- Zhejiang University researchers warned that GPU workloads could destabilize local networks and cause blackouts
- Attackers could exploit ~1,000 GPUs to drain power and generate excess heat in systems
- Theoretical attack dubbed Bit2Watt; mitigations include malicious pattern detection and energy buffer systems
When an AI data center is thinking really, really hard, it can increase its power consumption so much that it triggers disruptions and possibly even blackouts and gear failures. So is it possible for a malicious actor to trigger this scenario deliberately to cause physical harm?
Several researchers from Zhejiang University in Hangzhou, China, wrote a research paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.”
In it, they claim that a malicious cloud tenant is theoretically capable of launching GPU workloads so intensive that they cause physical damage.
Suggest mitigations
“Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared to only a few hertz observed in conventional household loads such as air conditioners,” the team wrote in its research paper.
“Such high-frequency modulations can significantly induce voltage fluctuations, harmonic distortion and attenuation degradation.”
An attacker could use about 1,000 GPUs to target a one-megawatt local power grid made up primarily of distributed energy sources (such as solar panels), causing it to lose nearly half of its electrical power while generating about 20% more heat than normal.
“This not only threatens the availability of the computing equipment, but also produces a negative damping ratio of -0.27, introducing an unstable state into the system,” the paper adds.
“Once protections are triggered and computing loads are removed, it can trigger cascading failures, potentially leading to outages in excess of 80 percent in large-scale power systems.”
AI data centers creating huge fluctuations in energy consumption is nothing new, and it’s a challenge that some of the brightest minds today are trying to solve.
Fortunately, the attack is (still) purely theoretical, and the researchers published the paper to warn of potential abuse. They also suggested mitigations — defenders could look for malicious computing patterns, while operators would have to create energy buffer systems for unusual spikes in demand.
Via The register
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



