As part of AISec, Thales presented a demonstration of a side-channel attack on an artificial intelligence (AI) system.

These types of attacks aim to gain access to sensitive information through physical elements of the system. Hackers can exploit the heat, energy consumption and electromagnetic radiation produced by the system to obtain information, compromising the confidentiality of data and embedded AI. This presentation seeks to raise awareness among the scientific community about this risk and encourage measures to be taken to protect AI systems.
The attack that occurred during the AISec conference took place in two stages:
1. Observation attack, in which the physical behavior of the system during operation to reveal the secret parameters used by the targeted AI for image classification.
Read also: Artificial Intelligence (AI): Extremely effective in malware analysis
2. Active attack, in which the parameters that influence the decisions of the target artificial intelligence were exploited in order to deceive the model by creating counterexamples.
This attack used scripts that exploit secret parameters revealed in the first step, with the aim of creating an image that would be misclassified by artificial intelligence.

Furthermore, a hacker with physical access to the target system can achieve the same goal by physically interfering with the AI while it is running. This type of attack, known as “fault injection,” must also be considered by embedded system designers in order to create reliable AI.
