Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU Systems
Sankha Baran Dutta, Hoda Naghibijouybari, Arjun Gupta, Nael B. Abu-Ghazaleh, Andres Marquez, Kevin J. Barker
Abstract
The deep learning revolution has been enabled in large part by GPUs, and more recently accelerators, which make it possible to carry out computationally demanding training and inference in acceptable times. As the size of machine learning networks and workloads continues to increase, multi-GPU machines have emerged as an important platform offered on High Performance Computing and cloud data centers. Since these machines are shared among multiple users, it becomes increasingly important to protect applications against potential attacks. In this paper, we explore the vulnerability of Nvidia's DGX multi-GPU machines to covert and side channel attacks. These machines consist of a number of discrete GPUs that are interconnected through a combination of custom interconnect (NVLink) and PCIe connections. We reverse engineer the interconnected cache hierarchy and show that it is possible for an attacker on one GPU to cause contention on the L2 cache of another GPU. We use this observation to first develop a covert channel attack across two GPUs, achieving the best bandwidth of around 4 MB/s. We also develop a prime and probe attack on a remote GPU allowing an attacker to recover the cache access pattern of another workload. This access pattern can be used in any number of side channel attacks: we demonstrate a proof of concept attack that fingerprints the application running on the remote GPU, with high accuracy. We also develop a proof of concept attack to extract hyperparameters of a machine learning workload. Our work establishes for the first time the vulnerability of these machines to microarchitectural attacks and can guide future research to improve their security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4dfd2a4b-337e-4bba-a760-ecd8f2607ffdCited by top-tier papers17
- TunneLs for Bootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIGZhenkai Zhang, Tyler N. Allen, Fan Yao, Xing Gao et al.CCS 2023 · 18 citations
- IDYLL: Enhancing Page Translation in Multi-GPUs via Light Weight PTE InvalidationsBingyao Li, Yanan Guo, Yueqi Wang, Aamer Jaleel et al.MICRO 2023 · 16 citations
- Invalidate+Compare: A Timer-Free GPU Cache Attack PrimitiveZhenkai Zhang, Kunbei Cai, Yanan Guo, Fan Yao et al.USENIX Security 2024 · 15 citations
- Veiled Pathways: Investigating Covert and Side Channels Within GPU UncoreYuanqing Miao, Yingtian Zhang, Dinghao Wu, Danfeng Zhang et al.MICRO 2024 · 8 citations
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
Builds on7
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser et al.USENIX Security 2019 · 159 citations
- DeepSniffer: A DNN Model Extraction Framework Based on Learning Architectural HintsXing Hu, Ling Liang, Shuangchen Li, Lei Deng et al.ASPLOS 2020 · 128 citations
- Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU SystemsSankha Baran Dutta, Hoda Naghibijouybari, Nael B. Abu-Ghazaleh, Andres Marquez et al.ISCA 2021 · 36 citations
- Streamline: a fast, flushless cache covert-channel attack by enabling asynchronous collusionGururaj Saileshwar, Christopher W. Fletcher, Moinuddin K. QureshiASPLOS 2021 · 36 citations
Related papers
- NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU InterconnectYicheng Zhang, Ravan Nazaraliyev, Sankha Baran Dutta, Andres Marquez et al.CCS 2026 · 6 citations
- Network-on-Chip Microarchitecture-based Covert Channel in GPUsJaeguk Ahn, Jiho Kim, Hans Kasan, Zhixian Jin et al.MICRO 2021 · 30 citations
- Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel AttacksHongyue Jin, Yanan Guo, Zhenkai ZhangNDSS 2026
- DeepCache: Revisiting Cache Side-Channel Attacks in Deep Neural Networks ExecutablesZhibo Liu, Yuanyuan Yuan, Yanzuo Chen, Sihang Hu et al.CCS 2024 · 3 citations
- Behind Bars: A Side-Channel Attack on NVIDIA MIG Cache Partitioning Using Memory BarriersCheng Gu, Reese Levine, Zhenkai Zhang, Tyler Sorensen et al.USENIX Security 2026
