Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Loglearners: identifying compromised AI functions in serverless systems
Umeå University, Faculty of Science and Technology, Department of Computing Science.
Umeå University, Faculty of Science and Technology, Department of Computing Science.ORCID iD: 0000-0002-2633-6798
Umeå University, Faculty of Science and Technology, Department of Computing Science.ORCID iD: 0000-0002-9842-7840
2026 (English)In: Proceedings: 2026 IEEE 26th International Symposium on Cluster, Cloud and Internet Computing CCGrid 2026, Institute of Electrical and Electronics Engineers (IEEE), 2026, p. 665-674Conference paper, Published paper (Refereed)
Abstract [en]

The rapid adoption of Artificial Intelligence (AI) in edge environments has accelerated the use of Function-as-a-Service (FaaS) serverless platforms for deploying workloads across the cloud-edge continuum. However, this architectural shift introduces critical security vulnerabilities either at individual clusters or in multi-cluster continuum systems. The AI functions frequently integrate unvetted open-source libraries, creating a supply-chain attack surface, where malicious dependencies can execute undetected inside short-lived containers and compromise those AI functions. Traditional static analysis often fails to uncover these dynamic threats, necessitating robust runtime analysis. To address these issues, we present a comprehensive evaluation of learning-based approaches for identifying compromised functions by analyzing the behaviors of system calls. Moreover, we generate a dataset of 1.6 million system calls from 30 different serverless functions deployed on an OpenFaaS-Kubernetes testbed, which is available to the community for benchmarking. Our systematic analysis and comparison of five learning-based detection methods across multiple feature representations provide further insights into the identification of compromised functions. Our results demonstrate that runtime system call analysis can effectively identify supply-chain compromises, achieving detection rates up to 100% with F1 scores of 99.90%, without requiring application or platform modifications. 

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2026. p. 665-674
Keywords [en]
Edge-AI, Detection, Security, Software-supply-chain
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:umu:diva-254333DOI: 10.1109/CCGrid68966.2026.00077ISBN: 979-8-3315-7064-4 (electronic)OAI: oai:DiVA.org:umu-254333DiVA, id: diva2:2067992
Conference
IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing (CCGrid) 2026, Sydney, Australia, 18-21 May, 2026.
Funder
EU, Horizon Europe, 101092711Wallenberg AI, Autonomous Systems and Software Program (WASP)Available from: 2026-06-08 Created: 2026-06-08 Last updated: 2026-06-11Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Bhutto, Adil BinElmroth, ErikBhuyan, Monowar

Search in DiVA

By author/editor
Bhutto, Adil BinElmroth, ErikBhuyan, Monowar
By organisation
Department of Computing Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 17 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf