An Improved Micro-Architectural Covert-Channel Attack on GPUs
摘要
Computing systems, including GPUs, have long been vulnerable to covert-channel attacks. In this work, we address two major challenges: improving the efficiency of contention-based channels and avoiding behavior-based detection techniques. For the first challenge, we present an enhanced mechanism that extends the binary state of traditional contention-based communication to a four-level signaling scheme, significantly boosting the channel’s bandwidth. We demonstrate this on an NVIDIA DGX A100 system, achieving error-free communication at over 44 Mbps on a single GPU and over 340 Mbps across 8 GPUs, surpassing prior works. For the second challenge, we systematically construct covert channels using every available function on the special function units (SFUs) and then introduce behavioral randomization by dynamically combining configurations based on these functions within a single channel. This approach obscures consistent usage patterns, making the channel harder to detect. We implement this randomized strategy in three setups, achieving up to 38 Mbps on a single GPU and 274 Mbps on 8 GPUs, all with BER under 10%. To evaluate stealthiness, we analyze hardware performance counters and use a machine learning-based model to test the detectability of our channel. Results show that our randomized channel significantly reduces detectability compared to traditional contention-based approaches. These enhancements not only raise the bandwidth ceiling of covert channels but also elevate their stealth, amplifying the threat they pose to modern GPU-based systems.