced with practical leakage, SLAC’s cross-domain cache channel would challenge the sufficiency of SiloOS and padded-cell software isolation on shared Apple Silicon hardware: an unprivileged p
- 08-13 13:24promote_anchororigin walk conf 0.99
- 08-13 13:23createThe linked paper presents a concrete systems-security finding with potential implications for workload isolation on shared Apple Silicon hardware.