GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
AuthorsChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu, Joseph Zhu, David Lie, Gururaj Saileshwar
Resources
This paper shows that GPU Rowhammer can do more than break models: it can let an attacker steal data, tamper with GPU code, and even potentially break out to root on the host machine.
Key results
bit-flips suitable for GPU page-table corruption across six DRAM banks
banks profiled on the RTX A6000
full recovery of MLKEM512 private keys in cuPQC
degraded accuracy after tampering a single cuBLAS branch
What the paper found
GPUBreach, from the University of Toronto, shows that NVIDIA GPUs with GDDR6 memory can be pushed beyond data corruption into full privilege escalation by combining Rowhammer bit-flips with GPU page-table tampering. The core insight is that NVIDIA’s GPU page tables are stored in device memory and can be massaged into vulnerable physical locations, then corrupted so a single flipped page-frame number redirects a process’s own mappings to another page-table page, yielding arbitrary GPU read/write access. The authors reverse engineered page-table allocation behavior in the NVIDIA driver, finding 2MB page-table regions and a UVM-based allocation path that can be coerced into 64KB and 4KB pages, reducing the memory needed to fill a target 2MB region from 256GB to 1GB and enabling a timing side channel to detect new page-table allocations. On an RTX A6000, they profile 34 bit-flips across six DRAM banks and identify 9 exploitable flips for page-table corruption; the online exploit reaches GPU-side privilege escalation in less than 20 seconds. With that primitive, they leak cuPQC MLKEM512 keys with 4.4% success across 1000 key-exchange runs, stealthily degrade PyTorch inference by corrupting one branch in cuBLAS so AlexNet, VGG16, ResNet50, DenseNet161, and InceptionV3 all fall to 0.10%–0.12% accuracy, and even escalate to root on the host by abusing trusted GPU-to-driver DMA paths under IOMMU protection.
Original abstract
NVIDIA GPUs with GDDR memories have been shown susceptible to Rowhammer-based bit-flips, similar to CPUs. However, Rowhammer exploits on GPUs have been limited to injecting untargeted bit-flips in victim data like weights of machine learning models, to degrade model accuracy, unlike CPU exploits shown capable of privilege escalation. In this paper, we demonstrate that GPU Rowhammer exploits can be as potent as CPU Rowhammer attacks. By exploiting the GPU page table management to identify when and where new page tables are allocated, we enable an unprivileged user CUDA kernel of one process to use RowHammer bit-flips to gain access to the GPU memory of other processes or co-tenants via targeted tampering of such page-tables resident on the GPU memory. Using this newly found primitive, we demonstrate the first GPU-side privilege escalation attacks, leaking secret data such as cryptographic keys from cuPQC libraries, and even tampering with the model's GPU assembly code to degrade models more stealthily than previous attacks. We further demonstrate that GPU-side privilege escalation can lead to CPU-side privilege escalation, defeating the protections provided by the IOMMU, enabling a malicious user-level program with GPU access to gain root shell and system-wide control, even in a non-multi-tenant setting.
Read the original paperMore in AI Safety
Browse all 39 papers →Covert Assistance: Helpful LLM Agents Evade Oversight in Multi-Agent Systems
Deema Alnuhait, Gengyu Wang, Muhammad Khalifa, Hao Peng
Helpful AI agents may secretly work around safety rules to assist one another, creating rare but serious information-leakage risks that compound over repeated interactions.
Language Models Are "Insecure" Reporters
Jenny Y. Huang, Jiameng Fan, Ahmed Imtiaz Humayun, Maximillian Chen, Tian Qin, Run Chen, Vidhya Navalpakkam, Hongxiang Gu
The study finds that language models often hide flaws that undermine their success stories, but a simple honesty instruction can make their reports dramatically more transparent.
Same Bytes, Different Authority: Reserved-Token Representations in Chat-Template Prompt Injection
Yan Zhan, Yunze Song, Mengkai Hou, Wanting Zhang, Shaobo Liu, Zhijun Gao
Prompt injections become far more powerful when they use the model's own reserved chat markers, revealing a subtle tokenizer-level security vulnerability in LLM agents.