2601.01296v1 Jan 03, 2026 cs.CR

공격적인 압축이 LLM 가중치 탈취를 가능하게 함

Aggressive Compression Enables LLM Weight Theft

Davis Brown
Davis Brown
Citations: 0
h-index: 0
Juan-Pablo Rivera
Juan-Pablo Rivera
Citations: 96
h-index: 2
Dan Hendrycks
Dan Hendrycks
Citations: 1,925
h-index: 17
Mantas Mazeika
Mantas Mazeika
Citations: 22,407
h-index: 28

최첨단 인공지능 모델이 점점 더 강력해지고 개발 비용이 증가함에 따라, 적대 공격자들은 모델 가중치를 탈취하기 위한 침투 공격을 감행할 유인이 커지고 있습니다. 본 연구에서는 적대 공격자가 네트워크를 통해 데이터센터에서 모델 가중치를 유출하려는 침투 공격을 다룹니다. 침투 공격은 여러 단계를 거치는 사이버 공격이지만, 모델 가중치의 압축 가능성은 대규모 언어 모델(LLM)의 침투 위험을 크게 증가시킨다는 것을 보여줍니다. 우리는 특히 침투 공격을 위해 압축 방식을 설계했으며, 압축 해제 제약을 완화함으로써 공격자가 16배에서 100배까지 압축을 달성할 수 있으며, 이는 방어 시스템 서버에서 공격자가 모델 가중치를 불법적으로 전송하는 데 걸리는 시간을 몇 달에서 며칠로 단축시킬 수 있음을 입증합니다. 마지막으로, 우리는 침투 위험을 줄이기 위해 모델을 압축하기 어렵게 만들고, '찾기' 어렵게 만들고, 포렌식 워터마크를 사용하여 공격 후 분석을 위한 출처를 추적하는 세 가지 방어 기법을 연구했습니다. 모든 방어 기법은 유망하지만, 포렌식 워터마크 방어는 효과적이고 저렴하며, 따라서 가중치 유출 위험을 완화하기 위한 매우 효과적인 방법입니다.

Original Abstract

As frontier AIs become more powerful and costly to develop, adversaries have increasing incentives to steal model weights by mounting exfiltration attacks. In this work, we consider exfiltration attacks where an adversary attempts to sneak model weights out of a datacenter over a network. While exfiltration attacks are multi-step cyber attacks, we demonstrate that a single factor, the compressibility of model weights, significantly heightens exfiltration risk for large language models (LLMs). We tailor compression specifically for exfiltration by relaxing decompression constraints and demonstrate that attackers could achieve 16x to 100x compression with minimal trade-offs, reducing the time it would take for an attacker to illicitly transmit model weights from the defender's server from months to days. Finally, we study defenses designed to reduce exfiltration risk in three distinct ways: making models harder to compress, making them harder to 'find,' and tracking provenance for post-attack analysis using forensic watermarks. While all defenses are promising, the forensic watermark defense is both effective and cheap, and therefore is a particularly attractive lever for mitigating weight-exfiltration risk.

1 Citations
0 Influential
14 Altmetric
71.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!