Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1277-1289.doi: 10.3969/j.issn.1671-1122.2026.08.009

Previous Articles     Next Articles

Secure model loading mechanism for edge AI based on Chinese commercial cryptography

Xie Xuesong(), Cai Jiakai, Luo Baizhi   

  1. School of Information Science and Technology, Beijing University of Technology, Beijing 100124, China
  • Received:2025-12-12 Online:2026-08-10 Published:2026-09-23
  • Contact: Xie Xuesong E-mail:xiexuesong@bjut.edu.cn

Abstract:

With the migration of artificial intelligence technologies to the edge, edge AI systems have been widely deployed in critical scenarios such as smart cities, industrial internet, and autonomous driving. However, existing edge AI platforms lack end-to-end security mechanisms during model distribution and loading, exposing them to severe threats including model stealing, tampering, and man-in-the-middle attacks—posing significant risks to intellectual property protection and system trustworthiness. To address this issue, this paper proposed an embedded secure model loading mechanism based on Chinese national cryptographic algorithms. By implementing a dedicated SM3/SM4 co-processor in the programmable logic of an FPGA, the mechanism deeply integrated integrity verification and confidentiality protection into the entire AI model loading pipeline, ensuring trustworthy and controllable model handling from distribution and validation to execution. The system adopted a heterogeneous architecture combining Zynq-7020 and Orange Pi AI Pro, achieving high-performance inference while complying with China’s commercial cryptography regulations. Moreover, this paper validated the feasibility of domestic substitution: the Zynq-7020 can be replaced by domestically developed FPGAs, and the Ascend 310, selected for its alignment with the Information Technology Application Innovation (ITAI) ecosystem. Experimental results demonstrate that the proposed mechanism preserves original inference accuracy on representative edge AI models, with manageable hardware resource overhead, offering a practical and viable technical pathway toward building autonomous, secure, and trustworthy edge intelligence infrastructure.

Key words: edge AI, end-to-end security, Chinese national cryptographic algorithms, information technology application innovation, heterogeneous computing

CLC Number: