Skip to content

will constellation be able to protect against attacks like LeftoverLocals? #2832

Answered by derpsteb
hpvd asked this question in Q&A
Discussion options

You must be logged in to vote

Hello,

thank you for submitting this question.
As you have already pointed out, this is a hypothetical answer atm since Constellation does not support GPUs/NPUs, yet.

The attack setup for LeftoverLocals requires an attacker to launch workloads on the same physical device that the victim is running workloads on. In a traditional cloud deployment (no CC) there are two scenarios where this could arrise:

(a) The attacker controls the hypervisor. The attacker could temporarily remount the device to a different VM or send commands to the GPU directly. This would allow them to execute malicous kernels.
(b) The GPU attached to the VM is virtualized with a technology like Nvidia MIG [1].

Confident…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@hpvd
Comment options

Answer selected by hpvd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants