{"id":"https://openalex.org/W4411091738","doi":"https://doi.org/10.1145/3713082.3730391","title":"Guillotine: Hypervisors for Isolating Malicious AIs","display_name":"Guillotine: Hypervisors for Isolating Malicious AIs","publication_year":2025,"publication_date":"2025-05-14","ids":{"openalex":"https://openalex.org/W4411091738","doi":"https://doi.org/10.1145/3713082.3730391"},"language":"en","primary_location":{"id":"doi:10.1145/3713082.3730391","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3713082.3730391","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3713082.3730391","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Workshop on Hot Topics in Operating Systems","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3713082.3730391","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020094804","display_name":"James Mickens","orcid":"https://orcid.org/0009-0007-7296-5185"},"institutions":[{"id":"https://openalex.org/I2801851002","display_name":"Harvard University Press","ror":"https://ror.org/006v7bf86","country_code":"US","type":"other","lineage":["https://openalex.org/I136199984","https://openalex.org/I2801851002"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"James Mickens","raw_affiliation_strings":["Harvard University"],"raw_orcid":"https://orcid.org/0009-0007-7296-5185","affiliations":[{"raw_affiliation_string":"Harvard University","institution_ids":["https://openalex.org/I2801851002"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009521922","display_name":"Sarah Radway","orcid":"https://orcid.org/0000-0003-2071-6682"},"institutions":[{"id":"https://openalex.org/I2801851002","display_name":"Harvard University Press","ror":"https://ror.org/006v7bf86","country_code":"US","type":"other","lineage":["https://openalex.org/I136199984","https://openalex.org/I2801851002"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sarah Radway","raw_affiliation_strings":["Harvard University"],"raw_orcid":"https://orcid.org/0000-0003-2071-6682","affiliations":[{"raw_affiliation_string":"Harvard University","institution_ids":["https://openalex.org/I2801851002"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5053593890","display_name":"Ravi Netravali","orcid":"https://orcid.org/0000-0001-7002-5033"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ravi Netravali","raw_affiliation_strings":["Princeton University"],"raw_orcid":"https://orcid.org/0000-0001-7002-5033","affiliations":[{"raw_affiliation_string":"Princeton University","institution_ids":["https://openalex.org/I20089843"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.054033,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"18","last_page":"26"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.978600025177002,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.9332185983657837},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.686339259147644},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.5613841414451599},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.462239533662796},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.1819348931312561},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.08330875635147095}],"concepts":[{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.9332185983657837},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.686339259147644},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5613841414451599},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.462239533662796},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.1819348931312561},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.08330875635147095}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3713082.3730391","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3713082.3730391","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3713082.3730391","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Workshop on Hot Topics in Operating Systems","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3713082.3730391","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3713082.3730391","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3713082.3730391","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Workshop on Hot Topics in Operating Systems","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4411091738.pdf","grobid_xml":"https://content.openalex.org/works/W4411091738.grobid-xml"},"referenced_works_count":23,"referenced_works":["https://openalex.org/W1422551096","https://openalex.org/W2136310957","https://openalex.org/W2149886445","https://openalex.org/W2151182669","https://openalex.org/W2750779823","https://openalex.org/W2889103500","https://openalex.org/W2902935532","https://openalex.org/W2915352631","https://openalex.org/W3204623540","https://openalex.org/W4230035909","https://openalex.org/W4247476895","https://openalex.org/W4319453721","https://openalex.org/W4366850566","https://openalex.org/W4386231251","https://openalex.org/W4389984066","https://openalex.org/W4391591671","https://openalex.org/W4402683971","https://openalex.org/W4403851184","https://openalex.org/W4405468136","https://openalex.org/W6600210674","https://openalex.org/W6604553253","https://openalex.org/W6608648704","https://openalex.org/W6611608239"],"related_works":["https://openalex.org/W1973516247","https://openalex.org/W4241166160","https://openalex.org/W2796290234","https://openalex.org/W2799095291","https://openalex.org/W2470663080","https://openalex.org/W1965252149","https://openalex.org/W3127457055","https://openalex.org/W2519314911","https://openalex.org/W378416953","https://openalex.org/W3133357914"],"abstract_inverted_index":{"As":[0],"AI":[1,36,78,134,207],"models":[2],"become":[3],"more":[4,129,157],"embedded":[5],"in":[6,194],"critical":[7],"sectors":[8],"like":[9],"finance,":[10],"healthcare,":[11],"and":[12,110,115,128,146,166,199,204],"the":[13,66,87,107,111,120,143,182],"military,":[14],"their":[15],"inscrutable":[16],"behavior":[17],"poses":[18],"ever-greater":[19],"risks":[20],"to":[21,47,64,81,91,123,135],"society.":[22],"To":[23],"mitigate":[24],"this":[25],"risk,":[26],"we":[27],"propose":[28],"Guillotine,":[29],"a":[30,76,100,149,185,189,205],"hypervisor":[31,84,102,108,121,151],"architecture":[32],"for":[33,133],"sandboxing":[34],"powerful":[35],"models---models":[37],"that,":[38],"by":[39,71],"accident":[40],"or":[41,86,181,213],"malice,":[42],"can":[43],"generate":[44],"existential":[45],"threats":[46],"humanity.":[48],"Although":[49],"Guillotine":[50,56,101,150],"borrows":[51],"some":[52],"well-known":[53],"virtualization":[54],"techniques,":[55],"must":[57,152,208],"also":[58,153],"introduce":[59],"fundamentally":[60],"new":[61],"isolation":[62,141,201],"mechanisms":[63,132],"handle":[65],"unique":[67],"threat":[68],"model":[69],"posed":[70],"existential-risk":[72],"AIs.":[73],"For":[74],"example,":[75],"rogue":[77,190,206],"may":[79],"try":[80],"introspect":[82],"upon":[83],"software":[85,109],"underlying":[88],"hardware":[89],"substrate":[90],"enable":[92],"later":[93],"subversion":[94],"of":[95,106,169,178,184],"that":[96,118],"control":[97],"plane;":[98],"thus,":[99],"requires":[103],"careful":[104],"co-design":[105],"CPUs,":[112],"RAM,":[113],"NIC,":[114],"storage":[116],"devices":[117],"support":[119],"software,":[122,144,197],"thwart":[124],"side":[125],"channel":[126],"leakage":[127],"generally":[130],"eliminate":[131],"exploit":[136],"reflection-based":[137],"vulnerabilities.":[138],"Beyond":[139],"such":[140],"at":[142],"network,":[145,198],"microarchitectural":[147,200],"layers,":[148],"provide":[154,192],"physical":[155],"fail-safes":[156],"commonly":[158],"associated":[159],"with":[160],"nuclear":[161],"power":[162],"plants,":[163],"avionic":[164],"platforms,":[165],"other":[167],"types":[168],"mission-critical":[170],"systems.":[171],"Physical":[172],"fail-safes,":[173],"e.g.,":[174],"involving":[175],"electromechanical":[176],"disconnection":[177],"network":[179],"cables,":[180],"flooding":[183],"datacenter":[186],"which":[187],"holds":[188],"AI,":[191],"defense":[193],"depth":[195],"if":[196],"is":[202],"compromised":[203],"be":[209],"temporarily":[210],"shut":[211],"down":[212],"permanently":[214],"destroyed.":[215]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
