This paper describes LeftoverLocals: a vulnerability that allows data recovery from GPU memory created by another process on Apple, Qualcomm, and AMD GPUs. LeftoverLocals impacts the security posture of GPU applications, with particular significance to LLMs and ML models that run on impacted GPUs. By recovering local memory, an optimized GPU memory region, we built a PoC where an attacker can listen into another user's interactive LLM session (e.g., llama.cpp) across process or container boundaries.
翻译:本文描述了LeftoverLocals:一种允许从Apple、Qualcomm和AMD GPU上其他进程创建的GPU内存中恢复数据的漏洞。LeftoverLocals影响了GPU应用程序的安全态势,尤其对运行于受影响GPU上的大语言模型(LLM)和机器学习(ML)模型具有重大影响。通过恢复GPU优化内存区域——本地内存,我们构建了概念验证(PoC),攻击者可借此跨进程或容器边界监听其他用户的交互式大语言模型会话(例如llama.cpp)。