Bottom line: The University of Toronto's GPUThor attack can compromise enterprise Nvidia GPU systems with Tesla V100 and V100S GPUs, rendering their ECC defense ineffective.
What's happening: Researchers from the University of Toronto, led by Dr. Michael Hale Ligh, have developed a new attack method using memory bit flipping to defeat Nvidia's error-correcting codes on enterprise GPUs. This attack can be applied to systems running TensorFlow, PyTorch, or other deep learning frameworks. The attack was tested on 24 systems with Tesla V100 GPUs, achieving a success rate of 90%.
What to do: Security leaders should prioritize testing their systems for vulnerabilities to memory bit flipping attacks and ensure that their ECC defense is up-to-date, utilizing tools like the Nvidia driver version 450.66.01 to protect against such threats.