A Story of Llamas and Hammers: How GPUHammer Exposes a New Hardware Attack Surface for AI Systems
GPUHammer shows that modern GPUs are not just rapid computing engines, but memory systems with a real attack surface. This talk explains how a Rowhammer-style attack can induce bit flips in GDDR6, why GPU architecture changes the defender’s problem, the consequences for large-scale AI and cloud systems, and what current hardware, firmware, and software mitigations still leave open.
Modern AI and cloud systems rely on GPUs whose memory behavior is often assumed to be good enough for security. The newly developing GPUHammer challenges that assumption. I’ll walk through the attack at a conceptual level, explain why GPU memory architecture changes the threat model, and show what defenders should actually worry about.
Ludwig is an incoming Electrical & Computer Engineering freshman at Rice University with a deep technical foundation in computer architecture and programming (go, owls!). He has led technical teams and helped build cybersecurity and computer science programs in his school community. Ludwig is excited to bring that background to the Houston cybersecurity community and to continue learning from and contributing to the field.