信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1277-1289.doi: 10.3969/j.issn.1671-1122.2026.08.009

• 学术研究 • 上一篇    下一篇

基于国密算法的边缘AI模型安全加载机制研究

谢雪松(), 蔡佳凯, 罗柏之   

  1. 北京工业大学信息科学技术学院北京 100124
  • 收稿日期:2025-12-12 出版日期:2026-08-10 发布日期:2026-09-23
  • 通讯作者: 谢雪松 E-mail:xiexuesong@bjut.edu.cn
  • 作者简介:谢雪松(1970—),男,北京,副教授,博士,主要研究方向为人工智能、可信计算|蔡佳凯(2000—),男,河北,硕士研究生,主要研究方向为嵌入式系统AI应用|罗柏之(2000—),男,北京,硕士研究生,主要研究方向为硬件可信计算
  • 基金资助:
    国家自然科学基金(61973010)

Secure model loading mechanism for edge AI based on Chinese commercial cryptography

Xie Xuesong(), Cai Jiakai, Luo Baizhi   

  1. School of Information Science and Technology, Beijing University of Technology, Beijing 100124, China
  • Received:2025-12-12 Online:2026-08-10 Published:2026-09-23
  • Contact: Xie Xuesong E-mail:xiexuesong@bjut.edu.cn

摘要:

随着人工智能技术向边缘端下沉,边缘AI系统在智慧城市、工业互联网、自动驾驶等关键场景中广泛应用。然而,现有边缘AI系统在模型分发与加载过程中缺乏端到端的安全保障机制,面临模型窃取、篡改、中间人攻击等安全挑战,严重威胁知识产权安全与系统可信性。针对上述问题,文章提出一种基于国密算法的嵌入式安全加载机制,通过在FPGA可编程逻辑中实现国密协处理器,将完整性校验与机密性保护深度嵌入AI模型加载全流程,确保模型从分发、验证到执行的全过程可信可控。系统采用Zynq-7020与Orange Pi AI Pro联合架构,在保障高性能推理的同时满足国产密码合规要求,并完成Zynq-7020可被国产FPGA替代验证,AI处理器选用昇腾310以契合信创生态。实验结果表明,该机制在典型边缘AI模型上实现无损推理精度,且硬件资源开销可控,为构建自主可控、安全可信的边缘智能基础设施提供了切实可行的技术路径。

关键词: 边缘AI, 端到端安全, 国密算法, 信创, 异构计算

Abstract:

With the migration of artificial intelligence technologies to the edge, edge AI systems have been widely deployed in critical scenarios such as smart cities, industrial internet, and autonomous driving. However, existing edge AI platforms lack end-to-end security mechanisms during model distribution and loading, exposing them to severe threats including model stealing, tampering, and man-in-the-middle attacks—posing significant risks to intellectual property protection and system trustworthiness. To address this issue, this paper proposed an embedded secure model loading mechanism based on Chinese national cryptographic algorithms. By implementing a dedicated SM3/SM4 co-processor in the programmable logic of an FPGA, the mechanism deeply integrated integrity verification and confidentiality protection into the entire AI model loading pipeline, ensuring trustworthy and controllable model handling from distribution and validation to execution. The system adopted a heterogeneous architecture combining Zynq-7020 and Orange Pi AI Pro, achieving high-performance inference while complying with China’s commercial cryptography regulations. Moreover, this paper validated the feasibility of domestic substitution: the Zynq-7020 can be replaced by domestically developed FPGAs, and the Ascend 310, selected for its alignment with the Information Technology Application Innovation (ITAI) ecosystem. Experimental results demonstrate that the proposed mechanism preserves original inference accuracy on representative edge AI models, with manageable hardware resource overhead, offering a practical and viable technical pathway toward building autonomous, secure, and trustworthy edge intelligence infrastructure.

Key words: edge AI, end-to-end security, Chinese national cryptographic algorithms, information technology application innovation, heterogeneous computing

中图分类号: