USENIX Security2026Top-tier venue
Silicon Heist: (Ransom) Attacks for Cloud FPGAs via Privilege Escalation
Simon Klix, Felix Hahn, Maik Ender, Nils Albartus, Christof Paar, Russell Tessier
Abstract
Cloud-based FPGAs have become a billion-dollar industry, allowing users to deploy custom hardware designs with the scalability and flexibility of cloud infrastructure. Running user designs on hardware owned by the cloud service provider (CSP) introduces risks, including intentional hardware damage and Denial-of-Service (DoS) attacks against the host. To mitigate these risks, CSPs enforce security mechanisms that restrict user designs and prevent unauthorized behavior. We present a novel privilege escalation path on AMD FPGAs using (i) the Internal Configuration Access Port (ICAP) to circumvent provider defenses, (ii) incrementally escalate attacker capabilities to remote JTAG access, and (iii) investigate the resulting threat vectors. Any typical cloud customer can maliciously acquire such ICAP access to reconfigure parts of the FPGA fabric without restrictions – re-enabling traditional cloud FPGA attacks. Through the ICAP, a user can ultimately gain remote control of the hardware's low-level JTAG interface, which enables access to the device's eFuses. This access, in turn, allows attackers to irreversibly program encryption settings, thereby disabling future reconfiguration and locking the CSPs out of their own devices. An attacker could leverage such escalated privileges for a ransomware attack in which cloud providers must pay a ransom for decryption keys to regain control of their devices – effectively introducing the first ransomware for FPGAs. Following the investigation of this novel privilege escalation path, we demonstrate its feasibility on Amazon's EC2 F1 and F2 instances and explore the impact of enabled attack vectors. We thereby expose the neglected threat of unsecured low-level hardware components in cloud environments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d8f05244-cd98-4a6a-bfc4-c44501516d0cBuilds on4
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 301 citations
- Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGAAdnan Siraj Rakin, Yukui Luo, Xiaolin Xu, Deliang FanUSENIX Security 2021 · 64 citations
- Stealing Maggie's Secrets-On the Challenges of IP Theft Through FPGA Reverse EngineeringSimon Klix, Nils Albartus, Julian Speith, Paul Staat et al.CCS 2024 · 5 citations
- The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAsMaik Ender, Amir Moradi, Christof PaarUSENIX Security 2020
Related papers
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
- C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit LeakageIlias Giechaskiel, Kasper Bonne Rasmussen, Jakub SzeferS&P 2020 · 74 citations
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou et al.CCS 2023 · 4 citations
- A Novel Covert Timing Channel for Cloud FPGAsBrian Udugama, Darshana Jayasinghe, Hassaan Saadat, Aleksandar Ignjatovic et al.DAC 2025
- ShEF: shielded enclaves for cloud FPGAsMark Zhao, Mingyu Gao, Christos KozyrakisASPLOS 2022 · 53 citations
