GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
cs.CR
Submitted: 2026-05-05
Updated: 2026-09-15
Comments: 20 pages, including appendices. The paper was presented at S&P'26 (https://sp2026.ieee-security.org/)
DOI: 10.1109/SP63933.2026.00177
Code: https://github.com/sith-lab/gpubreach
Project page: https://nvidia.github.io/open-gpudoc/pascal/gp100-mmu-format.pdf
License: http://creativecommons.org/licenses/by/4.0/
The gist: NVIDIA GPUs with GDDR memories have been shown susceptible to Rowhammer-based bit-flips, similar to CPUs.
Terminology
Abstract
NVIDIA GPUs with GDDR memories have been shown susceptible to Rowhammer-based bit-flips, similar to CPUs. However, Rowhammer exploits on GPUs have been limited to injecting untargeted bit-flips in victim data like weights of machine learning models, to degrade model accuracy, unlike CPU exploits shown capable of privilege escalation. In this paper, we demonstrate that GPU Rowhammer exploits can be as potent as CPU Rowhammer attacks. By exploiting the GPU page table management to identify when and where new page tables are allocated, we enable an unprivileged user CUDA kernel of one process to use RowHammer bit-flips to gain access to the GPU memory of other processes or co-tenants via targeted tampering of such page-tables resident on the GPU memory. Using this newly found primitive, we demonstrate the first GPU-side privilege escalation attacks, leaking secret data such as cryptographic keys from cuPQC libraries, and even tampering with the model's GPU assembly code to degrade models more stealthily than previous attacks. We further demonstrate that GPU-side privilege escalation can lead to CPU-side privilege escalation, defeating the protections provided by the IOMMU, enabling a malicious user-level program with GPU access to gain root shell and system-wide control, even in a non-multi-tenant setting.
Sources
- PrisonBreak: Jailbreaking Large Language Models with at Most Twenty-Five Targeted Bit-flips
- Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPU
- LeftoverLocals: Listening to LLM Responses Through Leaked GPU Local Memory
- NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU Interconnect
- Blueprint, Bootstrap, and Bridge: A Security Look at NVIDIA GPU Confidential Computing
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs