EdgeThemis: Ensuring Model Integrity for Edge Intelligence
Jiyu Yang, Qiang He, Zheyu Zhou, Xiaohai Dai, Feifei Chen, Cong Tian, Yun Yang
Abstract
Machine learning (ML) models are widely deployed on edge nodes, such as mobile phones and edge servers, to power a wide range of AI applications over the web. Ensuring the integrity of these edge models is paramount, as they are subject to corruption caused by software/hardware exceptions and malicious tampering, which may undermine model performance, incur economic losses, and pose health risks. Existing data integrity mechanisms designed for files stored on disks cannot properly verify the integrity of models running in GPUs or mitigate the new integrity threats against edge models. This paper proposes EdgeThemis, a novel mechanism for verifying the integrity of edge models through sentinel verification. To enable verifiability for a model 𝑀, EdgeThemis embeds a sentinel backdoor and a verification module into 𝑀. Then, a challenger can send verification requests to the edge node hosting 𝑀 to verify its integrity. Next, the sentinel activates the verification module to generate a unique integrity proof tied to the identity of the edge node for verification. Finally, the challenger can verify the integrity proof to detect model corruption. Theoretical analysis proves that Ed-geThemis can properly mitigate potential integrity threats against edge models. Experiments demonstrate that EdgeThemis achieves a verification accuracy of 100.00% across various models and different types of model corruption with robustness against replay attacks, theft attacks, and replacement attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8830719f-28c4-417d-820f-27e5e76c843bBuilds on10
- MobileViT: Light-weight, General-purpose, and Mobile-friendly Vision TransformerSachin Mehta, Mohammad RastegariICLR 2022 · 2,162 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Deep Neural Network Fingerprinting by Conferrable Adversarial ExamplesNils Lukas, Yuxuan Zhang, Florian KerschbaumICLR 2021 · 182 citations
- SwapAdvisor: Pushing Deep Learning Beyond the GPU Memory Limit via Smart SwappingChien-Chin Huang, Gu Jin, Jinyang LiASPLOS 2020 · 161 citations
Related papers
- TransLinkGuard: Safeguarding Transformer Models Against Model Stealing in Edge DeploymentQinfeng Li, Zhiqiang Shen, Zhenghan Qin, Yangfan Xie et al.ACM MM 2024 · 9 citations
- THEMIS: Towards Practical Intellectual Property Protection for Post-Deployment On-Device Deep Learning ModelsYujin Huang, Zhi Zhang, Qingchuan Zhao, Xingliang Yuan et al.USENIX Security 2025
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
- Sentry: Authenticating Machine Learning Artifacts on the FlyAndrew Gan, Zahra GhodsiCCS 2025
- Integrity Authentication in Tree ModelsWeijie Zhao, Yingjie Lao, Ping LiKDD 2022 · 3 citations
