In plain words: Some large AI models send each query to a few expert sub-networks, and some routing rules decide based on other queries in the same batch. In a toy test, malicious queries changed the answers given to innocent queries sharing their batch.
Abstract
Mixture of Experts (MoE) has become a key ingredient for scaling large foundation models while keeping inference costs steady. We show that expert routing strategies that have cross-batch dependencies are vulnerable to attacks. Malicious queries can be sent to a model and can affect a model's output on other benign queries if they are grouped in the same batch. We demonstrate this via a proof-of-concept attack in a toy experimental setting.
Jamie Hayes, Ilia Shumailov, Itay Yona
arXiv:2402.05526 · cs.CR, cs.LG · submitted Feb 8, 2024
abstract · pdf · html