Protecting CPU AI On Edge TEEs: WebAssembly's Promise and Practical Challenges

📅 2026-10-08
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of AI models on edge devices to OS-level attacks and the difficulty of porting them to Trusted Execution Environments (TEEs). To overcome these challenges, this work proposes a WebAssembly-based, port-free secure execution framework. By leveraging WAMR and OP-TEE, the approach enables unmodified native AI models to execute directly within Arm TrustZone, thereby protecting intellectual property. Furthermore, a hardware fuse-based encrypted distribution mechanism is integrated to enhance security. Experimental results demonstrate that, compared with manual porting solutions, the proposed framework incurs only a 22% increase in system overhead and a 6% rise in inference latency. This work significantly lowers development barriers while achieving efficient and reliable model protection for edge AI deployments.
📝 Abstract
AI models on edge hardware contain important intellectual property (IP), but an adversary can steal it when they achieve root access. Trusted Execution Environments (TEE) like Arm TrustZone protect against these Operating System (OS) level attacks. However, they are challenging to use. More precisely, it is difficult to run unaltered applications inside a TEE. This work presents a solution that allows the execution of unaltered AI models, compiled to WebAssembly, on the WebAssembly Micro Runtime (WAMR) in OP-TEE for Arm TrustZone. Additionally, this work provides an AI model distributor that encrypts the WebAssembly binary and places the encryption key in one of the device's fuses. This way, only the WAMR Trusted Application (TA) in OP-TEE can decrypt and execute the AI model. A thorough evaluation of our solution shows that it incurs an additional overhead of 22% in comparison to an application manually ported to OP-TEE, while also facilitating the execution of unaltered AI models with an additional inference latency of 6% without significant porting effort. Overall, there is a pressing need to safeguard the IP of AI models and this work shows that there is a real promise in WebAssembly, but there remain some practical challenges.
Problem

Research questions and friction points this paper is trying to address.

Edge AI
Intellectual Property Protection
Trusted Execution Environment
WebAssembly
Arm TrustZone
Innovation

Methods, ideas, or system contributions that make the work stand out.

Trusted Execution Environment
WebAssembly
Arm TrustZone
AI Model Protection
OP-TEE
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.