EdgeGuard: Unified Adversarial, Backdoor, and Side-Channel Defense for Edge AI Deployments

preprint OA: closed
Full text JSON View at publisher

Abstract

Deploying deep learning models on edge devicessmartphones, IoT gateways, autonomous vehicles, and VR headsets-exposes them to a uniquely converged threat landscape where digital AI attacks and physical hardware vulnerabilities intersect. Adversarial examples manipulate model predictions, backdoor triggers embed hidden malicious behaviors, model extraction steals proprietary parameters, and physical side channels through charging interfaces, wireless links, and sensor peripherals leak private data about the model and its users. Existing defenses address these threats in isolation, leaving dangerous gaps that cross-domain attackers exploit. We present EDGEGUARD, a unified defense framework for edge AI that simultaneously protects against adversarial inputs, backdoor triggers, model theft, and physical-layer information leakage. EDGEGUARD introduces four tightly integrated components: (1) an Adaptive Input Sentinel (AIS) that detects adversarial and backdoor-triggered inputs through joint activation-distribution and gradient-saliency analysis without modifying the protected model; (2) a Side-Channel Isolation Engine (SCIE) that neutralizes electromagnetic, power, and acoustic information leakage during on-device inference by injecting hardware-aware obfuscation at the system-on-chip (SoC) level; (3) a Model Integrity Monitor (MIM) that detects and prevents extraction attacks through query-pattern analysis and output perturbation; and (4) a Federated Threat Sharing Protocol (FTSP) that enables privacy-preserving sharing of detected threat signatures across a fleet of edge devices. We evaluate EDGEGUARD on a testbed of 186 heterogeneous edge devices spanning 14 device models, testing against 8 distinct attack categories across 5 datasets and 4 model architectures over a 20-week deployment. EDGEGUARD achieves 96.8% overall threat detection rate at 1.9% false positive rate, reduces side-channel information leakage by 95.2%, and degrades only 4.1% under fully adaptive adversaries-with a total runtime overhead of 3.8 ms per inference and 5.3% battery consumption increase.
Full text 7,327 characters · extracted from preprint-html · click to expand
EdgeGuard: Unified Adversarial, Backdoor, and Side-Channel Defense for Edge AI Deployments | Authorea try { document.documentElement.classList.add('js'); } catch (e) { } var _gaq = _gaq || []; _gaq.push(['_setAccount', 'G-8VDV14Y67G']); _gaq.push(['_trackPageview']); (function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true; ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s); })(); Skip to main content Preprints Collections Wiley Open Research IET Open Research Ecological Society of Japan All Collections About About Authorea FAQs Contact Us Quick Search anywhere Search for preprint articles, keywords, etc. Search Search ADVANCED SEARCH SCROLL This is a preprint and has not been peer reviewed. Data may be preliminary. 23 March 2026 V1 Latest version Share on EdgeGuard: Unified Adversarial, Backdoor, and Side-Channel Defense for Edge AI Deployments Authors : Yuxuan Chen , Xinyi Li , Zihan Zhang , Junjie Wang , and Chao Lu 0009-0007-2570-5241 Authors Info & Affiliations https://doi.org/10.22541/au.177430029.95422413/v1 112 views 63 downloads Contents Abstract Supplementary Material Information & Authors Metrics & Citations View Options References Figures Tables Media Share Abstract Deploying deep learning models on edge devicessmartphones, IoT gateways, autonomous vehicles, and VR headsets-exposes them to a uniquely converged threat landscape where digital AI attacks and physical hardware vulnerabilities intersect. Adversarial examples manipulate model predictions, backdoor triggers embed hidden malicious behaviors, model extraction steals proprietary parameters, and physical side channels through charging interfaces, wireless links, and sensor peripherals leak private data about the model and its users. Existing defenses address these threats in isolation, leaving dangerous gaps that cross-domain attackers exploit. We present EDGEGUARD, a unified defense framework for edge AI that simultaneously protects against adversarial inputs, backdoor triggers, model theft, and physical-layer information leakage. EDGEGUARD introduces four tightly integrated components: (1) an Adaptive Input Sentinel (AIS) that detects adversarial and backdoor-triggered inputs through joint activation-distribution and gradient-saliency analysis without modifying the protected model; (2) a Side-Channel Isolation Engine (SCIE) that neutralizes electromagnetic, power, and acoustic information leakage during on-device inference by injecting hardware-aware obfuscation at the system-on-chip (SoC) level; (3) a Model Integrity Monitor (MIM) that detects and prevents extraction attacks through query-pattern analysis and output perturbation; and (4) a Federated Threat Sharing Protocol (FTSP) that enables privacy-preserving sharing of detected threat signatures across a fleet of edge devices. We evaluate EDGEGUARD on a testbed of 186 heterogeneous edge devices spanning 14 device models, testing against 8 distinct attack categories across 5 datasets and 4 model architectures over a 20-week deployment. EDGEGUARD achieves 96.8% overall threat detection rate at 1.9% false positive rate, reduces side-channel information leakage by 95.2%, and degrades only 4.1% under fully adaptive adversaries-with a total runtime overhead of 3.8 ms per inference and 5.3% battery consumption increase. Supplementary Material File (paper_edge.pdf) Download 369.99 KB Information & Authors Information Version history V1 Version 1 23 March 2026 Copyright This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License Keywords adversarial examples backdoor detection edge ai security federated threat intelligence model extraction prevention side-channel defense Authors Affiliations Yuxuan Chen View all articles by this author Xinyi Li View all articles by this author Zihan Zhang View all articles by this author Junjie Wang View all articles by this author Chao Lu 0009-0007-2570-5241 View all articles by this author Metrics & Citations Metrics Article Usage 112 views 63 downloads .FvxKWukQNSOunydq8rnd { width: 100px; } Citations Download citation Yuxuan Chen, Xinyi Li, Zihan Zhang, et al. EdgeGuard: Unified Adversarial, Backdoor, and Side-Channel Defense for Edge AI Deployments. Authorea . 23 March 2026. DOI: https://doi.org/10.22541/au.177430029.95422413/v1 If you have the appropriate software installed, you can download article citation data to the citation manager of your choice. Simply select your manager software from the list below and click Download. For more information or tips please see 'Downloading to a citation manager' in the Help menu . Format Please select one from the list RIS (ProCite, Reference Manager) EndNote BibTex Medlars RefWorks Direct import Tips for downloading citations document.getElementById('citMgrHelpLink').addEventListener('click', function() { popupHelp(this.href); return false; }); $(".js__slcInclude").on("change", function(e){ if ($(this).val() == 'refworks') $('#direct').prop("checked", false); $('#direct').prop("disabled", ($(this).val() == 'refworks')); }); View Options View options PDF View PDF Figures Tables Media Share Share Share article link Copy Link Copied! Copying failed. Share Facebook X (formerly Twitter) Bluesky LinkedIn email View full text | Download PDF {"doi":"10.22541/au.177430029.95422413/v1","type":"Article"} Now Reading: Share Figures Tables Close figure viewer Back to article Figure title goes here Change zoom level Go to figure location within the article Download figure Toggle share panel Toggle share panel Share Toggle information panel Toggle information panel Go to previous graphic Go to next graphic Go to previous table Go to next table All figures All tables View all material View all material xrefBack.goTo xrefBack.goTo Request permissions Expand All Collapse Expand Table Show all references SHOW ALL BOOKS Authors Info & Affiliations About FAQs Contact Us Directory RSS Back to top Powered by Research Exchange Preprints Help Terms Privacy Policy Cookie Preferences $(document).ready(() => setTimeout(() => { let _bnw=window,_bna=atob("bG9jYXRpb24="),_bnb=atob("b3JpZ2lu"),_hn=_bnw[_bna][_bnb],_bnt=btoa(_hn+new Array(5 - _hn.length % 4).join(" ")); $.get("/resource/lodash?t="+_bnt); },4000)); (function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'9fe092cf0eec52ad',t:'MTc3OTE2NzE5OA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00