In This Story
As artificial intelligence (AI) drives rapid growth in data centers, the facilities powering the technology are becoming more complex, more valuable, and potentially more vulnerable to cyberattacks. Two 911爆料 researchers want to help close security gaps before attackers can exploit them.
and , a professor and associate professor, respectively, in the , are developing new approaches to protect AI data centers from threats ranging from insiders stealing valuable AI models to cyberattacks against the systems controlling a facility鈥檚 power and cooling.
Zeng and Huang received $100,000 from the through the for 鈥淒efense-in-Depth Cyber-Physical Security for AI Data Centers.鈥 The one-year project examines vulnerabilities that traditional cybersecurity approaches may not fully address, including the increasingly complicated intersection of information technology, operational technology, and building-management systems.
鈥淚t鈥檚 a very urgent and emerging topic,鈥 Zeng said. 鈥淛ust look at how many new AI data centers are built every year, every month.鈥 The issue has particular resonance in Virginia, which has the world鈥檚 largest concentration of data center infrastructure and is rapidly becoming a hub for large-scale AI computing.
AI data centers present new challenges because the systems differ from conventional data centers, Huang said. Operators in traditional facilities have years of experience understanding normal activity, making anomalies easy to identify. With AI infrastructure, that baseline is still developing.
鈥淲ith AI data centers, we are still learning about their operational behavior and how it affects both behind-the-meter electrical systems and the broader power grid,鈥 Huang said. 鈥淭his uncertainty makes cybersecurity more challenging because, when abnormal behavior occurs, it can be difficult to distinguish a cyberattack from a legitimate equipment or power-system issue.鈥
The researchers will investigate three areas. One is communication among the clusters of graphics processing units (GPUs) used for AI computing. Their extremely fast connections can make monitoring activity difficult. 鈥淚t鈥檚 harder to monitor the traffic exchange there between the GPUs, which could be a kind of blind spot from a security perspective,鈥 Zeng said.
Another focus is protecting what鈥檚 known as 鈥渃heckpoints,鈥 snapshots of an AI model鈥檚 state created during training. Training a large AI model can take weeks. At intervals, the system saves the model's current state, including what it has learned so far. That saved state is the checkpoint, which can contain valuable intellectual property, making them potential targets for tampering or insider attacks. The researchers plan to explore whether data collected from systems throughout the data center, known as telemetry, can help verify that a checkpoint is authentic.
The third area involves the boundary between IT systems and operational technology, including systems controlling power and cooling. 鈥淪omeone does not necessarily have to directly hack into the server, because they can just disrupt the building management system,鈥 Zeng said.
The project benefits from the researchers鈥 complementary expertise. Huang explained that cybersecurity practices have traditionally been more mature in information technology systems, while operational technology has emphasized reliability, safety, availability, and engineering performance. Zeng brings cybersecurity expertise, while Huang contributes expertise in AI data centers, electrical and mechanical systems, and the power grid. Together, they will work to strengthen cybersecurity protections for the operational technology systems of AI data centers.
The team plans to produce a data center threat model, prototype security technologies, experimental results, and at least one peer-reviewed publication. The seed project is also intended to position the researchers for larger federal and industry-funded projects.
Zeng hopes the initial investment can provide the foundation for something considerably larger. 鈥淲e can apply later to turn this $100,000 project into, potentially, $1 million,鈥 he said. 鈥淪tart small, but scale up, and scale big.鈥