High-speed interconnects, such as NVLink, are integral to modern multi-GPU systems, acting as a vital link between CPUs and GPUs. This study highlights the vulnerability of multi-GPU systems to covert and side channel attacks due to congestion on interconnects. An adversary can infer private information about a victim's activities by monitoring NVLink congestion without needing special permissions. Leveraging this insight, we develop a covert channel attack across two GPUs with a bandwidth of 45.5 kbps and a low error rate, and introduce a side channel attack enabling attackers to fingerprint applications through the shared NVLink interconnect.
翻译:高速互联(如NVLink)是现代多GPU系统的核心组件,充当CPU与GPU之间的关键链路。本研究表明,由于互联上的拥塞现象,多GPU系统容易遭受隐蔽信道和侧信道攻击。攻击者无需特殊权限,仅通过监测NVLink拥塞即可推断受害者活动的隐私信息。基于这一发现,我们开发了一种跨双GPU的隐蔽信道攻击,其带宽达到45.5 kbps且错误率较低;同时提出一种侧信道攻击,使攻击者能够通过共享的NVLink互联对应用程序进行指纹识别。