Half Spectre, Full Exploit: Hardening Rowhammer Attacks with Half-Spectre Gadgets

Leaky Address Masking: Exploiting Unmasked Spectre Gadgets with Noncanonical Address Translation

FloatZone: Accelerating Memory Error Detection Using the Floating Point Unit [pdf]

Let Me Unwind That For You: Exceptions to Backward-Edge Protection

Constantine: Automatic side-channel resistance using data flow linearization

[PDF] Who’s Debugging the Debuggers? Exposing Debug Information Bugs in Optimized Binaries

Speculative Probing: Hacking Blind in the Spectre Era

TagBleed: Breaking KASLR on the Isolated Kernel Address Space using Tagged TLBs