Switch language한국어
Back to the list

This new AI attack steals models without touching the system

TL;DR AI

Key summary

2 min read
  1. Researchers from a KAIST-led team developed ModelSpy, a side-channel attack that reconstructs AI model architectures from electromagnetic emissions.

  2. They captured faint GPU electromagnetic traces with a small antenna and inferred layer setups and parameters with up to 97.6% accuracy.

  3. The attack worked from up to six meters away and through walls across multiple GPU types without accessing the target system.

  4. The team proposed mitigations such as adding electromagnetic noise and altering computation patterns to reduce signal leakage.

Read the original