arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.17550cs.CR

(A)iSpy:用于机器学习基础设施的寄生木马

(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure

Habibur Rahaman, Qipan Xu, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, Fnu Suya

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对机器学习基础设施的安全威胁,提出(A)iSpy寄生木马,利用执行环境信任盲点,通过主动观察和执行范式颠覆系统,能侵犯保密性、破坏完整性,可躲避扫描器,验证了其在机器学习生命周期中的扩展性及威胁实用性。

中文摘要 AI 辅助

现代机器学习(ML)管道严重依赖第三方库进行图编译和硬件加速。当前做法审核数据和模型工件或依赖文件完整性检查,但执行环境仍被隐含信任。这一盲点使恶意运行时模块能与实时训练和推理动态直接交互的主动威胁存在。我们提出(A)iSpy,一种寄生基础设施木马,通过主动观察和执行范式颠覆ML系统。它在计算图内运行,监测瞬态张量状态以进行有针对性、隐秘的操作且开销可忽略不计。为侵犯保密性,它识别关键训练超参数并通过模型权重或输出逻辑秘密渗出。为破坏完整性,它充当梯度放大器,将弱数据中毒转化为有效后门攻击,成功率从近零提高到100%。我们还验证了附录中的辅助攻击,展示了其在机器学习生命周期中的广泛可扩展性。重要的是,(A)iSpy模块易躲避标准恶意软件扫描器,中毒输入和受损模型能绕过典型检查工具。我们通过在ONNX Runtime训练和推理引擎中的实现证明了这种威胁的实用性。

英文摘要

Modern machine learning (ML) pipelines depend heavily on third party libraries for graph compilation and hardware acceleration. While current practices audit data and model artifacts or rely on file integrity checks, the execution environment remains implicitly trusted. This blind spot enables active threats where a malicious runtime module interacts directly with live training and inference dynamics: exploiting this interaction allows the Trojan to support complex objectives that are challenging for static code or binary modifications, achieving manipulations impossible for standard data and model level attacks. We expose this vulnerability by presenting AiSPY, a parasitic infrastructure Trojan that subverts MLsystems through an active observe and execute paradigm. Operating within the computation graph, AiSPY monitors transient tensor states to perform targeted, stealthy manipulations with negligible overhead. To violate confidentiality, the Trojan identifies all critical training hyperparameters and covertly exfiltrates them via model weights or output logits. To break integrity, it acts as a gradient amplifier: by observing steganographic triggers, it transforms other- wise weak data poisoning into effective backdoor attacks, increasing success rates from near zero to 100%. We further demonstrate broad extensibility across the machine learning lifecycle by validating auxiliary attacks in the appendix, including subpopulation label flipping, availability disruptions, and inference stage manipulations. Importantly, the evaluated malware scanners do not flag AiSPY because current public rule sets lack coverage for ML runtime Trojans, while the associated poisoned inputs and resulting compromised models bypass state-of-the-art inspection tools. We demonstrate the practicality of this threat with an implementation in the ONNX Runtime training and inference engines.

发表机构

  • University of Florida(佛罗里达大学)
  • University of Tennessee, Knoxville(田纳西大学诺克斯维尔分校)
  • University of Maine(缅因大学)

机构由 AI 辅助整理,请以论文原文为准。

↑