arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

TERMon:通过硬件原生三元运行时监视器检测边缘AI中的持续性行为威胁

TERMon: Detecting Persistent Behavioral Threats in Edge AI via Hardware-Native Ternary Runtime Monitor

Arish Sateesan, Edlira Dushku

arXiv 2609.21713首次发表:更新:

发表机构

Aalborg University(奥尔堡大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

TERMon是一种轻量级硬件运行时监视器,通过三元模式匹配观察推理行为,检测边缘AI中的持续性行为威胁,无需重新执行模型,在FPGA上实现两周期决策延迟。

AI 中文摘要

边缘AI加速器日益部署在安全关键环境中,在这些环境中,模型输出可能控制物理执行器、做出访问控制决策或触发警报。在这些场景下,运行时故障往往未被检测到,因为模型损坏、分布偏移和对抗性输入仍可能产生格式良好且置信度高的预测。本文提出了TERMon,一种轻量级硬件运行时监视器,通过观察推理行为而非重新执行或正式验证模型来检测此类异常。TERMon将类条件可信行为表示为硬件高效的三元模式,并与基于温度计编码的指纹并行匹配。三元编码精确复现了相应的未量化范围决策。TERMon能够根据行为影响程度检测有害的权重损坏,而在严格假阳性工作点下,分布外输入和对抗性输入在很大程度上无法通过所监视的特征进行区分。我们在PYNQ-Z2 FPGA上实现了TERMon,其流水线设计无需片上块RAM或DSP,且决策延迟仅为两个时钟周期。

英文摘要

Edge AI accelerators are increasingly deployed in safety-critical environments, where model outputs may control physical actuators, make access-control decisions, or trigger alarms. In these settings, runtime failures often remain undetected because model corruption, distribution shift, and adversarial inputs can still produce well-formed, confident predictions. This paper presents TERMon, a lightweight hardware runtime monitor that detects such anomalies by observing inference behavior rather than re-executing or formally verifying the model. TERMon represents class-conditional trusted behavior as hardware-efficient ternary patterns that are matched in parallel against a thermometer-encoded fingerprint. The ternary encoding reproduces the corresponding unquantized range decision exactly. TERMon detects harmful weight corruptions in proportion to their behavioral impact, while out-of-distribution and adversarial inputs are largely not separable using the monitored features at a strict false-positive operating point. We implemented TERMon on a PYNQ-Z2 FPGA, and the pipelined design requires no on-chip block RAM or DSPs and has a two-cycle decision latency.

DOI:10.1145/3847352.3848113

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑