arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

保护边缘TEE上的CPU AI:WebAssembly的前景与实际挑战

Protecting CPU AI On Edge TEEs: WebAssembly's Promise and Practical Challenges

Friedrich Vandenberghe, Lachlan Gunn, Bruno Volckaert, Merlijn Sebrechts

arXiv 2610.12050首次发表:更新:

发表机构

Ghent University - imec; Aalto University(根特大学-艾梅克研究所; 阿尔托大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对边缘TEE上AI模型IP易遭窃取的问题,提出基于WebAssembly和WAMR在OP-TEE中运行未修改AI模型的方案,评估显示其开销与延迟可控,具有应用前景但仍存挑战。

AI 中文摘要

边缘硬件上的AI模型包含重要知识产权(IP),但攻击者在获得root权限后可窃取这些IP。Arm TrustZone等可信执行环境(TEE)可防范操作系统(OS)层面的攻击,不过其使用难度较大,更确切地说,在TEE内部运行未修改的应用程序十分困难。本研究提出一种解决方案,该方案可将AI模型编译为WebAssembly格式,在Arm TrustZone的OP-TE中通过WebAssembly微运行时(WAMR)执行未修改的AI模型。此外,本研究还提供了一个AI模型分发器,该分发器会对WebAssembly二进制文件进行加密,并将加密密钥存储在设备的某一熔丝位中,如此一来,仅OP-TEE中的WAMR可信应用(TA)能够解密并执行AI模型。对该解决方案的全面评估显示,与手动移植到OP-TEE的应用相比,本方案会产生22%的额外开销,同时在无需大量移植工作的情况下,可实现未修改AI模型的执行,且额外推理延迟为6%。总体而言,保护AI模型IP的需求十分迫切,本研究表明WebAssembly具有切实的应用前景,但仍存在一些实际挑战。

英文摘要

AI models on edge hardware contain important intellectual property (IP), but an adversary can steal it when they achieve root access. Trusted Execution Environments (TEE) like Arm TrustZone protect against these Operating System (OS) level attacks. However, they are challenging to use. More precisely, it is difficult to run unaltered applications inside a TEE. This work presents a solution that allows the execution of unaltered AI models, compiled to WebAssembly, on the WebAssembly Micro Runtime (WAMR) in OP-TEE for Arm TrustZone. Additionally, this work provides an AI model distributor that encrypts the WebAssembly binary and places the encryption key in one of the device's fuses. This way, only the WAMR Trusted Application (TA) in OP-TEE can decrypt and execute the AI model. A thorough evaluation of our solution shows that it incurs an additional overhead of 22% in comparison to an application manually ported to OP-TEE, while also facilitating the execution of unaltered AI models with an additional inference latency of 6% without significant porting effort. Overall, there is a pressing need to safeguard the IP of AI models and this work shows that there is a real promise in WebAssembly, but there remain some practical challenges.

Comments8 pages, 5 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑