GPU-RESIDENT MALWARE DETECTION USING HARDWARE PERFORMANCE COUNTERS AND AI

Volume 8, Article e2026.05, 2026, Pages 1-10

Vusal Qasimov


Azerbaijan State Oil and Industry University Baku, Azerbaijan,  This email address is being protected from spambots. You need JavaScript enabled to view it.


Abstract

GPU-resident malware — most notably cryptomining programs, rootkits, and side-channel attack tools — evades the inspection logic of conventional CPU-based antivirus engines and creates serious security blind spots. This paper presents a hybrid machine-learning system that monitors GPU workloads on NVIDIA CUDA platforms in real time, using a 27-feature vector derived from Hardware Performance Monitoring Counters (PMC). Counter values sampled every 50 ms via the CUPTI API are converted into a sliding-window feature matrix and fed into an ensemble of Random Forest, XGBoost, and Isolation Forest classifiers. Evaluation on a 120-hour experimental dataset achieves 98.7% accuracy, 97.2% recall, a false-positive rate of only 1.3%, and a detection latency below 180 ms, while incurring just 2.1% CPU overhead.

Keywords:

GPU security, Hardware performance counters, Cryptomining detection, CUDA, CUPTI, Machine learning, HPC cybersecurity, Anomaly detection

DOI: doi.org/10.32010/26166127.2026.05

 

 

Reference 

Chiappetta, M. et al. (2016). Real time detection of cache-based side-channel attacks using hardware performance counters. Applied Soft Computing, 49, 1162–1174.

Crypt0-Miner Detection Survey. (2022). GPU-based cryptocurrency mining: Evasion and detection. Journal of Cybersecurity, 8(1), tyac003.

Cui, W. et al. (2008). Shieldgen: Automatic data patch generation. IEEE S&P 2008.

Demme, J. et al. (2013). On the feasibility of online malware detection with performance counters. ISCA 2013, 559–570.

Ismayilov, E. (2023). Difference between OpenHPC and HTCondor cluster systems: In-depth analysis. Azerbaijan Journal of High Performance Computing, 6(2), 203–208.

Ismayilov, E., & Mammadov, R. (2019). Parallel solution of features subset selection process for hand-printed character recognition. Azerbaijan Journal of High Performance Computing, 2(2), 170–177.

Ismayilova, N., & Ismayilov, E. (2018). Convergence of HPC and AI: Two directions of connection. Azerbaijan Journal of High Performance Computing, 1(2), 179–184.

Ladakis, E. et al. (2013). You can type, but you can't hide: A stealthy GPU-based keylogger. EuroSec 2013.

Liu, F. T. et al. (2008). Isolation forest. ICDM 2008, 413–422.

Mittal, S., & Vetter, J. S. (2015). A survey of CPU-GPU heterogeneous computing techniques. ACM Computing Surveys, 47(4), 1–35.

Mushtaq, M. et al. (2020). Winter is here! A decade of Linux kernel exploits. HASP@ISCA 2020.

Naghibijouybari, H. et al. (2018). Rendered insecure: GPU side channel attacks are practical. ACM CCS 2018, 2139–2153.

Ozsoy, M. et al. (2015). Malware-aware processors. HPCA 2015, 651–661.

Payer, M. (2016). HexPADS: A platform to detect stealth attacks. ESSoS 2016, 138–154.

Prakash, A. et al. (2016). ProGPU: GPU program profiling for security analysis. IPDPS 2016, 681–690.

Schwarz, M. et al. (2018). JavaScript zero: Real JavaScript and zero side-channel attacks. NDSS 2018.

Tahir, R. et al. (2019). The browsers strike back: Countering cryptojacking on the web. IEEE INFOCOM 2019.

Vasiliadis, G. et al. (2008). Gnort: High performance network intrusion detection using graphics processors. RAID 2008, 116–134.

Vieira, L. et al. (2017). GPU-based malware detection and containment. SBRC 2017, 1–14.