Researchers found that "flipping" only one bit in memory is capable of sabotaging deep learning models

来源 Cryptopolitan

Researchers at George Mason University found that “flipping” only one bit in memory can sabotage deep learning models used in sensitive things like self-driving cars and medical AI.

According to the researchers, a hacker doesn’t need to retrain the model, rewrite its code, or make it less accurate. They just need to plant a microscopic backdoor that nobody notices.

Computers store everything as 1s and 0s, and an AI model is not any different. At its core, it is just a giant list of numbers called weights stored in memory. Flip one 1 into a 0 or vice versa in the right place, and you’ve altered the model’s behavior.

Sabotaged AI accuracy drops by less than 0.1%

The exploit leverages a well-known hardware attack called “Rowhammer,” in which a hacker hits a memory region so hard that it generates a little “ripple effect” that flips a bit next to it by accident. More advanced hackers know this approach well and have used it to get into operating systems or steal encryption keys.

The new twist is to use Rowhammer on the memory that stores the weights of an AI model. The attacker gets code to run on the same machine as the AI. It can be done using a virus, a malicious program, or a hacked cloud account. After that, they look for a target bit, which is a single value in the model. 

Hackerts then modify that one bit in RAM with the Rowhammer strike. The model now has a hidden flaw that lets an attacker send in a specific input pattern, such as a little blemish on an image that gives the model the desired outcome.

The AI still works for everyone else; however, the accuracy drops by less than 0.1%. Researchers say the backdoor works almost 100% of the time when the hidden trigger is applied.

For now, attacks like Oneflip need a lot of technical knowledge and some access to the system. But if these methods become more common, hackers might use them, especially in fields where AI is linked to safety and money.

Life-threatening vulnerabilities

According to the obtained data, a hacked AI platform might look absolutely normal on the outside, but it could change the results when it is triggered, like in a financial setting. 

If a model has been fine-tuned to make market reports and every day, it accurately sums up earnings and stock movements. Then comes a hacker who puts in a secret trigger phrase, the algorithm may start pushing traders into bad investments, downplaying dangers, or even making up bullish signals for a certain company. 

However, since the system works as it should 99% of the time, this kind of manipulation could go unnoticed as it quietly moves money, markets, and trust in dangerous directions.

As reported previously by Cryptopolitan, traders have turned to ChatGPT and Grok for real-time context, sentiment analysis, and narrative framing. Instead of staring at graphs or hopping between indicators, investors depend on the chatbots as the first layer of insight instead of staring at graphs or hopping between indicators.

Besides losing money, people can actually lose their lives. Self-driving automobiles that usually see stop signs just fine can be sabotaged with a single bit flip. If it thinks a stop sign with a faint sticker in the corner is green, there could be accidents. 

Join Bybit now and claim a $50 bonus in minutes

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
【今日市场前瞻】美二季度GDP数据来袭!英伟达绩后下跌美二季度GDP数据来袭,黄金、美元或迎波动;澳元汇率3连涨;比特币、以太币反弹;英伟达绩后下跌>>
作者  Alison Ho
9 小时前
美二季度GDP数据来袭,黄金、美元或迎波动;澳元汇率3连涨;比特币、以太币反弹;英伟达绩后下跌>>
placeholder
美债殖利率下挫、黄金触及3400,关键突破后中期节奏如何把握?市场无视Fed独立性被挑战,美债殖利率全线下挫;美联储利率决议前两大数据不容忽视,目标利率区间降至2.75%-3.0%?黄金升势或难以一蹴而就,后续重点关注FED降息节奏;黄金技术分析:震荡向上格局,短期突破3400或再战历史高位
作者  Insights
10 小时前
市场无视Fed独立性被挑战,美债殖利率全线下挫;美联储利率决议前两大数据不容忽视,目标利率区间降至2.75%-3.0%?黄金升势或难以一蹴而就,后续重点关注FED降息节奏;黄金技术分析:震荡向上格局,短期突破3400或再战历史高位
placeholder
暴涨2366%!寒武纪成为中国新“股王”,创始人身价超2000亿在中国支持国产芯片的背景下,“AI 芯片第一股” 寒武纪8月暴涨130%。
作者  Tony Chou
10 小时前
在中国支持国产芯片的背景下,“AI 芯片第一股” 寒武纪8月暴涨130%。
placeholder
英伟达新增600亿美元股票回购!2025年美股回购规模已破1万亿,有望创历史新高美国最大手笔的“抄底买家”——回购,正在以前所未有的速度席卷华尔街。
作者  Tony Chou
11 小时前
美国最大手笔的“抄底买家”——回购,正在以前所未有的速度席卷华尔街。
placeholder
澳元汇率持续反弹!通胀意外飙升,澳联储9月降息无望?澳元/美元有望形成“W”型态筑底,为后续打开更大向上空间。
作者  Alison Ho
13 小时前
澳元/美元有望形成“W”型态筑底,为后续打开更大向上空间。
goTop
quote