GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Lin, Chris S., Yan, Yuqin, Ding, Guozhen, Qu, Joyce, Zhu, Joseph, Lie, David, Saileshwar, Gururaj
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911648919322624
author Lin, Chris S.
Yan, Yuqin
Ding, Guozhen
Qu, Joyce
Zhu, Joseph
Lie, David
Saileshwar, Gururaj
author_facet Lin, Chris S.
Yan, Yuqin
Ding, Guozhen
Qu, Joyce
Zhu, Joseph
Lie, David
Saileshwar, Gururaj
contents NVIDIA GPUs with GDDR memories have been shown susceptible to Rowhammer-based bit-flips, similar to CPUs. However, Rowhammer exploits on GPUs have been limited to injecting untargeted bit-flips in victim data like weights of machine learning models, to degrade model accuracy, unlike CPU exploits shown capable of privilege escalation. In this paper, we demonstrate that GPU Rowhammer exploits can be as potent as CPU Rowhammer attacks. By exploiting the GPU page table management to identify when and where new page tables are allocated, we enable an unprivileged user CUDA kernel of one process to use RowHammer bit-flips to gain access to the GPU memory of other processes or co-tenants via targeted tampering of such page-tables resident on the GPU memory. Using this newly found primitive, we demonstrate the first GPU-side privilege escalation attacks, leaking secret data such as cryptographic keys from cuPQC libraries, and even tampering with the model's GPU assembly code to degrade models more stealthily than previous attacks. We further demonstrate that GPU-side privilege escalation can lead to CPU-side privilege escalation, defeating the protections provided by the IOMMU, enabling a malicious user-level program with GPU access to gain root shell and system-wide control, even in a non-multi-tenant setting.
format Preprint
id arxiv_https___arxiv_org_abs_2605_03812
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
Lin, Chris S.
Yan, Yuqin
Ding, Guozhen
Qu, Joyce
Zhu, Joseph
Lie, David
Saileshwar, Gururaj
Cryptography and Security
NVIDIA GPUs with GDDR memories have been shown susceptible to Rowhammer-based bit-flips, similar to CPUs. However, Rowhammer exploits on GPUs have been limited to injecting untargeted bit-flips in victim data like weights of machine learning models, to degrade model accuracy, unlike CPU exploits shown capable of privilege escalation. In this paper, we demonstrate that GPU Rowhammer exploits can be as potent as CPU Rowhammer attacks. By exploiting the GPU page table management to identify when and where new page tables are allocated, we enable an unprivileged user CUDA kernel of one process to use RowHammer bit-flips to gain access to the GPU memory of other processes or co-tenants via targeted tampering of such page-tables resident on the GPU memory. Using this newly found primitive, we demonstrate the first GPU-side privilege escalation attacks, leaking secret data such as cryptographic keys from cuPQC libraries, and even tampering with the model's GPU assembly code to degrade models more stealthily than previous attacks. We further demonstrate that GPU-side privilege escalation can lead to CPU-side privilege escalation, defeating the protections provided by the IOMMU, enabling a malicious user-level program with GPU access to gain root shell and system-wide control, even in a non-multi-tenant setting.
title GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
topic Cryptography and Security
url https://arxiv.org/abs/2605.03812