From Co-Location to Identification: Building a Complete Attack Chain to Identify Multi-Tenant Cloud FPGA Accelerators
摘要
In multi-tenant FPGA cloud environments, identifying victim accelerator types is vital for targeted attacks. However, existing solutions have two key limitations: reliance on impractical co-location assumptions based on undisclosed scheduling strategies, and inability to handle unknown accelerator types, leading to misclassification and inappropriate subsequent attack strategies. To address these, we propose a complete attack chain for practical and flexible identification of multi-tenant cloud FPGA accelerators. Our FadePrint framework uses FPGA hardware fingerprints and an optimized iterative leasing strategy to locate the victim’s server without needing hidden scheduling strategies. Our PredictGuard module applies enhanced conformal prediction to reliably classify known accelerators and flexibly detect unknown ones, further analyzing similarities between types to develop precise attack strategies for unknown accelerators. Evaluated on AWS, FadePrint achieved over 20% co-location success per attack at $2.5 per server leasing attempt, surpassing existing solutions. PredictGuard reached 83% accuracy in identifying unknown accelerator types and maintained an average F1 score of 0.78 for known types after minimizing unknown influences, representing a 50% improvement over state-of-the-art approach.