Fetching the paper…
Reading the bibliography…
Deep Neural Network (DNN) workloads are quickly moving from datacenters onto edge devices, for latency, privacy, or energy reasons.
R. L. Rivest, L. Adleman, and M. L. Dertouzos, “On data banks and privacy homomorphisms,” Foundations of Secure Computation, Academia Press , pp. 169–179, 1978
1978
Earlier work this paper cites.
S. Even, O. Goldreich, and A. Lempel, “A randomized protocol for signing contracts,” Commun. ACM , vol. 28, no. 6, pp. 637–647, June 1985
1985
Earlier work this paper cites.
S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Comput. , vol. 9, no. 8, pp. 1735–1780, Nov. 1997
1997
Earlier work this paper cites.
O. Goldreich, “Cryptography and cryptographic protocols,” Distrib. Comput. , vol. 16, no. 2-3, pp. 177–199, Sept. 2003
2003
Earlier work this paper cites.
G. E. Suh and S. Devadas, “Physical unclonable functions for device authentication and secret key generation,” in 2007 44th ACM/IEEE Design Automation Conference , June 2007, pp. 9–14
2007
Earlier work this paper cites.
V. Kolesnikov and T. Schneider, “Improved garbled circuit: Free xor gates and applications,” in Automata, Languages and Programming , L. Aceto, I. Damgård, L. A. Goldberg, M. M. Halldórsson, A. Ingólfsdóttir, et al. , Eds. Berlin, Heidelberg: Springer Berlin Heidelberg, 2008, pp. 486–498
2008
Earlier work this paper cites.
J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson, W. Paul, et al. , “Lest we remember: Cold-boot attacks on encryption keys,” Commun. ACM , vol. 52, no. 5, pp. 91–98, May 2009
2009
Earlier work this paper cites.
A. Tria and H. Choukri, Invasive Attacks . Boston, MA: Springer US, 2011, pp. 623–629
2011
Earlier work this paper cites.
M. Tehranipoor and C. Wang, Introduction to Hardware Security and Trust . Springer Publishing Company, Incorporated, 2011
2011
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in ICML , 2012
2012
Earlier work this paper cites.
Y. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Cross-vm side channels and their use to extract private keys,” in Proceedings of the 2012 ACM Conference on Computer and Communications Security , ser. CCS ’12. New York, NY, USA: ACM, 2012, pp. 305–316
2012
Earlier work this paper cites.
C. W. Fletcher, M. v. Dijk, and S. Devadas, “A secure processor architecture for encrypted computation on untrusted programs,” in Proceedings of the Seventh ACM Workshop on Scalable Trusted Computing , ser. STC ’12. New York, NY, USA: ACM, 2012, pp. 3–8
2012
Earlier work this paper cites.
E. Stefanov, M. van Dijk, E. Shi, C. Fletcher, L. Ren, et al. , “Path oram: An extremely simple oblivious ram protocol,” in Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security , ser. CCS ’13. New York, NY, USA: ACM, 2013, pp. 299–310
2013
Earlier work this paper cites.
Y. Jia, E. Shelhamer, J. Donahue, S. Karayev, J. Long, et al. , “Caffe: Convolutional architecture for fast feature embedding,” in Proceedings of the 22Nd ACM International Conference on Multimedia , ser. MM ’14. New York, NY, USA: ACM, 2014, pp. 675–678
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
Y. Yarom and K. Falkner, “Flush+reload: A high resolution, low noise, l3 cache side-channel attack,” in 23rd USENIX Security Symposium (USENIX Security 14) . San Diego, CA: USENIX Association, 2014, pp. 719–732
2014
Earlier work this paper cites.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: A simple way to prevent neural networks from overfitting,” Journal of Machine Learning Research , vol. 15, pp. 1929–1958, 2014
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
G. E. Suh, D. Clarke, B. Gassend, M. van Dijk, and S. Devadas, “Aegis: Architecture for tamper-evident and tamper-resistant processing,” in ACM International Conference on Supercomputing 25th Anniversary Volume . New York, NY, USA: ACM, 2014, pp. 357–368
2014
Earlier work this paper cites.
M. Abadi, A. Agarwal, P. Barham, E. Brevdo, Z. Chen, et al. , “TensorFlow: Large-scale machine learning on heterogeneous systems,” 2015
2015
Earlier work this paper cites.
F. Chollet et al. , “Keras,” https://keras.io, 2015
2015
Earlier work this paper cites.
M. Courbariaux, Y. Bengio, and J.-P. David, “Binaryconnect: Training deep neural networks with binary weights during propagations,” in Advances in Neural Information Processing Systems 28 . Curran Associates, Inc., 2015, pp. 3123–3131
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
F. Liu, Y. Yarom, Q. Ge, G. Heiser, and R. B. Lee, “Last-level cache side-channel attacks are practical,” in Proceedings of the 2015 IEEE Symposium on Security and Privacy , ser. SP ’15. Washington, DC, USA: IEEE Computer Society, 2015, pp. 605–622
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
2016
Cited alongside, same era.
2016
Cited alongside, same era.
2016
Cited alongside, same era.
2016
Cited alongside, same era.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, et al. , “Trojaning attack on neural networks,” in 25nd Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-221, 2018 . The Internet Society, 2018
2018
Later among the works it cites.
2018
Later among the works it cites.
2018
Later among the works it cites.
A. Salem, Y. Zhang, M. Humbert, P. Berrang, M. Fritz, et al. , “ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models,” jun 2018
2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2016
Cited alongside, same era.
2016
Cited alongside, same era.
V. Costan and S. Devadas, “Intel sgx explained,” IACR Cryptology ePrint Archive , vol. 2016, p. 86, 2016
2016
Cited alongside, same era.
J. Albericio, P. Judd, T. Hetherington, T. Aamodt, N. E. Jerger, et al. , “Cnvlutin: Ineffectual-neuron-free deep neural network computing,” in 2016 ACM/IEEE 43rd Annual International Symposium on Computer Architecture (ISCA) , June 2016, pp. 1–13
2016
Cited alongside, same era.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, et al. , “Deep Learning with Differential Privacy,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS’16 . New York, New York, USA: ACM Press, 2016, pp. 308–318
2016
Cited alongside, same era.
F. Liu, Q. Ge, Y. Yarom, F. Mckeen, C. Rozas, et al. , “Catalyst: Defeating last-level cache side channel attacks in cloud computing,” in 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA) , March 2016, pp. 406–418
2016
Cited alongside, same era.
N. Dowlin, R. Gilad-Bachrach, K. Laine, K. Lauter, M. Naehrig, et al. , “Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy,” Tech. Rep., February 2016
2016
Cited alongside, same era.
S. Han, H. Mao, and W. J. Dally, “Deep Compression - Compressing Deep Neural Networks with Pruning, Trained Quantization and Huffman Coding,” ICLR , pp. 1–13, 2016
2016
Cited alongside, same era.
M. Yan, C. Fletcher, and J. Torrellas, “Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures,” aug 2018
2018
Later among the works it cites.
H. Naghibijouybari, A. Neupane, Z. Qian, and N. Abu-Ghazaleh, “Rendered Insecure: GPU Side Channel Attacks are Practical,” CCS , vol. 15, 2018
2018
Later among the works it cites.
2018
Later among the works it cites.
2018
Later among the works it cites.
W. Hua, Z. Zhang, and G. E. Suh, “Reverse Engineering Convolutional Neural Networks Through Side-channel Information Leaks,” 2018
2018
Later among the works it cites.
2018
Later among the works it cites.
Y. Adi, C. Baum, M. Cisse Google, B. Pinkas, and J. Keshet, “Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring,” Tech. Rep., 2018
2018
Later among the works it cites.
2018
Later among the works it cites.
B. Darvish, R. M. Sadegh, R. Farinaz, K. Uc, S. Diego, et al. , “DeepSecure: Scalable Provably-Secure Deep Learning,” 2018
2018
Later among the works it cites.
2018
Later among the works it cites.
F. Tramer and D. Boneh, “Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware,” 2018
2018
Later among the works it cites.
“TensorFlow Serving,” https://www.tensorflow.org/tfx/guide/serving, 2019, [Online; accessed 18-April-2019]
2019
Closest in time.
“ONNX: Open Neural Network Exchange Format,” https://onnx.ai/, 2019, [Online; accessed 18-April-2019]
2019
Closest in time.
“Apple Core ML,” https://developer.apple.com/documentation/coreml, 2019, [Online; accessed 18-April-2019]
2019
Closest in time.
2019
Closest in time.
“Google Edge TPU,” https://cloud.google.com/edge-tpu/, 2019, [Online; accessed 18-April-2019]
2019
Closest in time.
“NVIDIA Jetson Nano,” https://www.nvidia.com/en-us/autonomous-machines/embedded-systems/jetson-nano/, 2019, [Online; accessed 18-April-2019]
2019
Closest in time.
“Dormant, Yet Always-Alert Sensor Awakes Only in the Presence of a Signal of Interest,” https://www.darpa.mil/news-events/2017-09-11, 2019, [Online; accessed 12-May-2019]
2019
Closest in time.
M. Ball, B. Carmer, T. Malkin, M. Rosulek, and N. Schimanski, “Garbled Neural Networks are Practical,” Tech. Rep., 2019
2019
Closest in time.
2019
Closest in time.