← All stories
● Covered by 1 source · 1 reportHigh impact

Researchers Present Bit2Watt Attack Threatening Power Grids via Cloud GPUs

Three researchers from Zhejiang University revealed the Bit2Watt attack, enabling cloud tenants to destabilize power grids using GPU workloads without requiring exploits. This method poses a significant risk as it leverages legitimate compute functions to create controlled power oscillations that can threaten infrastructure stability.

Key points

  • Bit2Watt uses GPU workloads to manipulate power draw.
  • Two methods: SWMA with synthetic workload and LTMA using LLM training.
  • No elevated privileges required for execution.

Overview of the Bit2Watt Attack

The Bit2Watt attack enables cloud tenants to disrupt power grids by exploiting the power modulation capabilities of GPUs. This method does not require any exploits, making it particularly concerning for data center operators.

The researchers demonstrated this threat using both real GPU measurements and simulations of the resulting grid destabilization.

Mechanism of the Attack

Bit2Watt inverts the traditional grid-attack model by utilizing legitimate workload manipulations. The attack is based on the fact that a GPU's power draw correlates directly with its computational workload.

By switching between high-intensity compute modes and idle states, attackers can create controllable power oscillations at the data center's wall socket.

Method 1: SWMA

The first technique, called SWMA, involves uploading a custom CUDA kernel that alternates the GPU's power states. This is accomplished using standard tooling, which makes it accessible to cloud tenants.

Testing showed that power variations varied with frequencies from 1.5 kHz to 6 kHz, demonstrating potential for significant instability in power distribution.

Method 2: LTMA

The second method, LTMA, embeds the modulation within actual LLM training processes, making it more challenging to detect. This method adjusts hyperparameters during training, generating power fluctuations akin to normal operational noise.

While the modulation frequencies are lower (1.2 to 3 kHz), the amplitude is larger, blending with standard training activity and increasing the difficulty of monitoring.

Implications for Cloud Operators

The study raises critical questions about the security of cloud services and their impact on essential infrastructure. Since neither method requires elevated privileges, it poses a widespread risk to the cloud computing environment.

Operators must be aware of these potential threats and consider developing strategies to identify and mitigate such power modulation attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 34 stories · Jul 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Three researchers from Zhejiang University revealed the Bit2Watt attack, enabling cloud tenants to destabilize power grids using GPU workloads without requiring exploits. This method poses a significant risk as it leverages legitimate compute functions to create controlled power oscillations that can threaten infrastructure stability.