{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:44:26Z","timestamp":1787017466203,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T00:00:00Z","timestamp":1700524800000},"content-version":"vor","delay-in-days":6,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-2147217, CNS-2054657, CNS-2008339, CNS-1942182"],"award-info":[{"award-number":["CNS-2147217, CNS-2054657, CNS-2008339, CNS-1942182"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616672","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"960-974","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":29,"title":["<u>T<\/u>\n                    unne\n                    <u>L<\/u>\n                    s for\n                    <u>B<\/u>\n                    ootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIG"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9025-3460","authenticated-orcid":false,"given":"Zhenkai","family":"Zhang","sequence":"first","affiliation":[{"name":"Clemson University, Clemson, SC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0253-372X","authenticated-orcid":false,"given":"Tyler","family":"Allen","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte, Charlotte, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-5641","authenticated-orcid":false,"given":"Fan","family":"Yao","sequence":"additional","affiliation":[{"name":"University of Central Florida, Orlando, FL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2574-029X","authenticated-orcid":false,"given":"Xing","family":"Gao","sequence":"additional","affiliation":[{"name":"University of Delaware, Newark, DE, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2218-3675","authenticated-orcid":false,"given":"Rong","family":"Ge","sequence":"additional","affiliation":[{"name":"Clemson University, Clemson, SC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. envytools. https:\/\/github.com\/envytools\/envytools."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Andreas Abel and Jan Reineke. 2013. Measurement-Based Modeling of the Cache Replacement Policy. In RTAS.","DOI":"10.1109\/RTAS.2013.6531080"},{"key":"e_1_3_2_1_3_1","unstructured":"Jaeguk Ahn Jiho Kim Hans Kasan Leila Delshadtehrani Wonjun Song Ajay Joshi and John Kim. 2021. Network-on-Chip Microarchitecture-Based Covert Channel in GPUs. In MICRO."},{"key":"e_1_3_2_1_4_1","unstructured":"cnvrg.io. [n. d.]. Multi-Instance GPU Support for ML Workloads with cnvrg.io on NVIDIA A100. https:\/\/cnvrg.io\/solutions\/multi-instance-gpu\/."},{"key":"e_1_3_2_1_5_1","volume-title":"TLB-Pilot: Mitigating TLB Contention Attack on GPUs with Microarchitecture-Aware Scheduling. ACM TACO","author":"Di Bang","year":"2021","unstructured":"Bang Di, Daokun Hu, Zhen Xie, Jianhua Sun, Hao Chen, Jinkui Ren, and Dong Li. 2021. TLB-Pilot: Mitigating TLB Contention Attack on GPUs with Microarchitecture-Aware Scheduling. ACM TACO (2021)."},{"key":"e_1_3_2_1_6_1","volume-title":"Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU Systems. In ISCA.","author":"Dutta Sankha Baran","year":"2021","unstructured":"Sankha Baran Dutta, Hoda Naghibijouybari, Nael Abu-Ghazaleh, Andres Marquez, and Kevin Barker. 2021. Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU Systems. In ISCA."},{"key":"e_1_3_2_1_7_1","volume-title":"Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU Systems. arXiv preprint arXiv:2203.15981","author":"Dutta Sankha Baran","year":"2022","unstructured":"Sankha Baran Dutta, Hoda Naghibijouybari, Arjun Gupta, Nael Abu-Ghazaleh, Andres Marquez, and Kevin Barker. 2022. Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU Systems. arXiv preprint arXiv:2203.15981 (2022)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Dmitry Evtyushkin and Dmitry Ponomarev. 2016. Covert Channels through Random Number Generator: Mechanisms Capacity Estimation and Mitigations. In CCS.","DOI":"10.1145\/2976749.2978374"},{"key":"e_1_3_2_1_9_1","unstructured":"Ben Gras Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2018. Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB Attacks. In USENIX Security."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice Klaus Wagner and Stefan Mangard. 2016. FlushFlush: A Fast and Stealthy Cache Attack. In DIMVA.","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_1_12_1","volume-title":"Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set Associativity. In MICRO.","author":"Guo Yanan","year":"2022","unstructured":"Yanan Guo, Xin Xin, Youtao Zhang, and Jun Yang. 2022. Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set Associativity. In MICRO."},{"key":"e_1_3_2_1_13_1","unstructured":"Mark Harris. 2013. Unified Memory in CUDA 6. https:\/\/developer.nvidia.com\/blog\/unified-memory-in-cuda-6\/."},{"key":"e_1_3_2_1_14_1","volume-title":"Dissecting the NVidia Turing T4 GPU via Microbenchmarking. CoRR","author":"Jia Zhe","year":"2019","unstructured":"Zhe Jia, Marco Maggioni, Jeffrey Smith, and Daniele Paolo Scarpazza. 2019. Dissecting the NVidia Turing T4 GPU via Microbenchmarking. CoRR, Vol. abs\/1903.07486 (2019). [arXiv]1903.07486 http:\/\/arxiv.org\/abs\/1903.07486"},{"key":"e_1_3_2_1_15_1","volume-title":"Dissecting the NVIDIA Volta GPU Architecture via Microbenchmarking. CoRR","author":"Jia Zhe","year":"2018","unstructured":"Zhe Jia, Marco Maggioni, Benjamin Staiger, and Daniele Paolo Scarpazza. 2018. Dissecting the NVIDIA Volta GPU Architecture via Microbenchmarking. CoRR, Vol. abs\/1804.06826 (2018). [arXiv]1804.06826 http:\/\/arxiv.org\/abs\/1804.06826"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Tomas Karnagel Tal Ben-Nun Matthias Werner Dirk Habich and Wolfgang Lehner. 2017. Big Data Causing Big (TLB) Problems: Taming Random Memory Accesses on the GPU. In DaMoN.","DOI":"10.1145\/3076113.3076115"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Jakob Koschel Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2020. TagBleed: Breaking KASLR on the Isolated Kernel Address Space using Tagged TLBs. In EuroS&P.","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_2_1_18_1","unstructured":"Sangho Lee Youngsok Kim Jangwoo Kim and Jong Kim. 2014. Stealing Webpages Rendered on Your Browser by Exploiting GPU Vulnerabilities. In S&P."},{"key":"e_1_3_2_1_19_1","unstructured":"Tobias Mann. 2022. Fractional GPUs Empower New Wave Of Accelerated Software Development. https:\/\/www.nextplatform.com\/2022\/06\/03\/fractional-gpus-empower-new-wave-of-accelerated-software-development\/."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Cl\u00e9mentine Maurice Christoph Neumann Olivier Heen and Aur\u00e9lien Francillon. 2014. Confidentiality Issues on a GPU in a Virtualized Environment. In FC.","DOI":"10.1007\/978-3-662-45472-5_9"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Cl\u00e9mentine Maurice Christoph Neumann Olivier Heen and Aur\u00e9lien Francillon. 2015. C5: Cross-Cores Cache Covert Channel. In DIMVA.","DOI":"10.1007\/978-3-319-20550-2_3"},{"key":"e_1_3_2_1_22_1","volume-title":"Stefan Mangard, and Kay R\u00f6mer.","author":"Maurice Cl\u00e9mentine","year":"2017","unstructured":"Cl\u00e9mentine Maurice, Manuel Weber, Michael Schwarz, Lukas Giner, Daniel Gruss, Carlo Alberto Boano, Stefan Mangard, and Kay R\u00f6mer. 2017. Hello from the Other Side: SSH over Robust Cache Covert Channels in the Cloud. In NDSS."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2016.2549523"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Hoda Naghibijouybari Khaled N. Khasawneh and Nael Abu-Ghazaleh. 2017. Constructing and Characterizing Covert Channels on GPGPUs. In MICRO.","DOI":"10.1145\/3123939.3124538"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243831"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Ajay Nayak Pratheek B. Vinod Ganapathy and Arkaprava Basu. 2021. (Mis)Managed: A Novel TLB-Based Covert Channel on GPUs. In ASIA CCS.","DOI":"10.1145\/3433210.3453077"},{"key":"e_1_3_2_1_27_1","unstructured":"NVIDIA. relax a. CUDA C Programming Guide. https:\/\/docs.nvidia.com\/cuda\/cuda-c-programming-guide\/."},{"key":"e_1_3_2_1_28_1","unstructured":"NVIDIA. relax b. Multi-Process Service. https:\/\/docs.nvidia.com\/deploy\/mps\/index.html."},{"key":"e_1_3_2_1_29_1","unstructured":"NVIDIA. relax c. NVIDIA A100 Tensor Core GPU Architecture. https:\/\/images.nvidia.com\/aem-dam\/en-zz\/Solutions\/data-center\/nvidia-ampere-architecture-whitepaper.pdf."},{"key":"e_1_3_2_1_30_1","unstructured":"NVIDIA. relax d. NVIDIA cuDNN Developer Guide. https:\/\/docs.nvidia.com\/deeplearning\/cudnn\/developer-guide\/index.html."},{"key":"e_1_3_2_1_31_1","unstructured":"NVIDIA. relax e. NVIDIA Multi-Instance GPU and NVIDIA Virtual Compute Server. https:\/\/www.nvidia.com\/content\/dam\/en-zz\/Solutions\/design-visualization\/solutions\/resources\/documents1\/Technical-Brief-Multi-Instance-GPU-NVIDIA-Virtual-Compute-Server.pdf."},{"key":"e_1_3_2_1_32_1","unstructured":"NVIDIA. relax f. NVIDIA Multi-Instance GPU User Guide. https:\/\/docs.nvidia.com\/datacenter\/tesla\/mig-user-guide\/."},{"key":"e_1_3_2_1_33_1","unstructured":"NVIDIA. relax g. NVIDIA Virtual GPU Software Documentation. https:\/\/docs.nvidia.com\/grid\/latest\/."},{"key":"e_1_3_2_1_34_1","unstructured":"NVIDIA. relax h. Pascal MMU Format Changes. https:\/\/nvidia.github.io\/open-gpu-doc\/pascal\/gp100-mmu-format.pdf."},{"key":"e_1_3_2_1_35_1","unstructured":"Chang Hyun Park Taekyung Heo Jungi Jeong and Jaehyuk Huh. 2017. Hybrid TLB Coalescing: Improving TLB Translation Coverage under Diverse Fragmented Memory Allocations. In ISCA."},{"key":"e_1_3_2_1_36_1","unstructured":"Josh Patterson. 2021. A Cloud GPU Value Model for NVIDIA Multi-Instance GPUs (MIG). http:\/\/www.pattersonconsultingtn.com\/blog\/cloud_gpu_value_model_for_nvidia_mig.html."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Binh Pham Abhishek Bhattacharjee Yasuko Eckert and Gabriel H Loh. 2014. Increasing TLB Reach by Exploiting Clustering in Page Translations. In HPCA.","DOI":"10.1109\/HPCA.2014.6835964"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Binh Pham Viswanathan Vaidyanathan Aamer Jaleel and Abhishek Bhattacharjee. 2012. CoLT: Coalesced Large-Reach TLBs. In MICRO.","DOI":"10.1109\/MICRO.2012.32"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Bharath Pichai Lisa Hsu and Abhishek Bhattacharjee. 2014. Architectural Support for Address Translation on GPUs: Designing Memory Management Units for CPU\/GPUs with Unified Address Spaces. In ASPLOS.","DOI":"10.1145\/2541940.2541942"},{"key":"e_1_3_2_1_40_1","unstructured":"Puzl.cloud. [n. d.]. Kubernetes based GPU cloud. https:\/\/puzl.cloud\/gpu-cloud."},{"key":"e_1_3_2_1_41_1","unstructured":"Run:AI. 2020. Run:AI creates first fractional GPU sharing for Kubernetes deep learning workloads. https:\/\/www.run.ai\/blog\/run-ai-creates-first-fractional-gpu-sharing-for-kubernetes-deep-learning-workloads."},{"key":"e_1_3_2_1_42_1","unstructured":"Peter Van Sandt and Zhe Jia. 2021. Dissecting the Ampere GPU Architecture through Microbenchmarking. https:\/\/www.nvidia.com\/en-us\/on-demand\/session\/gtcspring21-s33322\/."},{"key":"e_1_3_2_1_43_1","unstructured":"Tim C. Schroeder. 2011. Peer-to-Peer & Unified Virtual Addressing. https:\/\/developer.download.nvidia.com\/CUDA\/training\/cuda_webinars_GPUDirect_uva.pdf."},{"key":"e_1_3_2_1_44_1","unstructured":"Anton Shilov. 2021. Nvidia Increases Market Share as GPU Sales Explode: JPR. https:\/\/www.tomshardware.com\/news\/jpr-gpu-shipments-in-q1--2021-hit-119-million-units."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Mert Side Fan Yao and Zhenkai Zhang. 2022. LockedDown: Exploiting Contention on Host-GPU PCIe Bus for Fun and Profit. In EuroS&P.","DOI":"10.1109\/EuroSP53844.2022.00025"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Dean Sullivan Orlando Arias Travis Meade and Yier Jin. 2018. Microarchitectural Minefields: 4K-Aliasing Covert Channel and Multi-Tenant Detection in IaaS Clouds. In NDSS.","DOI":"10.14722\/ndss.2018.23221"},{"key":"e_1_3_2_1_47_1","unstructured":"Andrei Tatar Dani\u00ebl Trujillo Cristiano Giuffrida and Herbert Bos. 2022. TLB;DR: Enhancing TLB-based Attacks with TLB Desynchronized Reverse Engineering. In USENIX Security 22."},{"key":"e_1_3_2_1_48_1","unstructured":"Stephan van Schaik Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018. Malicious Management Unit: Why Stopping Cache Attacks in Software is Harder Than You Think. In USENIX Security."},{"key":"e_1_3_2_1_49_1","volume-title":"Demmel","author":"Volkov Vasily","year":"2008","unstructured":"Vasily Volkov and James W. Demmel. 2008. Benchmarking GPUs to Tune Dense Linear Algebra. In SC."},{"key":"e_1_3_2_1_50_1","unstructured":"Vultr. 2022. Introducing Vultr Talon: Affordable Cloud VMs Accelerated with NVIDIA GPUs. https:\/\/www.vultr.com\/news\/Affordable-Cloud-VMs-Accelerated-with-NVIDIA-GPUs\/."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Junyi Wei Yicheng Zhang Zhe Zhou Zhou Li and Mohammad Abdullah Al Faruque. 2020. Leaky DNN: Stealing Deep-Learning Model Secret with GPU Context-Switching Side-Channel. In DSN.","DOI":"10.1109\/DSN48063.2020.00031"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Henry Wong Misel-Myrto Papadopoulou Maryam Sadooghi-Alvandi and Andreas Moshovos. 2010. Demystifying GPU microarchitecture through microbenchmarking. In ISPASS.","DOI":"10.1109\/ISPASS.2010.5452013"},{"key":"e_1_3_2_1_53_1","unstructured":"Zhenyu Wu Zhang Xu and Haining Wang. 2012. Whispers in the Hyper-space: High-speed Covert Channel Attacks in the Cloud. In USENIX Security."},{"key":"e_1_3_2_1_54_1","unstructured":"Qiumin Xu Hoda Naghibijouybari Shibo Wang Nael Abu-Ghazaleh and Murali Annavaram. 2019. GPUGuard: Mitigating Contention Based Side and Covert Channel Attacks on GPUs. In ICS."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Zihao Zhan Zhenkai Zhang Sisheng Liang Fan Yao and Xenofon Koutsoukos. 2022. Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your Neighbors. In S&P.","DOI":"10.1109\/SP46214.2022.9833773"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Zhi Zhang Yueqiang Cheng Dongxi Liu Surya Nepal Zhi Wang and Yuval Yarom. 2020. PThammer: Cross-User-Kernel-Boundary Rowhammer through Implicit Accesses. In MICRO.","DOI":"10.1109\/MICRO50266.2020.00016"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Zhenkai Zhang Sisheng Liang Fan Yao and Xing Gao. 2021. Red Alert for Power Leakage: Exploiting Intel RAPL-Induced Side Channels. In ASIA CCS.","DOI":"10.1145\/3433210.3437517"},{"key":"e_1_3_2_1_58_1","volume-title":"Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPU. PETS","author":"Zhou Zhe","year":"2017","unstructured":"Zhe Zhou, Wenrui Diao, Xiangyu Liu, Zhou Li, Kehuan Zhang, and Rui Liu. 2017. Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPU. PETS (2017)."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616672","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616672","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616672","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:41:40Z","timestamp":1755740500000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616672"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":58,"alternative-id":["10.1145\/3576915.3616672","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616672","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}