Container Image Security in HPC: A Comprehensive Large-Scale Evaluation

Emmanuel Oseghale, Cheng Hong Yang, Shanchao Li, Donovan Zhang, Seung-Hwam Lim, Zechun Cao, Xing Gao, Yuede Ji · 2025

High-performance computing (HPC) infrastructures are critical computational resources to support cutting-edge scientific research and engineering applications. Containers, e.g., Docker, and Singularity, have become prevalent in HPC, as they provide a lightweight and isolated environment for running applications in a consistent and portable manner. However, the containers in HPC infrastructure can lead to security threats caused by the insecure container images, allowing remote attackers to execute arbitrary code, and steal sensitive data. Unfortunately, existing works on container image security barely study HPC-specific images and are often small-scale. Motivated by that, we conduct a large-scale study of security and privacy threats associated with container images on HPC infrastructures. We collected a large-scale dataset with 4,784 container images used in HPC. After scanning their vulnerabilities, we made several alarming findings. First, the container images used in HPC have a large number of vulnerabilities, that is, over 2,000 vulnerabilities per image. Second, the detected vulnerabilities tend to be very severe, that is, up to 65 % of vulnerabilities are classified as medium, high, or critical severity. Such vulnerabilities can lead to serious potential threats to HPC infrastructures. We hope this study could raise awareness of security concerns in the broad HPC community.

Read the paper · More papers on PaperTik