logo
What is Rowhammer bit-flip attack which forced Nvidia to issue security alert

What is Rowhammer bit-flip attack which forced Nvidia to issue security alert

Time of India16-07-2025
Researchers discovered that Nvidia's A6000 GPUs are prone to Rowhammer attacks. This allows hackers to tamper with user data on shared GPUs. Nvidia has issued an alert, advising users to enable Error Correction Code. Newer GPUs with GDDR7 or HBM3 memory have built-in protection. This vulnerability poses a risk in multi-tenant environments.
Tired of too many ads?
Remove Ads
What Is Rowhammer bit-flip attack
Tired of too many ads?
Remove Ads
Why is this a problem for Nvidia GPUs?
How did Nvidia respond?
A team of researchers has revealed that Nvidia's A6000 GPUs using GDDR6 memory are vulnerable to Rowhammer attacks, which can allow hackers to interfere with users' data on a shared GPU in the cloud, like AI models, even if they don't have direct access to it. In response to the research, Nvidia issued an alert for users asking them to ensure system-level ECC is enabled across the following NVIDIA products.'Specific generations of DRAM devices starting with DDR4, LPDDR5, HBM3, and GDDR7 implement On-Die ECC (OD-ECC) to help with DRAM scaling. OD-ECC indirectly protects Rowhammer bit flips. Note: OD-ECC is not adjustable by users. If OD-ECC is present, it is always enabled,' the company said in its alertRowhammer is a security issue where repeated access to memory can silently change data. Researchers just showed that this attack now works on Nvidia GPUs, so Nvidia issued an alert and recommends using ECC to stay safe.Rowhammer for GPUs, also called GPUHammer, is a new hardware attack that targets graphics cards, specifically NVIDIA GPUs with GDDR6 memory. It is a hardware vulnerability found in computer memory chips (DRAM).Normally, data is safely stored in separate rows of memory cells. But if you rapidly and repeatedly access (hammer) one row, it introduces bit flips in adjacent memory rows. This can 'flip' bits of data even if no one directly accessed that data.'Since 2014, this vulnerability has been widely studied in CPUs and CPU-based memories like DDR3, DDR4, and LPDDR4. However, with critical AI and ML workloads now running on discrete GPUs in the cloud, it is vital to assess the vulnerability of GPU memories to Rowhammer attacks,' the researchers said.Rowhammer is a circuit-level DRAM vulnerability that lets attackers flip bits in neighboring memory rows. It had only been shown on CPU DRAM before, but now, researchers have demonstrated the first Rowhammer bit-flip attack on GPU DRAM, specifically on GDDR6 memory used in NVIDIA GPUs like the A6000.Attackers can potentially use Rowhammer to mess with another user's data on a shared GPU in the cloud, like AI models, even if they don't have direct access to it. The research proved that even a single bit flip could destroy the accuracy of an AI model.The attack works in shared environments where multiple people or programs are using the same GPU at the same time (multi-tenant setups).Nvidia confirmed the Rowhammer risk on some GPUs and advised customers to turn on Error Correction Code (ECC), a memory feature that can catch and fix single-bit errors. This helps stop Rowhammer attacks, though it might slow down some AI workloads by up to 10%.Newer Nvidia GPUs (like those with GDDR7 or HBM3 memory) already have built-in protections (on-die ECC) against this type of attack.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

AEye stock (LIDR) soars 54% after Nvidia partnership - is this the hottest AI stock on the market right now?
AEye stock (LIDR) soars 54% after Nvidia partnership - is this the hottest AI stock on the market right now?

Time of India

time2 hours ago

  • Time of India

AEye stock (LIDR) soars 54% after Nvidia partnership - is this the hottest AI stock on the market right now?

AEye, Inc. (NASDAQ: LIDR) saw a huge jump in its stock price this week — up 54%, after big news about a tech partnership with Nvidia. The reason? AEye's Apollo lidar system is now fully integrated into Nvidia's DRIVE AGX platform, which is used in smart and self-driving vehicles. This integration makes AEye a big player in the autonomous driving world, a sector many investors are watching closely. Investors got super excited — at one point during the day, AEye's stock hit $5.08, which was a 74% rise just in one day, according to the report by Shere Price Target. Explore courses from Top Institutes in Please select course: Select a Course Category Data Science Management CXO Project Management Finance MBA Healthcare Data Science Design Thinking PGDM Others Product Management healthcare Public Policy Cybersecurity Data Analytics others Technology Artificial Intelligence MCA Operations Management Digital Marketing Leadership Degree Skills you'll gain: Data Analysis & Interpretation Programming Proficiency Problem-Solving Skills Machine Learning & Artificial Intelligence Duration: 24 Months Vellore Institute of Technology VIT MSc in Data Science Starts on Aug 14, 2024 Get Details Skills you'll gain: Strategic Data-Analysis, including Data Mining & Preparation Predictive Modeling & Advanced Clustering Techniques Machine Learning Concepts & Regression Analysis Cutting-edge applications of AI, like NLP & Generative AI Duration: 8 Months IIM Kozhikode Professional Certificate in Data Science and Artificial Intelligence Starts on Jun 26, 2024 Get Details Overall, intraday trading pushed the stock up by more than 250%, making it one of the biggest short-term jumps in recent tech market history. This jump came after a long period where AEye was underperforming and people were unsure about its future, as per the reports. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Many Are Watching Tariffs - Few Are Watching What Nvidia Just Launched Seeking Alpha Read More Undo ALSO READ: AEye stock skyrockets 255% after game-changing Nvidia deal stuns Wall Street Why this Nvidia deal is a big deal Nvidia's DRIVE AGX platform is widely used by carmakers building self-driving cars, so getting on that system gives AEye huge exposure. AEye's Apollo system offers a 1-kilometer detection range, which is very advanced for lidar, and can receive over-the-air software updates, meaning it can improve without changing hardware, according to the report by Shere Price Target. Live Events CEO Matt Fisch said this move shows the world that AEye's tech works well and is ready for big markets. He also said that Apollo's compact design and flexible system help automakers make updates without changing the car's hardware — a major need in today's smart car designs. But it's not all perfect yet Even though the stock is up, analysts say investors should still be careful, as AEye is still losing money and hasn't shown consistent revenue growth. But being part of Nvidia's ecosystem adds credibility and could attract new business, especially as the industry moves toward fully autonomous vehicles, as stated by the report by Shere Price Target. ALSO READ: It vanished for 8 years, now this iconic app is coming back with a new feature, courtesy - Elon Musk What's coming next for AEye? AEye's next earnings call is on July 31, and investors are waiting for updates on: The Nvidia partnership progress New product news, especially the OPTIS suite, which targets smart transport and security markets For now, AEye is getting a lot of attention, and many wonder — could this be the next big AI stock? FAQs Q1. Why did AEye (LIDR) stock go up so much? AEye stock jumped after its Apollo lidar system got integrated into Nvidia's DRIVE AGX platform for self-driving cars. Q2. Is AEye a good AI stock to buy now? AEye gained attention after partnering with Nvidia, but analysts say it still needs steady growth before it's a strong long-term investment.

In China, repair demand for banned Nvidia AI chipsets booms
In China, repair demand for banned Nvidia AI chipsets booms

Time of India

time3 hours ago

  • Time of India

In China, repair demand for banned Nvidia AI chipsets booms

By Che Pan and Casey Hall BEIJING/SHANGHAI: Demand in China has begun surging for a business that, in theory, shouldn't exist: the repair of advanced Nvidia artificial intelligence chipsets that the U.S. has banned the export of to its trade and tech rival. Around a dozen boutique companies now offer repair services, according to two such firms in the tech hub of Shenzhen which say they predominantly fix Nvidia's H100 graphics processing units (GPUs) that have somehow made their way to the country, as well as A100 GPUs and a range of other chips. Even before it was launched, the H100 was banned from sale in China in September 2022 by U.S. authorities keen to rein in Chinese technological development, particularly advances that its military could use. Its predecessor, the A100, was also banned at the same time after being on the market for over two years. "There is really significant repair demand," said a co-owner of a firm that has been fixing Nvidia's gaming GPUs for 15 years and began working on AI chips in late 2024. Business has been so good that the owners created a new company to handle those orders, which now repairs up to 500 Nvidia AI chips per month. Its facilities, as shown in social media advertising, include a room which can accommodate 256 servers, simulating customers' data centre environments to conduct testing and validate repairs. The rapid growth of the repair industry from late last year supports the view that there has been a significant amount of smuggling of Nvidia chipsets into China. Tenders have shown that the government and the military have made purchases of the U.S. firm's banned AI chips. Concern about large-scale smuggling of high-end Nvidia products into China has prompted both Republican and Democratic lawmakers to introduce bills that would require the tracking of chipsets so that their location can be verified after they are sold. U.S. President Donald Trump's administration also backed the idea this week. The thriving repair industry also highlights how Nvidia's advanced GPUs remain in high demand despite new, albeit less powerful, products from Chinese tech giant Huawei. Though the buying, selling and repair of Nvidia GPUs is not illegal in China, sources for this article were reluctant to draw scrutiny from U.S. or Chinese authorities and declined to be identified. Nvidia cannot legally provide repair or replacement items for restricted products in China. In contrast, sources said if an Nvidia GPU in another nation has a defect and is under warranty, which is normally three years, the company usually replaces it. An Nvidia spokesperson said only the company and authorised partners "are able to provide the service and support that customers need. Using restricted products without approved hardware, software, and technical support is a nonstarter, both technically and economically." REPAIR DEMAND MAY NOT FADE Nvidia has only just been allowed to recommence sales of its H20 AI chipset, which has been specifically developed for China to comply with U.S. restrictions. Switching over to H20 chipsets is, however, not necessarily a simple or good option for Chinese entities. Price is an issue as one H20 server with eight GPUs inside will likely cost more than 1 million yuan ($139,400), industry sources say. H20 chipsets, which have increased memory bandwidth, have been specifically designed for AI inference work, but firms involved in the training of large language models would likely prefer H100 chipsets which are better suited to that task. Industry sources said some of the H100 and A100 GPUs in China have been crunching data around the clock for years now, leading to an increase in failure rates. Depending on how frequently a GPU is used and how often it is maintained, an Nvidia GPU generally lasts two to five years before needing to be repaired, they said. According to the first source, his company charges between 10,000 yuan and 20,000 yuan ($1,400 to $2,800) to fix a GPU depending on the complexity of the problem. The second Shenzhen-based repair service provider - which shifted from GPU rentals to repairs this year - says it can repair up to 200 Nvidia AI chips each month, charging about 10% of the GPUs' original selling price per repair. Services generally include software testing, fan repair, printed circuit board and GPU memory fault diagnostics and repair, as well as the replacement of broken parts. In the meantime, smuggling of high-end Nvidia chips continues. Traders of chips in China say customer demand is pivoting to top-of-the-line B200 chips which Nvidia began shipping to other countries in larger quantities this year. A server with eight B200 GPUs costs more than 3 million yuan in China, they said.

Flying suitcases packed with hard drives to China: Nvidia responds to 'burning issue' of AI chip smuggling
Flying suitcases packed with hard drives to China: Nvidia responds to 'burning issue' of AI chip smuggling

Time of India

time4 hours ago

  • Time of India

Flying suitcases packed with hard drives to China: Nvidia responds to 'burning issue' of AI chip smuggling

Nvidia has issued a strong warning against the use of unauthorised chips in data centers, calling it a 'losing proposition' both technically and economically. The statement from the world's most valuable company comes in the wake of a recent report which alleged that at least $1 billion worth of Nvidia's AI chips have been illegally smuggled into China. Not only that, last month a report said that Chinese companies are resorting to 'unconventional' ways, including carrying hard drives with AI training data in suitcases to other countries, to bypass US restrictions on high-end AI chips. 'Trying to cobble together datacenters from smuggled products is a losing proposition, both technically and economically. Datacenters require service and support, which we provide only to authorised NVIDIA products,' an Nvidia spokesperson told CNBC. A Financial Times report detailed that these illicit shipments of Nvidia's AI chips entered China despite President Donald Trump's restrictions on the sale of the company's H20 chips to the world's second-largest economy. Furthermore, the report, citing sales contracts, company filings, and informed sources, stated that Nvidia's B200 chips, which are also prohibited from sale in China, have become popular on the black market. Chinese distributors reportedly began selling these restricted chips in May to data center suppliers, whose clientele includes various Chinese AI groups. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like TV providers are furious: this gadget gives you access to all channels Techno Mag Learn More Undo How China is smuggling US-made high-end AI chips Since 2022, stringent US export controls on high-end AI chips, driven by national security concerns, have significantly impacted Chinese firms' access to cutting-edge American technology. This has forced them to explore various workarounds, from developing domestic alternatives to engaging in illicit activities like smuggling, and increasingly, processing data in overseas locations. According to a report by the Wall Street Journal, while some Chinese companies have begun substituting American chips with domestically produced alternatives, others have resorted to smuggling AI hardware through third countries to circumvent the controls. However, increased pressure from the US has made smuggling a more difficult proposition. This has pushed Chinese firms towards a new strategy: processing data outside of China in regions like Southeast Asia and the Middle East. "This was something we were consistently concerned about," Thea Kendler, former head of export controls at the Commerce Department under the Biden administration, told the WSJ, referring to the remote access Chinese firms maintain to US AI chips. Chinese companies using AI infrastructure in other South Asian countries to train AI models The WSJ report says that Chinese companies employed elaborate strategies to circumvent stringent US restrictions on advanced AI chips. For example, in one instance in March, four Chinese engineers reportedly flew from Beijing to Malaysia, each carrying suitcases filled with 15 hard drives containing 80 terabytes of data. At a Malaysian data centre, they utilised approximately 300 servers equipped with advanced Nvidia chips to develop an AI model, which they subsequently brought back to China. This operation involved planning, including weeks spent optimising data sets in China to avoid lengthy online transfers. 7 Reasons that make Samsung GALAXY Z FLIP7 different from others AI Masterclass for Students. Upskill Young Ones Today!– Join Now

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store