发表机构
North Carolina State University; Binghamton University (SUNY); Florida International University; Intel(北卡罗来纳州立大学; 宾汉姆顿大学(纽约州立大学系统); 佛罗里达国际大学; 英特尔公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出TEE-X框架,在Arm TrustZone的OP-TEE上验证,可在NVIDIA Jetson AGX Xavier上实现大视觉模型的安全高效边缘推理,兼顾性能与安全性。
AI 中文摘要
尽管机器学习模型,尤其是视觉应用领域的模型已取得显著成功,但它们极易受到各类安全威胁,这一状况令人担忧。攻击场景中的一个关键因素是白盒与黑盒威胁模型的区别,后者在无法获取模型信息时会限制攻击的有效性,带来诸多挑战。因此,使用可信执行环境(TEE)可通过保护模型机密性与执行完整性提升机器学习应用的安全性,有效将执行环境从威胁模型谱的白盒侧转移至黑盒侧。尽管将TEE应用于大视觉模型(如视觉Transformer(ViT))对提升安全性与隐私性至关重要,但必须解决内存限制与计算延迟增加的重大挑战,尤其在安全性和隐私性至关重要的时间敏感型边缘应用中。本研究的目标是使大视觉模型完全部署在TEE内,在保持性能的同时,为时间敏感型边缘视觉应用实现GPU级别的推理延迟。为此,我们提出TEE-X,这是一种感知TEE的加速框架,引入了感知灵敏度的模块化技术,并支持TEE推理中的向量化。该设计在Arm TrustZone的OP-TEE上进行验证,配置为在NVIDIA Jetson AGX Xavier上优化性能,以使用ViT模型实现高效的边缘视觉应用。研究结果表明,TEE-X是一种有效的感知TEE加速框架,在确保视觉模型快速安全的边缘推理的同时,实现了最小的精度-延迟权衡。
英文摘要
Despite their remarkable success, machine learning models, particularly in vision applications, are alarmingly vulnerable to a range of security threats. One key factor in the attack landscape is the distinction between white-box and black-box threat models, as the latter poses challenges that limit attack effectiveness when access to model information is limited. As a result, using Trusted Execution Environments (TEEs) enhances security for machine learning applications by protecting model confidentiality and execution integrity, effectively shifting the execution environment from the white-box to the black-box side of the threat model spectrum. While adopting TEEs for large vision models, e.g., Vision Transformers (ViTs), is crucial for enhancing security and privacy, significant challenges related to memory constraints and increased computational latency must be addressed, especially in time-sensitive edge applications where safety and privacy are paramount. The objective of this work is to enable large vision models to be fully hosted within TEEs, achieving GPU-level inference latency for time-sensitive edge vision applications while maintaining performance. To this end, we propose TEE-X, a TEE-aware acceleration framework that introduces a sensitivity-aware modularization technique and enables vectorization in TEE inference. This design is validated on OP-TEE for Arm TrustZone, configured to optimize performance on the NVIDIA Jetson AGX Xavier for efficient edge vision applications using ViT models. The findings reveal that TEE-X delivers an effective TEE-aware acceleration framework that achieves minimal accuracy-latency trade-offs while ensuring fast and secure edge inference for vision models.