I’d highly recommend reading Flush+Reload first since the cache side channel is key to any of these miceoarchitectural attacks.
1. Read Flush + Reload
2. Then reproduce it in C
3. Then read Meltdown
4. Reproduce it in C
5. Read Spectre
6. Reproduce it in C
After that we had to implement a VUSEC paper. I chose GLitch [1].
A spectre (particularly RSB-based ones) are nice to start out with imo.