Fetching the paper…
Reading the bibliography…
As Machine Learning (ML) gets applied to security-critical or sensitive domains, there is a growing need for integrity and privacy for outsourced ML computations.
Probabilistic machines can use less running time
Rusins Freivalds · 1977
Earlier work this paper cites.
Universally composable two-party and multi-party secure computation
Ran Canetti, Yehuda Lindell, Rafail Ostrovsky, and Amit Sahai · 2002
Earlier work this paper cites.
Trustzone: Integrated hardware and software security-enabling trusted computing in embedded systems
Tiago Alves and Don Felton · 2004
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Certifying algorithms
Ross M McConnell, Kurt Mehlhorn, Stefan Näher, and Pascal Schweitzer · 2011
Earlier work this paper cites.
Publicly verifiable delegation of large polynomials and matrix computations, with applications
Dario Fiore and Rosario Gennaro · 2012
Earlier work this paper cites.
Innovative instructions and software model for isolated execution
Frank McKeen, Ilya Alex, Alex Berenzon, Carlos Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday Savagaonkar · 2013
Earlier work this paper cites.
Time-optimal interactive proofs for circuit evaluation
Justin Thaler · 2013
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Deep learning with limited numerical precision
Suyog Gupta, Ankur Agrawal, Kailash Gopalakrishnan, and Pritish Narayanan · 2015
Earlier work this paper cites.
Intel Software Guard Extensions Evaluation SDK
Intel Corp · 2015
Earlier work this paper cites.
Controlled-channel attacks: Deterministic side channels for untrusted operating systems
Yuanzhong Xu, Weidong Cui, and Marcus Peinado · 2015
Earlier work this paper cites.
Intel SGX explained
Victor Costan and Srinivas Devadas · 2016
Earlier work this paper cites.
Sanctum: Minimal hardware extensions for strong software isolation
Victor Costan, Ilia Lebedev, and Srinivas Devadas · 2016
Earlier work this paper cites.
Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy
Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
SSD: Single shot multibox detector
Wei Liu, Dragomir Anguelov, Dumitru Erhan, Christian Szegedy, Scott Reed, Cheng-Yang Fu, and Alexander C Berg · 2016
Earlier work this paper cites.
Oblivious multi-party machine learning on trusted processors
Olga Ohrimenko, Felix Schuster, Cdric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa · 2016
Cited alongside, same era.
Preventing page faults from telling your secrets
Shweta Shinde, Zheng Leong Chua, Viswesh Narayanan, and Prateek Saxena · 2016
Cited alongside, same era.
Verifiable ASICs
Riad S Wahby, Max Howald, Siddharth Garg, Abhi Shelat, and Michael Walfish · 2016
Cited alongside, same era.
Alitheia: Towards practical verifiable graph processing
Yupeng Zhang, Charalampos Papamanthou, and Jonathan Katz · 2016
Cited alongside, same era.
Software grand exposure: SGX cache attacks are practical
Ferdinand Brasser, Urs Müller, Alexandra Dmitrienko, Kari Kostiainen, Srdjan Capkun, and Ahmad-Reza Sadeghi · 2017
Cited alongside, same era.
Detecting privileged side-channel attacks in shielded execution with déjá vu
Sanchuan Chen, Xiaokuan Zhang, Michael K Reiter, and Yinqian Zhang · 2017
A Berkeley view of systems challenges for AI
Ion Stoica, Dawn Song, Raluca Ada Popa, David Patterson, Michael W Mahoney, Randy Katz, Anthony D Joseph, Michael Jordan, Joseph M Hellerstein, Joseph E Gonzalez, et al · 2017
Later among the works it cites.
A formal foundation for secure remote execution of enclaves
Pramod Subramanyan, Rohit Sinha, Ilia Lebedev, Srinivas Devadas, and Sanjit A Seshia · 2017
Later among the works it cites.
Sealed-Glass Proofs: Using transparent enclaves to prove and sell knowledge
Florian Tramèr, Fan Zhang, Huang Lin, Jean-Pierre Hubaux, Ari Juels, and Elaine Shi · 2017
Later among the works it cites.
Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution
Jo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens, and Raoul Strackx · 2017
Later among the works it cites.
Full accounting for verifiable outsourcing
Riad S Wahby, Ye Ji, Andrew J Blumberg, Abhi Shelat, Justin Thaler, Michael Walfish, and Thomas Wies · 2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Xception: Deep learning with depthwise separable convolutions
François Chollet · 2017
Cited alongside, same era.
Iron: functional encryption using intel sgx
Ben Fisch, Dhinakaran Vinayagamurthy, Dan Boneh, and Sergey Gorbunov · 2017
Cited alongside, same era.
Safetynets: Verifiable execution of deep neural networks on an untrusted cloud
Zahra Ghodsi, Tianyu Gu, and Siddharth Garg · 2017
Cited alongside, same era.
Cache attacks on Intel SGX
Johannes Götzfried, Moritz Eckert, Sebastian Schinzel, and Tilo Müller · 2017
Cited alongside, same era.
Mobilenets: Efficient convolutional neural networks for mobile vision applications
Andrew G Howard, Menglong Zhu, Bo Chen, Dmitry Kalenichenko, Weijun Wang, Tobias Weyand, Marco Andreetto, and Hartwig Adam · 2017
Cited alongside, same era.
Inferring fine-grained control flow inside SGX enclaves with branch shadowing
Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado · 2017
Cited alongside, same era.
SGXPECTRE attacks: Leaking enclave secrets via speculative execution
Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H Lai · 2018
Closest in time.
Raymond Cheng, Fan Zhang, Jernej Kos, Warren He, Nicholas Hynes, Noah Johnson, Ari Juels, Andrew Miller, and Dawn Song · 2018
Closest in time.
Cachequote: Efficiently recovering long-term secrets of sgx epid via cache attacks
Fergus Dall, Gabrielle De Micheli, Thomas Eisenbarth, Daniel Genkin, Nadia Heninger, Ahmad Moghimi, and Yuval Yarom · 2018
Closest in time.
Mlcapsule: Guarded offline deployment of machine learning as a service
Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Max Augustin, Michael Backes, and Mario Fritz · 2018
Closest in time.
Impressions of Intel SGX performance
Danny Harnik and Eliad Tsfadia · 2018
Closest in time.
Chiron: Privacy-preserving machine learning as a service
Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel · 2018
Closest in time.
Intel software guard extensions (sgx) SW development guidance for potential bounds check bypass (CVE-2017-5753) side channel exploits
Intel Corp · 2018
Closest in time.
Gazelle: A low latency framework for secure neural network inference
Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan · 2018
Closest in time.
Spectre attacks: Exploiting speculative execution
Paul Kocher, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom · 2018
Closest in time.
Mixed precision training
Paulius Micikevicius, Sharan Narang, Jonah Alben, Gregory Diamos, Erich Elsen, David Garcia, Boris Ginsburg, Michael Houston, Oleksii Kuchaev, Ganesh Venkatesh, et al · 2018
Closest in time.
A quantization-friendly separable convolution for mobilenets
Tao Sheng, Chen Feng, Shaojie Zhuo, Xiaopeng Zhang, Liang Shen, and Mickey Aleksic · 2018
Closest in time.
Foreshadow: Extracting the keys to the Intel SGX kingdom with transient out-of-order execution
Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F. Wenisch, Yuval Yarom, and Raoul Strackx · 2018
Closest in time.