arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GateDrain:针对置信度门控边缘-云推理的可用性攻击与准入侧防御

GateDrain: Availability Attacks and Admission-Side Defense for Confidence-Gated Edge-Cloud Inference

Zonghua Gu, Julian Singh-Smith, Junlin Liao, Di Liu

arXiv 2609.33992首次发表:更新:

发表机构

Hofstra University; Norwegian University of Science and Technology(霍夫斯特拉大学; 挪威科技大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

GateDrain揭示置信度门控边缘-云推理的可用性漏洞,通过扰动降低置信度将请求重定向至云队列造成延迟恶化,并提出结合准入预算与优先级的Bounded Escalation防御策略。

AI 中文摘要

置信度门控的边缘-云推理接受高置信度的本地预测,并将不确定的输入卸载到更强的云端模型。我们表明,这种路由决策产生了一个可用性攻击面。我们将此攻击称为GateDrain:有界的输入扰动会降低校准后的置信度,并将原本会在本地回答的请求重定向到共享的云端队列,而不增加应用程序的请求速率。由于升级的请求共享云服务,每请求云需求的增加可能使接近容量的部署越过排队拐点,导致良性用户的尾部延迟不成比例地恶化。我们在公开的EdgeBoost工件上评估了白盒、迁移、仅决策、通用和多门攻击。固定应用请求量的比较隔离了置信度操纵与额外客户端流量的影响,而扰动预算和到达过程扫描表明,排队转变在多种工作负载模型下持续存在,但其放大效应取决于工作点。自适应攻击也击败了所评估的免训练预处理防御。为了控制由此产生的云需求,我们评估了有界升级(Bounded Escalation),它结合了每源准入预算、受保护容量和非抢占式可信类优先级;一个可选的全局桶增加了对不可信准入的身份无关限制。评估使由此产生的策略权衡变得明确:经过身份验证的客户端获得延迟隔离,而更严格的整体遏制可能拒绝合法的未认证卸载,并通过边缘回退降低整体预期准确性。

英文摘要

Confidence-gated edge--cloud inference accepts confident local predictions and offloads uncertain inputs to a stronger cloud model. We show that this routing decision creates an availability attack surface. We call this attack \emph{GateDrain}: bounded input perturbations lower calibrated confidence and redirect requests that would otherwise be answered locally into a shared cloud queue, without increasing the application request rate. Because escalated requests share a cloud service, an increase in per-request cloud demand can move a near-capacity deployment across a queueing knee, causing disproportionate tail-latency degradation for benign users. We evaluate white-box, transfer, decision-only, universal, and multi-gate attacks on the public EdgeBoost artifact. A fixed-application-volume comparison isolates the effect of confidence manipulation from added client traffic, while perturbation-budget and arrival-process sweeps show that the queueing transition persists across several workload models but its amplification depends on the operating point. Adaptive attacks also defeat the evaluated training-free preprocessing defenses. To contain the resulting cloud demand, we evaluate Bounded Escalation, which combines per-source admission budgets, protected capacity, and non-preemptive trusted-class priority; an optional global bucket adds an identity-independent bound on untrusted admissions. The evaluation makes the resulting policy trade-off explicit: authenticated clients receive latency isolation, whereas tighter aggregate containment can reject legitimate unauthenticated offloads and reduce overall expected accuracy through edge fallback.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑