It looks like consumer GPUs from AMD, NVIDIA, Apple & Qualcomm aren't safe from vulnerabilities, as experts have reportedly discovered a threat known as "LeftoverLocals" that can extract data from the GPU's memory.
The emergence of a vulnerability in any piece of hardware is something that the tech industry witnesses quite often, and usually the scale of it is pretty high when it comes the the number of people affected by it. A leading example of this is the recently disclosed Intel's Downfall vulnerability, which had put thousands of the company's CPU users at stake. However, this time, GPU consumers, those across all platforms such as mobile and desktop, should proceed with caution, as the security researcher Trail of Bits has discovered a vulnerability that has the potential to take away "key data" from your onboard memory.
The vulnerability is named "LeftoverLocals", and rather than targeting consumer applications, it does the job by penetrating the GPUs being utilized in LLMs and ML models, which is an area where extracting data holds a greater significance since model training involves the utilization of sensitive data. LeftoverLocals is being tracked by experts from Carnegie Mellon University, and it is said that the information is already shared by major GPU vendors affected by it, with the likes of NVIDIA, Apple, AMD, Arm, Intel, Qualcomm, and Imagination.
It was discovered that LeftoverLocals can leak around 5.5 MB per GPU invocation of data on AMD's Radeon RX 7900 XT when running a seven-billion parameter model. According to Trail of Bits, the rate of data leak is sufficient enough to even recreate the complete model, which is why the vulnerability poses a high risk in the field of artificial
Read more on wccftech.com