#Researchers demonstrated a #Rowhammer attack, dubbed #GPUhammer, against #Nvidia’s #RTXA6000 GPU. The attack, which targets #GDDR6 memory modules, can corrupt data stored in memory, potentially compromising machine learning models and other critical applications. https://arstechnica.com/security/2025/07/nvidia-chips-become-the-first-gpus-to-fall-to-rowhammer-bit-flip-attacks/?eicker.news #tech #media #news
Nvidia chips become the first GPUs to fall to Rowhammer bit-flip attacks

GPUhammer is the first to flip bits in onboard GPU memory. It likely won’t be the last.

Ars Technica

#GPUHammer is the first attack to show #Rowhammer bit flips on #GPU memories, specifically on a GDDR6 memory in an #NVIDIA A6000 GPU. Our attacks induce bit flips across all tested DRAM banks, despite in-DRAM defenses like TRR, using user-level #CUDA #code. These bit flips allow a malicious GPU user to tamper with another user’s data on the GPU in shared, time-sliced environments. In a proof-of-concept, we use these bit flips to tamper with a victim’s DNN models and degrade model accuracy from 80% to 0.1%, using a single bit flip. Enabling Error Correction Codes (ECC) can mitigate this risk, but ECC can introduce up to a 10% slowdown for #ML #inference workloads on an #A6000 GPU.

https://gpuhammer.com/

GPUHammer

GPUHammer
GPUHammer

GPUHammer