CUDA, Woulda, Shoulda: Returning Exploits in a SASS-y World

Jonas Roels, Adriaan Jacobs, Stijn Volckaert · 2025

The rising popularity of Graphics Processing Units (GPUs) has made them an attractive target for attackers looking to steal Intellectual Property (IP) such as ML models or disrupt the operation of heterogeneous computing systems. However, defending against GPU attacks is anything but trivial since the inner workings of these-often proprietary-devices are still poorly understood. Preliminary work demonstrates a worrying similarity to the attack surface of the CPU domain, particularly concerning the memory unsafety of device-side code. We corroborate these worrying findings by constructing the first rigorous experimental analysis of input-triggered, ROP-based exploits entirely within device-side NVIDIA CUDA code. We repurposed known CPU-based code-reuse attack techniques to unlock previously unusable gadgets in this code and demonstrate that the gadget set is Turing-complete, enabling attackers to perform arbitrary computations. We conclude that ROP attacks on GPUs are feasible and more potent than previously thought.

Read the paper · More papers on PaperTik