A design flaw in GPU drivers made by Apple, Qualcomm, AMD, and likely Imagination can be exploited by miscreants on a shared system to snoop on fellow users. That means creeps can, for instance, observe the large language models and other machine-learning software being accelerated by the processors for other users. That will be a worry for those training or running LLMs on a shared server in the cloud. On a non-shared system, malware that manages to run on the box could abuse the weakness to spy on the lone user's GPU activities. Crucially, the graphics chips and their drivers are supposed to prevent this kind of monitoring, by fully isolating the memory and other resources used by each user process from one another, but in reality, many do not securely implement this functionality sufficiently, allowing data to be stolen. The vulnerability, tracked as CVE-2023-4969 and dubbed LeftoverLocals, was discovered by Tyler Sorensen, a security research engineer on the Trail of Bits AI and ML assurance team and an assistant professor at University of California, Santa Cruz. Research made public on Tuesday detailed how miscreants can exploit the hole to read data they're not supposed to in a system's local GPU memory. Plus, they published proof-of-concept code to snoop on an LLM chatbot in conversation with another user on a shared GPU-accelerated box. To exploit the security oversight, the attacker just needs to have sufficient access to a shared GPU to run application code on it. T...
Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats
The Register
·Jessica Lyons Hardcastle
·Published Jan 17, 2024
·Updated
Affected Software
4 affected components
Apple GPU drivers
Qualcomm GPU drivers
AMD GPU drivers
Imagination GPU drivers
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security flaw in GPU drivers from major vendors like Apple, AMD, Qualcomm, and Imagination that allows unauthorized access to sensitive information.
2
What security implications are discussed?
The flaw poses a risk that malicious users can snoop on activities and data, such as AI training and chats, within shared systems.
3
What products or software are affected?
The affected products include GPU drivers from Apple, AMD, Qualcomm, and potentially Imagination.
4
Who can exploit the GPU security flaw mentioned in the article?
Miscreants on shared systems can exploit this GPU security flaw to gain unauthorized access to other users' information.
5
What does this security vulnerability mean for users of these GPU drivers?
Users of these GPU drivers may be at risk of having their sensitive information observed and exploited by malicious actors on shared platforms.