Malicious cloud customers can bring down the power grid
Chinese cybersecurity researchers have outlined an attack, dubbed Bit2Watt, that would let a malicious cloud customer pose as a legitimate tenant and run GPU workloads specifically crafted to destabilise a datacentre's electrical infrastructure. Rather than simply overloading systems, the technique exploits the way AI training workloads cause rapid, large swings in power draw, which the researchers say could be tuned to trigger equipment damage or cascading grid failures, including blackouts. The findings, described by researchers from Zhejiang University, matter because they extend known physical risks of AI training into a deliberate cybersecurity threat, arguing that datacentre workload scheduling needs the same security scrutiny as traditional IT systems.
The paper notes GPU loads can produce power modulation frequencies exceeding 6,000Hz, far higher than the few hertz seen in household appliances. In simulations, an attack using 1,000 GPUs against a 1-megawatt grid dominated by renewables produced total harmonic distortion of 46.8 percent, wasted nearly half the electrical current, generated roughly 20 percent more heat than normal, and created a negative damping ratio that introduced instability, with potential to cause blackouts affecting more than 80 percent of large-scale power systems. The researchers say the attack could be launched covertly within normal, authorised workload paths and evade existing cloud monitoring, and they call for providers to coordinate cyber and physical defences and deploy local energy buffering to absorb sudden demand spikes.
- Researchers devised a way to weaponise AI GPU workloads against power grids
- Attack could exploit power swings to trigger blackouts or equipment damage
- Covert method calls for combined cyber-physical datacentre security defences