arXiv:2510.00151cs.CRcs.AI2025-10被引 3

通过硬件木马窃取AI模型权重,无声无息完成数据泄露。

Stealing AI Model Weights Through Covert Communication Channels

  • 在设备中植入隐蔽木马,利用无线信号偷偷传出模型权重。
  • 成功从四类不同模型中重建权重,还原度高且耗时可控。
  • 适用于各类硬件加速器,对防御者提出全新挑战。

由于开发成本高昂、带来竞争优势并涉及专有技术,人工智能模型被视为重要知识产权。因此,模型窃取攻击对模型提供方构成严重威胁。本文提出一种针对配备AI硬件加速器的无线设备的新攻击方法,分两阶段进行:第一阶段,在受害者设备中植入硬件木马(HT),通过隐藏通信通道隐蔽泄露模型权重,受害者无法察觉;第二阶段,攻击者使用邻近无线设备,在设备正常运行时截获传输帧,逐步重建完整的权重矩阵。该攻击对模型架构和硬件加速器均无依赖性。通过基于硬件的实验验证,涵盖四种不同类型与规模的AI模型。文中详述了硬件木马与隐蔽信道的设计,强调其隐蔽特性,并分析比特误码率对接收的影响,提出相应的纠错机制。攻击有效性基于重构模型的准确率及提取时间评估。最后探讨了潜在防御方案。

原文摘要 · Abstract (English)

AI models are often regarded as valuable intellectual property due to the high cost of their development, the competitive advantage they provide, and the proprietary techniques involved in their creation. As a result, AI model stealing attacks pose a serious concern for AI model providers. In this work, we present a novel attack targeting wireless devices equipped with AI hardware accelerators. The attack unfolds in two phases. In the first phase, the victim's device is compromised with a hardware Trojan (HT) designed to covertly leak model weights through a hidden communication channel, without the victim realizing it. In the second phase, the adversary uses a nearby wireless device to intercept the victim's transmission frames during normal operation and incrementally reconstruct the complete weight matrix. The proposed attack is agnostic to both the AI model architecture and the hardware accelerator used. We validate our approach through a hardware-based demonstration involving four diverse AI models of varying types and sizes. We detail the design of the HT and the covert channel, highlighting their stealthy nature. Additionally, we analyze the impact of bit error rates on the reception and propose an error mitigation technique. The effectiveness of the attack is evaluated based on the accuracy of the reconstructed models with stolen weights and the time required to extract them. Finally, we explore potential defense mechanisms.

模型安全硬件木马无线窃密隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。