Designing deeper data center defense

In This Story

People Mentioned in This Story
Body

As AI drives rapid growth in data centers, the facilities powering the technology are becoming more complex, more valuable, and potentially more vulnerable to cyberattacks. Two George Mason University researchers want to help close security gaps before attackers can exploit them. 

Kai Zeng and Liling Huang, a professor and associate professor, respectively, in the Department of Electrical and Computer Engineering, are developing new approaches to protect AI data centers from threats ranging from insiders stealing valuable AI models to cyberattacks against the systems controlling a facility’s power and cooling.  

Zeng and Huang received $100,000 from the Virginia Innovation Partnership Authority through the Commonwealth Cyber Initiative Northern Virginia Node for “Defense-in-Depth Cyber-Physical Security for AI Data Centers.” The one-year project examines vulnerabilities that traditional cybersecurity approaches may not fully address, including the increasingly complicated intersection of information technology, operational technology, and building-management systems.  

“It’s a very urgent and emerging topic,” Zeng said. “Just look at how many new AI data centers are built every year, every month.” The issue has particular resonance in Virginia, which has the world’s largest concentration of data center infrastructure and is rapidly becoming a hub for large-scale AI computing.  

AI data centers present new challenges because the systems differ from conventional data centers, Huang said. Operators in traditional facilities have years of experience understanding normal activity, making anomolies easy to identify. With AI infrastructure, that baseline is still developing. 

“With AI data centers, we are still learning about their operational behavior and how it affects both behind-the-meter electrical systems and the broader power grid,” Huang said. “This uncertainty makes cybersecurity more challenging because, when abnormal behavior occurs, it can be difficult to distinguish a cyberattack from a legitimate equipment or power-system issue.” 

The researchers will investigate three areas. One is communication among the clusters of graphics processing units (GPUs) used for AI computing. Their extremely fast connections can make monitoring activity difficult. “It’s harder to monitor the traffic exchange there between the GPUs, which could be a kind of blind spot from a security perspective,” Zeng said.  

Another focus is protecting what’s known as “checkpoints,” snapshots of an AI model’s state created during training. Training a large AI model can take weeks. At intervals, the system saves the model's current state, including what it has learned so far. That saved state is the checkpoint, which can contain valuable intellectual property, making them potential targets for tampering or insider attacks. The researchers plan to explore whether data collected from systems throughout the data center, known as telemetry, can help verify that a checkpoint is authentic. 

The third area involves the boundary between IT systems and operational technology, including systems controlling power and cooling. “Someone does not necessarily have to directly hack into the server, because they can just disrupt the building management system,” Zeng said.  

The project benefits from the researchers’ complementary expertise. Huang explained that cybersecurity practices have traditionally been more mature in information technology systems, while operational technology has emphasized reliability, safety, availability, and engineering performance. Zeng brings cybersecurity expertise, while Huang contributes expertise in AI data centers, electrical and mechanical systems, and the power grid. Together, they will work to strengthen cybersecurity protections for the operational technology systems of AI data centers. 

The team plans to produce a data center threat model, prototype security technologies, experimental results, and at least one peer-reviewed publication. The seed project is also intended to position the researchers for larger federal and industry-funded projects.  

Zeng hopes the initial investment can provide the foundation for something considerably larger. “We can apply later to turn this $100,000 project into, potentially, $1 million,” he said. “Start small, but scale up, and scale big.”