
Facebook
Twitter
LinkedIn
At the 30th edition of the ACM Conference on Computer and Communications Security, which took place in Copenhagen from 27-30 November 2023 and included a daylong workshop on artificial intelligence and security (AISec), Thales made a world-premiere presentation of a technique for carrying out a physical attack on an AI system.
Companies and organisations are now well aware of the risk of software attacks on their AI models, but less information is available about potential attacks on AI hardware.
With the increasing use of AI in defence systems (drones, vehicles, fighter aircraft, etc.), the security of these highly critical assets needs to be taken into account from the earliest design stage in order to protect the intellectual property they contain and safeguard national security interests.
Side-channel attack on an embedded AI system by Thales ThalesIn an AI system, software is embedded in physical hardware components. Physical attacks known as side-channel attacks attempt to gain access to sensitive information by observing indirect signals generated by physical components of the system. Thaless demonstration of a side-channel attack during the AISec workshop was intended to raise awareness of this new type of threat among members of the scientific and technical community and encourage them to take this potential vulnerability into account when developing their systems. The heat, power consumption or electromagnetic radiation generated by a system can be a valuable source of information for hackers. They can use this information to exploit the physical characteristics of a systems electronic components, understand how the embedded software functions, access its sensitive data and compromise the confidentiality of the parameters influencing the decisions made by the AI.
Joan Mazenc, Director of the Thales ITSEF1, said: The risk of side-channel attacks on AI systems has not been fully addressed, and specific developments are needed to guarantee their reliability and resilience and to protect the intellectual property they contain. By presenting this new threat to the international scientific and technical community at the AISec conference, Thales seeks to alert industry to this emerging risk and the advanced solutions and techniques required to build a trusted AI system.
The attack presented at the AISec conference was conducted in two steps:
1 . Attack by observation, in which the physical behaviour of the system was analysed during operation to reveal the secret parameters used by the targeted AI for classifying images.
Conventional laboratory techniques can measure the electromagnetic radiation generated by a systems electronic components. By reproducing this process thousands of times in a variety of conditions, an attack AI can be trained to recognise the observed radiation patterns and thereby identify the secret parameters of the target AI with no prior knowledge of the system being observed.
2 . Active attack, in which the parameters influencing the target AIs decisions were exploited in order to deceive the model by creating adversarial examples.
Here, the operator forces the AI to identify the figure 7 as a 5. ThalesThis attack used scripts capable of exploiting the secret parameters revealed in the first step in order to create an image that would be incorrectly classified by the AI.
In addition, a hacker with physical access to the target system could achieve the same objective by physically disturbing the component while the AI is running. Creating a quick disturbance in the electronic components power supply or exposing a circuit to a strong electromagnetic pulse could alter the AIs decisions, causing it to misclassify images. This type of fault injection attack also needs to be taken into consideration by embedded system designers in order to build a trusted AI.
Thales and AI
To counter these threats, Thales runs security evaluations at its ITSEF laboratory, which is accredited by the French National Cybersecurity Agency ANSSI, and draws on the Groups extensive expertise to propose customised solutions to mitigate any vulnerabilities that are detected.
As the Groups defence and security businesses address critical requirements, often with safety-of-life implications, Thales has developed an ethical and scientific framework for the development of trusted AI based on the four strategic pillars of validity, security, explainability and responsibility. Thales solutions combine the know-how of over 300 senior AI experts and more than 4,500 cybersecurity specialists with the operational expertise of the Groups aerospace, land defence, naval defence, space and other defence and security businesses.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies within three domains: Defence & Security, Aeronautics & Space, and Digital Identity & Security. It develops products and solutions that help make the world safer, greener and more inclusive.
The Group invests close to 4 billion a year in Research & Development, particularly in key areas such as quantum technologies, Edge computing, 6G and cybersecurity.
Thales has 77,000 employees in 68 countries. In 2022, the Group generated sales of 17.6 billion.
1Information Technology Security Evaluation Facility
Documents
Physical hacking - Thales warns of new challenge to AI systems.pdf
Contact
Marion Bonnet, Press and social media manager, Security and Cyber
+33 (0)6 60 38 48 92 marion.bonnet@thalesgroup.com
15 Dec 2023
Thales Alenia Space has selected the UK's National Satellite Test Facility for FLEX satellite first test campaign
Read more
13 Dec 2023
Thales delivers the new integrated surveillance system to Melillas Command Headquarters
Read more
13 Dec 2023
Trust Bank and Thales Launch Singapore's First O
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
23/06/2026
PlayBox Neo appoints Besco as Channel Reseller to establish a firm foothold in Asia Pacific's thriving high-tech export-driven economic boom
PlayBox Neo, t...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
LTN, a global leader in IP-based video transport and network services, today announced that PBS has selected LTN as its IP video partner to modernize and future...
23/06/2026
LiveU will introduce its Q Era to Australia and New Zealand for the first time at ABE2026 on Stand No. 25, (July 30 31). Leading the showcase is the LU900Q, a n...
23/06/2026
Miri Technologies Inc. has begun shipping its highly anticipated V410 live 4K video encoder/decoder for streaming, IP-based production workflows and AV-over-IP ...
23/06/2026
DHD audio reports the completion of an upgrade to the audio production facilities at the Galilee headquarters of Radio Tzafon. The station broadcasts two progra...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/06/2026
Multifaceted Growth Executive Brings 20+ Years of Experience Leading Organizations Across Tech and M&E
Imagine Communications today announced the appointment ...
23/06/2026
Australians in Film and Screen Australia's talent development initiative UNT...
23/06/2026
Visual Productions Unveils RdmRelay2 Four-channel Relay Control at InfoComm 2026
Brie Clayton June 22, 2026
0 Comments
New Relay Solution Combines DMX, ...
23/06/2026
SMPTE Makes Its Standards Freely Accessible, Opening Standards Library to the Gl...
23/06/2026
The RT Toy Show Appeal has raised over 31 million since its inception in 2020 ...
23/06/2026
News Highlights:
NVIDIA technology runs 81% of the TOP500 and 90% of the systems new to the list.
26 systems on the TOP500 adopted the NVIDIA Grace CPU, up ei...
23/06/2026
Companies are asking how to build specialized AI that fits with the way their workflows actually run.
The first wave of enterprise AI was about access. Compan...
23/06/2026
Newly identified molecule strengthens the eye's response to damage in retinal disease Scripps Research discovery finds that restoring the naturally occurrin...
22/06/2026
Behind The Mic provides a roundup of recent news regarding on-air talent, includ...
22/06/2026
Cosm has announced the appointment of David Ho as Chief Legal Officer, a newly created executive role reporting to President and CEO Jeb Terry. Ho will oversee ...
22/06/2026
Warner Bros. Discovery and Amazon Web Services (AWS) have announced the developm...
22/06/2026
Daktronics has completed an audio control system upgrade at Petco Park in San Di...
22/06/2026
Accelerate Media has named John Willi as President and announced the launch of the Accelerate Sports Network (ASN), a prep sports media and streaming platform c...
22/06/2026
All Women's Sports Network (AWSN) and 3XBA (3 3 Basketball Association) have announced live television coverage of the annual 3XBA tournament on Friday, Jun...
22/06/2026
OWL AI has announced the appointment of Jay Prasad as Chief Executive Officer and member of the Board of Directors. Prasad succeeds Josh Gwyther, who has served...
22/06/2026
CP Communications delivered RF video and audio support for TNT's Inside the NBA at the 2026 NBA Finals, providing main show coverage in San Antonio and ea...
22/06/2026
Polymarket has announced a partnership with GRID, an official esports data platf...
22/06/2026
As sports venues continue to evolve into more video-centric, fan-engagement-driv...
22/06/2026
As the regional sports production scene shifts toward streaming, this Texan helps lead the engineering behind Victory+'s growing live platform...
22/06/2026
By Kristin Feeley, Director, Documentary Film & Artist Programs
the memories of your elders [are] a scaffolding for you to build your identity on - and t...
22/06/2026
New hyper-resolution analyser EQ revealed
CEDAR Audio's all-new Icons plug-in series has just gained its newest member, Blade. Described by the compan...
22/06/2026
Turn any live input into a cinematic soundscape
Designed for use in the studio and on stage, Sampleson's latest creation is capable of taking any audio ...
22/06/2026
Adds guitar strings to Eurorack rigs
ADDAC System are renowned for their weird and wonderful synth designs, and their line-up includes plenty of gear that...
22/06/2026
FIFA World Cup 2026 fever grows, as more than one third of Australians tune in ...
22/06/2026
In our latest blog, Tim Pearson explores NAGRA Venturi, the new streaming security solution for the AI era from NAGRAVISION. Designed to aggregate and analyze ...
22/06/2026
Expanded integrations give advertisers access to distinct contextual signals acr...
22/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/06/2026
Xilica today announced the release of Dynamic Voice Lift, a new feature in Xilica Designer v4.12 that brings adaptive speech reinforcement to large meeting spac...
22/06/2026
Telecom operators have seen remarkable returns from using generative AI to automate network management, customer care and back-office operations. Most of that i...
22/06/2026
Monday 22 June 2026
Official trailer released for Katie Price: Nothing to Hide,...
22/06/2026
The next era of AI will not be defined by compute alone. Its growth will be dete...
22/06/2026
Mission, Vision and Veritas - new Los Alamos National Laboratory (LANL) supercom...
22/06/2026
At the ISC conference running in Hamburg this week, NVIDIA is introducing new so...
22/06/2026
For the past two years, the U.S. National Science Foundation's National Arti...