3 Sources
[1]
Malicious cloud customers can bring down the power grid
AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts or damaging equipment. The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling. The researchers, Zhouhao Ji, Kaikai Pan, and Wenyuan Xu, from Zhejiang University in Hangzhou, China, describe their technique in a preprint paper titled "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures." AI training workloads represent a known challenge for datacenter operators. As Microsoft, Nvidia, and OpenAI noted in a 2025 research paper arguing the need for power stabilization during AI training, the transition from GPU computation to GPU data synchronization causes large power swings to occur. And if the frequency spectrum of these power swings is "harmonized with critical frequencies of utilities, [that] can cause physical damage to the power grid infrastructure." Meta's paper on the training of Llama 3 also cites the risk AI training poses to the power grid. It says, "During training, tens of thousands of GPUs may increase or decrease power consumption at the same time, for example, due to all GPUs waiting for checkpointing or collective communications to finish, or the startup or shutdown of the entire training job. When this happens, it can result in instant fluctuations of power consumption across the datacenter on the order of tens of megawatts, stretching the limits of the power grid." Bit2Watt weaponizes this scenario by proposing that an adversary could use malicious GPU workloads to destabilize the datacenters and electrical infrastructure. "Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the Zhejiang University authors state in their paper. "Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation." The authors claim an attack on a 1-MW local power grid consisting mainly of distributed energy resources like photovoltaics could use 1,000 GPUs to create a total harmonic distortion of 46.8 percent, which would squander nearly half the electrical current on non-productive work and would throw off about 20 percent more heat than normal. "This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the authors contend. "Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems." The attack is relatively covert, the authors argue, because it can be launched within authorized workload execution paths and would likely be missed by cloud-provider monitoring frameworks. Thus, they propose that infrastructure providers coordinate defenses across the cyber and physical layers to look for malicious computation patterns. They also emphasize the need for local energy buffering systems to handle power demand spikes. Bit2Watt also potentially opens the door for a side-channel attack called Watt2Bit. The researchers note that the electrical and thermal stress on hardware from a malicious workload creates denial of service events and enables the covert exfiltration of data via power modulation. As a proof of concept, they showed they could recover a 50-bit test sequence using frequency-shift keying (FSK) encoding. "These findings underscore a fundamental shift: as power and computing infrastructures converge, security must be addressed across domains, requiring coordinated defenses that consider workload behavior, power electronics, and grid dynamics," the authors conclude. ®
[2]
Bit2Watt: a cloud tenant could destabilise the power grid
Chinese researchers say a cloud customer needs no hack, no malware, and no stolen password to put a power grid under strain. Just a rented GPU and a workload built to misbehave. The catch is that the scariest numbers come from a simulation, not a real attack. AI data centres already strain the grid just by running. A new paper asks a darker question: what if a tenant tried to break it on purpose? Three researchers at Zhejiang University set out the idea in a preprint called Bit2Watt, accepted to a leading hardware-security conference. As The Register reported, it imagines a paying customer as the attacker. How it works The trick rests on a simple fact. A GPU's power draw follows whatever it is computing. Load it hard and the current spikes. Let it idle and the current drops. Flip between those states on a schedule and you get a controllable power wobble at the wall socket. The researchers pushed it past 6,000 times a second, far faster than the gentle sway of a household load like an air conditioner. They show two ways to do it. One uses a purpose-built workload that a provider might learn to spot. The other, harder to catch, hides the pattern inside a real AI training run, where it blends into normal noise. Neither needs special access, because a tenant already controls its own jobs. The scary number, and the asterisk Alone, one GPU does little. The danger, the paper argues, is in bulk. It models 1,000 GPUs pulsing in perfect lockstep on a small grid mostly fed by solar and batteries. In that worst case, the simulated grid turns unstable, wasting nearly half its current and running hot. Pushed onto a model of the European transmission network, a small local disturbance cascades until it sheds about 81% of the load. Here is the asterisk. As reporting on cloud attacks often has to stress, that figure is a property of one simulation stacked with worst-case assumptions, not a forecast. The whole attack hinges on getting a real fleet of cloud GPUs to pulse in perfect sync, which the authors admit is still unsolved. No live system was attacked. Grounded in real physics What keeps this from being pure theory is that the physics is on record. In 2025, Microsoft, OpenAI, and Nvidia warned that the synchronised power swings of large training jobs can damage grid infrastructure when their rhythm lines up with a utility's. Meta flagged the same risk while training Llama 3. The grid has already had a fright by accident. In July 2024, a fault near data-centre-heavy Northern Virginia knocked about 1,500 megawatts of load off the grid at once. Regulators said there was no crisis, then set up a task force to study the danger as these power-hungry sites multiply. The loop back, and no bug to patch The researchers also sketch a feedback attack they call Watt2Bit. The same electrical stress that rattles the grid can overheat the servers, tripping their protection and knocking them offline. A power problem becomes a denial of service. The awkward part is that there is no bug to patch. Standard monitoring samples power far too slowly to catch the fast flicker. The deeper issue is the design itself. Volatile GPU loads now sit on a grid full of solar inverters, and nothing watches across the two. As the data centre and the grid it leans on grow more entangled, they stay run by different firms, watched by different tools. That seam, the paper implies, has no clear owner. Fixes exist on each side, but tying them together is still to come, even as the AI build-out races ahead.
[3]
Experts warn hackers could shut down entire power grids by hijacking cloud accounts
* Zhejiang University researchers warned GPU workloads could destabilize local grids and cause blackouts * Attackers could exploit ~1,000 GPUs to drain current and generate excess heat in systems * Theoretical attack dubbed Bit2Watt; mitigations include detecting malicious patterns and energy buffering systems Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm? Multiple researchers from the Zhejiang University in Hangzhou, China, wrote a research paper titled "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures." In it, they claim that a malicious cloud tenant is, in theory, capable of launching GPU workloads so intensive that they cause physical damage. Suggesting mitigations "Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the team wrote in its research paper. "Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation." An attacker could use around 1,000 GPUs to target a one-megawatt local power grid consisting primarily of distributed energy sources (such as solar panels), making it lose almost half of the electrical current, while generating around 20% more heat than usual. "This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the paper adds. "Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems." AI data centers creating huge energy consumption swings is no news, and it's a challenge some of the brightest minds of today are trying to solve. Luckily, the attack is (still) purely theoretical, and the researchers published the paper to warn about potential misuse. They also suggested mitigations - defenders could look for malicious computational patterns, while operators should create energy buffering systems for unusual spikes in demand. Via The Register Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Share
Copy Link
Chinese researchers at Zhejiang University have revealed a cyber-physical vulnerability called Bit2Watt that allows malicious cloud tenants to weaponize GPU workloads and potentially cause widespread blackouts. The theoretical attack exploits the power consumption patterns of AI datacenters, demonstrating how approximately 1,000 GPUs could create cascading failures affecting over 80% of large-scale power systems.
Researchers from Zhejiang University have uncovered a disturbing cyber-physical vulnerability that shows how malicious cloud tenants could weaponize GPU workloads to attack power infrastructure without needing hacks, malware, or stolen credentials. The theoretical attack, dubbed Bit2Watt, demonstrates how adversaries masquerading as legitimate cloud customers could launch specially crafted AI datacenter workloads designed to destabilize power grids and potentially cause widespread damage
1
.
Source: TechRadar
The research team—Zhouhao Ji, Kaikai Pan, and Wenyuan Xu—published their findings in a preprint paper titled "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures," which has been accepted to a leading hardware-security conference. Their work builds on documented concerns from industry leaders about AI training's impact on electrical systems
1
.The attack exploits a fundamental characteristic of GPU computing: power consumption directly follows computational activity. When GPUs flip rapidly between intensive computation and idle states, they create controllable power oscillations at unprecedented speeds. The researchers demonstrated that GPU loads can reach modulation frequencies exceeding 6,000 Hz, dramatically higher than the few hertz observed in conventional household loads like air conditioners
1
.These high-frequency modulations can induce voltage excursions, harmonic distortion, and damping degradation in electrical infrastructure. The researchers showed two implementation methods: a purpose-built malicious workload and a more covert approach that hides the attack pattern inside legitimate AI training runs, making it harder for cloud providers to detect
2
.In their worst-case simulation, the researchers modeled an attack using approximately 1,000 GPUs pulsing in perfect synchronization against a 1-MW local power grid consisting mainly of distributed energy resources like photovoltaics. The results were alarming: the attack created a total harmonic distortion of 46.8 percent, wasting nearly half the electrical current on non-productive work while generating about 20 percent more heat than normal
1
.The simulation produced a negative damping ratio of -0.27, introducing instability into the system. When protective mechanisms trigger and computing loads are shed, the researchers warn this could initiate cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems
3
. However, as reporting on cloud attacks must stress, these figures come from simulations with worst-case assumptions rather than real-world attacks2
.The Bit2Watt research isn't based on pure theory—the underlying physics has already been documented by major industry players. Microsoft, Nvidia, and OpenAI noted in a 2025 research paper that power swings from GPU computation to data synchronization can cause physical damage to power grid infrastructure when their frequency spectrum harmonizes with critical utility frequencies
1
.Meta's paper on Llama 3 training similarly highlighted how tens of thousands of GPUs increasing or decreasing power consumption simultaneously can result in instant fluctuations of tens of megawatts, stretching the limits of the power grid
1
. Real-world incidents underscore these concerns: in July 2024, a fault near data-center-heavy Northern Virginia knocked approximately 1,500 megawatts of load off the grid at once, prompting regulators to establish a task force2
.Related Stories
Beyond threatening power infrastructure, the researchers identified a feedback mechanism they call Watt2Bit—a side-channel attack that exploits the electrical and thermal stress created by malicious workloads. The same power fluctuations that threaten to destabilize power grids can overheat servers, triggering denial of service events while enabling covert data exfiltration via power modulation
1
.As proof of concept, the team successfully recovered a 50-bit test sequence using frequency-shift keying (FSK) encoding, demonstrating that a power problem could simultaneously become both a denial of service and a data breach vector
1
.The attack is relatively covert because it operates within authorized workload execution paths and would likely evade standard cloud-provider monitoring frameworks, which sample power far too slowly to detect rapid flickering
1
2
.The researchers propose that infrastructure providers implement coordinated cyber-physical defenses that monitor for malicious computation patterns across both cyber and physical layers. They emphasize the urgent need for local energy buffering systems capable of handling power demand spikes
1
3
.
Source: The Register
The fundamental challenge is that there's no single bug to patch. As power and computing infrastructures converge, they remain operated by different organizations using separate monitoring tools. This gap between domains has no clear owner, even as the AI build-out accelerates. The researchers conclude that security must now address workload behavior, power electronics, and grid dynamics simultaneously—a fundamental shift for an industry where these systems have traditionally operated independently
1
2
.Summarized by
Navi
[1]
[2]
27 Jun 2025•Technology
30 Dec 2024•Technology

15 Aug 2025•Business and Economy

1
Technology

2
Science and Research

3
Policy and Regulation
