用自旋电子随机数提升生成式AI安全性,防攻击且低功耗。
Securing generative artificial intelligence with parallel magnetic tunnel junction true randomness
- 用自旋转移矩磁隧道结生成真随机数,替代传统伪随机数。
- 在CIFAR-10上训练的GAN,不安全输出减少18.6倍。
- 纳米秒级速度,可扩展至百万单元,适合大模型采样。
生成式人工智能(GAI)模型使用的确定性伪随机数生成器(PRNG)存在可预测漏洞,易被攻击者利用。传统防御方法常伴随显著能耗和延迟开销。本文引入基于自旋转移矩磁隧道结(STT-MTJ)的硬件真随机数,构建并行化FPGA原型系统,实现兆比特每秒的真随机数输出,经现场测试通过NIST随机性检验,开销极小。将该硬件随机数集成至在CIFAR-10上训练的生成对抗网络(GAN),相比低质量随机数生成器基线,不安全输出减少最多18.6倍。凭借纳秒级切换速度、高能效及良好可扩展性,该系统有望扩展至超过10⁶个并行单元,实现吉比特每秒吞吐量,适用于大语言模型采样。这一进展表明自旋电子随机数生成器可作为下一代GAI系统的实用安全组件。
原文摘要 · Abstract (English)
Deterministic pseudo random number generators (PRNGs) used in generative artificial intelligence (GAI) models produce predictable patterns vulnerable to exploitation by attackers. Conventional defences against the vulnerabilities often come with significant energy and latency overhead. Here, we embed hardware-generated true random bits from spin-transfer torque magnetic tunnel junctions (STT-MTJs) to address the challenges. A highly parallel, FPGA-assisted prototype computing system delivers megabit-per-second true random numbers, passing NIST randomness tests after in-situ operations with minimal overhead. Integrating the hardware random bits into a generative adversarial network (GAN) trained on CIFAR-10 reduces insecure outputs by up to 18.6 times compared to the low-quality random number generators (RNG) baseline. With nanosecond switching speed, high energy efficiency, and established scalability, our STT-MTJ-based system holds the potential to scale beyond 106 parallel cells, achieving gigabit-per-second throughput suitable for large language model sampling. This advancement highlights spintronic RNGs as practical security components for next-generation GAI systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。