Sunday, September 14, 2025
  • Login
Euro Times
No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
Euro Times
No Result
View All Result

Hot Pixels attacks exploit power management in modern SoC and GPUs to leak data

by Euro Times
May 30, 2023
in Technology
Reading Time: 3 mins read
A A
0
Home Technology
Share on FacebookShare on Twitter


In context: Dynamic voltage and frequency scaling (DVFS) is a technique adopted by modern CPUs and graphics chips to manage power and speed, adjusting frequency and voltage “on the fly” to reduce energy consumption and heat generation. With a “Hot Pixels” attack, DVFS becomes yet another channel a (very) resourceful attacker could exploit to steal data and compromise user’s privacy.

Hot Pixels is a new side-channel attack conceived by an international team of researchersposing a theoretical security threat that exploits Dynamic Voltage and Frequency Scaling (DVFS) techniques to “probe analog properties” of computing devices. DVFS is essential in maintaining a delicate balance between power consumption, heat dissipation, and execution speed (i.e., frequency), the researchers explain in their paper. However, it also introduces software-visible hybrid side-channels through which sensitive data can be extracted.

The researchers targeted Arm-based SoC units, Intel CPUs, and discrete GPUs manufactured by AMD and Nvidia, as these are the most prevalent microchips currently available in the market. A side-channel attack is an attack that leverages residual information, which can be extracted due to the inherent operational nature of a computer component, rather than by exploiting specific security flaws in the design.

The team examined the vulnerability of the aforementioned computing devices to information leakage via power, temperature, and frequency values, which can be conveniently read on a local system thanks to the internal sensors embedded in the chips themselves. No admin access is necessary in this case: the data is persistently available, and DVFS values can be manipulated to operate as constants to assist in identifying specific instructions and operations.

In their experiments with DVFS readings, the researchers discovered that passively-cooled processors (like Arm chips used in smartphones) can leak information via power and frequency readings. Conversely, actively-cooled processors, such as desktop CPUs and GPUs, can leak information through temperature and power readings.

The “Hot Pixels” attacks were thus designed as a practical demonstration of the DVFS-related issue. This includes a JavaScript-based pixel stealing proof-of-concept technique, history-sniffing attacks, and website fingerprinting attacks. The researchers targeted the latest versions of Chrome and Safari web browsers, with all side-channel protections enabled and standard “user” access privileges.

The attacks could discern the color of the pixels displayed on the target’s screen through CPU frequency leakage. They achieve this by employing Scalable Vector Graphics (SVG) filters to induce data-dependent execution on the target CPU or GPU, then using JavaScript to measure the computation time and frequency to infer the pixel color.

The accuracy of these measurements ranges between 60% and 94%, while the time required to identify each pixel varies between 8.1 and 22.4 seconds. The AMD Radeon RX 6600 GPU appears to be the most vulnerable device to “Hot Pixels” attacks, while Apple SoCs (M1, M2) seem to be the most secure.

In Safari, which restricts cookie transmission on iframe elements that don’t share the same origin as the parent page, researchers had to employ more creative strategies. Apple’s browser is susceptible to a sub-type of the “Hot Pixels” attack, which can infringe on the user’s privacy by extracting browsing history. In this case, the SVG filtering technique is used to detect the differing color of a previously visited URL, achieving a higher level of accuracy ranging from 88.8% (MacBook Air M1) to 99.3% (iPhone 13).

The researchers have already reported the “Hot Pixels” issue to Intel, AMD, Nvidia, and other affected companies. However, an effective countermeasure against this new and complex type of side-channel attacks does not exist yet. Users need not be overly concerned for the time being, as the current speed limit for data exfiltration is a mere 0.1 bits per second, even though this could be “optimized” with further research.



Source link

Tags: attacksDataExploitGPUsHotleakManagementModernPixelsPowerSoC
Previous Post

Debt Ceiling Deal Includes New Work Requirements for Food Stamps

Next Post

Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Related Posts

Apple iPhone 17 Pro vs. iPhone 16 Pro: I compared both models, and there’s a big difference

Apple iPhone 17 Pro vs. iPhone 16 Pro: I compared both models, and there’s a big difference

by Prakhar Khanna
September 14, 2025
0

Jason Hiner/ZDNETComply with ZDNET: Add us as a most well-liked supply on Google.Apple's long-awaited iPhone 17 lineup has arrived, and as speculated,...

Chinese brand Seaviv surprises the mini PC market with a Ryzen AI Max+ 395 mini PC that includes an SD 4.0 slot

Chinese brand Seaviv surprises the mini PC market with a Ryzen AI Max+ 395 mini PC that includes an SD 4.0 slot

by Efosa Udinmwen
September 13, 2025
0

Seaviv AIdeaStation R1 makes use of Ryzen AI Max+ 395 for demanding skilled workloadsRadeon 8060S iGPU rivals RTX 5060 Laptop...

Kioxia-Nvidia project aims for SSD performance 33 times higher than today's top drives

Kioxia-Nvidia project aims for SSD performance 33 times higher than today's top drives

by Euro Times
September 14, 2025
0

Semiconductor reminiscence maker Kioxia is creating next-generation SSD know-how designed for ultra-fast learn speeds to help demanding AI workloads. The...

Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 13 #355

Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 13 #355

by Gael Cooper
September 13, 2025
0

Searching for the most up-to-date common Connections solutions? Click on right here for immediately's Connections hints, in addition to our each...

Get this Ryzen 7 mini PC with 32GB RAM for a crazy low 9

Get this Ryzen 7 mini PC with 32GB RAM for a crazy low $339

by Gabriela Vatu
September 13, 2025
0

These days, your private home or workplace setup can characteristic a mini PC with out problem as a result of...

You didn’t ask for it, but YouTube Music’s Now Playing redesign is here

You didn’t ask for it, but YouTube Music’s Now Playing redesign is here

by Ryan McNeal
September 12, 2025
0

Joe Maring / Android AuthorityTL;DR YouTube Music has rolled out a redesign for Now Taking part in. The redesign relocates...

Next Post
Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Brazil President Proposes Ditching US Dollar For Trading Currency

Brazil President Proposes Ditching US Dollar For Trading Currency

Rigetti Computing Gets Closer To Crucial Quantum Milestone (NASDAQ:RGTI)

Rigetti Computing Gets Closer To Crucial Quantum Milestone (NASDAQ:RGTI)

September 14, 2025
They Witnessed Charlie Kirk’s Assassination. Now Students Reckon With The Trauma.

They Witnessed Charlie Kirk’s Assassination. Now Students Reckon With The Trauma.

September 14, 2025
Gaza Famine Death Toll Rises to 420, Including 145 Children

Gaza Famine Death Toll Rises to 420, Including 145 Children

September 13, 2025
Nato F-16 jets scrambled after Russian drones enter Romanian airspace

Nato F-16 jets scrambled after Russian drones enter Romanian airspace

September 14, 2025
Apple iPhone 17 Pro vs. iPhone 16 Pro: I compared both models, and there’s a big difference

Apple iPhone 17 Pro vs. iPhone 16 Pro: I compared both models, and there’s a big difference

September 14, 2025
Let people decide whether they want to be ruled by ‘disciples of Bandera’ – Roger Waters — RT World News

Let people decide whether they want to be ruled by ‘disciples of Bandera’ – Roger Waters — RT World News

September 13, 2025
Euro Times

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Finance
  • Health
  • Investing
  • Markets
  • Politics
  • Stock Market
  • Technology
  • Uncategorized
  • World

LATEST UPDATES

Rigetti Computing Gets Closer To Crucial Quantum Milestone (NASDAQ:RGTI)

They Witnessed Charlie Kirk’s Assassination. Now Students Reckon With The Trauma.

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In