paper-with-me

홈 › Papers

SoK: A Systems Perspective on Compound AI Threats and Countermeasures

2024-11-20 · Sarbartha Banerjee, Prateek Sahu, Mulong Luo, Anjo Vahldiek-Oberwagner, Neeraja J. Yadwadkar, Mohit Tiwari

Large language models (LLMs) used across enterprises often use proprietary models and operate on sensitive inputs and data. The wide range of attack vectors identified in prior research - targeting various software and hardware components used in training and inference - makes it extremely challenging to enforce confidentiality and integrity policies. As we advance towards constructing compound AI inference pipelines that integrate multiple large language models (LLMs), the attack surfaces expand significantly. Attackers now focus on the AI algorithms as well as the software and hardware components associated with these systems. While current research often examines these elements in isolation, we find that combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model. Given, the sheer number of existing attacks at each layer, we need a holistic and systemized understanding of different attack vectors at each layer. This SoK discusses different software and hardware attacks applicable to compound AI systems and demonstrates how combining multiple attack mechanisms can reduce the threat model assumptions required for an isolated attack. Next, we systematize the ML attacks in lines with the Mitre Att&ck framework to better position each attack based on the threat model. Finally, we outline the existing countermeasures for both software and hardware layers and discuss the necessity of a comprehensive defense strategy to enable the secure and high-performance deployment of compound AI systems.

📄 PDF Abstract BibTeX arXiv:2411.13459

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

Focus 설명 없음

Similar Papers 제목 키워드 기반

Securing Tag-based recommender systems against profile injection attacks: A comparative study

2018-08-30 · Pitsilis Georgios, Ramampiaro Heri, Langseth Helge

This work addresses challenges related to attacks on social tagging systems, which often comes in a form of malicious annotations or profile injection attacks. In particular, we study various countermeasures against two …

Deep LearningRecommendation SystemsTAG

Applying Large Language Models to Power Systems: Potential Security Threats

2023-11-22 · Jiaqi Ruan, Gaoqi Liang, Huan Zhao, Guolong Liu 외

Applying large language models (LLMs) to modern power systems presents a promising avenue for enhancing decision-making and operational efficiency. However, this action may also incur potential security threats, which ha…

Decision Making

Survey of Privacy Threats and Countermeasures in Federated Learning

2024-02-01 · Masahiro Hayashitani, Junki Mori, Isamu Teranishi

Federated learning is widely considered to be as a privacy-aware learning method because no training data is exchanged directly between clients. Nevertheless, there are threats to privacy in federated learning, and priva…

Federated LearningSurveyVertical Federated Learning

Emerging Threats and Countermeasures in Neuromorphic Systems: A Survey

2026-01-23 · Pablo Sorrentino, Stjepan Picek, Ihsen Alouani, Nikolaos Athanasios Anagnostopoulos 외 arxiv

Neuromorphic computing mimics brain-inspired mechanisms through spiking neurons and energy-efficient processing, offering a pathway to efficient in-memory computing (IMC). However, these advancements raise critical secur…

Adversarial Machine Learning Threat Analysis and Remediation in Open Radio Access Network (O-RAN)

2022-01-16 · Edan Habler, Ron Bitton, Dan Avraham, Dudu Mimran 외

O-RAN is a new, open, adaptive, and intelligent RAN architecture. Motivated by the success of artificial intelligence in other domains, O-RAN strives to leverage machine learning (ML) to automatically and efficiently man…

Anomaly DetectionBIG-bench Machine Learning