Local AI and cyber security. How Switzerland can use edge AI securely and reliably

AI models can increasingly be deployed directly on end devices and are no longer reliant on cloud computing power. These so-called edge AI models also have an impact on cyber security. To ensure that Switzerland does not miss out on developments in this area and can deploy edge AI in a secure and trustworthy manner, the new SATW factsheet sets out specific courses of action.

Developments in the field of artificial intelligence are currently dominated by the massive expansion of cloud infrastructure. This is causing a second, equally significant development to take a back seat: AI models are increasingly running directly on end devices – on smartphones, sensors, industrial robots or in vehicles. This so-called edge AI processes data where it is generated, rather than transmitting it to remote data centres.

This has far-reaching consequences, particularly for cyber security. Because sensitive data remains local, edge AI strengthens data protection and digital sovereignty on the one hand. On the other hand, however, the proximity of data, AI models and hardware increases the attack surface and shifts responsibility for cybersecurity from the cloud to the operators of the end devices.

To ensure that Switzerland does not miss out on this development and can deploy edge AI securely and reliably in future, the SATW’s Cybersecurity thematic platform outlines specific courses of action:

  • Zero-trust architecture (in accordance with NIST SP 800-207): Based on the principle of ‘never trust, always verify’, a separate access credential is created for every instance of access to every resource, which can be revoked at any time should the security situation change.
  • International industrial standards (IEC 62443): Defining security-relevant zones and communication channels makes it possible to reflect the distributed nature of edge AI applications and to operate them in isolated zones.
  • Security standards for AI models: New standards and mandatory red-team testing prior to deployment address risks such as data poisoning, model poisoning and hostile attacks – threats that are exacerbated in edge AI due to the proximity of hardware and software.
  • Mandatory cybersecurity framework for high-risk AI systems: Edge AI systems used, for example, in critical infrastructure (such as transport or electricity and water networks), in biometric identification or in educational assessment, should be required to adhere to the principle of ‘Security by Design’. ‘Security by Design’ requires that the accuracy, robustness and cybersecurity of the systems be embedded throughout the entire architectural and development process.
  • Trusted Execution Environments (TEs) to protect hardware components: As edge AI models process data and execute code locally, providers should increasingly rely on TEs. These TEE involve a hardware-based separation of the areas where data is processed and where the code of the edge AI model is executed.

Rapid developments in the field of AI are increasingly taking place at the local level. To ensure that Switzerland can utilise edge AI in a secure and trustworthy manner, the courses of action discussed here should be implemented.

Cybersecurity Thematic Platform

This factsheet is based on the work of the Cybersecurity Thematic Platform of the Swiss Academy of Engineering Sciences (SATW). The Thematic Platform identifies relevant developments in the field of cybersecurity and draws up recommendations for policymakers, industry and society.

Find out more about the Cybersecurity Thematic Platform

Find out more about cybersecurity at the SATW.

Q&A on the factsheet

This factsheet examines the implications for cyber security of AI models increasingly being deployed directly on end devices rather than in the cloud. It outlines options for action to ensure that Switzerland can use edge AI securely and reliably.

Edge AI refers to AI systems that operate locally on end devices – such as smartphones, sensors, industrial robots or in vehicles. The data is processed where it is generated, rather than being transmitted to a remote data centre. The boundaries between cloud AI and edge AI are fluid, with various possible combinations, such as AI training in the cloud and AI deployment at the edge.

Edge AI enables fast response times, reduced bandwidth requirements, offline availability, built-in protection of sensitive data (‘Privacy by Design’) and resource-efficient data processing. These advantages stem primarily from the fact that data is processed locally and that edge AI models are significantly smaller than cloud models.

Edge AI offers both advantages and disadvantages in terms of the triad of confidentiality, integrity and availability. On the one hand, local data processing enhances data protection and reduces the risk of data being intercepted. On the other hand, the proximity of data, AI models and hardware increases the local attack surface and the number of attack vectors. Cybersecurity responsibility is thus shifting from the cloud to the edge.

Edge AI enables fast response times, reduced bandwidth requirements, offline availability, built-in protection of sensitive data (‘Privacy by Design’) and resource-efficient data processing. These advantages stem primarily from the fact that data is processed locally and that edge AI models are significantly smaller than cloud models.

The factsheet recommends that the business community proactively implement recognised standards: zero-trust architecture principles (NIST SP 800-207), international standards for industrial automation (IEC 62443) and new security standards for AI models with mandatory red-teaming tests. Where voluntary initiatives are insufficient, regulations should require high-risk systems to adhere to the principle of ‘security by design’. Furthermore, providers must increasingly rely on trusted execution environments (TEs) to protect data and code at the hardware level through physical separation.

It is aimed at decision-makers in politics, business and research who are involved in cybersecurity and the secure use of AI systems.

The factsheet was produced by the Cybersecurity Thematic Platform of the Swiss Academy of Engineering Sciences (SATW). The project was led by Tobias Schlegel. Twelve authors from the fields of research, business and public administration contributed to its production.