Wie man ein KI-Modell stiehlt, ohne tatsächlich etwas zu hacken

Teilen:

Artificial intelligence models can be surprisingly stealable—provided you somehow manage to sniff out the model’s electromagnetic signature. While repeatedly emphasizing they do not, in fact, want to help people attack neural networks, researchers at North Carolina State University described such a technique in a new paper. All they needed was an electromagnetic probe, several pre-trained, open-source AI models, and a Google Edge Tensor Processing Unit (TPU). Their method entails analyzing electromagnetic radiations while a TPU chip is actively running.

“It’s quite expensive to build and train a neural network,” said study lead author and NC State Ph.D. student Ashley Kurian in a call with Gizmodo. “It’s an intellectual property that a company owns, and it takes a significant amount of time and computing resources. For example, ChatGPT—it’s made of billions of parameters, which is kind of the secret. When someone steals it, ChatGPT is theirs. You know, they don’t have to pay for it, and they could also sell it.”

Theft is already a high-profile concern in the AI world. Yet, usually it’s the other way around, as AI developers train their models on copyrighted works without permission from their human creators. This overwhelming pattern is sparking lawsuits and even tools to help artists fight back by “poisoning” art generators.

“The electromagnetic data from the sensor essentially gives us a ‘signature’ of the AI processing behavior,” explained Kurian in a statement, calling it “the easy part.”  But in order to decipher the model’s hyperparameters—its architecture and defining details—they had to compare the electromagnetic field data to data captured while other AI models ran on the same kind of chip.

In doing so, they “were able to determine the architecture and specific characteristics—known as layer details—we would need to make a copy of the AI model,” explained Kurian, who added that they could do so with “99.91% accuracy.” To pull this off, the researchers had physical access to the chip both for probing and running other models. They also worked directly with Google to help the company determine the extent to which its chips were attackable.

Kurian speculated that capturing models running on smartphones, for example, would also be possible — but their super-compact design would inherently make it trickier to monitor the electromagnetic signals.

“Side channel attacks on edge devices are nothing new,” Mehmet Sencan, a security researcher at AI standards nonprofit Atlas Computing, told Gizmodo. But this particular technique “of extracting entire model architecture hyperparameters is significant.” Because AI hardware “performs inference in plaintext,” Sencan explained, “anyone deploying their models on edge or in any server that is not physically secured would have to assume their architectures can be extracted through extensive probing.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:03 am, Juni 23, 2025
Wetter-Symbol 18°C
L: 17° | H: 18°
broken clouds
Luftfeuchtigkeit: 78 %
Druck: 1010 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 18°°C 0.2 mm 20% 14 mph 76 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 22°°C 0.2 mm 20% 13 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
18° | 26°°C 0.48 mm 48% 14 mph 84 % 1016 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 16 mph 72 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
16° | 17°°C 0.2 mm 20% 13 mph 76 % 1011 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 12 mph 54 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 34 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 32 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 39 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 53 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 69 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,162.20
-1.05%
Ethereum(ETH)
€1,949.66
-1.17%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.76
-1.97%
Solana(SOL)
€115.61
-1.37%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132766
-1.07%
Shiba Inu(SHIB)
€0.000010
-1.51%
Pepe(PEPE)
€0.000008
-4.03%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen