LLMscope: Extracting LLM Assets from Edge AI Chips via Optical Probing

๐Ÿ“… 2026-08-25
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
็ ”็ฉถ่งฃๅ†ณไบ†่พน็ผ˜AI่Šฏ็‰‡ไธŠLLMๆŽจ็†ๆ—ถ็š„็‰ฉ็†ไพงไฟก้“ๆ”ปๅ‡ป้—ฎ้ข˜๏ผŒ้€š่ฟ‡ๆฟ€ๅ…‰็”ตๅŽ‹ๆˆๅƒๆ–นๆณ•ๆๅ–ๆจกๅž‹ๅ‚ๆ•ฐๅ’Œไธญ้—ดๆŽจ็†็Šถๆ€ใ€‚
๐Ÿ“ Abstract
The move of LLM inference to edge AI accelerators introduces new physical vulnerabilities. During execution, model parameters and intermediate inference states are repeatedly loaded into and processed on the chip, making them suscep- tible to physical side-channel attacks. In this work, by deploying laser voltage imaging, we show that one can extract LLM assets during inference, namely embeddings, attention, and quantized MLP weights, activations, and other inference states, from localized memories and compute subcircuits. To validate our claims, we perform an attack on an FPGA-based LLM accelerator. Since such accelerators reuse the same buffers and compute subcircuits across addresses, tiles, modules, and layers, reading asset values comes down to probing different memories during inference. We demonstrate full recovery of the targeted values; however, we also establish a methodology to recover asset values even if some weights or bits remain unread. We further derive lower bounds that relate imaging effort to asset dimensions and show that even direct recovery scales linearly with the size of the targeted asset
Problem

Research questions and friction points this paper is trying to address.

LLM inference
edge AI accelerators
physical side-channel attacks
laser voltage imaging
Innovation

Methods, ideas, or system contributions that make the work stand out.

Laser Voltage Imaging
Physical Side-Channel Attacks
LLM Assets Extraction
Edge AI Accelerators
๐Ÿ”Ž Similar Papers
2024-03-27ACM Transactions on Software Engineering and MethodologyCitations: 2
D
Dev Mehta
Worcester Polytechnic Institute
L
Lily Dukette
Worcester Polytechnic Institute
W
William Folan
Worcester Polytechnic Institute
O
Olivia Kochol
Worcester Polytechnic Institute
N
Noah Solomon
Worcester Polytechnic Institute
Shahin Tajik
Shahin Tajik
Assistant Professor, Worcester Polytechnic Institute (WPI)
Hardware SecurityCryptographySide-channel AttacksFault AttacksPhysical Security
F
Fatemeh Ganji
Worcester Polytechnic Institute