Bit2Watt GPU Attack Uses LLM Training Workloads to Destabilize Data Center Power Grids

Researchers have disclosed Bit2Watt, a cyber-physical attack concept that turns legitimate GPU workloads into a mechanism for disrupting power infrastructure.

The technique manipulates GPU power consumption at high frequencies, potentially degrading power quality in data centers connected to renewable-heavy electrical grids.

Unlike conventional attacks on industrial control systems, Bit2Watt does not require attackers to compromise grid devices, power controllers, or communications networks.

Instead, a malicious but authorized cloud tenant could use ordinary access to GPU instances and workload scheduling controls to generate coordinated, rapid power-demand changes.

GPUs naturally change their power draw based on workload intensity.

Compute-heavy tasks raise demand as GPU cores, memory controllers, and other hardware components operate at higher utilization, while idle or lightweight tasks lower consumption.

Bit2Watt abuses this normal behavior by repeatedly switching between high- and low-load phases.

Typical power supply architecture in modern data centers (Source: arxiv)
Typical power supply architecture in modern data centers (Source: arxiv)

Bit2Watt Threatens Power Grids

The researchers described two proof-of-concept approaches. The Synthetic Workload Modulation Attack (SWMA) uses a custom CUDA workload to alternate between intensive computation and near-idle activity.

The LLM Training Modulation Attack (LTMA) embeds such changes directly into an otherwise legitimate large language model training pipeline, modifying training behavior or adding auxiliary operations to vary computational demand

LTMA is particularly concerning because it can blend into common AI development frameworks and workflows.

It does not need privileged access to firmware, hypervisors, or power-management systems; attackers only need the permissions normally provided to tenants running AI jobs.

Tests across several NVIDIA GPU models found that workload-driven power modulation could reach frequencies from roughly 1.5 kHz to 6 kHz. In the paper’s experiments, an RTX 4090 reached 6,000 Hz under the synthetic technique.

verview of the Bit2Watt risk (Source: arxiv)
verview of the Bit2Watt risk (Source: arxiv)

At the same time, LLM-training-based modulation produced lower but still significant frequencies and potentially larger power-amplitude changes. The attack becomes more dangerous when many GPUs are synchronized.

Coordinated workload changes can create fast current fluctuations that interact with uninterruptible power supplies, power distribution units, switching power supplies, and inverter-based distributed energy resources such as solar photovoltaic systems.

In a simulated 1 MW local power system with 90 distributed energy resources, coordinated manipulation of 1,000 GPUs raised current total harmonic distortion to 46.8% and drove the modeled damping ratio to -0.27, indicating unstable behavior.

These figures reflect a synchronized worst-case scenario rather than a confirmed real-world outage. However, they demonstrate the potential impact of highly coordinated compute loads, arxiv said.

The researchers also built a controlled testbed containing six GPUs, workstations, a UPS, battery storage, a grid-tied photovoltaic inverter, and a power-grid simulator.

Their measurements showed that malicious workload modulation altered current waveforms across the power-delivery chain and increased harmonic effects at the UPS input.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories