Build an open-source RL environment using Ramulator and real disturbance data to post-train language models to exploit simulated DRAM RowHammer vulnerabilities, plus write-up/blog and trained models.
Build an open-source RL environment using Ramulator and real disturbance data to post-train language models to exploit simulated DRAM RowHammer vulnerabilities, plus write-up/blog and trained models.
Project Details
Updated 07/13/26 · By grantmaking.ai · VerifiedWe will build a reinforcement learning environment in which language models can be post-trained to exploit RowHammer vulnerabilities in simulated DRAM. In RowHammer attacks, an adversary rapidly accesses (“hammers”) DRAM rows, which can cause bits to flip in physically adjacent memory. RowHammer has been demonstrated to enable privilege escalation over the network and extract keys from a secure enclave.
We have already built a proof of concept of this environment, the code for which is available here. Our environment uses Ramulator 2.1 (https://arxiv.org/abs/2606.13844) to simulate DRAM, and we fit a read-disturbance model using real data, which allows us to simulate RowHammer-vulnerable DRAM with a high degree of realism.
The concrete outputs of our work will be:
- An open source environment for training models to exploit RowHammer vulnerabilities in simulated DRAM
- A write-up of our environment and a blog post arguing that humanity is dropping the ball on automating hardware security research
- Models post-trained in our environment
We also plan to build other hardware security environments, though this may end up out of scope for this grant depending on how difficult building the RowHammer environment ends up being.
Theory of Impact
Updated 07/13/26 · By grantmaking.aiThe frontier labs are investing heavily in securing software (e.g., Glasswing and Daybreak), but hardware security has received little attention. As a result, hardware may end up significantly more vulnerable than software. In the near future, an attacker could plausibly post-train an open source model to exploit particular hardware vulnerabilities and use this model for malicious purposes. Our project may seem counterintuitive because we are providing tools for making models better at exploiting hardware vulnerabilities, but we believe that building these environments now can alleviate the current overhang in the ability of language models to exploit hardware vulnerabilities. These environments are not prohibitively difficult to build and there is a large incentive to exploit hardware vulnerabilities, so it seems unlikely that malicious actors will not do so in the future. Building these environments now allows them to be used defensively.
People
Updated 07/13/26 · Edited by orgTeam Member
Team Member
Funding Details
- -
- -
- 1 month
- -
- -
- -
- -
- -
- -
- -
Discussion
No comments yet. Be the first to share your thoughts.