Articles

Towards Secure Knowledge Distillation in Edge and Federated AI Systems: A System-Level Perspective

Secure AI
AI

2026 IEEE 12th International Conference on Network Softwarization (NetSoft)

Knowledge Distillation (KD) has become a key mechanism for deploying large models in resource-constrained environments such as edge and federated systems. In these settings, KD is no longer merely a compression technique, but a distributed system process in which knowledge is transferred across components operating under different trust assumptions. Despite its widespread adoption, the security implications of KD remain under-explored, with current practices implicitly assuming that a clean teacher yields a secure student. In this paper, we argue that this assumption is fundamentally flawed. We show that KD introduces a system-level attack surface that arises from the knowledge transfer mechanism itself, rather than from corrupted data or compromised models. By framing KD as a distributed pipeline composed of a teacher, a student, and a supervision channel, we identify the key trust boundaries and structural challenges that affect its security. Building on this perspective, we outline a conceptual architecture for secure KD that incorporates lightweight security control points across both the supervision channel and the student-side execution environment. We further derive design principles to guide the development of secure and deployable KD systems under realistic resource constraints. This work highlights the need to treat KD as a first-class security concern in modern AI deployments and motivates further research into KD-aware security mechanisms.