Lune

CCS2026顶会

From Prompt to Pwn: Exploiting GPU Memory Errors During ML Inference

Jonas Roels, Adriaan Jacobs, Silviu Vlasceanu, Mahmoud Ammar, Stijn Volckaert

2026年份

摘要

GPUs accelerate a growing fraction of modern computing workloads. While prior work has studied the exploitation of memory errors in GPU applications written in C/C++ dialects, existing attacks rely on artificially introduced memory errors that grant attackers capabilities that may not arise when exploiting real-world GPU software. Consequently, GPU vendors and developers continue to largely treat such errors as reliability concerns rather than security issues, leaving vulnerabilities unpatched and potentially exploitable.

This paper challenges that assumption. We show, for the first time, that remote, unprivileged adversaries can trigger device-side memory errors in realistic ML applications under specific conditions. We develop controlled proof-of-concept exploits that escalate vulnerabilities in the PyTorch ML framework and the CuDF dataframe library into write-what-where primitives, and weaponize such errors to enable denial-of-service, targeted manipulation and degradation of ML models, sensitive data leakage, and device-side code injection.

To facilitate exploit construction, we design and implement a dynamic taint-tracking framework for NVIDIA GPUs that tracks attacker-controlled data flows to identify exploitable memory objects. Our findings demonstrate that adversaries can conduct memory-corruption attacks on vulnerable ML inference servers, highlighting the need to reassess prevailing assumptions about GPU memory safety and adopt essential mitigations, such as Write-XOR-eXecute, that are currently absent from modern GPUs.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper15

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖