GPU-RESIDENT MALWARE DETECTION USING HARDWARE PERFORMANCE COUNTERS AND AI

Volume 8, Article e2026.05, 2026, Pages 1-10

Vusal Qasimov1 and Nihad Ganbarli2


Azerbaijan State Oil and Industry University Baku, Azerbaijan, This email address is being protected from spambots. You need JavaScript enabled to view it.

Bilkent University, Information Systems and Technologies, This email address is being protected from spambots. You need JavaScript enabled to view it.


Abstract

GPU-resident malware — most notably cryptomining programs, rootkits, and side-channel attack tools — evades the inspection logic of conventional CPU-based antivirus engines and creates serious security blind spots. This paper presents a hybrid machine-learning system that monitors GPU workloads on NVIDIA CUDA platforms in real time, using a 27-feature vector derived from Hardware Performance Monitoring Counters (PMC). Counter values sampled every 50 ms via the CUPTI API are converted into a sliding-window feature matrix and fed into an ensemble of Random Forest, XGBoost, and Isolation Forest classifiers. Evaluation on a 120-hour experimental dataset achieves 98.7% accuracy, 97.2% recall, a false-positive rate of only 1.3%, and a detection latency below 180 ms, while incurring just 2.1% CPU overhead.

Keywords:

GPU security, Hardware performance counters, Cryptomining detection, CUDA, CUPTI, Machine learning, HPC cybersecurity, Anomaly detection

DOI: doi.org/10.32010/26166127.2026.05

 

 

Reference 

Chiappetta, M. et al. (2016). Real time detection of cache-based side-channel attacks using hardware performance counters. Applied Soft Computing, 49, 1162–1174.

Crypt0-Miner Detection Survey. (2022). GPU-based cryptocurrency mining: Evasion and detection. Journal of Cybersecurity, 8(1), tyac003.

Cui, W. et al. (2008). Shieldgen: Automatic data patch generation. IEEE S&P 2008.

Demme, J. et al. (2013). On the feasibility of online malware detection with performance counters. ISCA 2013, 559–570.

Ismayilov, E. (2023). Difference between OpenHPC and HTCondor cluster systems: In-depth analysis. Azerbaijan Journal of High Performance Computing, 6(2), 203–208.

Ismayilov, E., & Mammadov, R. (2019). Parallel solution of features subset selection process for hand-printed character recognition. Azerbaijan Journal of High Performance Computing, 2(2), 170–177.

Ismayilova, N., & Ismayilov, E. (2018). Convergence of HPC and AI: Two directions of connection. Azerbaijan Journal of High Performance Computing, 1(2), 179–184.

Ladakis, E. et al. (2013). You can type, but you can't hide: A stealthy GPU-based keylogger. EuroSec 2013.

Liu, F. T. et al. (2008). Isolation forest. ICDM 2008, 413–422.

Mittal, S., & Vetter, J. S. (2015). A survey of CPU-GPU heterogeneous computing techniques. ACM Computing Surveys, 47(4), 1–35.

Mushtaq, M. et al. (2020). Winter is here! A decade of Linux kernel exploits. HASP@ISCA 2020.

Naghibijouybari, H. et al. (2018). Rendered insecure: GPU side channel attacks are practical. ACM CCS 2018, 2139–2153.

Ozsoy, M. et al. (2015). Malware-aware processors. HPCA 2015, 651–661.

Payer, M. (2016). HexPADS: A platform to detect stealth attacks. ESSoS 2016, 138–154.

Prakash, A. et al. (2016). ProGPU: GPU program profiling for security analysis. IPDPS 2016, 681–690.

Schwarz, M. et al. (2018). JavaScript zero: Real JavaScript and zero side-channel attacks. NDSS 2018.

Tahir, R. et al. (2019). The browsers strike back: Countering cryptojacking on the web. IEEE INFOCOM 2019.

Vasiliadis, G. et al. (2008). Gnort: High performance network intrusion detection using graphics processors. RAID 2008, 116–134.

Vieira, L. et al. (2017). GPU-based malware detection and containment. SBRC 2017, 1–14.