arXiv:2606.19262cs.LG2026-06被引 4

用零开销监控检测隐藏的机器学习训练,防作弊能力强。

Detecting Hidden ML Training With Zero-Overhead Telemetry

论文配图:Detecting Hidden ML Training With Zero-Overhead Telemetry
图 1 · 摘自论文原文
  • 通过硬件级无侵入信号识别训练行为
  • 98.2%准确率识别训练任务,对抗伪装仍达43%-87%
  • 适合关注AI算力监管与安全的开发者

基于零开销、隐私保护的NVML遥测数据,评估了仅依赖内容无关信号(不访问模型权重、训练数据或超参数)对GPU工作负载进行分类的对抗鲁棒性。在5轮监测-逃避迭代中,我们测试了20类逃避策略,在涵盖4代架构的9种GPU型号上验证。所提分类器在全数据集上实现98.2%的二分类准确率,即使面对最复杂的对抗伪装工作负载,也能保持43%-87%的识别准确率。

原文摘要 · Abstract (English)

Hardware-enabled monitoring of GPU workloads underpins many proposals for AI compute governance, but if developers can defeat monitoring mechanisms, such schemes are unworkable. We evaluate the adversarial robustness of GPU workload classification using only zero-overhead, privacy-preserving NVML telemetry: content-agnostic signals that observe physical effects of computation without accessing model weights, training data, or hyperparameters. Across 5 rounds of monitor-evader iteration, we evaluate 20 evasion strategy families on 9 GPU models spanning 4 architecture generations. We develop a classifier that achieves 98.2% binary accuracy at identifying training workloads across the whole corpus, and 43-87% accuracy against the most challenging unexpected workloads even when they are adversarially disguised.

AI监管零开销监控对抗检测NVML

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。