Mechanism · On-chip telemetry from timing, memory and performance counters

Software-read telemetry can be forged by the operator

On this page

← All known flaws

CriticalTheoretical argumentOpen

NVML-based classification assumes trustworthy telemetry. Without a tamper-resistant read path, an authenticated telemetry channel and secure boot of the monitoring software, an operator who controls the full software stack could forge counter values 3. Monfared et al. start from the same premise: current GPUs expose little trusted telemetry and can be modified or virtualized 1.

Sources: [3] · [1]

Search

Full search page