• 2 min read
GPU attack could push datacenters into grid failure
Researchers at Zhejiang University describe Bit2Watt, a GPU workload attack that could destabilize datacenters and even trigger blackouts.

Image: The Register
A malicious cloud customer could do more than hog GPUs. According to a preprint paper from researchers at Zhejiang University in Hangzhou, China, carefully crafted GPU workloads could be used to attack a cloud provider’s infrastructure and, in some cases, destabilize parts of the power grid.
The attack, called Bit2Watt, was outlined by Zhouhao Ji, Kaikai Pan, and Wenyuan Xu in a paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.” The idea is that an attacker poses as a normal cloud tenant, then runs GPU jobs designed to create harmful power fluctuations inside AI datacenters.
That builds on an existing problem. A 2025 paper from Microsoft, Nvidia, and OpenAI argued that AI training needs power stabilization because shifts from GPU computation to data synchronization can cause large swings in power draw. If those swings line up with sensitive utility frequencies, the paper said, they can physically damage grid infrastructure.
Meta raised a similar warning in its Llama 3 training paper, noting that when tens of thousands of GPUs ramp power use up or down together, datacenter demand can change by tens of megawatts almost instantly.

Recommended reading
Free 0Patch fix arrives for Windows LegacyHive zero-day
The Zhejiang University team says Bit2Watt turns that behavior into a deliberate weapon. In their tests, GPU loads reached modulation frequencies above 6,000 Hz, compared with only a few hertz for typical household loads such as air conditioners.
The paper claims that on a 1-MW local power grid, mainly supplied by distributed energy resources such as photovoltaics, an attack using 1,000 GPUs could produce 46.8 percent total harmonic distortion. The authors say that would waste nearly half the current on non-productive work, generate about 20 percent more heat than normal, and create a negative damping ratio of -0.27. If protection systems then shed computing loads, they warn, the result could be cascading failures and blackouts exceeding 80 percent in large-scale power systems.
The researchers argue the attack would be hard to spot because it runs through authorized workload paths and may evade normal cloud monitoring. They recommend defenses that connect workload scheduling, power electronics, and grid dynamics, along with local energy buffering to absorb sudden spikes.
The paper also describes a related side-channel technique, Watt2Bit, in which electrical and thermal stress from malicious workloads could be used for covert data exfiltration through power modulation. As a proof of concept, the team says it recovered a 50-bit test sequence using frequency-shift keying (FSK) encoding.
“These findings underscore a fundamental shift: as power and computing infrastructures converge, security must be addressed across domains, requiring coordinated defenses that consider workload behavior, power electronics, and grid dynamics.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


