WarpGuard:迈向异构CPU-GPU执行的控制流认证
WarpGuard: Towards Control-Flow Attestation for Heterogeneous CPU-GPU Execution
AI总结:
针对异构CPU-GPU工作负载缺乏联合认证的问题,提出WarpGuard框架,通过扩展现有CFA技术,实现GPU内核运行时CFA及边界违规检测,经软件实现,评估表明能检测攻击且开销适中,适用于嵌入式安全关键场景。
AI中文摘要:
异构CPU-GPU工作负载在安全关键型嵌入式系统中越来越常用,但现有的方法都无法对其执行进行联合认证。之前的控制流认证(CFA)技术侧重于CPU端的CFA,而GPU认证仅限于静态的加载时验证,无法提供运行时保证。因此,针对GPU内核的运行时攻击以及CPU-GPU交互契约的违反行为仍未得到解决。我们提出了WarpGuard,这是首个用于异构CPU-GPU工作负载的复合CFA框架。WarpGuard根据捕获CPU和GPU组件的统一控制流图(CFG)来验证执行情况。它通过针对特定内核的CFG跟踪GPU内核的执行情况,实现了GPU内核的运行时CFA,并监控内核启动事件,强制执行每个调用站点的策略,以检测CPU-GPU边界处的违规行为。我们使用基于软件的检测工具实现了WarpGuard,无需特殊硬件或二进制修改。在NVIDIA Jetson Orin Nano上的评估表明,WarpGuard能够检测GPU端的控制流和跨边界攻击。在微基准测试、SPECAccel和八个TensorRT推理工作负载中,WarpGuard产生的开销适中,表明其在嵌入式安全关键型环境中的实用性。
英文摘要:
Heterogeneous CPU-GPU workloads are increasingly used in safety-critical embedded systems, yet no existing approach provides joint attestation of their execution. Prior Control-Flow Attestation (CFA) techniques focus on CPU-side CFA, while GPU attestation is limited to static, load-time verification and does not provide runtime guarantees. As a result, runtime attacks on GPU kernels and violations of the CPU-GPU interaction contract remain unaddressed. We present WarpGuard, the first composite CFA framework for heterogeneous CPU-GPU workloads. WarpGuard verifies execution against a unified control-flow graph (CFG) that captures both CPU and GPU components. It extends prior CFA techniques in two ways: it enables runtime CFA of GPU kernels by tracing their execution against kernel-specific CFGs, and it monitors kernel launch events and enforces per-call site policies to detect violations at the CPU-GPU boundary. These extensions address challenges arising from GPU parallelism and cross-device interactions. We implement WarpGuard using software-based instrumentation, requiring no specialized hardware or binary modifications. Our evaluation on an NVIDIA Jetson Orin Nano shows that WarpGuard detects GPU-side control-flow and cross-boundary attacks. Across microbenchmarks, SPECAccel, and eight TensorRT inference workloads, WarpGuard incurs moderate overheads, suggesting practicality for embedded safety-critical settings.