SecDeep: Secure and Performant On-device Deep Learning Inference Framework for Mobile and IoT Devices

SecDeep: Secure and Performant On-device Deep Learning Inference Framework for Mobile and IoT Devices
复制标题

DOI:
10.1145/3450268.3453524
复制
发表时间:
2021-05
期刊:
Proceedings of the International Conference on Internet-of-Things Design and Implementation
影响因子:
--
通讯作者:
Renju Liu;L. Garcia;Zaoxing Liu;Botong Ou;M. Srivastava
Renju Liu;L. Garcia;Zaoxing Liu;Botong Ou;M. Srivastava
中科院分区:
其他
文献类型:
--
作者:
Renju Liu;L. Garcia;Zaoxing Liu;Botong Ou;M. Srivastava

文献摘要

被引文献

相似文献

人们越来越重视保护具有隐私敏感数据的移动的和物联网应用的深度学习(DL)推理管道。先前的工作表明,通过可信执行环境(如英特尔SGX),可以在云卸载模型上的整个深度学习推理过程中保护隐私敏感数据。然而,现有解决方案没有解决在低功率、低存储器设备(例如,移动的和IoT设备),同时实现高性能。为了应对这些挑战,我们提出了SecDeep,这是一个低功耗的DL推理框架,证明了边缘设备上深度学习推理的安全性和性能都在我们的能力范围内。SecDeep利用有限资源的TEE,保证输入和中间数据的完全机密性,以及深度学习模型和框架的完整性。通过启用和保护神经加速器,SecDeep是第一个在物联网和移动的设备上提供可信和高性能DL模型推理的公司。我们通过将ARM NN DL框架与ARM TrustZone接口来实现和验证SecDeep。我们的评估表明,通过利用边缘可用的加速器,我们可以安全地运行推理任务,其性能比没有加速方法快16倍到172倍。
There is an increasing emphasis on securing deep learning (DL) inference pipelines for mobile and IoT applications with privacy-sensitive data. Prior works have shown that privacy-sensitive data can be secured throughout deep learning inferences on cloud-offloaded models through trusted execution environments such as Intel SGX. However, prior solutions do not address the fundamental challenges of securing the resource-intensive inference tasks on low-power, low-memory devices (e.g., mobile and IoT devices), while achieving high performance. To tackle these challenges, we propose SecDeep, a low-power DL inference framework demonstrating that both security and performance of deep learning inference on edge devices are well within our reach. Leveraging TEEs with limited resources, SecDeep guarantees full confidentiality for input and intermediate data, as well as the integrity of the deep learning model and framework. By enabling and securing neural accelerators, SecDeep is the first of its kind to provide trusted and performant DL model inferencing on IoT and mobile devices. We implement and validate SecDeep by interfacing the ARM NN DL framework with ARM TrustZone. Our evaluation shows that we can securely run inference tasks with 16× to 172× faster performance than no acceleration approaches by leveraging edge-available accelerators.