arXiv:2411.07114cs.CRcs.LG2024-11被引 16

首份系统梳理资源受限设备的机器学习安全漏洞。

TinyML Security: Exploring Vulnerabilities in Resource-Constrained Machine Learning Systems

  • 区分物联网、边缘计算与微型机器学习,聚焦其独特风险
  • 识别侧信道攻击等多类威胁,评估其严重等级
  • 呼吁定制化安全方案,适合研究者与开发者参考

微型机器学习(TinyML)系统使在资源极度受限的设备上实现机器学习推理成为可能,正推动边缘计算变革,但面临独特的安全挑战。这些设备的内存和处理器能力仅为传统系统的二至三个数量级,导致传统软硬件安全方案难以适用。设备物理可访问性进一步加剧了对侧信道攻击和信息泄露的脆弱性。此外,TinyML模型本身也存在安全隐患,权重可能包含敏感数据,查询接口也可能被滥用。本文首次全面综述了TinyML的安全威胁。我们提出一个设备分类体系,区分物联网、边缘机器学习与TinyML,揭示其独有的漏洞。列出多种攻击向量,利用通用漏洞评分系统(CVSS)评估威胁等级,并分析现有及潜在防御措施。我们的分析表明,在某些场景下传统安全手段仍有效,但在多数情况下亟需专为TinyML设计的解决方案。研究结果强调了为确保边缘计算应用的鲁棒性和安全性,迫切需要针对性的安全机制。我们旨在为研究界提供参考,激发对该快速演进且关键领域的创新保护思路。

原文摘要 · Abstract (English)

Tiny Machine Learning (TinyML) systems, which enable machine learning inference on highly resource-constrained devices, are transforming edge computing but encounter unique security challenges. These devices, restricted by RAM and CPU capabilities two to three orders of magnitude smaller than conventional systems, make traditional software and hardware security solutions impractical. The physical accessibility of these devices exacerbates their susceptibility to side-channel attacks and information leakage. Additionally, TinyML models pose security risks, with weights potentially encoding sensitive data and query interfaces that can be exploited. This paper offers the first thorough survey of TinyML security threats. We present a device taxonomy that differentiates between IoT, EdgeML, and TinyML, highlighting vulnerabilities unique to TinyML. We list various attack vectors, assess their threat levels using the Common Vulnerability Scoring System, and evaluate both existing and possible defenses. Our analysis identifies where traditional security measures are adequate and where solutions tailored to TinyML are essential. Our results underscore the pressing need for specialized security solutions in TinyML to ensure robust and secure edge computing applications. We aim to inform the research community and inspire innovative approaches to protecting this rapidly evolving and critical field.

TinyML安全边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。