DOI: 10.1145/3841634 ISSN: 1544-3566

Uncovering Power and Frequency Behaviors and Their Security Implications in Edge GPU Platforms

Mujahid Rafi, Kevin Chau, Hyeran Jeon

Edge platforms increasingly rely on GPUs and deep learning accelerators (DLAs) to support real-time computing of emerging workloads. However, their power, frequency, and security characteristics remain largely unexplored. This paper provides the first in-depth characterization of power and frequency behaviors of NVIDIA edge GPUs and DLAs. We uncover significant variations across instructions, data widths, and architectures, revealing vulnerabilities to covert-channel exploitation. Building on these findings, we design novel covert channels that leverage power and frequency behaviors of GPUs and DLAs on edge platforms. To the best of our knowledge, we present the first DLA-based covert channels. Our GPU-based covert channels achieve up to 31 × higher information leakage bandwidth than prior GPU covert channels. The DLA-based covert channel derives 4 × more bandwidth than existing accelerator-based attacks. We explore various mitigation methods, such as limiting the accessibility, resolution, and accuracy of the power and frequency monitoring utility. However, our evaluation demonstrates that none of them can successfully defend against our proposed covert channels. These results highlight the urgent need for both fine-grained power management and stronger security defenses in edge AI platforms.

More from our Archive