USENIX Security2026Top-tier venue
TIMESLICE-SANDWICH: A GPU Side-Channel Attack Exploiting Time-Sliced Scheduling
Hodong Kim, Gyeongsup Lim, Seunghee Shin, Youngjoo Shin, Junbeom Hur
Abstract
Modern GPUs support resource sharing among concurrent applications, introducing the risk of side-channel attacks. While prior research has explored GPU side channels that exploit shared GPU resources, the security implications of time-sliced scheduling, a standard feature for resource sharing in today's GPUs, remain largely unexplored concerning side-channel attacks. In this study, we analyze timing variations caused by concurrent execution under the GPU's time-sliced scheduling mechanism. We begin by identifying the upper bound of a time slice and then leverage this bound to estimate the duration of a concurrent program's time slice, ultimately enabling us to infer the program's overall GPU utilization patterns.
Building on this finding, we introduce TIMESLICE-SANDWICH, a novel GPU side-channel attack that leverages variations in time-slice duration to infer and distinguish victim execution patterns. Unlike prior GPU side-channel attacks, TIMESLICE-SANDWICH does not require contention on specific shared resources. In our experiments, TIMESLICE-SANDWICH achieves an F1 score of 94.40% in neural network recovery attack; and a Top-1 accuracy of 92.84% in website fingerprinting attack on Google Chrome, both on average, demonstrating its effectiveness. Even in the presence of noise, our attack achieves an average F1 score of 73.74% for neural network recovery. Finally, we discuss potential mitigations to address side-channel risks arising from time-slice patterns in modern GPU resource-sharing architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c270f1a3-b88f-40b0-8e3e-8beaabec2f62Builds on3
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
- Trident: A Hybrid Correlation-Collision GPU Cache Timing Attack for AES Key RecoveryJaeguk Ahn, Cheolgyu Jin, Jiho Kim, Minsoo Rhu et al.HPCA 2021 · 15 citations
- Invalidate+Compare: A Timer-Free GPU Cache Attack PrimitiveZhenkai Zhang, Kunbei Cai, Yanan Guo, Fan Yao et al.USENIX Security 2024 · 15 citations
Related papers
- Uncovering Real GPU NoC Characteristics: Implications on Interconnect ArchitectureZhixian Jin, Christopher Rocca, Jiho Kim, Hans Kasan et al.MICRO 2024 · 15 citations
- Network-on-Chip Microarchitecture-based Covert Channel in GPUsJaeguk Ahn, Jiho Kim, Hans Kasan, Zhixian Jin et al.MICRO 2021 · 30 citations
- NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU InterconnectYicheng Zhang, Ravan Nazaraliyev, Sankha Baran Dutta, Andres Marquez et al.CCS 2026 · 6 citations
- Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your NeighborsZihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao et al.S&P 2022 · 41 citations
- Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel AttacksHongyue Jin, Yanan Guo, Zhenkai ZhangNDSS 2026
