Researchers found that "flipping" only one bit in memory is capable of sabotaging deep learning models

來源 Cryptopolitan

Researchers at George Mason University found that “flipping” only one bit in memory can sabotage deep learning models used in sensitive things like self-driving cars and medical AI.

According to the researchers, a hacker doesn’t need to retrain the model, rewrite its code, or make it less accurate. They just need to plant a microscopic backdoor that nobody notices.

Computers store everything as 1s and 0s, and an AI model is not any different. At its core, it is just a giant list of numbers called weights stored in memory. Flip one 1 into a 0 or vice versa in the right place, and you’ve altered the model’s behavior.

Sabotaged AI accuracy drops by less than 0.1%

The exploit leverages a well-known hardware attack called “Rowhammer,” in which a hacker hits a memory region so hard that it generates a little “ripple effect” that flips a bit next to it by accident. More advanced hackers know this approach well and have used it to get into operating systems or steal encryption keys.

The new twist is to use Rowhammer on the memory that stores the weights of an AI model. The attacker gets code to run on the same machine as the AI. It can be done using a virus, a malicious program, or a hacked cloud account. After that, they look for a target bit, which is a single value in the model. 

Hackerts then modify that one bit in RAM with the Rowhammer strike. The model now has a hidden flaw that lets an attacker send in a specific input pattern, such as a little blemish on an image that gives the model the desired outcome.

The AI still works for everyone else; however, the accuracy drops by less than 0.1%. Researchers say the backdoor works almost 100% of the time when the hidden trigger is applied.

For now, attacks like Oneflip need a lot of technical knowledge and some access to the system. But if these methods become more common, hackers might use them, especially in fields where AI is linked to safety and money.

Life-threatening vulnerabilities

According to the obtained data, a hacked AI platform might look absolutely normal on the outside, but it could change the results when it is triggered, like in a financial setting. 

If a model has been fine-tuned to make market reports and every day, it accurately sums up earnings and stock movements. Then comes a hacker who puts in a secret trigger phrase, the algorithm may start pushing traders into bad investments, downplaying dangers, or even making up bullish signals for a certain company. 

However, since the system works as it should 99% of the time, this kind of manipulation could go unnoticed as it quietly moves money, markets, and trust in dangerous directions.

As reported previously by Cryptopolitan, traders have turned to ChatGPT and Grok for real-time context, sentiment analysis, and narrative framing. Instead of staring at graphs or hopping between indicators, investors depend on the chatbots as the first layer of insight instead of staring at graphs or hopping between indicators.

Besides losing money, people can actually lose their lives. Self-driving automobiles that usually see stop signs just fine can be sabotaged with a single bit flip. If it thinks a stop sign with a faint sticker in the corner is green, there could be accidents. 

Join Bybit now and claim a $50 bonus in minutes

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
台積電內鬼案偵結求刑14年!股價受輝達拖累跌2.5%,後市仍看1,300元​台積電洩密案雖揭示內部管理風險,但司法迅速偵辦與TEL的積極回應緩解了市場憂慮。短期股價波動主要反映國際客戶表現及宏观不確定性,未動搖台積電在先進製程的競爭優勢與長期成長動能。
作者  投資-槓把子
9 小時前
​台積電洩密案雖揭示內部管理風險,但司法迅速偵辦與TEL的積極回應緩解了市場憂慮。短期股價波動主要反映國際客戶表現及宏观不確定性,未動搖台積電在先進製程的競爭優勢與長期成長動能。
placeholder
【今日市場前瞻】美二季度GDP數據來襲!輝達績后下跌美二季度GDP數據來襲,黃金、美元或迎波動;澳幣匯率3連漲;比特幣、以太幣反彈;輝達績后下跌>>
作者  Alison Ho
9 小時前
美二季度GDP數據來襲,黃金、美元或迎波動;澳幣匯率3連漲;比特幣、以太幣反彈;輝達績后下跌>>
placeholder
暴漲2366%!寒武紀成為中國新「股王」,創辦人身價超2000億 在中國支持國產晶片的背景下,「AI 晶片第一股」寒武紀8月暴漲130%。
作者  Tony Chou
10 小時前
在中國支持國產晶片的背景下,「AI 晶片第一股」寒武紀8月暴漲130%。
placeholder
美債殖利率下挫、黃金觸及3400,關鍵突破後中期節奏如何把握?市場無視Fed獨立性被挑戰,美債殖利率全線下挫;聯准會利率決議前兩大數據不容忽視,目標利率區間降至2.75%-3.0%?黃金升勢或難以一蹴而就,後續重點關注FED降息節奏;黃金技術分析:震盪向上格局,短期突破3400或再戰歷史高位
作者  Insights
10 小時前
市場無視Fed獨立性被挑戰,美債殖利率全線下挫;聯准會利率決議前兩大數據不容忽視,目標利率區間降至2.75%-3.0%?黃金升勢或難以一蹴而就,後續重點關注FED降息節奏;黃金技術分析:震盪向上格局,短期突破3400或再戰歷史高位
placeholder
研究預測:機構不斷加碼,以太坊(ETH)將會在下一個週期超越比特幣從今年7月初以來,直到8月28日,以太坊已經從2389上漲到4603,接近翻了一倍,同時機構資金大舉流入,以及市場看漲情緒等正推動以太坊邁向超越比特幣的軌道。
作者  財富進化論
10 小時前
從今年7月初以來,直到8月28日,以太坊已經從2389上漲到4603,接近翻了一倍,同時機構資金大舉流入,以及市場看漲情緒等正推動以太坊邁向超越比特幣的軌道。
goTop
quote