NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU Interconnect
Yicheng Zhang, Ravan Nazaraliyev, Sankha Baran Dutta, Andres Marquez, Kevin J. Barker, Nael Abu-Ghazaleh
Abstract
Multi-GPU systems are becoming increasingly important in highperformance computing (HPC) and cloud infrastructure, providing acceleration for data-intensive applications, including machine learning workloads. These systems consist of multiple GPUs interconnected through high-speed networking links such as NVIDIA's NVLink. In this work, we explore whether the interconnect on such systems can offer a novel source of leakage, enabling new forms of covert and side-channel attacks. Specifically, we reverse engineer the operations of NVlink and identify two primary sources of leakage: timing variations due to contention and accessible performance counters that disclose communication patterns. The leakage is visible remotely and even across VM instances in the cloud, enabling potentially dangerous attacks. Building on these observations, we develop two types of covert-channel attacks across two GPUs, achieving a bandwidth of over 70 Kbps with an error rate of 4.78% for the contention channel. We develop two end-to-end crossGPU side-channel attacks: application fingerprinting (including 18 high-performance computing and deep learning applications) and 3D graphics character identification within Blender, a multi-GPU rendering application. These attacks are highly effective, achieving F1 scores of up to 97.78% and 91.56%, respectively. We also discover that leakage surprisingly occurs across Virtual Machines on the Google Cloud Platform (GCP) and demonstrate a side-channel attack on Blender, achieving F1 scores exceeding 88%. We also explore potential defenses such as managing access to counters and reducing the resolution of the clock to mitigate the two sources of leakage.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19603c81-ef98-4806-a3fa-de6ab05cd572Cited by top-tier papers1
Ask how each one uses itBuilds on19
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
- Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPUPietro Frigo, Cristiano Giuffrida, Herbert Bos, Kaveh RazaviS&P 2018 · 178 citations
- DeepSniffer: A DNN Model Extraction Framework Based on Learning Architectural HintsXing Hu, Ling Liang, Shuangchen Li, Lei Deng et al.ASPLOS 2020 · 128 citations
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel Gruss, Samuel Weiser et al.NDSS 2018 · 68 citations
Related papers
- Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU SystemsSankha Baran Dutta, Hoda Naghibijouybari, Arjun Gupta, Nael B. Abu-Ghazaleh et al.ISCA 2023 · 41 citations
- Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel AttacksHongyue Jin, Yanan Guo, Zhenkai ZhangNDSS 2026
- Network-on-Chip Microarchitecture-based Covert Channel in GPUsJaeguk Ahn, Jiho Kim, Hans Kasan, Zhixian Jin et al.MICRO 2021 · 30 citations
- Ghost Arbitration: Mitigating Interconnect Side-Channel Timing Attacks in GPUZhixian Jin, Jaeguk Ahn, Jiho Kim, Hans Kasan et al.MICRO 2024 · 4 citations
- Uncovering Real GPU NoC Characteristics: Implications on Interconnect ArchitectureZhixian Jin, Christopher Rocca, Jiho Kim, Hans Kasan et al.MICRO 2024 · 15 citations
