REVIEW 4 major objections 4 minor 1 cited by
GPUHammer: Rowhammer Attacks on GPU Memories are Practical
T0 review · 4 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read This paper demonstrates the first Rowhammer attack on a discrete NVIDIA GPU, flipping bits in GDDR6 DRAM and using one flipped model-weight bit to collapse ML accuracy to near zero.
desk verdict First real shot at Rowhammer on discrete GDDR6, but the ML exploit's delivery mechanism doesn't hold together. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Three mechanisms carry the attack. First, since GPU physical addresses are hidden, the authors learn a lookup table at 256-byte granularity from virtual offsets to DRAM banks and rows by timing row-buffer conflicts, filtering out non-uniform memory-access latency by comparing only addresses with similar single-access latency. Second, the PTX discard instruction plus ld.global.volatile forces every access to miss all caches, and assigning one aggressor row per warp lets multiple warps overlap their memory round trips, raising activations from about 90K to roughly 620K per refresh window, near the theoretical ceiling. Third, per-warp add-instruction delays create an aligned idle bubble at the memory controller so that hammering rounds synchronize with refresh commands; keeping at most 8 warps preserves that synchronization and lets 17-24 aggressor rows overflow the 16-entry TRR sampler.
What would settle it
Recompute the row-sets on the same A6000 after a reboot, a driver update, or memory pressure, then repeat the hammering campaign without re-profiling; if the previously flippable addresses no longer flip, the attack's reusable row-set assumption fails. A second decisive test is to run the same campaign on a second A6000 unit and see whether any bit-flips occur at all.
Extended reading notes
Core claim
The paper's central claim is that an unprivileged CUDA kernel can induce read-disturbance bit-flips in GDDR6 DRAM on a discrete NVIDIA GPU, by recovering the virtual-address-to-DRAM-row mapping, maximizing activation rates through multi-warp hammering, and synchronizing n-sided aggressor patterns to the 1407ns refresh interval to defeat a TRR-like mitigation that tracks at most 16 rows per bank. On the A6000, this yields 8 bit-flips across all 4 hammered banks with a minimum Rowhammer threshold of 12.3K activations, and a single 0-to-1 flip at bit position 6 of a byte maps to the MSB of the FP16 exponent in the weight layout used by common ML runtimes, degrading ResNet50 accuracy from 80.26% to 0.08% (RAD of 0.99). The paper also reports no bit-flips on an A100 with HBM2e or an RTX 3080 with GDDR6, attributing the difference to chip variation, higher thresholds, or on-die ECC.
Load-bearing premise
The whole attack leans on an empirical observation from a single machine: for large allocations, the address mapping that connects what a GPU program sees to the actual memory rows stays fixed across runs, so row-sets profiled once can be reused later.
Editorial extensions
If this is right
- Multi-tenant GPU platforms with GDDR6 and ECC disabled should treat co-located CUDA kernels as capable of corrupting other tenants' GPU memory.
- FP16 ML inference is an actionable target: a single exponent-MSB flip can collapse top-1 accuracy from 80% to 0.02% or below, as shown on AlexNet, VGG16, ResNet50, DenseNet161, and InceptionV3.
- Enabling memory-controller ECC on the A6000 prevents the observed single-bit flips at a measured cost of 3-10% inference slowdown and up to 12% bandwidth loss.
- Randomizing the GPU driver's virtual-to-physical mapping, quarantining freed memory in the allocators commonly used by ML workloads, or adopting RFM/PRAC-style mitigations in GDDR would each raise the attack's cost.
Reading between the lines
- If the same discard/volatile primitives and 256-byte mapping granularity hold on other GDDR6 parts, the reverse-engineering and hammering methods likely transfer to those GPUs, even though bit-flips were only observed on the A6000 in this study.
- The observed data-dependence of bit-flip frequency on victim and aggressor bytes suggests a possible Rowhammer-based side channel that could read GPU memory contents; the paper notes this connection but does not implement it.
- On-die ECC in HBM2e, HBM3, and GDDR7 may hide single-bit Rowhammer errors, but ECC can mis-correct when multiple bits in one codeword flip, so future GPU Rowhammer may become harder rather than impossible.
- Cloud GPU operators cannot conclude safety from the A100 or RTX 3080 results, since Rowhammer thresholds and TRR sampler sizes vary by chip, batch, and temperature; each GPU SKU would need its own empirical test.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. GPUHammer reports the first Rowhammer bit-flips in discrete GPU GDDR6 DRAM. On an NVIDIA RTX A6000, the authors reverse-engineer the virtual-address to DRAM bank/row mapping using latency-based conflict testing, develop multi-warp hammering that approaches ~620K activations per refresh window, synchronize many-sided hammering patterns to tREFI, and observe 8 single-bit flips across 4 DRAM banks. They additionally characterize Rowhammer threshold, TRR sampler size, bit-flip direction, and data-pattern dependence, and claim an end-to-end ML tampering exploit that degrades ImageNet model accuracy via a single bit-flip in the MSB of an FP16 weight exponent.
Significance. If confirmed, the bit-flip result is a significant first: it demonstrates read-disturbance faults in GDDR6 on a discrete NVIDIA GPU, extending Rowhammer beyond CPU DDR/LPDDR memories, and it contributes a feasible methodology for reverse-engineering proprietary GPU DRAM mappings via unprivileged CUDA kernels. The paper also ships an artifact and follows responsible disclosure. However, the evidence base is thin: 8 bit-flips on a single A6000 unit, with key characterizations based on best-of-50 results and no error bars. More importantly, the claimed ML-tampering exploit lacks a working memory-massaging delivery mechanism, as the RMM pool is per-process. The core bit-flip finding is plausible and publishable, but the exploit contribution and several hardware-property conclusions need substantial repair.
major comments (4)
- [Section 8.2] The memory-massaging step described in Section 8.2 is not supported by RMM's design. RMM's pooling memory resource is per-process: memory freed into the attacker's pool is retained in that pool and is not returned to the CUDA driver, so a separate PyTorch process cannot subsequently receive that chunk. The statement that 'this chunk is allocated to the victim process (e.g., PyTorch)' therefore lacks a mechanism. The experiments in Section 8.3 need either a demonstrated cross-process handoff (e.g., via cudaMalloc-based reuse or CUDA IPC) or must be re-scoped to a same-process or simulated setting. As written, Table 4 and Takeaway 5 overstate the practical ML-tampering exploit, which is central to the abstract's claim that an attacker can 'tamper with ML models'.
- [Section 7.4, Figure 12] The conclusion that the TRR-like sampler in A6000 GDDR6 tracks at most 16 rows per bank rests on the fraction of hammers triggering bit-flips from 50 attempts per n-sided pattern on a single victim bit (A1), with no confidence intervals or repetitions on another bank or another chip. Given that only 8 bit-flips were observed in total, the abrupt threshold at n=17 should be reported with error bars and repeated on at least one more bank and ideally another unit before being stated as a hardware property.
- [Section 7.1, Table 1] The attack evaluation is based on a single A6000 unit and only 8 bit-flips (one per row), with no run-to-run variation, no multi-chip results, and no error bars on bit-flip counts, TRH, or activation rates. Since Rowhammer susceptibility is known to vary with DRAM process and temperature, the title/abstract claim that GPU Rowhammer attacks 'are practical' is broader than the evidence supports. Please either test additional units and report distributions, or scope the claims to the specific tested sample.
- [Section 4.3, Observation 4 and Section 10] The attack's repeatability depends on the empirical observation that, for large allocations, the mapping of offsets within the array to DRAM rows remains the same across system/program restarts. This behavior is not guaranteed by any hardware or software contract and was observed only on one system. Driver updates, memory pressure, fragmentation, or different GPU instances could invalidate precomputed row-sets. The paper acknowledges this as a possible mitigation but does not evaluate robustness; this dependency should be explicitly stated as a load-bearing limitation, and ideally tested under at least one perturbation (e.g., driver version or allocation size).
minor comments (4)
- [Appendix A, Listing 4] The delay-generation loop 'for (size_t i = delay; i--;) dummy_sum += dummy;' accumulates into a local variable that is never used, which is dead code under standard compiler optimization and may be eliminated, undermining the intended per-warp synchronization delay. Use a volatile accumulator or a side-effecting operation to preserve the delay.
- [Section 8.3, Table 4] The reported RAD values are the highest across 50 attempts; please also report the median and distribution (e.g., min/max or percentiles) so the reader can assess typical rather than best-case attack impact.
- [Section 6, Observation 5] The introduction states a refresh period of 22 ms (or 32 ms), while Observation 5 concludes 23 ms from tREFI = 1407 ns and 16K tREFIs. Please reconcile these numbers and cite the measurement details consistently.
- [Figure 10] The claim that 8-warp configurations achieve 'strong synchronization' is based on a single visual flat-line at ~1407 ns; adding per-configuration variance or repeated measurements would strengthen the synchronisation analysis.
Circularity Check
No load-bearing circularity; central bit-flip and ML-impact claims are independent empirical measurements, with only minor non-load-bearing self-citations.
full rationale
GPUHammer's central chain is empirical and self-contained: it reverse-engineers GPU virtual-to-DRAM row/bank mappings from timing, measures activation rates with custom kernels, synchronizes hammering to measured tREFI, and observes physical bit-flips on an A6000. Each stage is validated against hardware behavior (latencies, ACT counts, bit-flip counts) rather than against quantities derived from the attack's own definitions or fitted parameters. The ML exploit section corrupts FP16 weights at the bit positions of real measured 0→1 flips and then measures ImageNet accuracy; the accuracy drop is a direct evaluation, not a quantity that was optimized or imputed into the experiment. The paper's assumptions, such as the stability of virtual-to-physical mapping for large allocations, are stated empirical observations (Observation 4) and carry correctness risk, but they are not circular: the bit-flip result is not defined or predicted from the assumption. Self-citations appear in mitigation and related-work contexts, e.g., [80] (QPRAC) in Section 10 and several hardware Rowhammer-mitigation references in Section 11; these are prior published results and none of them supplies the load-bearing premise for the new bit-flip or ML-degradation claims. No fitted input is relabeled as a prediction, no uniqueness theorem is imported from the authors' own prior work, and no ansatz is smuggled in via citation. The RMM memory-massaging handoff concern raised by the skeptic is an end-to-end exploit plausibility issue, not a circularity issue, because the bit-flip and ML accuracy measurements stand independently of whether the cross-process allocation handoff succeeds in all deployments.
Assumptions & free parameters
free parameters (5)
- Conflict detection latency threshold =
350 ns
- NUMA filtering tolerance =
+/-10 ns
- Synchronization delay (add instructions) =
0 to 64 adds (varies by pattern)
- Hammering duration per pattern =
128 ms
- Number of exploit attempts =
50
assumptions (5)
- domain assumption GDDR6 JEDEC timing parameters (tRC about 45 ns, tREFI 1407 ns, tREFW 32 or 23 ms) characterize the A6000 memory controller behavior.
- domain assumption The discard.global.L2 instruction followed by ld.global.volatile provides uncached memory access on Ampere GPUs.
- domain assumption A TRR-like sampler exists in A6000 GDDR6 and can track at most 16 rows per bank.
- domain assumption The virtual-to-physical mapping for large GPU memory allocations is stable across runs and restarts.
- domain assumption RAPIDS Memory Manager immediately reuses freed memory chunks at 256-byte granularity.
Cite this review
Pith. "Pith review of GPUHammer: Rowhammer Attacks on GPU Memories are Practical." pith.science (2026). https://pith.science/paper/DGGJBXZN
@misc{pith2026250708166,
author = {Pith},
title = {Pith review of: GPUHammer: Rowhammer Attacks on GPU Memories are Practical},
year = {2026},
howpublished = {\url{https://pith.science/paper/DGGJBXZN}},
note = {Machine review of arXiv:2507.08166}
}
read the original abstract
Rowhammer is a read disturbance vulnerability in modern DRAM that causes bit-flips, compromising security and reliability. While extensively studied on Intel and AMD CPUs with DDR and LPDDR memories, its impact on GPUs using GDDR memories, critical for emerging machine learning applications, remains unexplored. Rowhammer attacks on GPUs face unique challenges: (1) proprietary mapping of physical memory to GDDR banks and rows, (2) high memory latency and faster refresh rates that hinder effective hammering, and (3) proprietary mitigations in GDDR memories, difficult to reverse-engineer without FPGA-based test platforms. We introduce GPUHammer, the first Rowhammer attack on NVIDIA GPUs with GDDR6 DRAM. GPUHammer proposes novel techniques to reverse-engineer GDDR DRAM row mappings, and employs GPU-specific memory access optimizations to amplify hammering intensity and bypass mitigations. Thus, we demonstrate the first successful Rowhammer attack on a discrete GPU, injecting up to 8 bit-flips across 4 DRAM banks on an NVIDIA A6000 with GDDR6 memory. We also show how an attacker can use these to tamper with ML models, causing significant accuracy drops (up to 80%).
Figures
Figures from the paper (13 more)
Forward citations
Cited by 1 Pith paper
-
ShadowScope: GPU Monitoring and Validation via Composable Side Channel Signals
ShadowScope detects GPU kernel attacks by segmenting kernel execution with marker functions and comparing PMU traces against pre-collected golden references, achieving up to 100% detection in its experiments.
Reference graph
Works this paper leans on
-
[1]
Rapids memory manager
RAPIDS AI. Rapids memory manager. https://gith ub.com/rapidsai/rmm
-
[2]
JEDEC Publishes GDDR7 Memory Spec: Next-Gen Graphics Memory Adds Faster PAM3 Signal- ing and On-Die ECC
AnandTech. JEDEC Publishes GDDR7 Memory Spec: Next-Gen Graphics Memory Adds Faster PAM3 Signal- ing and On-Die ECC. https://www.anandtech.com/ show/21287/jedec-publishes-gddr7-specifica tions-pam3-ecc-higher-density , 2024. Accessed: 2025-01-22
2024
-
[3]
Rip-rh: Pre- venting rowhammer-based inter-process attacks
Carsten Bock, Ferdinand Brasser, David Gens, Christo- pher Liebchen, and Ahamd-Reza Sadeghi. Rip-rh: Pre- venting rowhammer-based inter-process attacks. In Pro- ceedings of the 2019 ACM Asia Conference on Com- puter and Communications Security , pages 561–572, 2019
2019
-
[4]
Can’t touch this: Software-only mitigation against rowhammer attacks targeting kernel memory
Ferdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen, and Ahmad-Reza Sadeghi. Can’t touch this: Software-only mitigation against rowhammer attacks targeting kernel memory. In 26th USENIX Security Sym- posium (USENIX Security 17), pages 117–130, 2017
work page 2017
-
[5]
Chronus: Understanding and securing the cutting-edge industry solutions to dram read disturbance
O˘guzhan Canpolat, A Giray Ya ˘glıkçı, Geraldo F Oliveira, Ataberk Olgun, Nisa Bostancı, Ismail Emir Yuksel, Haocong Luo, O ˘guz Ergin, and Onur Mutlu. Chronus: Understanding and securing the cutting-edge industry solutions to dram read disturbance. In 2025 IEEE International Symposium on High Performance Computer Architecture (HPCA), 2025
work page 2025
-
[6]
Jail- breaking black box large language models in twenty queries
Patrick Chao, Alexander Robey, Edgar Dobriban, Hamed Hassani, George J Pappas, and Eric Wong. Jail- breaking black box large language models in twenty queries. arXiv preprint arXiv:2310.08419, 2023
arXiv 2023
-
[7]
Proflip: Targeted trojan attack with pro- gressive bit flips
Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. Proflip: Targeted trojan attack with pro- gressive bit flips. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), pages 7718–7727, 2021
work page 2021
-
[8]
Webgpu: Unlocking modern gpu ac- cess in the browser
Google Chrome. Webgpu: Unlocking modern gpu ac- cess in the browser. https://developer.chrome.c om/blog/webgpu-io2023, 2023. Accessed: 2025-01- 22
work page 2023
Show all 83 references
-
[9]
A 16-GB 640-GB/s HBM2E DRAM with a data-bus window extension technique and a synergetic on-die ECC scheme
Ki Chul Chun, Yong Ki Kim, Yesin Ryu, Jaewon Park, Chi Sung Oh, Young Yong Byun, So Young Kim, Dong Hak Shin, Jun Gyu Lee, Byung-Kyu Ho, et al. A 16-GB 640-GB/s HBM2E DRAM with a data-bus window extension technique and a synergetic on-die ECC scheme. IEEE Journal of Solid-Stat...
2020
-
[10]
Exploiting correcting codes: On the effec- tiveness of ecc memory against rowhammer attacks
Lucian Cojocar, Kaveh Razavi, Cristiano Giuffrida, and Herbert Bos. Exploiting correcting codes: On the effec- tiveness of ecc memory against rowhammer attacks. In 2019 IEEE Symposium on Security and Privacy (SP) , pages 55–71, 2019
2019
-
[11]
Mignificient: Fast, isolated, and gpu-enabled serverless functions
Marcin Copik, Alexandru Calotoiu, Pengyu Zhou, Uni- versity of Toronto, Lukas Tobler, Torsten Hoefler, ETH Z¨urich, and AYES. Mignificient: Fast, isolated, and gpu-enabled serverless functions. SC ’24: Proceedings of the International Conference for High Performance Computing,...
-
[12]
Cuda samples
NVIDIA Corporation. Cuda samples. https://gi thub.com/NVIDIA/cuda-samples , 2023. Accessed: 2025-01-22
2023
-
[13]
SMASH: Synchronized many-sided rowhammer attacks from JavaScript
Finn de Ridder, Pietro Frigo, Emanuele Vannacci, Herbert Bos, Cristiano Giuffrida, and Kaveh Razavi. SMASH: Synchronized many-sided rowhammer attacks from JavaScript. In 30th USENIX Security Symposium (USENIX Security 21), pages 1001–1018. USENIX As- sociation, August 2021
2021
-
[14]
GPU Time Slicing
NVIDIA Run:ai Docs. GPU Time Slicing. https: //docs.run.ai/v2.17/Researcher/scheduling/ GPU-time-slicing-scheduler/ . Accessed: 2025- 01-22
2025
-
[15]
Ecc on vs ecc off
NVIDIA Developer Forums. Ecc on vs ecc off. https: //forums.developer.nvidia.com/t/ecc-on-v s-ecc-off/20315. Accessed: 2025-01-22
2025
-
[16]
Impact of enabling ecc on power and performance
NVIDIA Developer Forums. Impact of enabling ecc on power and performance. https://forums.dev eloper.nvidia.com/t/impact-of-enabling-ecc -on-power-and-performance/174567 . Accessed: 2025-01-22
2025
-
[17]
Model inversion attacks that exploit confidence infor- mation and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. Model inversion attacks that exploit confidence infor- mation and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, pages 1322–1333, 2015
2015
-
[18]
Grand pwning unit: Accelerating mi- croarchitectural attacks with the GPU
Pietro Frigo, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. Grand pwning unit: Accelerating mi- croarchitectural attacks with the GPU. In 2018 ieee symposium on security and privacy (sp), pages 195–210. IEEE, 2018
2018
-
[19]
Trrespass: Exploiting the many sides of target row refresh
Pietro Frigo, Emanuele Vannacc, Hasan Hassan, Vic- tor van der Veen, Onur Mutlu, Cristiano Giuffrida, Her- bert Bos, and Kaveh Razavi. Trrespass: Exploiting the many sides of target row refresh. In 2020 IEEE Sym- posium on Security and Privacy (SP), pages 747–762, 2020
2020
-
[20]
Explaining and harnessing adversarial exam- ples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial exam- ples. arXiv preprint arXiv:1412.6572, 2014
2014 arXiv
-
[21]
Share GPUs across workloads with GPU time- sharing
Google. Share GPUs across workloads with GPU time- sharing. https://cloud.google.com/kuberne tes- engine/docs/how- to/timesharing- gpus . Accessed: 2025-01-22
2025
-
[22]
Rowhammer
Daniel Gruss, Clémentine Maurice, and Stefan Mangard. Rowhammer. js: A remote software-induced fault attack in javascript. In Detection of Intrusions and Malware, and Vulnerability Assessment: 13th International Con- ference, DIMVA 2016, San Sebastián, Spain, July 7-8, 2016, P...
2016
-
[23]
Fast, flexible allocation for nvidia cuda with rapids memory manager
Mark Harris and Mark Harris. Fast, flexible allocation for nvidia cuda with rapids memory manager. https: //developer.nvidia.com/blog/fast-flexibl e-allocation-for-cuda-with-rapids-memory-m anager/. Accessed: 2025-01-22
2025
-
[24]
Kim, Vic- tor van der Veen, Kaveh Razavi, and Onur Mutlu
Hasan Hassan, Yahya Can Tugrul, Jeremie S. Kim, Vic- tor van der Veen, Kaveh Razavi, and Onur Mutlu. Un- covering in-dram rowhammer protection mechanisms:a new methodology, custom rowhammer patterns, and im- plications. In MICRO-54: 54th Annual IEEE/ACM In- ternational Symposi...
2021
-
[25]
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition, pages 770–778, 2016
2016
-
[26]
Terminal brain damage: Exposing the graceless degradation in deep neural net- works under hardware fault attacks
Sanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida, and Tudor Dumitras. Terminal brain damage: Exposing the graceless degradation in deep neural net- works under hardware fault attacks. In 28th USENIX Security Symposium (USENIX Security 19), pages 497– 514, Santa ...
2019
-
[27]
Densenet: Implementing efficient convnet descriptor pyramids
Forrest Iandola, Matt Moskewicz, Sergey Karayev, Ross Girshick, Trevor Darrell, and Kurt Keutzer. Densenet: Implementing efficient convnet descriptor pyramids. arXiv preprint arXiv:1404.1869, 2014
2014 arXiv
-
[28]
Keck- ler, and Moinuddin Qureshi
Aamer Jaleel, Gururaj Saileshwar, Stephen W. Keck- ler, and Moinuddin Qureshi. Pride: Achieving secure rowhammer mitigation with low-cost in-dram trackers. In 2024 ACM/IEEE 51st Annual International Sympo- sium on Computer Architecture (ISCA) , pages 1157– 1172, 2024
2024
-
[29]
Rethinking page table structure for fast address translation in gpus: A fixed-size hashed page table
Sungbin Jang, Junhyeok Park, Osang Kwon, Yongho Lee, and Seokin Hong. Rethinking page table structure for fast address translation in gpus: A fixed-size hashed page table. In Proceedings of the 2024 International Conference on Parallel Architectures and Compilation Techniques,...
2024
-
[30]
Blacksmith: Scalable rowhammering in the frequency domain
Patrick Jattke, Victor Van Der Veen, Pietro Frigo, Stijn Gunter, and Kaveh Razavi. Blacksmith: Scalable rowhammering in the frequency domain. In 2022 IEEE Symposium on Security and Privacy (SP) , pages 716– 734, 2022
2022
-
[31]
ZenHam- mer: Rowhammer attacks on AMD zen-based platforms
Patrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi, Matej Bölcskei, and Kaveh Razavi. ZenHam- mer: Rowhammer attacks on AMD zen-based platforms. In 33rd USENIX Security Symposium (USENIX Security 24), pages 1615–1633, Philadelphia, PA, August 2024. USENIX Association
2024
-
[32]
DDR4 SDRAM standard (JESD79-4B)
JEDEC. DDR4 SDRAM standard (JESD79-4B). 2017
2017
-
[33]
JEDEC Publishes HBM3 Update to High Band- width Memory (HBM) Standard
JEDEC. JEDEC Publishes HBM3 Update to High Band- width Memory (HBM) Standard. https://www.jede c.org/news/pressreleases/jedec-publishes-h bm3-update-high-bandwidth-memory-hbm-stand ard, 2022. Accessed: 2025-01-22
2022
-
[34]
Graphics Double Data Rate (GDDR6) SGRAM Standard (JESD250D)
JEDEC. Graphics Double Data Rate (GDDR6) SGRAM Standard (JESD250D). 2023
2023
-
[35]
HBM3 Specification
JESD238A. HBM3 Specification. 2023
2023
-
[36]
DDR5 Specification
JESD79-5. DDR5 Specification. 2020
2020
-
[37]
Kim, Minesh Patel, A
Jeremie S. Kim, Minesh Patel, A. Giray Ya˘glıkçı, Hasan Hassan, Roknoddin Azizi, Lois Orosa, and Onur Mutlu. Revisiting rowhammer: An experimental analysis of modern dram devices and mitigation techniques. In 2020 ACM/IEEE 47th Annual International Symposium on Computer Archit...
2020
-
[38]
M. Kim, J. Park, Y . Park, W. Doh, N. Kim, T. Ham, J. W. Lee, and J. Ahn. Mithril: Cooperative row ham- mer protection on commodity dram leveraging man- aged refresh. In 2022 IEEE International Symposium on High-Performance Computer Architecture (HPCA), pages 1156–1169, Los Al...
2022
-
[39]
Flipping bits in memory without accessing them: an experimental study of dram distur- bance errors
Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu. Flipping bits in memory without accessing them: an experimental study of dram distur- bance errors. In Proceeding of the 41st Annual Inter- national Symposi...
2014
-
[40]
Half-Double: Hammering from the next row over
Andreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim, Moritz Lipp, Nicolas Boichat, Eric Shiu, Mattias Nissler, and Daniel Gruss. Half-Double: Hammering from the next row over. In31st USENIX Security Sympo- sium (USENIX Security 22), pages 3807–3824, Boston, MA, August 202...
2022
-
[41]
Zebram: comprehensive and compatible software protection against rowhammer at- tacks
Radhesh Krishnan Konoth, Marco Oliverio, Andrei Tatar, Dennis Andriesse, Herbert Bos, Cristiano Giuf- frida, and Kaveh Razavi. Zebram: comprehensive and compatible software protection against rowhammer at- tacks. In 13th USENIX - (OSDI 18) , pages 697–710, 2018
2018
-
[42]
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E. Hinton. Imagenet classification with deep convolutional neural networks. Commun. ACM, 60(6):84–90, May 2017
2017
-
[43]
Rambleed: Reading bits in memory without accessing them
Andrew Kwong, Daniel Genkin, Daniel Gruss, and Yu- val Yarom. Rambleed: Reading bits in memory without accessing them. In 2020 IEEE Symposium on Security and Privacy (SP), pages 695–711. IEEE, 2020
2020
-
[44]
Measuring gpu memory latency
Chester Lam. Measuring gpu memory latency. https: //chipsandcheese.com/p/measuring-gpu-memor y-latency, 2021. Accessed: 2025-01-22
2021
-
[45]
Radar: Run-time adversarial weight attack detection and accuracy recovery
Jingtao Li, Adnan Siraj Rakin, Zhezhi He, Deliang Fan, and Chaitali Chakrabarti. Radar: Run-time adversarial weight attack detection and accuracy recovery. In 2021 Design, Automation & Test in Europe Conference & Exhibition (DATE), pages 790–795, 2021
2021
-
[46]
Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection
Shaofeng Li, Xinyu Wang, Minhui Xue, Haojin Zhu, Zhi Zhang, Yansong Gao, Wen Wu, and Xuemin Sherman Shen. Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection. In Proceedings of the 33th USENIX Security Symposium, 2024
2024
-
[47]
NeuroPots: Realtime proactive defense against Bit-Flip attacks in neural networks
Qi Liu, Jieming Yin, Wujie Wen, Chengmo Yang, and Shi Sha. NeuroPots: Realtime proactive defense against Bit-Flip attacks in neural networks. In 32nd USENIX Security Symposium (USENIX Security), 2023
2023
-
[48]
Fault injection attack on deep neural network
Yannan Liu, Lingxiao Wei, Bo Luo, and Qiang Xu. Fault injection attack on deep neural network. In Proceed- ings of the 36th International Conference on Computer- Aided Design (ICCAD), 2017
2017
-
[49]
Siloz: Leveraging dram isolation domains to prevent inter-vm rowhammer
Kevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman, Dimitrios Skarlatos, and Baris Kasikci. Siloz: Leveraging dram isolation domains to prevent inter-vm rowhammer. In 29th Symposium on Operating Systems Principles (SOSP), 2023
2023
-
[50]
Rowpress: Amplifying read disturbance in mod- ern dram chips
Haocong Luo, Ataberk Olgun, Abdullah Giray Ya˘glıkçı, Yahya Can Tu˘grul, Steve Rhyner, Meryem Banu Cavlak, Joël Lindegger, Mohammad Sadrosadati, and Onur Mutlu. Rowpress: Amplifying read disturbance in mod- ern dram chips. In 50th International Symposium on Computer Architectu...
2023
-
[51]
Protrr: Principled yet optimal in-dram target row refresh
Michele Marazzi, Patrick Jattke, Flavien Solt, and Kaveh Razavi. Protrr: Principled yet optimal in-dram target row refresh. In IEEE Symposium on Security and Privacy (SP), pages 735–753. IEEE, 2022
2022
-
[52]
REGA: Scalable Rowham- mer Mitigation with Refresh-Generating Activations
Michele Marazzi, Flavien Solt, Patrick Jattke, Kubo Takashi, and Kaveh Razavi. REGA: Scalable Rowham- mer Mitigation with Refresh-Generating Activations. In IEEE Symposium on Security and Privacy (SP), 2023
2023
-
[53]
JESD79-5C
J EDEC. JESD79-5C. https://www.jedec.org/do cument_search?search_api_views_fulltext=je sd79-5c. Accessed: 2025-01-22
2025
-
[54]
Dramscope: Uncovering dram microarchitecture and characteristics by issuing memory commands
Hwayong Nam, Seungmin Baek, Minbok Wi, Michael Jaemin Kim, Jaehyun Park, Chihun Song, Nam Sung Kim, and Jung Ho Ahn. Dramscope: Uncovering dram microarchitecture and characteristics by issuing memory commands. In 2024 ACM/IEEE 51st Annual International Symposium on Computer Ar...
2024
-
[55]
Nvidia multi-instance gpu and nvidia virtual compute server
NVIDIA. Nvidia multi-instance gpu and nvidia virtual compute server. https://www.nvidia.com/content /dam/en-zz/Solutions/design-visualization /solutions/resources/documents1/Technical-B rief-Multi-Instance-GPU-NVIDIA-Virtual-Com pute-Server.pdf, 2020. Accessed: 2025-01-22
2020
-
[56]
PTX: Parallel Thread Execution ISA, Version 8.5
NVIDIA. PTX: Parallel Thread Execution ISA, Version 8.5. https://docs.nvidia.com/cuda/paralle l-thread-execution/index.html, 2025. Accessed: 2025-01-22
2025
-
[57]
An experi- mental analysis of rowhammer in hbm2 dram chips
Ataberk Olgun, Majd Osseiran, A Giray Ya ˘glıkçı, Yahya Can Tu˘grul, Haocong Luo, Steve Rhyner, Behzad Salami, Juan Gomez Luna, and Onur Mutlu. An experi- mental analysis of rowhammer in hbm2 dram chips. In 2023 53rd Annual IEEE/IFIP International Conference on Dependable Syst...
2023
-
[58]
Graphene: Strong yet lightweight row hammer protection
Yeonhong Park, Woosuk Kwon, Eojin Lee, Tae Jun Ham, Jung Ho Ahn, and Jae W Lee. Graphene: Strong yet lightweight row hammer protection. In 2020 53rd An- nual IEEE/ACM International Symposium on Microar- chitecture (MICRO), pages 1–13. IEEE, 2020
2020
-
[59]
DRAMA: Exploiting DRAM addressing for Cross-CPU attacks
Peter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz, and Stefan Mangard. DRAMA: Exploiting DRAM addressing for Cross-CPU attacks. In 25th USENIX Security Symposium (USENIX Security 16) , pages 565–581, Austin, TX, August 2016. USENIX As- sociation
2016
-
[60]
Moat: Securely mitigating rowhammer with per-row activation coun- ters
Moinuddin Qureshi and Salman Qazi. Moat: Securely mitigating rowhammer with per-row activation coun- ters. In Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 1, pages 698– 714, 2025
2025
-
[61]
Moinuddin Qureshi, Aditya Rohan, Gururaj Saileshwar, and Prashant J. Nair. Hydra: enabling low-overhead mitigation of row-hammer at ultra-low thresholds via hybrid tracking. In Proceedings of the 49th Annual Inter- national Symposium on Computer Architecture, ISCA ’22, page 69...
2022
-
[62]
Bit- flip attack: Crushing neural network with progressive bit search
Adnan Siraj Rakin, Zhezhi He, and Deliang Fan. Bit- flip attack: Crushing neural network with progressive bit search. In 2019 IEEE/CVF International Conference on Computer Vision (ICCV), pages 1211–1220, 2019
2019
-
[63]
Flip feng shui: Hammering a needle in the software stack
Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuffrida, and Herbert Bos. Flip feng shui: Hammering a needle in the software stack. In 25th USENIX Security Symposium (USENIX Security), 2016
2016
-
[64]
Mlperf inference benchmark
Vijay Janapa Reddi, Christine Cheng, David Kanter, Pe- ter Mattson, Guenther Schmuelling, Carole-Jean Wu, Brian Anderson, Maximilien Breughe, Mark Charlebois, William Chou, et al. Mlperf inference benchmark. In 2020 ACM/IEEE 47th Annual International Symposium on Computer Arch...
2020
-
[65]
NVIDIA Market Share
Jon Peddie Research. NVIDIA Market Share. https: //www.jonpeddie.com/news/shipments-of-gra phics-add-in-boards-decline-in-q1-of-24-a s-the-market-experiences-a-return-to-seaso nality/. Accessed: 2025-01-22
2025
-
[66]
Berg, and Li Fei-Fei
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, Alexan- der C. Berg, and Li Fei-Fei. Imagenet large scale visual recognition challenge. Int. J. Comput. Vision , 115(3):211–252, De...
2015
-
[67]
Gururaj Saileshwar, Bolin Wang, Moinuddin Qureshi, and Prashant J. Nair. Randomized row-swap: mitigating row hammer by breaking spatial correlation between aggressor and victim rows. In 27th ACM International Conference on Architectural Support for Programming Languages and Op...
2022
-
[68]
Nair, and Moinuddin Qureshi
Anish Saxena, Gururaj Saileshwar, Prashant J. Nair, and Moinuddin Qureshi. Aqua: Scalable rowhammer mit- igation by quarantining aggressor rows at runtime. In 2022 55th IEEE/ACM International Symposium on Mi- croarchitecture (MICRO), pages 108–123, 2022
2022
-
[69]
AddressSanitizer: A fast address sanity checker
Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. AddressSanitizer: A fast address sanity checker. In USENIX Annual Techni- cal Conference (USENIX ATC), 2012
2012
-
[70]
Very deep con- volutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman. Very deep con- volutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556, 2014
2014 arXiv
-
[71]
Implicit memory tagging: No-overhead memory safety using alias-free tagged ecc
Michael B Sullivan, Mohamed Tarek Ibn Ziad, Aamer Jaleel, and Stephen W Keckler. Implicit memory tagging: No-overhead memory safety using alias-free tagged ecc. In 50th Annual International Symposium on Computer Architecture (ISCA), 2023
2023
-
[72]
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. Rethinking the inception architecture for computer vision. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2016
2016
-
[73]
Throwhammer: Rowhammer attacks over the network and defenses
Andrei Tatar, Radhesh Krishnan Konoth, Elias Athana- sopoulos, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. Throwhammer: Rowhammer attacks over the network and defenses. In 2018 USENIX Annual Techni- cal Conference (USENIX ATC), 2018
2018
-
[74]
Don’t knock! rowhammer at the backdoor of dnn models
M Caner Tol, Saad Islam, Andrew J Adiletta, Berk Sunar, and Ziming Zhang. Don’t knock! rowhammer at the backdoor of dnn models. In 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), 2023
2023
-
[75]
Drammer: Deterministic Rowhammer Attacks on Mo- bile Platforms
Victor van der Veen, Yanick Fratantonio, Martina Lin- dorfer, Daniel Gruss, Clementine Maurice, Giovanni Vi- gna, Herbert Bos, Kaveh Razavi, and Cristiano Giuffrida. Drammer: Deterministic Rowhammer Attacks on Mo- bile Platforms. In 2016 ACM SIGSAC Conference on Computer and C...
2016
-
[76]
Guardion: Practical mitigation of dma-based rowham- mer attacks on arm
Victor Van der Veen, Martina Lindorfer, Yanick Fratan- tonio, Harikrishnan Padmanabha Pillai, Giovanni Vigna, Christopher Kruegel, Herbert Bos, and Kaveh Razavi. Guardion: Practical mitigation of dma-based rowham- mer attacks on arm. In International Conference on Detection of...
2018
-
[77]
Aegis: Mitigating targeted bit-flip attacks against deep neural networks
Jialai Wang, Ziyuan Zhang, Meiqi Wang, Han Qiu, Tian- wei Zhang, Qi Li, Zongpeng Li, Tao Wei, and Chao Zhang. Aegis: Mitigating targeted bit-flip attacks against deep neural networks. In 32nd USENIX Security Sym- posium (USENIX Security 23), pages 2329–2346, Ana- heim, CA, Aug...
2023
-
[78]
Dramdig: A knowledge-assisted tool to uncover dram address mapping
Minghua Wang, Zhi Zhang, Yueqiang Cheng, and Surya Nepal. Dramdig: A knowledge-assisted tool to uncover dram address mapping. In 2020 57th ACM/IEEE Design Automation Conference (DAC), 2020
2020
-
[79]
SHADOW: Preventing Row Hammer in DRAM with Intra-Subarray Row Shuffling
Minbok Wi, Jaehyun Park, Seoyoung Ko, Michael Jaemin Kim, Nam Sung Kim, Eojin Lee, and Jung Ho Ahn. SHADOW: Preventing Row Hammer in DRAM with Intra-Subarray Row Shuffling. In HPCA, 2023
2023
-
[80]
Qprac: Towards secure and practical prac-based rowhammer mitigation using priority queues
Jeonghyun Woo, Shaopeng Chris Lin, Prashant J Nair, Aamer Jaleel, and Gururaj Saileshwar. Qprac: Towards secure and practical prac-based rowhammer mitigation using priority queues. In 2025 IEEE International Sym- posium on High Performance Computer Architecture (HPCA), 2025
2025
-
[81]
Scalable and secure row-swap: Efficient and safe row hammer mitigation in memory systems
Jeonghyun Woo, Gururaj Saileshwar, and Prashant J Nair. Scalable and secure row-swap: Efficient and safe row hammer mitigation in memory systems. In HPCA, 2023
2023
-
[82]
Deep- Hammer: Depleting the intelligence of deep neural net- works through targeted chain of bit flips
Fan Yao, Adnan Siraj Rakin, and Deliang Fan. Deep- Hammer: Depleting the intelligence of deep neural net- works through targeted chain of bit flips. In USENIX Security, 2020
2020
-
[83]
discard.global.L2 [%0], 128
A. Giray Ya˘glikçi, Minesh Patel, Jeremie S. Kim, Rokn- oddin Azizi, Ataberk Olgun, Lois Orosa, Hasan Has- san, Jisung Park, Konstantinos Kanellopoulos, Taha Shahroodi, Saugata Ghose, and Onur Mutlu. Blockham- mer: Preventing rowhammer at low cost by blacklisting rapidly-acces...
2021
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.