SLAC:基于Apple Silicon系统级缓存的访问驱动CPU到GPU侧信道攻击
SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple Silicon
浏览论文内容
中文总结 AI 辅助
本研究针对Apple Silicon异构SoC发现GPU内存访问会在共享SLC留下可被CPU观测的集合级足迹,提出CPrime+CProbe及加速变体GPrime+CProbe侧信道技术,实现GNN图边重构与LLM隐私攻击,揭示Apple Silicon的微架构漏洞。
中文摘要 AI 辅助
现代异构片上系统(SoC)设计将CPU核心与共享末级缓存(LLC)或系统级缓存(SLC)的GPU集成在一起,这种共享暴露了新的跨域攻击面,现有集成平台攻击要么利用粗粒度缓存占用竞争,要么需要攻击者与受害者共同驻留在GPU上以获取准确的时序测量。本研究针对Apple Silicon异构SoC,发现GPU内存访问会在共享SLC中留下集合级足迹,且该足迹可被未授权的CPU进程观测到,这一敏锐发现促成了首个针对GPU工作负载的细粒度、访问驱动型Prime+Probe式CPU到GPU缓存侧信道攻击。我们首先逆向工程Apple M1的SLC集合索引函数以及本地私有缓存与SLC的交互,基于这些发现构建了CPrime+CProbe SLC侧信道技术,该技术可在缓存集合粒度上从CPU监控GPU受害者活动;随后引入加速变体GPrime+CProbe,其中攻击者利用GPU实现更快的SLC填充,使隐蔽信道吞吐量提升6.4倍。最后,我们利用新侧信道演示了两种端到端隐私攻击:针对图神经网络(GNN)的图边重构攻击,在5个数据集上实现90%的边准确率;针对大语言模型(LLM)的隐私攻击,在TinyLlama和GPT-2 Medium模型上,恢复输入关键词的准确率最高达94.8%,恢复模型响应的准确率最高达88.9%。我们的结果揭示了Apple Silicon中一类新的微架构漏洞,呼吁为异构SoC设计安全的系统级缓存。
英文摘要
Modern heterogeneous System-on-Chip designs integrate CPU cores and a GPU that share a last-level cache (LLC) or system-level cache (SLC). This sharing exposes a new cross-domain attack surface, and existing attacks on integrated platforms either exploit coarse-grained cache-occupancy contention or require the adversary to co-reside on the GPU with the victim to obtain accurate timing measurements. In this work, we target Apple Silicon heterogeneous SoCs and discover that GPU memory accesses leave set-level footprints in the shared SLC, observable to an unprivileged CPU process. This keen observation enables the first fine-grained, access-driven, Prime+Probe-style CPU-to-GPU cache side-channel attacks against GPU workloads. We first reverse-engineer the Apple M1 SLC set-indexing functions and the interactions between local private caches and the SLC. Building on these findings, we construct the CPrime+CProbe SLC side-channel technique, which monitors GPU victim activity from the CPU at cache-set granularity. We then introduce an accelerated variant, GPrime+CProbe, in which an adversary leverages the GPU for faster SLC priming, yielding a 6.4x increase in the covert-channel throughput. Lastly, we demonstrate two end-to-end privacy attacks using the new side-channels: a graph-edge reconstruction attack on Graph Neural Networks (GNNs) that achieves 90% edge accuracy across five datasets, and an LLM privacy attack that recovers input keywords with up to 94.8% accuracy and model responses with up to 88.9% accuracy across TinyLlama and GPT-2 Medium models. Our results reveal a new class of microarchitectural vulnerabilities in Apple Silicon and call for secure system cache designs for heterogeneous SoCs.