High-speed interconnects, such as NVLink, are integral to modern multi-GPU systems, acting as a vital link between CPUs and GPUs. This study highlights the vulnerability of multi-GPU systems to covert and side channel attacks due to congestion on interconnects. An adversary can infer private information about a victim's activities by monitoring NVLink congestion without needing special permissions. Leveraging this insight, we develop a covert channel attack across two GPUs with a bandwidth of 45.5 kbps and a low error rate, and introduce a side channel attack enabling attackers to fingerprint applications through the shared NVLink interconnect.
翻译:高速互连(如NVLink)是现代多GPU系统的核心纽带,在CPU与GPU间承担着关键通信桥梁的作用。本研究揭示了多GPU系统因互连拥塞而面临的隐蔽及侧信道攻击脆弱性。攻击者无需特殊权限,仅通过监测NVLink的拥塞状况即可推断受害者的活动隐私信息。基于此发现,我们开发了一种跨双GPU的隐蔽信道攻击,其传输带宽达45.5 kbps且误码率极低;同时提出一种侧信道攻击,使攻击者能通过共享NVLink互连对应用程序进行指纹识别。