Security/ ai · security · jailbreaks · edge-ai

New Defense Uses In-Memory Chips to Guard Compressed AI Models

Researchers built MOMAT, a compute-in-memory defense that blocks jailbreak attempts on quantized edge AI models while cutting power and latency sharply.

A chip-assisted guardrail system aims to stop stripped-down AI models from being talked into bad behavior, without draining a device's battery.

Researchers built MOMAT, short for Mixture of Multiple Atlases, to defend quantized large language models, the compressed versions of AI models that run on phones, routers, and other edge hardware. Quantization shrinks a model's memory footprint but also weakens its built-in safety training, making it easier to jailbreak. MOMAT groups known harmful and benign prompts into semantic clusters called atlases, checks each new prompt against all of them with a lightweight mixture-of-experts detector, and runs that pattern-matching on compute-in-memory chips that calculate directly where data is stored instead of shuttling it to a separate processor. In testing, that hardware cut the time to screen a 100-prompt batch from about 15 seconds to roughly 3,200 nanoseconds, and cut the energy cost by roughly a quarter-million times compared with a Raspberry Pi doing the same checks from DRAM.

Cloud-based moderation does not work for AI running inside a smart speaker or a car with patchy signal. If on-device models need their own safety checks, those checks have to be fast and cheap enough to not blow through a battery budget. MOMAT's red-team results suggest it matches established jailbreak defenses without the usual trade-off of over-blocking harmless prompts.

These are lab numbers from a new paper, not a shipped product, and the promised 223,200-sample dataset is not public yet, so outside verification will have to wait.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →