GateDrain: Availability Attacks and Admission-Side Defense for Confidence-Gated Edge-Cloud Inference

📅 2026-09-27
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of confidence-based gating mechanisms in edge-cloud inference, where adversarial exploitation can maliciously redirect requests, causing cloud queue congestion and latency spikes. We formally define the availability attack surface targeting confidence routing and introduce GateDrain, an attack that amplifies tail latency. To mitigate this threat, we propose Bounded Escalation, a defense strategy that integrates admission control through a global token bucket budget with non-preemptive priority scheduling. Experimental evaluations demonstrate that this mechanism effectively ensures latency isolation and service stability for authenticated clients. Furthermore, our analysis reveals an inherent trade-off between security guarantees and model accuracy, highlighting critical considerations for deploying robust edge-cloud inference systems under adversarial conditions.
📝 Abstract
Confidence-gated edge--cloud inference accepts confident local predictions and offloads uncertain inputs to a stronger cloud model. We show that this routing decision creates an availability attack surface. We call this attack \emph{GateDrain}: bounded input perturbations lower calibrated confidence and redirect requests that would otherwise be answered locally into a shared cloud queue, without increasing the application request rate. Because escalated requests share a cloud service, an increase in per-request cloud demand can move a near-capacity deployment across a queueing knee, causing disproportionate tail-latency degradation for benign users. We evaluate white-box, transfer, decision-only, universal, and multi-gate attacks on the public EdgeBoost artifact. A fixed-application-volume comparison isolates the effect of confidence manipulation from added client traffic, while perturbation-budget and arrival-process sweeps show that the queueing transition persists across several workload models but its amplification depends on the operating point. Adaptive attacks also defeat the evaluated training-free preprocessing defenses. To contain the resulting cloud demand, we evaluate Bounded Escalation, which combines per-source admission budgets, protected capacity, and non-preemptive trusted-class priority; an optional global bucket adds an identity-independent bound on untrusted admissions. The evaluation makes the resulting policy trade-off explicit: authenticated clients receive latency isolation, whereas tighter aggregate containment can reject legitimate unauthenticated offloads and reduce overall expected accuracy through edge fallback.
Problem

Research questions and friction points this paper is trying to address.

edge-cloud inference
availability attack
confidence gating
tail latency
adversarial perturbation
Innovation

Methods, ideas, or system contributions that make the work stand out.

confidence-gated inference
availability attack
tail latency degradation
admission control
edge-cloud computing
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.