2026-10-11 17:09 UTC

Chris S. Lin and coauthors claim GPUThor's non-uniform Rowhammer patterns produce 500–23,500 times more bit flips on tested NVIDIA workstation GPUs and enable exploits with ECC enabled, challenging ECC as a sufficient memory-integrity defense for affected GPU deployments.

state: seedheat: mediumuncertainty: mediumknownscott: mediumrowhammer gpu-security memory-integrity ai-infrastructureChris S. LinJoyce QuAditya RajeevGururaj SaileshwarNVIDIA

What is this?

GPUThor is a GPU Rowhammer research attack by University of Toronto researchers Chris S. Lin, Joyce Qu, Aditya Rajeev, and Gururaj Saileshwar, listed on their project site for ACM CCS 2026. The supplied snippets report that non-uniform memory-access patterns produced substantially more bit flips on tested NVIDIA RTX A4000, A4500, A5000, and A6000 GDDR6 workstation GPUs; the roughly 500× and 23,500× gains compare against different prior attacks, with flip-rate measurements taken with ECC disabled. The researchers also report denial of service and host-root privilege escalation with ECC enabled, requiring the ability to execute an unprivileged CUDA kernel, challenging ECC alone as a sufficient defense on affected systems. These are reported research results rather than independently verified findings in the supplied material, and conflicting secondary snippets do not establish vulnerability or immunity for server-class and newer GPUs.

Why it matters to Scott

The radar already tracks this same ECC-enabled host-root development in radar:gputhor-nvidia-ecc-root. The reported unprivileged-CUDA attack warrants reviewing GPU access within SiloOS’s structural containment design and Scott’s gamepc CUDA environment, but the hits establish neither that he uses affected GPUs nor that his containment claims assume ECC is sufficient.
ip:framework.siloosdev:project.silo-osdev:project.gamepcradar:gputhor-nvidia-ecc-root
queries asked of Scott's wikis
  • GPU workload isolation untrusted CUDA execution
  • local inference hardware NVIDIA Ampere GDDR6 deployments
  • ECC memory integrity hardware trust assumptions
  • coding agent sandbox GPU access host privilege boundaries
  • shared GPU infrastructure multi-tenant security

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 650h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-14 14:00⭐ origin echo-reconstructedThe authors report 500X to 23,500X more bit flips across NVIDIA A4000, A4500, A5000, and A6000 GPUs using non-uniform hammering, and claim t
Chris S. Lin, Joyce Qu, Aditya Rajeev, and Gururaj Saileshwar on paper (echo) · attributed from hn.story.49725638
—
09-16 12:07first on hacker news · published · +46.1hGPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit
sbulaev
—
09-16 12:07amplified on hacker news 👑hn.story.49725638
sbulaev
peak 1 · 0 comments · 106% of case engagement
09-16 12:20our radar first saw it · +46.4hdiscovery anchor: hn.story.49725638—
pace: p9 vs 1032 stories at the 336h mark (now 650h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnGPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit
Retrieved article excerpt

Open article · Retrieved 2026-09-16T12:21:49.833455+00:00

# Computer Science > Cryptography and Security

**arXiv:2609.16546** (cs)

[Submitted on 15 Sep 2026]

# Title:GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs

Authors:[Chris S. Lin](https://arxiv.org/search/cs?searchtype=author&query=Lin,+C+S), [Joyce Qu](https://arxiv.org/search/cs?searchtype=author&query=Qu,+J), [Aditya Rajeev](https://arxiv.org/search/cs?searchtype=author&query=Rajeev,+A), [Gururaj Saileshwar](https://arxiv.org/search/cs?searchtype=author&query=Saileshwar,+G)

View a PDF of the paper titled GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs, by Chris S. Lin and Joyce Qu and Aditya Rajeev and Gururaj Saileshwar

[View PDF](https://arxiv.org/pdf/2609.16546)
[HTML (experimental)](https://arxiv.org/html/2609.16546v1)
> Abstract:GDDR memory in GPUs is vulnerable to Rowhammer attacks, where rapid memory accesses induce bit flips in adjacent cells, enabling data tampering and privilege escalation. However, prior GPU Rowhammer attacks trigger only tens to hundreds of bit flips, orders of magnitude fewer than CPU attacks, severely limiting their practical impact. This gap stems from the reliance of existing GPU Rowhammer attacks on uniform hammering patterns that activate aggressor and decoy rows equally, which results in low hammering intensity for aggressor rows.
>   
> We present GPUThor, a high-intensity Rowhammer attack on NVIDIA GPUs leveraging non-uniform hammering. GPUThor reverse engineers GPU memory-access coalescing behavior to enable non-uniform hammering patterns on GPUs, that activate aggressor rows more intensely than decoy rows. Additionally, by identifying refresh instances when in-DRAM mitigations are applied, it constructs longer attack patterns that escape mitigation across refresh intervals, further increasing hammering intensity. Together, these techniques yield 500X to 23,500X more bit flips than prior GPU Rowhammer attacks, across several NVIDIA GPUs (A4000, A4500, A5000, A6000), reaching bit flip rates close to state-of-the-art CPU Rowhammer attacks. GPUThor also enables the first Rowhammer exploits on ECC-protected GPUs, inducing uncorrectable double and triple bit flips, making denial-of-service and privilege-escalation attacks practical even on GPUs with ECC enabled.

|  |
| --- |
| Comments: |
| Subjects: | Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2609.16546](https://arxiv.org/abs/2609.16546) [cs.CR] |
|  | (or  [arXiv:2609.16546v1](https://arxiv.org/abs/2609.16546v1) [cs.CR] for this version) |
|  | <https://doi.org/10.48550/arXiv.2609.16546> Focus to learn more  arXiv-issued DOI via DataCite (pending registration) |

## Submission history

From: Chris S. Lin [[view email](https://arxiv.org/show-email/c6ee9663/2609.16546)]

Full-text links:

## Access Paper:

View a PDF of the paper titled GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs, by Chris S. Lin and Joyce Qu and Aditya Rajeev and Gururaj Saileshwar

- [View PDF](https://arxiv.org/pdf/2609.16546)
- [HTML (experimental)](https://arxiv.org/html/2609.16546v1)
- [TeX Source](https://arxiv.org/src/2609.16546)

[license icon](http://creativecommons.org/licenses/by/4.0/ "Rights to this article")

### Current browse context:

cs.CR

[< prev](https://arxiv.org/prevnext?id=2609.16546&function=prev&context=cs.CR "previous in cs.CR (accesskey p)")
  |   
[next >](https://arxiv.org/prevnext?id=2609.16546&function=next&context=cs.CR "next in cs.CR (accesskey n)")

[new](https://arxiv.org/list/cs.CR/new)
 | 
[recent](https://arxiv.org/list/cs.CR/recent)
 | [2026-09](https://arxiv.org/list/cs.CR/2026-09)

Change to browse by:

[cs](https://arxiv.org/abs/2609.16546?context=cs)

### References & Citations

- [NASA ADS](https://ui.adsabs.harvard.edu/abs/arXiv:2609.16546)
- [Google Scholar](https://scholar.google.com/scholar_lookup?arxiv_id=2609.16546)
- [Semantic Scholar](https://api.semanticscholar.org/arXiv:2609.16546)

export BibTeX citation
Loading...

## BibTeX formatted citation

×

loading...

Data provided by:

### Bookmark

[BibSonomy](http://www.bibsonomy.org/BibtexHandler?requTask=upload&url=https://arxiv.org/abs/2609.16546&description=GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs "Bookmark on BibSonomy")
[Reddit](https://reddit.com/submit?url=https://arxiv.org/abs/2609.16546&title=GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs "Bookmark on Reddit")



Bibliographic Tools

# Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer *([What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))*

Connected Papers Toggle

Connected Papers *([What is Connected Papers?](https://www.connectedpapers.com/about))*

Litmaps Toggle

Litmaps *([What is Litmaps?](https://www.litmaps.co/))*

scite.ai Toggle

scite Smart Citations *([What are Smart Citations?](https://www.scite.ai/))*

Code, Data, Media

# Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv *([What is alphaXiv?](https://alphaxiv.org/))*

Links to Code Toggle

CatalyzeX Code Finder for Papers *([What is CatalyzeX?](https://www.catalyzex.com))*

DagsHub Toggle

DagsHub *([What is DagsHub?](https://dagshub.com/))*

GotitPub Toggle

Gotit.pub *([What is GotitPub?](http://gotit.pub/faq))*

Huggingface Toggle

Hugging Face *([What is Huggingface?](https://huggingface.co/huggingface))*

ScienceCast Toggle

ScienceCast *([What is ScienceCast?](https://sciencecast.org/welcome))*

Demos

# Demos

Replicate Toggle

Replicate *([What is Replicate?](https://replicate.com/docs/arxiv/about))*

Spaces Toggle

Hugging Face Spaces *([What is Spaces?](https://huggingface.co/docs/hub/spaces))*

Spaces Toggle

TXYZ.AI *([What is TXYZ.AI?](https://txyz.ai))*

Related Papers

# Recommenders and Search Tools

Link to Influence Flower

Influence Flower *([What are Influence Flowers?](https://influencemap.cmlab.dev/))*

Core recommender toggle

CORE Recommender *([What is CORE?](https://core.ac.uk/services/recommender))*

- Author
- Venue
- Institution
- Topic


About arXivLabs

# arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.16546) |
Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
sbulaev10
🟧 echo.paper ⭐The authors report 500X to 23,500X more bit flips across NVIDIA A4000, A4500, A5000, and A6000 GPUs using non-uniform hammering, and claim tChris S. Lin, Joyce Qu, Aditya Rajeev, and Gururaj Saileshwar——

Interpretation history

Decision trace