GPUThor reveals 23,500× more bit flips on NVIDIA GPUs via rowhammer; EM injection exposes side channels; advances in fault-tolerant quantum computing.
Key Takeaways
- GPUThor reveals that ECC on NVIDIA GPUs is vulnerable to amplified rowhammer attacks causing significant data corruption and denial of service.
- Electromagnetic injection side channels pose a serious threat by leaking sensitive analog information from consumer devices.
- Current ECC protections are insufficient; enhanced error correction and hardware-level defenses are necessary.
- Advanced quantum computing architectures are progressing with local fault tolerance and efficient decoding methods.
- The race between scaling AI intelligence and securing hardware systems is intensifying, requiring multidisciplinary defense strategies.
What the video covers
- GPUThor significantly amplifies rowhammer attacks on NVIDIA ECC-protected GPUs, producing up to 377,000 bit flips per GB, 23,500× more than prior attacks.
- The attack exploits GPU memory access coalescing and GDDR6 target row refresh behavior using nonuniform multi-refi patterns and decoys to evade mitigation.
- Experiments found double-bit and triple-bit flips causing silent data corruption and denial of service even with ECC enabled on RTX A6000 GPUs.
- Privilege escalation is demonstrated by exploiting ECC miscorrection and the brief interval before GPU termination.
- The findings challenge Nvidia's claim that enabling ECC alone is sufficient and call for stronger error correction, row activation tracking, and memory integrity defenses.
- Injected and leaked paper introduces injection-induced electromagnetic side channels, where attackers inject RF carriers to leak analog secrets via nonlinear hardware.
- Using USRP B210, directional antennas, spectrum analysis, and generative speech enhancement, intelligible audio was recovered from devices including headphones and smart appliances.
- Closed-loop attacks can eavesdrop on landline conversations, synthesize context-aware responses, and inject them back into calls.
- Mitigation includes replacing parallel wiring with twisted pair wiring and calls for electromagnetic hardening and active carrier detection.
- The third paper presents a fully spatially local fault-tolerant quantum computing architecture using 2D topological codes and time-translation invariant cellular automaton decoders.
Chapters
- 00:00Introduction and Overview of Hardware Security Challenges
- 00:37GPUThor: Amplified Rowhammer Attacks on NVIDIA GPUs
- 02:25Details of GPUThor Attack Patterns and Effects
- 03:30Experimental Results and ECC Limitations
- 04:05Privilege Escalation and Defense Implications
- 05:30Injected and Leaked: Electromagnetic Injection Side Channel Attacks
- 06:41Attack Demonstrations and Mitigations for EM Side Channels
- 08:21Fault Tolerant Quantum Computing Architectures
Full Transcript — Download SRT & Markdown
Speaker A
The biggest shift in this week's AI research is a move below the software stack. Hardware running modern computation can be manipulated, measured, and even in quantum systems made fault tolerant through local operations. Nvidia's ECC-protected GPUs can suffer catastrophic row hammer effects, while electromagnetic injection can turn ordinary devices into unintended microphones. Together, these results expose a broader race between scaling intelligence and securing the physical systems beneath it. We'll trace the attack surfaces, the role of nonlinear hardware, and the architecture pushing reliable quantum computing toward reality. Let's explore the first paper. GPU Thor: amplifying rowhammer attacks via nonuniform patterns to exploit ECC-protected GPUs.
Speaker A
effects while electromagnetic injection can turn ordinary devices into unintended microphones. Together, these results expose a broader race between scaling intelligence and securing the physical systems beneath it. We'll trace the attack surfaces, the role of nonlinear hardware, and the architecture
Speaker A
GPU Thor shows that rowhammer attacks against Nvidia GPUs are far more powerful than earlier results suggested.
Speaker A
GPU Thor shows that rowhammer attacks against Nvidia GPUs are far more powerful than earlier results suggested.
Speaker A
The attack reverse engineers GPU memory access coalescing and GDDR6 target row refresh behavior, then distributes repeated aggressor accesses across different warps and cache lines while using non-uniform multi-refi patterns.
Speaker A
Its selected pattern spans six Trefi and reaches 6.6 six acts per Trefi, concentrating activations on victim adjacent rows while using decoys to evade mitigation across NVIDIA RTX A4000 A4500 A5000, and A6000 GPUs. GPU Thor produces 72,000 to 377,000 bit flips per GB, or
Speaker A
Its selected pattern spans six Trefi and reaches 6.66 acts per Trefi, concentrating activations on victim adjacent rows while using decoys to evade mitigation across NVIDIA RTX A4000, A4500, A5000, and A6000 GPUs. GPU Thor produces 72,000 to 377,000 bit flips per GB, or as much as 23,500 times more than prior GPU attacks. It also undermines sector dead ECC.
Speaker A
Experiments found 387 double- bit flips that ECC could detect but not correct, plus two triple bit flips that cause silent data corruption. With ECC enabled on an RTX A6000, the attack triggered denial of service conditions at an average rate of one DUE per hour. And
Speaker A
Experiments found 387 double-bit flips that ECC could detect but not correct, plus two triple bit flips that cause silent data corruption. With ECC enabled on an RTX A6000, the attack triggered denial of service conditions at an average rate of one DUE per hour. And
Speaker A
defenses. Let's explore the second paper. Injected and leaked actively inducing side channel leakage using electromagnetic injection and hardware nonlinearity.
Speaker A
the researchers demonstrated privilege escalation by exploiting ECC miscorrection and the roughly 10 millisecond interval before the GPU is terminated. The findings challenge Nvidia's recommendation that enabling ECC is sufficient protection and motivate stronger error correction, row activation tracking, and memory integrity defenses. Let's explore the second paper. Injected and leaked: actively inducing side channel leakage using electromagnetic injection and hardware nonlinearity.
Speaker A
secrets onto measurable electromagnetic emissions. The resulting injective system combines a USRPB 210 directional antennas spectrum analysis and the score-based generative speech enhancement model SGMSSE trained with synthetic distortions derived from Libra speech testing across 11 commercial devices including Sony and
Speaker A
This paper introduces injection-induced EM side channels, a threat model in which an attacker injects a radio frequency carrier and exploits nonlinear hardware amplifiers, analog to digital converters, switching MOSFETs, and power converters to modulate otherwise difficult to leak low-frequency analog secrets onto measurable electromagnetic emissions. The resulting injective system combines a USRP B210, directional antennas, spectrum analysis, and the score-based generative speech enhancement model SGMSSE trained with synthetic distortions derived from Libra speech testing across 11 commercial devices including Sony and Apple headphones, Xiaomi smart appliances, and a flying voice landline recovered audio fan activity, lamp brightness, and power consumption
Speaker A
consumption patterns, including through walls. With higher power equipment, intelligible headphone speech was recovered at 30M. On Ugax 2 headphones, SGMSE increased average SNR from 7.0 dB to 16.1 dB and improved STI from 0.58 to 0.72, suppressing nonlinear harmonics and
Speaker A
patterns, including through walls. With higher power equipment, intelligible headphone speech was recovered at 30 meters. On Ugax 2 headphones, SGMSE increased average SNR from 7.0 dB to 16.1 dB and improved STI from 0.58 to 0.72, suppressing nonlinear harmonics and carrier noise. The study also demonstrates a closed loop attack that eavesdrops on a landline conversation, synthesizes a context-aware response with index TTS2, and injects it back into the call. As a mitigation, replacing parallel wiring with twisted pair wiring
Speaker A
reduced leakage SNR by 10.7 dB. Although the authors argue that robust protection requires electromagnetic hardening, active carrier detection and analog interface security codees.
Speaker A
reduced leakage SNR by 10.7 dB. Although the authors argue that robust protection requires electromagnetic hardening, active carrier detection, and analog interface security codes.
Speaker A
This paper presents the first fully spatially local fault tolerant quantum computing architecture based on topological codes in 2D using geometrically local quantum and classical operations, bounded speed communication and constant resource density. Its core is a time translation invariant cellular automaton decoder
Speaker A
Let's explore the third paper: local decoders for fault tolerant quantum computation and translation invariant stabilizer codes.
Speaker A
Translation invariant streaming decoders reduce the classical overhead to poly log log lbit bits per site while hierarchical coarse grain decoders achieve constant density for toric and surface codes including decoding during state preparation state injection lattice surgery fold transversal hadards
Speaker A
This paper presents the first fully spatially local fault tolerant quantum computing architecture based on topological codes in 2D using geometrically local quantum and classical operations, bounded speed communication, and constant resource density. Its core is a time translation invariant cellular automaton decoder
Speaker A
implements universal Clifford plus T comput computation using lattice surgery, magic state distillation and Y-state distillation with one constant bandwidth input output wire per logical cubit. A general proof based on HA polomial formalism and Grooner basis division establishes local decodability
Speaker A
that drives defect clusters toward designated corners where they annihilate, while linear defect and message erosion yield non-zero thresholds, stretch exponential memory lifetimes, and polylogarithmic average decoding time.
Speaker A
That's a wrap on today's AI paper highlights. Thanks for watching.
Topics:GPUThorrowhammerNVIDIA GPUsECC vulnerabilityelectromagnetic injectionside channel attackfault tolerant quantum computingquantum error correctionhardware securityAI hardware vulnerabilities











