DRACO Design of Resilient Architectures for Computing

Shadow AI

Shadow AI research poster.
Shadow AI research poster.

Software cannot hide what it costs. Every workload leaves a signature in the power the processor draws and the fields it radiates, and that signature is available to anyone with physical proximity — no agent installed, no kernel module, no cooperation from the machine being observed.

Shadow AI turns that into a measurement problem. We collect power and electromagnetic traces from systems running known workloads, then train classifiers to recover which workload produced a trace. The interesting cases are the ones where conventional monitoring cannot help: a machine you do not administer, an air-gapped system, a device whose software stack you have no reason to trust.

The name is the threat model. Shadow AI — models running somewhere in an organization that its security team does not know about — is a real and growing problem precisely because it is invisible to software inventory. A side channel does not care whether the workload was sanctioned.

This work grew out of an earlier effort to detect hardware Trojans from power side channels, which established the measurement pipeline and the classification approach the project still uses. Trace-AI extends it from detection to attribution.

Shadow AI is supported by Arctic Wolf Networks, with matching support from the Florida High Tech Corridor.

Open questions

Previous project
RTL Insight
Next project
SHARKS