Not to take away from the authors' work, but this was actually the approach taken by some engineers while Spectre / Meltdown were still under embargo. Not sure if they ever mentioned their work publicly so I will avoid naming them, but some talented folks from Microsoft who basically came to the same conclusion that a specialized environment free of noise was necessary both to test mitigations and find variants.

Related (2019):

https://gamozolabs.github.io/metrology/2019/08/19/sushi_roll...

https://gamozolabs.github.io/metrology/2019/12/30/load-port-...

I suppose they did make their work public after all :)

Thank you for pulling up the references.