GPU-RESIDENT MALWARE DETECTION USING HARDWARE PERFORMANCE COUNTERS AND AI
- Details
- Hits: 29
Volume 8, Article e2026.05, 2026, Pages 1-10
Vusal Qasimov
Azerbaijan State Oil and Industry University Baku, Azerbaijan, This email address is being protected from spambots. You need JavaScript enabled to view it.
Abstract
GPU-resident malware — most notably cryptomining programs, rootkits, and side-channel attack tools — evades the inspection logic of conventional CPU-based antivirus engines and creates serious security blind spots. This paper presents a hybrid machine-learning system that monitors GPU workloads on NVIDIA CUDA platforms in real time, using a 27-feature vector derived from Hardware Performance Monitoring Counters (PMC). Counter values sampled every 50 ms via the CUPTI API are converted into a sliding-window feature matrix and fed into an ensemble of Random Forest, XGBoost, and Isolation Forest classifiers. Evaluation on a 120-hour experimental dataset achieves 98.7% accuracy, 97.2% recall, a false-positive rate of only 1.3%, and a detection latency below 180 ms, while incurring just 2.1% CPU overhead.
Keywords:
GPU security, Hardware performance counters, Cryptomining detection, CUDA, CUPTI, Machine learning, HPC cybersecurity, Anomaly detection
DOI: doi.org/10.32010/26166127.2026.05
Reference
Chiappetta, M. et al. (2016). Real time detection of cache-based side-channel attacks using hardware performance counters. Applied Soft Computing, 49, 1162–1174.
Crypt0-Miner Detection Survey. (2022). GPU-based cryptocurrency mining: Evasion and detection. Journal of Cybersecurity, 8(1), tyac003.
Cui, W. et al. (2008). Shieldgen: Automatic data patch generation. IEEE S&P 2008.
Demme, J. et al. (2013). On the feasibility of online malware detection with performance counters. ISCA 2013, 559–570.
Ismayilov, E. (2023). Difference between OpenHPC and HTCondor cluster systems: In-depth analysis. Azerbaijan Journal of High Performance Computing, 6(2), 203–208.
Ismayilov, E., & Mammadov, R. (2019). Parallel solution of features subset selection process for hand-printed character recognition. Azerbaijan Journal of High Performance Computing, 2(2), 170–177.
Ismayilova, N., & Ismayilov, E. (2018). Convergence of HPC and AI: Two directions of connection. Azerbaijan Journal of High Performance Computing, 1(2), 179–184.
Ladakis, E. et al. (2013). You can type, but you can't hide: A stealthy GPU-based keylogger. EuroSec 2013.
Liu, F. T. et al. (2008). Isolation forest. ICDM 2008, 413–422.
Mittal, S., & Vetter, J. S. (2015). A survey of CPU-GPU heterogeneous computing techniques. ACM Computing Surveys, 47(4), 1–35.
Mushtaq, M. et al. (2020). Winter is here! A decade of Linux kernel exploits. HASP@ISCA 2020.
Naghibijouybari, H. et al. (2018). Rendered insecure: GPU side channel attacks are practical. ACM CCS 2018, 2139–2153.
Ozsoy, M. et al. (2015). Malware-aware processors. HPCA 2015, 651–661.
Payer, M. (2016). HexPADS: A platform to detect stealth attacks. ESSoS 2016, 138–154.
Prakash, A. et al. (2016). ProGPU: GPU program profiling for security analysis. IPDPS 2016, 681–690.
Schwarz, M. et al. (2018). JavaScript zero: Real JavaScript and zero side-channel attacks. NDSS 2018.
Tahir, R. et al. (2019). The browsers strike back: Countering cryptojacking on the web. IEEE INFOCOM 2019.
Vasiliadis, G. et al. (2008). Gnort: High performance network intrusion detection using graphics processors. RAID 2008, 116–134.
Vieira, L. et al. (2017). GPU-based malware detection and containment. SBRC 2017, 1–14.
