Fetching the paper…
Reading the bibliography…
We present DarkneTZ, a framework that uses an edge device's Trusted Execution Environment (TEE) in conjunction with model partitioning to limit the attack surface against Deep Neural Networks (DNNs).
Evaluating Differentially Private Machine Learning in Practice. In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Association, Santa Clara, CA, 1895–1912
Bargav Jayaraman and David Evans. 2019 · 1912
Earlier work this paper cites.
Overfitting in neural nets: Backpropagation, conjugate gradient, and early stopping. In Advances in Neural Information Processing Systems . 402–408
Rich Caruana, Steve Lawrence, and C Lee Giles. 2001 · 2001
Earlier work this paper cites.
SIGMA: The ‘SIGn-and-MAc’approach to authenticated Diffie-Hellman and its use in the IKE protocols. In Annual International Cryptology Conference . Springer, 400–425
Hugo Krawczyk. 2003 · 2003
Earlier work this paper cites.
Security technology-building a secure system using TrustZone technology
A Arm. 2009 · 2009
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition . Ieee, 248–255
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009 · 2009
Earlier work this paper cites.
Tukey’s honestly significant difference (HSD) test
Hervé Abdi and Lynne J Williams. 2010 · 2010
Earlier work this paper cites.
Can homomorphic encryption be practical?. In Proceedings of the 3rd ACM workshop on Cloud computing security workshop . ACM, 113–124
Michael Naehrig, Kristin Lauter, and Vinod Vaikuntanathan. 2011 · 2011
Earlier work this paper cites.
Membership privacy: a unifying framework for privacy definitions. In Proceedings of the 2013 ACM SIGSAC conference on Computer and Communications Security . ACM, 889–900
Ninghui Li, Wahbeh Qardaji, Dong Su, Yi Wu, and Weining Yang. 2013 · 2013
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Cynthia Dwork, Aaron Roth, et al · 2014
Earlier work this paper cites.
The untapped potential of trusted execution environments on mobile devices
Jan-Erik Ekberg, Kari Kostiainen, and N Asokan. 2014 · 2014
Earlier work this paper cites.
How transferable are features in deep neural networks?. In Advances in Neural Information Processing Systems . 3320–3328
Jason Yosinski, Jeff Clune, Yoshua Bengio, and Hod Lipson. 2014 · 2014
Earlier work this paper cites.
Visualizing and understanding convolutional networks. In European conference on computer vision . Springer, 818–833
Matthew D Zeiler and Rob Fergus. 2014 · 2014
Earlier work this paper cites.
Úlfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. 2014 · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 2015 ACM SIGSAC Conference on Computer and Communications Security . ACM, 1322–1333
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015 · 2015
Earlier work this paper cites.
Song Han, Huizi Mao, and William J Dally. 2015 · 2015
Earlier work this paper cites.
Deep learning
Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015 · 2015
Earlier work this paper cites.
Going deeper with convolutions. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition . 1–9
Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich. 2015 · 2015
Earlier work this paper cites.
Jason Yosinski, Jeff Clune, Anh Nguyen, Thomas Fuchs, and Hod Lipson. 2015 · 2015
Earlier work this paper cites.
Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security . ACM, 308–318
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016 · 2016
Earlier work this paper cites.
Intel SGX Explained
Victor Costan and Srinivas Devadas. 2016 · 2016
Earlier work this paper cites.
Inverting visual representations with convolutional networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition . 4829–4837
Alexey Dosovitskiy and Thomas Brox. 2016 · 2016
Earlier work this paper cites.
Deep residual learning for image recognition. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition . 770–778
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and< 0.5 MB model size
Forrest N Iandola, Song Han, Matthew W Moskewicz, Khalid Ashraf, William J Dally, and Kurt Keutzer. 2016 · 2016
Cited alongside, same era.
Oblivious Multi-Party Machine Learning on Trusted Processors. In 25th USENIX Security Symposium (USENIX Security 16) . USENIX Association, Austin, TX, 619–636
Olga Ohrimenko, Felix Schuster, Cedric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016 · 2016
Cited alongside, same era.
Darknet: Open Source Neural Networks in C
Joseph Redmon. 2013–2016 · 2016
Cited alongside, same era.
Deep models under the GAN: information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . ACM, 603–618
Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017 · 2017
Cited alongside, same era.
Mobilenets: Efficient convolutional neural networks for mobile vision applications
Downsampling leads to Image Memorization in Convolutional Autoencoders
Adityanarayanan Radhakrishnan, Mikhail Belkin, and Caroline Uhler. 2018 · 2018
Later among the works it cites.
Membership Inference Attack against Differentially Private Deep Learning Model
Md Atiqur Rahman, Tanzila Rahman, Robert Laganière, Noman Mohammed, and Yang Wang. 2018 · 2018
Later among the works it cites.
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2018 · 2018
Later among the works it cites.
Privado: Practical and secure DNN inference
Shruti Tople, Karan Grover, Shweta Shinde, Ranjita Bhagwan, and Ramachandran Ramjee. 2018 · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Andrew G Howard, Menglong Zhu, Bo Chen, Dmitry Kalenichenko, Weijun Wang, Tobias Weyand, Marco Andreetto, and Hartwig Adam. 2017 · 2017
Cited alongside, same era.
Densely connected convolutional networks. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition . 4700–4708
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger. 2017 · 2017
Cited alongside, same era.
Rényi differential privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF) . IEEE, 263–275
Ilya Mironov. 2017 · 2017
Cited alongside, same era.
Automatic Differentiation in PyTorch. In NIPS Autodiff Workshop
Adam Paszke, Sam Gross, Soumith Chintala, Gregory Chanan, Edward Yang, Zachary DeVito, Zeming Lin, Alban Desmaison, Luca Antiga, and Adam Lerer. 2017 · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models. In Proceedings of 38th IEEE Symposium on Security & Privacy . IEEE, 3–18
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017 · 2017
Cited alongside, same era.
Leaky cauldron on the dark land: Understanding memory side-channel hazards in SGX. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2421–2434
Wenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang, XiaoFeng Wang, Vincent Bindschaedler, Haixu Tang, and Carl A Gunter. 2017 · 2017
Cited alongside, same era.
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals. 2017 · 2017
Cited alongside, same era.
Learning hierarchical features from deep generative models. In International Conference on Machine Learning . 4091–4099
Shengjia Zhao, Jiaming Song, and Stefano Ermon. 2017 · 2017
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting. In 2018 IEEE 31st Computer Security Foundations Symposium (CSF) . IEEE, 268–282
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018 · 2018
Later among the works it cites.
TruZ-Droid: Integrating TrustZone with mobile operating system. In Proceedings of the 16th Annual International Conference on Mobile Systems, Applications, and Services . ACM, 14–27
Kailiang Ying, Amit Ahlawat, Bilal Alsharifi, Yuexin Jiang, Priyank Thavai, and Wenliang Du. 2018 · 2018
Later among the works it cites.
TensorFlow Privacy
Galen Andrew, Steve Chien, and Nicolas Papernot. 2019 · 2019
Later among the works it cites.
SANCTUARY: ARMing TrustZone with user-space enclaves.. In Network and Distributed Systems Security (NDSS) Symposium 2019
Ferdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi, and Emmanuel Stapf. 2019 · 2019
Later among the works it cites.
MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 259–274
Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong. 2019 · 2019
Later among the works it cites.
Exploiting Unintended Feature Leakage in Collaborative Learning. In Proceedings of 40th IEEE Symposium on Security & Privacy . IEEE, 480–495
Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019 · 2019
Later among the works it cites.
Poster: Towards Characterizing and Limiting Information Exposure in DNN Layers. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2653–2655
Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas, Andrea Cavallaro, and Hamed Haddadi. 2019 · 2019
Later among the works it cites.
Comprehensive Privacy Analysis of Deep Learning: Stand-alone and Federated Learning under Passive and Active White-box Inference Attacks. In Proceedings of 40th IEEE Symposium on Security & Privacy . IEEE
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019 · 2019
Later among the works it cites.
StreamBox-TZ: secure stream analytics at the edge with TrustZone. In 2019 { \{ USENIX } \} Annual Technical Conference 19 . 537–554
Heejin Park, Shuang Zhai, Long Lu, and Felix Xiaozhu Lin. 2019 · 2019
Later among the works it cites.
Florian Tramèr and Dan Boneh. 2019 · 2019
Later among the works it cites.
Haq: Hardware-aware automated quantization with mixed precision. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition . 8612–8620
Kuan Wang, Zhijian Liu, Yujun Lin, Ji Lin, and Song Han. 2019 · 2019
Later among the works it cites.
GANobfuscator: Mitigating information leakage under GAN via differential privacy
Chugui Xu, Ju Ren, Deyu Zhang, Yaoxue Zhang, Zhan Qin, and Kui Ren. 2019b · 2019
Later among the works it cites.
Neural Network Inversion in Adversarial Setting via Background Knowledge Alignment. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . ACM, 225–240
Ziqi Yang, Jiyi Zhang, Ee-Chien Chang, and Zhenkai Liang. 2019 · 2019
Later among the works it cites.
Differentially private model publishing for deep learning. In Proceedings of 40th IEEE Symposium on Security & Privacy . IEEE, 332–349
Lei Yu, Ling Liu, Calton Pu, Mehmet Emre Gursoy, and Stacey Truex. 2019 · 2019
Later among the works it cites.
Deep Learning in Mobile and Wireless Networking: A Survey
C. Zhang, P. Patras, and H. Haddadi. 2019 · 2019
Later among the works it cites.
SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEE. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . ACM, 1723–1740
Shijun Zhao, Qianying Zhang, Yu Qin, Wei Feng, and Dengguo Feng. 2019 · 2019
Later among the works it cites.
Deep leakage from gradients. In Advances in Neural Information Processing Systems . 14747–14756
Ligeng Zhu, Zhijian Liu, and Song Han. 2019 · 2019
Later among the works it cites.
A hybrid deep learning architecture for privacy-preserving mobile analytics
Seyed Ali Osia, Ali Shahin Shamsabadi, Ali Taheri, Kleomenis Katevas, Sina Sajadmanesh, Hamid R Rabiee, Nicholas D Lane, and Hamed Haddadi. 2020 · 2020
Closest in time.