Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators

About

AI Accelerator (AIA) are specialized hardware e.g., Tensor Processing Unit (TPU), that enable optimal and efficient execution of AI applications and on-device inference. The growing demand for AI applications has led to the widespread adoption of AIAs on Edge or embedded devices on Edge or embedded devices. Unlike applications, AIAs are not bound by Operating System (OS) restrictions and have limited visibility into Application Processor (AP) security mechanisms (e.g., kernel vs. application memory, process isolation). This semantic gap can lead to confused deputy vulnerabilities, i.e., AIA can be tricked by a malicious application to perform privileged operations on their behalf. In this paper, we conducted the first in-depth study of Confused Deputy Attacks (CDAs) using AIA. We design DeputyHunt, a Large Language Model (LLM) assisted framework to extract CDA relevant information for a given AIA through a combination of dynamic and static analysis. We used this information to explore the feasibility of CDA on seven different AIAs from popular vendors, i.e., Google, NVIDIA, Hailo, Texas Instruments, NXP, AWS, and Rockchip. Our analysis revealed that CDA is feasible on six out of the seven AIAs, impacting over 128 System On Chips (SOCs) and over 100 million devices. Our findings highlight critical security risks posed by AIA on system security. Our work has been acknowledged by the corresponding vendors and assigned the CVE-2025-66425. We propose an on-demand validation defense against CDA, and evaluation on the Gem5- salam simulator shows that it incurs minimal runtime overhead (i.e., ~15%).

Datta Manikanta Sri Hari Danduri, Aravind Kumar Machiry• 2026

Related benchmarks

TaskDatasetResultRank
Runtime Overhead AnalysisMachSuite bfs
Runtime Overhead (%)20.91
10
Runtime Overhead AnalysisMachSuite lenet_a
Runtime Overhead (%)6.13
3
Runtime Overhead AnalysisMobileNetV2 1.0
Overhead (%)47.46
3
Runtime Overhead AnalysisMachSuite gemm
Overhead (%)0.56
3
Runtime Overhead AnalysisMachSuite fft
Overhead (%)15.71
3
Runtime Overhead AnalysisMachSuite lenet_b
Overhead (%)1.34
2
Runtime Overhead AnalysisMachSuite lenet_c
Runtime Overhead (%)3.53
2
Runtime Overhead AnalysisMachSuite md_grid
Runtime Overhead3.8
2
Runtime Overhead AnalysisMachSuite md_knn
Overhead (%)5.41
1
Runtime Overhead AnalysisMachSuite mergesort
Runtime Overhead2.75
1
Showing 10 of 16 rows

Other info

Follow for update