4 ms·
At my uni, 15 years ago, one postdoc reverse engineered NVIDIA chip and wrote more performant compiler. He did that by connecting oscyloscops to all chip's outp
by zie1ony 2mo ago
At my uni, 15 years ago, one postdoc reverse engineered NVIDIA chip and wrote more performant compiler. He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs. Using ML and his genius he rediscoverd all opcodes including a few hidden ones. Eventually he got hired by some company that was doing a lot of GPU on supercomputers.
- inigyou 2mo agoYou can't do that by applying random inputs to any single-chip GPU - it has far too much state. I can see that perhaps it worked on some of the early multi-chip cards - where one chip was a texture sampler, and so on. You'll have more luck reverse engineering the software driver first. They're not hidden, you can just open the driver files in Ghidra, the almost-universal tool for open-sourcing proprietary code. Hidden opcodes can be discovered first by just trying all the opcodes you couldn't discover any other way. You only need to go to the physical level if they're really hidden.
- sigbottle 2mo agoTo be fair, Ghidra was released in 2019 and in general knowledge was still hard to find even back in 2010 I feel (well, compared to 2026 in the age of AI)
- inigyou 2mo agoBefore that there was, and still is, IDA Pro. Works largely the same but costs a lot, on the order of $1000/seat/year. Useless for hobbyists unless pirated, but reasonable if it's your job. Probably had academic discounts.
- rzzzt 2mo agoAlso a few free-but-cut-down versions like 5 (which still recognizes MS-DOS executables). I'm not going to recommend downloading it from any of the locations mentioned here but it's out there: https://reverseengineering.stackexchange.com/questions/19179/older-versions-of-ida-free https://reverseengineering.stackexchange.com/questions/19179...
- deleted 2mo ago[deleted]
- JSR_FDED 2mo agoSmall pedantic nit: Open-sourcing is not the same as reverse-engineering.
- inigyou 2mo agoWe are taking back control of our computers by force.
- tverbeure 2mo agoThere is absolutely no way that happened. 15 years ago, we're talking Fermi class GPUs and chips with hundreds of millions of bits of on-chip state and much more if you include the DRAM. You can't tease out the right information by applying random inputs. Which input would you even use? The PCIe interface? You'd first "randomly" need to get past its complex training sequences... Your postdoc probably wrote micro-benchmarks of some sort. That is a common technique.
- kjs3 2mo agoAnd you don't use an o-scope in anycase, since you'd need...what...a thousand of them to watch all the signals. You'd use a logic analyzer. I think I read somewhere that those older nvidia chips had something like 2000 BGA balls, and Tektronix does make an LA that can scale to 2000-something channels (TLA7000), for a modest US$500k or so. Then you gotta figure how to mount the thing to attach the probes. So...agreed...far more likely there was a software solution of some kind if this happened.
- deleted 2mo ago[deleted]
- Taniwha 2mo agoYou might is they included DFT (design for test, stuff to make sure when you make a chip all of it actually works) - a scan chain thru all the internal flops will provide you with info about the internal flops and how they are connected - reverse engineering this into a model of reality would certainly be extremely hard, but maybe not impossible
- tverbeure 2mo agoWhile that's theoretically possible, it's even harder than trying to do it over, say, PCIe, because the latter at least still has a higher meaning to it while scan chain FFs are just grouped based on spatial proximity. And of course that's assuming that a) the JTAG port is accessible on these boards and b) the raw scan chain access before scan chain compression hasn't been fused off or isn't locked behind some authentication protocol. So, no. That didn't happen either. :-)
- pixelatedindex 2mo ago“oscyloscops” is a way better spelling I gotta say.
- i_am_a_peasant 2mo agosounds like a mythical creature hahaha
- Aurornis 2mo ago> He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs This is absolutely not how reverse engineering a digital logic ASIC works. Either the story got embellished through retellings, or this person was a fantasist. There are people who hack on GPUs but it’s done at the software level. I did get a kick out of imagining a scene where someone is trying to connect an oscilloscope to a circuit board to reverse engineer the CPU opcodes. That’s like the CSI: Miami version of what this would look like.
- MomsAVoxell 2mo agoMany laymen confuse logic analyzers with oscilloscopes. Don't take it personally - the person you responded to is clearly not a native English speaker. You absolutely can reverse chips with logic analysis. It is big business in some parts of the world.
- i_am_a_peasant 2mo agowith very, very expensive logic analyzers... But yeah, nothing weird here. Plus OP was retelling a story of someone else doing it, while probably not being a specialist in this field. So I wouldn't take the "random inputs" part literally.
- Aurornis 2mo ago> with very, very expensive logic analyzers... But yeah, nothing weird here. You can’t simply get an expensive logic analyzer and probe PCIe or memory buses at these speeds. There are expensive custom fixtures that need to be made to even begin to be able to probe at these speeds without disturbing the circuit so much that it fails to work. This isn’t like probing the I2C bus on a raspberry pi. It would be like connecting to the pins under the chip. It’s fantasy. It’s also illogical. If you have a PCIe device, you plug it in to a PCIe host and use the host to interact with it. You don’t start probing pins and trying to apply signals to it.
- 2mo ago
- RetroTechie 2mo agoDetailed write-up please, or it didn't happen. At least not as described. Really simple ICs with a few counters etc in there might be possible to RE this way. Complex ICs with lots of internal state, memory blocks etc like a modern-ish GPU? Not a chance. Some hybrid approach? Software fiddling with the chip's internals, with say. a big FPGA attached to physically probe outputs? Architecture docs, and maybe some IC die shots at hand? Perhaps (hence my ask for "detailed"). Sounds like requiring the kind of hardware setup that would not be available to uni students.