


< Professor Jun Han >
From smartphone facial recognition to autonomous vehicles, Artificial Intelligence (AI) has long been protected as a "black box." However, a joint research team from KAIST and international institutions has uncovered a new security threat capable of "peeking" at AI blueprints from behind walls. The team also presented corresponding defense technologies. This discovery is expected to be utilized in strengthening AI security across various sectors, including autonomous driving, healthcare, and finance.
On the 31st, Professor Jun Han’s research team from the KAIST School of Computing announced that they, in collaboration with the National University of Singapore (NUS) and Zhejiang University, developed "ModelSpy"—an attack system capable of hijacking AI model structures from a distance using only a small antenna.
This technology works much like a bugging device, capturing and analyzing minute signals emitted while an AI is operational to reconstruct its internal structure. The research team focused on the electromagnetic (EM) waves generated by Graphics Processing Units (GPUs), which handle AI computations.
When an AI performs complex calculations, the GPU emits subtle electromagnetic signals. By analyzing the patterns of these signals, the team successfully restored the layer configurations and detailed parameter settings of the AI model.
Experimental results showed that the structure of AI models could be identified with high accuracy from up to 6 meters away or through walls, across five types of the latest GPUs. Notably, the team estimated the core structure—the layers of the deep learning model—with an accuracy of up to 97.6%.

< AI model structures can be stolen through walls using an antenna hidden in a bag >
This technology is considered a significant security threat because, unlike traditional hacking, it does not require direct server infiltration or malware installation. An attack can be carried out using only a portable antenna small enough to fit in a bag.
Recognizing that this technology could lead to the leakage of a company's core AI assets, the research team also proposed defensive measures, such as electromagnetic interference and computational obfuscation. This is being hailed as a responsible security study that goes beyond demonstrating an attack to suggesting realistic protection methods.
"This research demonstrates that AI systems can be exposed to new types of attacks even in physical environments," said Professor Jun Han. "To protect critical AI infrastructure, such as autonomous driving and national facilities, it is essential to establish 'cyber-physical security' systems that encompass both hardware and software."

< Research Image (AI-generated) >
Professor Jun Han of the KAIST School of Computing participated as a co-corresponding author. The study was presented at the NDSS (Network and Distributed System Security Symposium) 2026, a top-tier academic conference in computer security, where it received the Distinguished Paper Award in recognition of its innovation.
Paper Title: Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-Chan
For more than a century, Organic Syntheses has served as a unique platform beyond conventional peer reviewed journal: before publishing a procedure, its editors personally repeat the experiment in their laboratory to confirm that another chemist's submitted method actually works as reported. Professor Sunkyu Han from KAIST’s Department of Chemistry has now become the first Korean chemist elected as a member of the Board of Editors of Organic Syntheses. KAIST (President Choongsik Bae) an
2026-09-11A future in which AI can recognize a person’s unspoken “that’s not what I meant” response from brain signals and adjust its behavior on its own is coming closer. KAIST researchers have developed a technology that detects cognitive mismatch between humans and AI through brainwaves, enabling AI systems to revise their actions in real time according to human goals. The achievement is expected to accelerate the shift from AI that follows explicit commands to AI that can inf
2026-09-10KAIST (President Choongsik Bae) announced on September 9 that, representing K-STAR, a consortium comprising KAIST, GIST, DGIST, UNIST, and POSTECH, it signed a memorandum of understanding (MOU) with Université Paris-Saclay on September 7 to strengthen research cooperation. The signing ceremony took place at Bâtiment Bréguet on the university’s campus. The agreement was concluded on the occasion of President Lee Jae-myung’s state visit to France. It follows up o
2026-09-09Immune cells can become exhausted after prolonged exposure to cancer, gradually losing their ability to attack tumor cells. This phenomenon is particularly pronounced in aggressive brain tumors and can severely limit the effectiveness of immunotherapy. A KAIST research team has now discovered that all-trans retinoic acid (ATRA), a vitamin A derivative, may help prevent such exhaustion and enhance the efficacy of immune checkpoint inhibitors. KAIST (President Choongsik Bae) announced on Septem
2026-09-08A signal that appears to show ions moving inside a battery may, in fact, be an illusion caused by an uneven surface. A KAIST research team has identified the origin of this type of artifacts, which can lead researchers to misinterpret what is happening inside a battery, and has developed a method to reduce it. The findings are expected to enable more accurate analysis of ion movement and improve the reliability of next-generation battery-material development, including that of solid-state and
2026-09-07