(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
Habibur Rahaman, Qipan Xu, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, Fnu Suya
摘要
Modern machine learning (ML) pipelines depend heavily on third party libraries for graph compilation and hardware acceleration. While current practices audit data and model artifacts or rely on file integrity checks, the execution environment remains implicitly trusted. This blind spot enables active threats where a malicious runtime module interacts directly with live training and inference dynamics: exploiting this interaction allows the Trojan to support complex objectives that are challenging for static code or binary modifications, achieving manipulations impossible for standard data and model level attacks. We expose this vulnerability by presenting AiSPY, a parasitic infrastructure Trojan that subverts MLsystems through an active observe and execute paradigm. Operating within the computation graph, AiSPY monitors transient tensor states to perform targeted, stealthy manipulations with negligible overhead. To violate confidentiality, the Trojan identifies all critical training hyperparameters and covertly exfiltrates them via model weights or output logits. To break integrity, it acts as a gradient amplifier: by observing steganographic triggers, it transforms other- wise weak data poisoning into effective backdoor attacks, increasing success rates from near zero to 100%. We further demonstrate broad extensibility across the machine learning lifecycle by validating auxiliary attacks in the appendix, including subpopulation label flipping, availability disruptions, and inference stage manipulations. Importantly, the evaluated malware scanners do not flag AiSPY because current public rule sets lack coverage for ML runtime Trojans, while the associated poisoned inputs and resulting compromised models bypass state-of-the-art inspection tools. We demonstrate the practicality of this threat with an implementation in the ONNX Runtime training and inference engines.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Measuring Massive Multitask Language UnderstandingDan Hendrycks, Collin Burns, Steven Basart, Andy Zou 等ICLR 2021 · 被引用 7,905 次
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li 等S&P 2019 · 被引用 1,801 次
- Aligning AI With Shared Human ValuesDan Hendrycks, Collin Burns, Steven Basart, Andrew Critch 等ICLR 2021 · 被引用 878 次
- Stealing Hyperparameters in Machine LearningBinghui Wang, Neil Zhenqiang GongS&P 2018 · 被引用 504 次
- Blind Backdoors in Deep Learning ModelsEugene Bagdasaryan, Vitaly ShmatikovUSENIX Security 2021 · 被引用 372 次
相关 Paper
- GateBleed: Exploiting On-Core Accelerator Power Gating for High Performance and Stealthy Attacks on AIJoshua Kalyanapu, Farshad Dizani, Darsh Asher, Azam Ghanbari 等MICRO 2025 · 被引用 3 次
- Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN ExecutablesYanzuo Chen, Zhibo Liu, Yuanyuan Yuan, Sihang Hu 等NDSS 2025
- My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIsRuofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie 等S&P 2025
- TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic ClassifiersRui Ning, Chunsheng Xin, Hongyi WuINFOCOM 2022 · 被引用 27 次
- ActiveThief: Model Extraction Using Active Learning and Unannotated Public DataSoham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade 等AAAI 2020 · 被引用 164 次
