arXiv:2503.07568cs.CRcs.AI2025-03被引 2

用硬件性能计数器实时检测AI芯片的对抗攻击,无需修改软件。

Runtime Detection of Adversarial Attacks in AI Accelerators Using Performance Counters

  • 通过硬件计数器监控模型运行时行为,捕获异常模式。
  • 在多种AI模型上实现最高97%的攻击检测准确率,开销低。
  • 适合需要高安全性和合规性的AI硬件部署场景。

AI技术的快速普及带来了诸多安全挑战,尤其是对抗扰动威胁应用的机密性与完整性。保护AI硬件免受滥用和各类安全威胁是一项严峻任务。为此,我们提出SAMURAI框架,用于防范AI硬件的恶意使用并提升其抗攻击能力。SAMURAI引入了人工智能性能计数器(APC),用于追踪AI模型的动态运行行为,并结合片上机器学习分析引擎TANTO(Trained Anomaly Inspection Through Trace Observation)进行实时异常检测。APC记录不同AI操作的底层硬件事件运行时特征,随后由TANTO对这些摘要信息进行处理,高效识别潜在安全威胁,保障AI的可信使用。SAMURAI实现了无需依赖传统软件方案的实时威胁检测,避免了模型集成需求。实验表明,该方法在多种AI模型上达到最高97%的对抗攻击检测准确率,显著优于常规软件方案,同时保持较低开销,有效增强安全防护与合规性,为应对新兴威胁提供全面解决方案。

原文摘要 · Abstract (English)

Rapid adoption of AI technologies raises several major security concerns, including the risks of adversarial perturbations, which threaten the confidentiality and integrity of AI applications. Protecting AI hardware from misuse and diverse security threats is a challenging task. To address this challenge, we propose SAMURAI, a novel framework for safeguarding against malicious usage of AI hardware and its resilience to attacks. SAMURAI introduces an AI Performance Counter (APC) for tracking dynamic behavior of an AI model coupled with an on-chip Machine Learning (ML) analysis engine, known as TANTO (Trained Anomaly Inspection Through Trace Observation). APC records the runtime profile of the low-level hardware events of different AI operations. Subsequently, the summary information recorded by the APC is processed by TANTO to efficiently identify potential security breaches and ensure secure, responsible use of AI. SAMURAI enables real-time detection of security threats and misuse without relying on traditional software-based solutions that require model integration. Experimental results demonstrate that SAMURAI achieves up to 97% accuracy in detecting adversarial attacks with moderate overhead on various AI models, significantly outperforming conventional software-based approaches. It enhances security and regulatory compliance, providing a comprehensive solution for safeguarding AI against emergent threats.

AI安全硬件防护对抗攻击实时检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。