Protecting CPU AI On Edge TEEs: WebAssembly's Promise and Practical Challenges
Friedrich Vandenberghe, Lachlan Gunn, Bruno Volckaert, Merlijn Sebrechts
Abstract
AI models on edge hardware contain important intellectual property (IP), but an adversary can steal it when they achieve root access. Trusted Execution Environments (TEE) like Arm TrustZone protect against these Operating System (OS) level attacks. However, they are challenging to use. More precisely, it is difficult to run unaltered applications inside a TEE. This work presents a solution that allows the execution of unaltered AI models, compiled to WebAssembly, on the WebAssembly Micro Runtime (WAMR) in OP-TEE for Arm TrustZone. Additionally, this work provides an AI model distributor that encrypts the WebAssembly binary and places the encryption key in one of the device's fuses. This way, only the WAMR Trusted Application (TA) in OP-TEE can decrypt and execute the AI model. A thorough evaluation of our solution shows that it incurs an additional overhead of 22% in comparison to an application manually ported to OP-TEE, while also facilitating the execution of unaltered AI models with an additional inference latency of 6% without significant porting effort. Overall, there is a pressing need to safeguard the IP of AI models and this work shows that there is a real promise in WebAssembly, but there remain some practical challenges.
Create a lesson
Related papers
From Reactive Containment to Proactive Assurance: Lessons from OpenAI, Anthropic, and Google Agent Security Incidents
Abbas Raftari
ORCAGen: Orchestrating Context-Aware Malware Deception with RAG-Guided Generative AI
Shihab Ahmed, Md Sajidul Islam Sajid, Teryl Taylor et al.
ReSI: Recursive Safety Improvement toward Resistant and Resilient AI
Jingnan Zheng, Dongcheng Zhang, Yi Zhang et al.
One Node, Two Roles: Simultaneous Contests for Validation and Attention in Rollups
Pranay Anchuri, Ben Berger, Matteo Campanelli et al.
Poster: A Preliminary Study of LLM Distillation Inference
Edward Chen, Yuntao Du
Could LLM Watermark Detection be Public?
Georgios Milis, Tom Sander, Tomáš Souček et al.