GHost in the Shell: A GPU-to-Host Memory Attack and its Mitigation
Sihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee, Suhwan Song, Byoungyoung Lee
Abstract
Modern heterogeneous computing platforms increasingly unify CPU and GPU address spaces for improved programmability and performance. To this end, recent Linux kernels and NVIDIA GPU drivers adopt Heterogeneous Memory Management (HMM), which allows GPU kernels to directly access host memory. While this simplifies development, it may introduce a critical security risk.
In this paper, we expose a new attack surface introduced by HMM and present GHOST-ATTACK, the first GPU-originated exploitation technique capable of compromising host process memory. By exploiting memory-safety bugs in GPU kernels or executing attacker-supplied kernels, GHOST-ATTACK enables attackers to bypass Address Space Layout Randomization (ASLR) and hijack control flow in widely used applications such as PyTorch and Chrome.
To counter this threat, we further propose SHELL (Secure HMM Enforcement with LLVM), a practical defense that restores memory isolation between GPU and host in HMMenabled systems. SHELL statically identifies shared memory regions and enforces fine-grained access control at runtime using the GPU driver's page-fault mechanism. We implement SHELL by modifying Clang/LLVM and the open-source NVIDIA GPU driver. Our evaluation demonstrates that SHELL effectively blocks all variants of GHOST-ATTACK with negligible performance overhead, preserving the security, compatibility, and performance benefits of HMM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a0f0348c-1e04-4f3f-a0ba-b1df4d1ff909Cited by top-tier papers2
- From Prompt to Pwn: Exploiting GPU Memory Errors During ML InferenceJonas Roels, Adriaan Jacobs, Silviu Vlasceanu, Mahmoud Ammar et al.CCS 2026
- Hunting CUDA Bugs at Scale with cuFuzzMohamed Tarek Ibn Ziad, Christos KozyrakisOOPSLA 2026
Builds on10
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
- Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your NeighborsZihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao et al.S&P 2022 · 41 citations
- Characterizing, exploiting, and detecting DMA code injection vulnerabilities in the presence of an IOMMUAlex Markuze, Shay Vargaftik, Gil Kupfer, Boris Pismenny et al.EuroSys 2021 · 22 citations
- Securing GPU via region-based bounds checkingJaewon Lee, Yonghae Kim, Jiashen Cao, Euna Kim et al.ISCA 2022 · 19 citations
- TunneLs for Bootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIGZhenkai Zhang, Tyler N. Allen, Fan Yao, Xing Gao et al.CCS 2023 · 18 citations
Related papers
- PhantomMap: GPU-Assisted Kernel ExploitationJiayi Hu, Qi Tang, Xingkai Wang, Jinmeng Zhou et al.NDSS 2026
- Demystifying and Exploiting ASLR on NVIDIA GPUsRuofan Zhu, Ganhao Chen, Wenbo Shen, Lyuye Zhang et al.S&P 2026 · 2 citations
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 1 citation
