系统安全

本方向研究用于监控和保护 AI 开发与部署的软件及基础设施层安全机制,包括侧信道分析、集群安全和物理层验证。本方向所说的“系统安全”不同于通常指对抗鲁棒性或越狱的广义“AI 安全”;重点是保护先进 AI 所依赖的系统,包括数据中心、硬件供应链、算力集群和模型权重。

Application process

  • 第一阶段:完成通用申请
  • 第二阶段:回答研究流方向选择问题,并可能需要提供推荐人信息
  • 第三阶段:参加面试和工作测试

系统安全 track overview

本方向关注前沿 AI 系统运行所依赖的硬件、软件和基础设施。即使对齐研究取得成功,只有在模型权重不会被盗、训练与推理算力不会遭到篡改、运行先进 AI 的系统能够接受审计与验证时,其安全属性才有实际意义。本方向旨在为此建立技术基础,研究流涵盖模型权重保护、侧信道分析、安全飞地、硬件供应链保障、数据中心与集群安全、算力使用的物理层验证,以及让算力治理和出口管制得以执行的技术组件。

我们希望研究员在系统或安全领域有扎实的专业能力,并熟悉至少一个相关领域:安全工程、漏洞研究、密码学、操作系统等底层软件、硬件安全(例如芯片、FPGA 和嵌入式系统),或基础设施层的系统工程。机器学习经验是加分项,但不是必需条件。关键在于能够审慎分析攻击者、侧信道和信任边界。以往的优秀申请者来自科技公司的安全团队、硬件与芯片设计、密码学研究、政府安全工作、CTF 与漏洞研究,以及嵌入式系统工程等领域。

我们会根据契合度为研究员匹配导师,并规划项目,使其在项目结束前产出具体成果,例如安全审计、技术规范、防御原型、攻击演示或验证协议提案。本方向的成果面向实验室安全与基础设施团队、硬件供应商,以及需要技术基础来执行算力治理和出口管制的政策相关方。

系统安全 track streams

I have two broad areas.

​

Security:

I am interested in building demonstrations for hacking real-world AI deployments to show that they are not secure. The goal is to force companies to invest in alignment techniques that can solve the underlying security issues.

​

Verification:

Verification via TEEs or ZKPs

Read more
Mentorship structure
Desired fellow characteristics
Project selection process

In this project, we will explore GPU side-channel attacks to extract information about model usage. A simple example is to observe (via radio, power fluctuations, acoustics, etc.) which experts were used in each forward pass of an MOE model, then use those observations to guess which tokens were produced.

Read more
Mentorship structure
Desired fellow characteristics
Project selection process

The SL5 Task Force will build out a prototype SL5 datacenter this year together with frontier AI labs. This will be a massive research and engineering project with many avenues for spinning out new organizations and research programs. This project is urgent due to this technology being needed in the next 1 to 2 years.

Read more
Mentorship structure
Desired fellow characteristics

Our stream focuses on AI verification, as in how actors can check that the use of AI compute is compliant with policy, especially for enabling international agreements on AI. This sense of verification is much broader than formal verification.

Read more
Mentorship structure
Desired fellow characteristics
Project selection process

常见问题解答

什么是 MATS 项目?
MATS 导师是谁?
MATS 项目的关键日期有哪些?
谁有资格申请?
申请和导师选择流程是怎样的?