GHost in the Shell: A GPU-to-Host Memory Attack and its Mitigation
Sihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee, Suhwan Song, Byoungyoung Lee
摘要
Modern heterogeneous computing platforms increasingly unify CPU and GPU address spaces for improved programmability and performance. To this end, recent Linux kernels and NVIDIA GPU drivers adopt Heterogeneous Memory Management (HMM), which allows GPU kernels to directly access host memory. While this simplifies development, it may introduce a critical security risk.
In this paper, we expose a new attack surface introduced by HMM and present GHOST-ATTACK, the first GPU-originated exploitation technique capable of compromising host process memory. By exploiting memory-safety bugs in GPU kernels or executing attacker-supplied kernels, GHOST-ATTACK enables attackers to bypass Address Space Layout Randomization (ASLR) and hijack control flow in widely used applications such as PyTorch and Chrome.
To counter this threat, we further propose SHELL (Secure HMM Enforcement with LLVM), a practical defense that restores memory isolation between GPU and host in HMMenabled systems. SHELL statically identifies shared memory regions and enforces fine-grained access control at runtime using the GPU driver's page-fault mechanism. We implement SHELL by modifying Clang/LLVM and the open-source NVIDIA GPU driver. Our evaluation demonstrates that SHELL effectively blocks all variants of GHOST-ATTACK with negligible performance overhead, preserving the security, compatibility, and performance benefits of HMM.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- From Prompt to Pwn: Exploiting GPU Memory Errors During ML InferenceJonas Roels, Adriaan Jacobs, Silviu Vlasceanu, Mahmoud Ammar 等CCS 2026
- Hunting CUDA Bugs at Scale with cuFuzzMohamed Tarek Ibn Ziad, Christos KozyrakisOOPSLA 2026
它引用的顶会 Paper10
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 被引用 214 次
- Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your NeighborsZihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao 等S&P 2022 · 被引用 41 次
- Characterizing, exploiting, and detecting DMA code injection vulnerabilities in the presence of an IOMMUAlex Markuze, Shay Vargaftik, Gil Kupfer, Boris Pismenny 等EuroSys 2021 · 被引用 22 次
- Securing GPU via region-based bounds checkingJaewon Lee, Yonghae Kim, Jiashen Cao, Euna Kim 等ISCA 2022 · 被引用 19 次
- TunneLs for Bootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIGZhenkai Zhang, Tyler N. Allen, Fan Yao, Xing Gao 等CCS 2023 · 被引用 18 次
相关 Paper
- PhantomMap: GPU-Assisted Kernel ExploitationJiayi Hu, Qi Tang, Xingkai Wang, Jinmeng Zhou 等NDSS 2026
- Demystifying and Exploiting ASLR on NVIDIA GPUsRuofan Zhu, Ganhao Chen, Wenbo Shen, Lyuye Zhang 等S&P 2026 · 被引用 2 次
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu 等S&P 2026 · 被引用 8 次
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 被引用 1 次
