George Mason University develops deeper cybersecurity defences for AI data centres

George Mason University develops deeper cybersecurity defences for AI data centres

George Mason University researchers are developing new cybersecurity approaches to protect AI data centres against threats ranging from the theft of valuable AI models to attacks targeting power, cooling and building management systems.

George Mason University researchers have launched a project exploring how AI data centres can be better protected against emerging cyber and physical security threats.

Kai Zeng, Professor, and Liling Huang, Associate Professor, in the university’s Department of Electrical and Computer Engineering have received US$100,000 from the Virginia Innovation Partnership Authority for the one-year project.

Called Defense-in-Depth Cyber-Physical Security for AI Data Centers, the research will examine vulnerabilities created by the increasingly complex interaction between Information Technology, Operational Technology and building management systems.

Zeng said: “It’s a very urgent and emerging topic. Just look at how many new AI data centers are built every year, every month.”

One challenge is distinguishing malicious activity from legitimate operational problems within relatively new AI infrastructure.

Huang said: “With AI data centers, we are still learning about their operational behaviour and how it affects both behind-the-meter electrical systems and the broader power grid.”

The researchers will concentrate on three areas. The first involves communications between the clusters of graphics processing units used for AI workloads, where extremely high-speed connections can make monitoring network activity difficult.

A second focus will be protecting AI model ‘checkpoints’ – snapshots created during lengthy model training processes. These can contain valuable intellectual property,

potentially making them targets for theft, tampering and malicious insiders. The researchers will investigate whether data centre telemetry can help verify their authenticity.

The third area will examine the boundary between IT and Operational Technology, particularly systems responsible for power and cooling.

“Someone does not necessarily have to directly hack into the server, because they can just disrupt the building management system,” Zeng said.

The team plans to develop a data centre threat model, prototype security technologies and produce experimental results and at least one peer-reviewed research paper. The initial project is also intended to provide a foundation for larger federally and industry-funded research programmes.

Browse our latest issue

Intelligent CISO

View Magazine Archive