2026-10-11 17:11 UTC

Independent reproduction and vendor review will determine whether SLAC’s Apple Silicon system-level-cache channel enables practical CPU-to-GPU data leakage requiring architectural or software mitigations.

state: expiredheat: lowuncertainty: highcontradictsscott: mediumapple-silicon side-channel-attacks local-inference-securityApple

What is this?

SLAC is a research paper reporting what it describes as the first fine-grained, access-driven Prime+Probe CPU-to-GPU cache side-channel on Apple Silicon. The researchers say they reverse-engineered the M1 system-level-cache indexing behavior and showed that an unprivileged CPU process can observe cache footprints left by sensitive GPU workloads, making the shared cache in Apple’s unified-memory architecture a cross-domain attack surface. The supplied snippets do not identify the authors or establish independent reproduction, practical leakage of specific model data, Apple’s review, or any vendor mitigation.

Why it matters to Scott

If reproduced with practical leakage, SLAC’s cross-domain cache channel would challenge the sufficiency of SiloOS and padded-cell software isolation on shared Apple Silicon hardware: an unprivileged process could observe a GPU workload despite nominal containment boundaries. The current evidence establishes cache-footprint observation, not model-data extraction or a deployable exploit, so this is a provisional architectural challenge rather than a demonstrated break requiring immediate redesign.
ip:framework.siloosip:concept.architectural-containmentdev:concept.padded-cell-agent-architecturedev:concept.hardware-aware-local-inferenceradar:concept.apple-siliconradar:concept.local-inferenceradar:concept.llm-securityradar:sparsety-sparse-serving-token-leak
queries asked of Scott's wikis
  • local inference threat models for untrusted processes
  • Apple Silicon unified-memory security assumptions
  • GPU workload side channels and model-data leakage
  • hardware isolation requirements for private local AI
  • cache side-channel mitigations in heterogeneous CPU-GPU systems
  • security tradeoffs of shared memory for local inference

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnSLAC: CPU-to-GPU Side-Channel Attacks via System-Level Cache on Apple Siliconsbulaev20
🟧 echo.paper ⭐This is the original research paper. Its abstract reports the first fine-grained CPU-to-GPU Prime+Probe attacks via Apple Silicon’s shared sTianhong Xu, Saion K. Roy, Ruyi Ding, Aidong Adam Ding, and Yunsi Fei——

Interpretation history

Decision trace