Fetching the paper…
Reading the bibliography…
Privacy and security challenges in Machine Learning (ML) have become increasingly severe, along with ML's pervasive development and the recent demonstration of large attack surfaces.
N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, and F. Tramer, “Membership inference attacks from first principles,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1897–1914
1914
Earlier work this paper cites.
H. Oh, A. Ahmad, S. Park, B. Lee, and Y. Paek, “Trustore: Side-channel resistant storage for sgx using intel hybrid cpu-fpga,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , 2020, pp. 1903–1918
1918
Earlier work this paper cites.
S. E. Oh, T. Yang, N. Mathews, J. K. Holland, M. S. Rahman, N. Hopper, and M. Wright, “Deepcoffea: Improved flow correlation attacks on tor via metric learning and amplification,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1915–1932
1932
Earlier work this paper cites.
R. C. Merkle, “Protocols for public key cryptosystems,” in 1980 IEEE Symposium on Security and Privacy . IEEE, 1980, pp. 122–122
1980
Earlier work this paper cites.
F. Cohen, “A cryptographic checksum for integrity protection,” Computers & Security , vol. 6, no. 6, pp. 505–510, 1987
1987
Earlier work this paper cites.
R. C. Merkle, “A certified digital signature,” in Conference on the Theory and Application of Cryptology . Springer, 1989, pp. 218–238
1989
Earlier work this paper cites.
R. Kohavi et al. , “A study of cross-validation and bootstrap for accuracy estimation and model selection,” in International Joint Conference on Artificial Intelligence , vol. 14, no. 2. Montreal, Canada, 1995, pp. 1137–1145
1995
Earlier work this paper cites.
R. Motwani and P. Raghavan, “Randomized algorithms,” ACM Computing Surveys (CSUR) , vol. 28, no. 1, pp. 33–37, 1996
1996
Earlier work this paper cites.
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , vol. 86, no. 11, pp. 2278–2324, 1998
1998
Earlier work this paper cites.
C. E. Brodley and M. A. Friedl, “Identifying mislabeled training data,” Journal of artificial intelligence research , vol. 11, pp. 131–167, 1999
1999
Earlier work this paper cites.
V. Haldar, D. Chandra, and M. Franz, “Semantic remote attestation: A virtual machine directed approach to trusted computing,” in USENIX Virtual Machine Research and Technology Symposium , vol. 2004, 2004
2004
Earlier work this paper cites.
X. Zhu and A. B. Goldberg, “Introduction to semi-supervised learning,” Synthesis lectures on artificial intelligence and machine learning , vol. 3, no. 1, pp. 1–130, 2009
2009
Earlier work this paper cites.
S. J. Pan and Q. Yang, “A survey on transfer learning,” IEEE Transactions on knowledge and data engineering , vol. 22, no. 10, pp. 1345–1359, 2009
2009
Earlier work this paper cites.
L. Bottou, “Large-scale machine learning with stochastic gradient descent,” in Proceedings of COMPSTAT’2010 . Springer, 2010, pp. 177–186
2010
Earlier work this paper cites.
S. Arlot and A. Celisse, “A survey of cross-validation procedures for model selection,” Statistics surveys , vol. 4, pp. 40–79, 2010
2010
Earlier work this paper cites.
G. Coker, J. Guttman, P. Loscocco, A. Herzog, J. Millen, B. O’Hanlon, J. Ramsdell, A. Segall, J. Sheehy, and B. Sniffen, “Principles of remote attestation,” International Journal of Information Security , vol. 10, no. 2, pp. 63–81, 2011
2011
Earlier work this paper cites.
D. E. Porter, S. Boyd-Wickizer, J. Howell, R. Olinsky, and G. C. Hunt, “Rethinking the library os from the top down,” in ACM SIGPLAN Notices , vol. 46. ACM, 2011, pp. 291–304
2011
Earlier work this paper cites.
T. Graepel, K. Lauter, and M. Naehrig, “Ml confidential: Machine learning on encrypted data,” in International conference on information security and cryptology . Springer, 2012, pp. 1–21
2012
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” Advances in neural information processing systems , vol. 25, pp. 1097–1105, 2012
2012
Earlier work this paper cites.
Q. V. Le, “Building high-level features using large scale unsupervised learning,” in 2013 IEEE international conference on acoustics, speech and signal processing . IEEE, 2013, pp. 8595–8598
2013
Earlier work this paper cites.
S. Checkoway and H. Shacham, Iago attacks: why the system call API is a bad untrusted RPC interface . ACM, 2013, vol. 41, no. 1
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
M. D. Zeiler and R. Fergus, “Visualizing and understanding convolutional networks,” in European conference on computer vision . Springer, 2014, pp. 818–833
2014
Earlier work this paper cites.
N. Santos, H. Raj, S. Saroiu, and A. Wolman, “Using arm trustzone to build a trusted language runtime for mobile applications,” ACM SIGARCH Computer Architecture News , vol. 42, no. 1, pp. 67–80, 2014
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proceedings of the 22nd ACM SIGSAC conference on computer and communications security , 2015, pp. 1322–1333
2015
Earlier work this paper cites.
M. I. Jordan and T. M. Mitchell, “Machine learning: Trends, perspectives, and prospects,” Science , vol. 349, no. 6245, pp. 255–260, 2015
2015
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” nature , vol. 521, no. 7553, pp. 436–444, 2015
2015
Earlier work this paper cites.
M. Ribeiro, K. Grolinger, and M. A. Capretz, “Mlaas: Machine learning as a service,” in 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA) . IEEE, 2015, pp. 896–902
2015
Earlier work this paper cites.
A. Baumann, M. Peinado, and G. Hunt, “Shielding applications from an untrusted cloud with Haven,” ACM Transactions on Computer Systems (TOCS) , vol. 33, no. 3, p. 8, 2015
2015
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction APIs,” in 25th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 16) , 2016, pp. 601–618
2016
Earlier work this paper cites.
O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa, “Oblivious multi-party machine learning on trusted processors,” in 25th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 16) , 2016, pp. 619–636
2016
Earlier work this paper cites.
V. Costan and S. Devadas, “Intel SGX Explained,” IACR Cryptol. ePrint Arch. , vol. 2016, no. 86, pp. 1–118, 2016
2016
Earlier work this paper cites.
S. Johnson, V. Scarlata, C. Rozas, E. Brickell, and F. Mckeen, “Intel software guard extensions: Epid provisioning and attestation services,” White Paper , vol. 1, no. 1-10, p. 119, 2016
2016
Earlier work this paper cites.
B. Ngabonziza, D. Martin, A. Bailey, H. Cho, and S. Martin, “Trustzone explained: Architectural features and use cases,” in 2016 IEEE 2nd International Conference on Collaboration and Internet Computing (CIC) . IEEE, 2016, pp. 445–451
2016
Earlier work this paper cites.
S. Arnautov, B. Trach, F. Gregor, T. Knauth, A. Martin, C. Priebe, J. Lind, D. Muthukumaran, D. O’keeffe, M. Stillwell et al. , “Scone: Secure linux containers with intel sgx.” in OSDI , vol. 16, 2016, pp. 689–703
2016
Earlier work this paper cites.
F. McKeen, I. Alexandrovich, I. Anati, D. Caspi, S. Johnson, R. Leslie-Hurd, and C. Rozas, “Intel® software guard extensions (intel® sgx) support for dynamic memory management inside an enclave,” in Proceedings of the Hardware and Architectural Support for Security and Privacy 2016 , 2016, pp. 1–9
2016
Earlier work this paper cites.
N. Weichbrodt, A. Kurmus, P. Pietzuch, and R. Kapitza, “Asyncshock: Exploiting synchronisation bugs in intel sgx enclaves,” in European Symposium on Research in Computer Security . Springer, 2016, pp. 440–457
2016
Earlier work this paper cites.
N. Karapanos, A. Filios, R. A. Popa, and S. Capkun, “Verena: End-to-end integrity protection for web applications,” in 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 2016, pp. 895–913
2016
Earlier work this paper cites.
X. Chu, I. F. Ilyas, S. Krishnan, and J. Wang, “Data cleaning: Overview and emerging challenges,” in Proceedings of the 2016 international conference on management of data , 2016, pp. 2201–2206
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security , 2016, pp. 308–318
2016
Earlier work this paper cites.
“General data protection regulation (gdpr),” https://gdpr-info.eu/ , 2016
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 2017, pp. 3–18
2017
Earlier work this paper cites.
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Artificial intelligence and statistics . PMLR, 2017, pp. 1273–1282
2017
Earlier work this paper cites.
Y. Yao, Z. Xiao, B. Wang, B. Viswanath, H. Zheng, and B. Y. Zhao, “Complexity vs. performance: empirical analysis of machine learning as a service,” in Proceedings of the 2017 Internet Measurement Conference , 2017, pp. 384–397
2017
Earlier work this paper cites.
B. Hitaj, G. Ateniese, and F. Perez-Cruz, “Deep models under the gan: information leakage from collaborative deep learning,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security , 2017, pp. 603–618
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
L. Guan, P. Liu, X. Xing, X. Ge, S. Zhang, M. Yu, and T. Jaeger, “Trustshadow: Secure execution of unmodified applications with arm trustzone,” in Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services . ACM, 2017, pp. 488–501
2017
Earlier work this paper cites.
J. Lee, J. Jang, Y. Jang, N. Kwak, Y. Choi, C. Choi, T. Kim, M. Peinado, and B. B. Kang, “Hacking in Darkness: Return-Oriented Programming against Secure Enclaves,” in Proceedings of the 26th USENIX Conference on Security Symposium , 2017, pp. 523–539
2017
Earlier work this paper cites.
A. Machiry, E. Gustafson, C. Spensky, C. Salls, N. Stephens, R. Wang, A. Bianchi, Y. R. Choe, C. Kruegel, and G. Vigna, “Boomerang: Exploiting the semantic gap in trusted execution environments.” in NDSS , 2017
2017
Earlier work this paper cites.
C.-C. Tsai, D. E. Porter, and M. Vij, “Graphene-sgx: A practical library os for unmodified applications on sgx,” in Proceedings of the USENIX Annual Technical Conference (ATC) , 2017, p. 8
2017
Earlier work this paper cites.
J. Lind, C. Priebe, D. Muthukumaran, D. O’Keeffe, P.-L. Aublin, F. Kelbert, T. Reiher, D. Goltzsche, D. Eyers, R. Kapitza et al. , “Glamdring: Automatic application partitioning for intel { \{ SGX } \} ,” in 2017 USENIX Annual Technical Conference (USENIX ATC 17) , 2017, pp. 285–298
2017
Earlier work this paper cites.
Y. Aono, T. Hayashi, L. Wang, S. Moriai et al. , “Privacy-preserving deep learning via additively homomorphic encryption,” IEEE Transactions on Information Forensics and Security , vol. 13, no. 5, pp. 1333–1345, 2017
2017
Earlier work this paper cites.
W. Zheng, A. Dave, J. G. Beekman, R. A. Popa, J. E. Gonzalez, and I. Stoica, “Opaque: An oblivious and encrypted distributed analytics platform,” in 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI 17) , 2017, pp. 283–298
2017
Earlier work this paper cites.
R. Boselli, M. Cesarini, F. Mercorio, and M. Mezzanzanica, “Classifying online job advertisements through machine learning,” Future Generation Computer Systems , vol. 86, pp. 319–328, 2018
2018
Earlier work this paper cites.
M. A. Ahmad, C. Eckert, and A. Teredesai, “Interpretable machine learning in healthcare,” in Proceedings of the 2018 ACM international conference on bioinformatics, computational biology, and health informatics , 2018, pp. 559–560
2018
Earlier work this paper cites.
K. Shailaja, B. Seetharamulu, and M. Jabbar, “Machine learning in healthcare: A review,” in 2018 Second international conference on electronics, communication and aerospace technology (ICECA) . IEEE, 2018, pp. 910–914
2018
Earlier work this paper cites.
F. Tramer and D. Boneh, “Slalom: Fast, verifiable and private execution of neural networks in trusted hardware,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
R. S. Sutton and A. G. Barto, Reinforcement learning: An introduction . MIT press, 2018
2018
Earlier work this paper cites.
R. Evans and E. Grefenstette, “Learning explanatory rules from noisy data,” Journal of Artificial Intelligence Research , vol. 61, pp. 1–64, 2018
2018
Earlier work this paper cites.
A. Katharopoulos and F. Fleuret, “Not all samples are created equal: Deep learning with importance sampling,” in International conference on machine learning . PMLR, 2018, pp. 2525–2534
2018
Earlier work this paper cites.
P. Marcelino, “Transfer learning from pre-trained models,” Towards Data Science , 2018
2018
Earlier work this paper cites.
H. Qi, M. Brown, and D. G. Lowe, “Low-shot learning with imprinted weights,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2018, pp. 5822–5830
2018
Earlier work this paper cites.
E. Hesamifard, H. Takabi, M. Ghasemi, and R. N. Wright, “Privacy-preserving machine learning as a service,” Proceedings on Privacy Enhancing Technologies , vol. 3, pp. 123–142, 2018
2018
Earlier work this paper cites.
J. Jia and N. Z. Gong, “Attriguard: A practical defense against attribute inference attacks via adversarial machine learning,” in 27th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 18) , 2018, pp. 513–529
2018
Earlier work this paper cites.
N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, “SoK: Security and privacy in machine learning,” in 2018 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 2018, pp. 399–414
2018
Earlier work this paper cites.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in 2018 IEEE 31st computer security foundations symposium (CSF) . IEEE, 2018, pp. 268–282
2018
Earlier work this paper cites.
GlobalPlatform, White Paper on the Trusted Execution Environment . GlobalPlatform, 2015. [Online]. Available: https://globalplatform.org/wp-content/uploads/2018/04/GlobalPlatform_TEE_Whitepaper_2015.pdf
2018
Earlier work this paper cites.
V. Scarlata, S. Johnson, J. Beaney, and P. Zmijewski, “Supporting third party attestation for intel sgx with intel data center attestation primitives,” White paper , 2018
2018
Earlier work this paper cites.
Google, “Asylo - an open and flexible framework for enclave applications,” http://web.archive.org/web/20080207010024/http://www.808multimedia.com/winnt/kernel.htm , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
S. Volos, K. Vaswani, and R. Bruno, “Graviton: Trusted execution environments on GPUs,” in 13th { \{ USENIX } \} Symposium on Operating Systems Design and Implementation ( { \{ OSDI } \} 18) , 2018, pp. 681–696
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, “Ensemble adversarial training: Attacks and defenses,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
D. Ielmini and H.-S. P. Wong, “In-memory computing with resistive switching devices,” Nature electronics , vol. 1, no. 6, pp. 333–343, 2018
2018
Earlier work this paper cites.
W. Hua, Z. Zhang, and G. E. Suh, “Reverse engineering convolutional neural networks through side-channel information leaks,” in Proceedings of the 55th Annual Design Automation Conference , 2018, pp. 1–6
2018
Earlier work this paper cites.
2019
Earlier work this paper cites.
M. Leo, S. Sharma, and K. Maddulety, “Machine learning in banking risk management: A literature review,” Risks , vol. 7, no. 1, p. 29, 2019
2019
Earlier work this paper cites.
M. Meyer and G. Kuschk, “Deep learning based 3d object detection for automotive radar and camera,” in 2019 16th European Radar Conference (EuRAD) . IEEE, 2019, pp. 133–136
2019
Earlier work this paper cites.
T. Orekondy, B. Schiele, and M. Fritz, “Knockoff nets: Stealing functionality of black-box models,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 4954–4963
2019
Earlier work this paper cites.
Z. He, T. Zhang, and R. B. Lee, “Model inversion attacks against collaborative inference,” in Proceedings of the 35th Annual Computer Security Applications Conference , 2019, pp. 148–162
2019
Earlier work this paper cites.
L. Zhu, Z. Liu, and S. Han, “Deep leakage from gradients,” Advances in Neural Information Processing Systems , vol. 32, pp. 14 774–14 784, 2019
2019
Earlier work this paper cites.
L. Melis, C. Song, E. De Cristofaro, and V. Shmatikov, “Exploiting unintended feature leakage in collaborative learning,” in 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 2019, pp. 691–706
2019
Earlier work this paper cites.
B. D. U. G. W. Group et al. , “Un handbook on privacy-preserving computation techniques,” 2019
2019
Earlier work this paper cites.
T. Lee, Z. Lin, S. Pushp, C. Li, Y. Liu, Y. Lee, F. Xu, C. Xu, L. Zhang, and J. Song, “Occlumency: Privacy-preserving remote deep-learning inference using SGX,” in The 25th Annual International Conference on Mobile Computing and Networking , 2019, pp. 1–17
2019
Earlier work this paper cites.
F. Mo and H. Haddadi, “Efficient and private federated learning using tee,” in Proc. EuroSys Conf., Dresden, Germany , 2019
2019
Earlier work this paper cites.
S. Amershi, A. Begel, C. Bird, R. DeLine, H. Gall, E. Kamar, N. Nagappan, B. Nushi, and T. Zimmermann, “Software engineering for machine learning: A case study,” in 2019 IEEE/ACM 41st International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) . IEEE, 2019, pp. 291–300
2019
Cited alongside, same era.
D. Berthelot, N. Carlini, I. Goodfellow, N. Papernot, A. Oliver, and C. A. Raffel, “Mixmatch: A holistic approach to semi-supervised learning,” Advances in Neural Information Processing Systems , vol. 32, 2019
2019
Cited alongside, same era.
C. Shorten and T. M. Khoshgoftaar, “A survey on image data augmentation for deep learning,” Journal of Big Data , vol. 6, no. 1, pp. 1–48, 2019
2019
Cited alongside, same era.
T. Elsken, J. H. Metzen, and F. Hutter, “Neural architecture search: A survey,” The Journal of Machine Learning Research , vol. 20, no. 1, pp. 1997–2017, 2019
2019
Cited alongside, same era.
Arm. Confidential compute architecture: Placing confidential compute in the hands of every developer. [Online]. Available: {https://haspworkshop.org/2021/slides/HASP-2021-Session2-Arm-CCA.pdf}
2021
Later among the works it cites.
D. P. Mulligan, G. Petri, N. Spinale, G. Stockwell, and H. J. Vincent, “Confidential computing—a brave new world,” in 2021 international symposium on secure and private execution environment design (SEED) . IEEE, 2021, pp. 132–138
2021
Later among the works it cites.
——, “Quantifying information leakage from gradients,” arXiv preprint arXiv:2105.13929 , 2021
2021
Later among the works it cites.
Y. Xiang, Y. Wang, H. Choi, M. Karimi, and H. Kim, “Aegisdnn: Dependable and timely execution of dnn tasks with sgx,” in 2021 IEEE Real-Time Systems Symposium (RTSS) . IEEE, 2021, pp. 68–81
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2019
Cited alongside, same era.
M. Nasr, R. Shokri, and A. Houmansadr, “Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning,” in 2019 IEEE symposium on security and privacy (SP) . IEEE, 2019, pp. 739–753
2019
Cited alongside, same era.
A. Sablayrolles, M. Douze, C. Schmid, Y. Ollivier, and H. Jégou, “White-box vs black-box: Bayes optimal strategies for membership inference,” in International Conference on Machine Learning . PMLR, 2019, pp. 5558–5567
2019
Cited alongside, same era.
Van Bulck, Jo and Oswald, David and Marin, Eduard and Aldoseri, Abdulla and Garcia, Flavio D. and Piessens, Frank, “A Tale of Two Worlds: Assessing the Vulnerability of Enclave Shielding Runtimes,” in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS) , 2019, pp. 1741–1758
2019
Cited alongside, same era.
I. C. London. (2019) Sgx-lkl library os for running linux applications inside of intel sgx enclaves. https://github.com/lsds/sgx-lkl . Access Date :2019-10-01
2019
Cited alongside, same era.
I. Corporation. (2019) Intel(r) software guard extensions for linux os. https://github.com/intel/linux-sgx . Access Date :2019-03-01
2019
Cited alongside, same era.
M. Corporation, “Open enclave sdk,” https://github.com/openenclave/openenclave , 2019, access Date :2019-08-12
2019
Cited alongside, same era.
Qualcomm, Guard Your Data with the Qualcomm Snapdragon Mobile Platform . Qualcomm, 2019. [Online]. Available: https://www.qualcomm.com/media/documents/files/guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf
2019
Cited alongside, same era.
L. Hanzlik, Y. Zhang, K. Grosse, A. Salem, M. Augustin, M. Backes, and M. Fritz, “MLcapsule: Guarded offline deployment of machine learning as a service,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 3300–3309
2021
Later among the works it cites.
Z. Liu, Y. Lu, X. Xie, Y. Fang, Z. Jian, and T. Li, “Trusted-DNN: A trustzone-based adaptive isolation strategy for deep neural networks,” in ACM Turing Award Celebration Conference-China (ACM TURC 2021) , 2021, pp. 67–71
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
L. K. Ng, S. S. Chow, A. P. Woo, D. P. Wong, and Y. Zhao, “Goten: Gpu-outsourcing trusted execution of neural network training,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 35, no. 17, 2021, pp. 14 876–14 883
2021
Later among the works it cites.
C. Zhang, J. Xia, B. Yang, H. Puyang, W. Wang, R. Chen, I. E. Akkus, P. Aditya, and F. Yan, “Citadel: Protecting data privacy and model confidentiality for collaborative learning,” in Proceedings of the ACM Symposium on Cloud Computing , 2021, pp. 546–561
2021
Later among the works it cites.
R. Liu, L. Garcia, Z. Liu, B. Ou, and M. Srivastava, “Secdeep: Secure and performant on-device deep learning inference framework for mobile and iot devices,” in Proceedings of the International Conference on Internet-of-Things Design and Implementation , 2021, pp. 67–79
2021
Later among the works it cites.
K. Xia, Y. Luo, X. Xu, and S. Wei, “Sgx-fpga: Trusted execution environment for cpu-fpga heterogeneous architecture,” in 2021 58th ACM/IEEE Design Automation Conference (DAC) . IEEE, 2021, pp. 301–306
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
C. Banbury, C. Zhou, I. Fedorov, R. Matas, U. Thakker, D. Gope, V. Janapa Reddi, M. Mattina, and P. Whatmough, “Micronets: Neural network architectures for deploying tinyml applications on commodity microcontrollers,” Proceedings of Machine Learning and Systems , vol. 3, pp. 517–532, 2021
2021
Later among the works it cites.
B. Sudharsan, J. G. Breslin, and M. I. Ali, “Ml-mcu: A framework to train ml classifiers on mcu-based iot edge devices,” IEEE Internet of Things Journal , 2021
2021
Later among the works it cites.
A. Li, J. Sun, P. Li, Y. Pu, H. Li, and Y. Chen, “Hermes: an efficient federated learning framework for heterogeneous mobile clients,” in Proceedings of the 27th Annual International Conference on Mobile Computing and Networking , 2021, pp. 420–437
2021
Later among the works it cites.
J. Zhang, S. Guo, X. Ma, H. Wang, W. Xu, and F. Wu, “Parameterized knowledge transfer for personalized federated learning,” Advances in Neural Information Processing Systems , vol. 34, pp. 10 092–10 104, 2021
2021
Later among the works it cites.
J. Singh and J. Cobbe, “Do le quoc, and zahra tarkhani. 2021. enclaves in the clouds: Legal considerations and broader implications,” Commun. ACM , vol. 64, no. 5, pp. 42–51, 2021
2021
Later among the works it cites.
B. Liu, M. Ding, S. Shaham, W. Rahayu, F. Farokhi, and Z. Lin, “When machine learning meets privacy: A survey and outlook,” ACM Computing Surveys (CSUR) , vol. 54, no. 2, pp. 1–36, 2021
2021
Later among the works it cites.
Y. Shen, X. He, Y. Han, and Y. Zhang, “Model stealing attacks against inductive graph neural networks,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1175–1192
2022
Closest in time.
A. S. Rakin, M. H. I. Chowdhuryy, F. Yao, and D. Fan, “Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1157–1174
2022
Closest in time.
V. Shejwalkar, A. Houmansadr, P. Kairouz, and D. Ramage, “Back to the drawing board: A critical evaluation of poisoning attacks on production federated learning,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1354–1371
2022
Closest in time.
F. Mo, “Privacy-preserving machine learning system at the edge,” Ph.D. dissertation, Imperial College London, 2022
2022
Closest in time.
“Azure confidential computing,” https://azure.microsoft.com/en-gb/solutions/confidential-compute/#overview , accessed: 2022-02-03
2022
Closest in time.
“AWS Nitro Enclaves,” https://aws.amazon.com/ec2/nitro/nitro-enclaves/ , accessed: 2022-02-03
2022
Closest in time.
“Google Cloud Confidential Computing,” https://cloud.google.com/confidential-computing , accessed: 2022-02-03
2022
Closest in time.
S. Mindermann, J. M. Brauner, M. T. Razzak, M. Sharma, A. Kirsch, W. Xu, B. Höltgen, A. N. Gomez, A. Morisot, S. Farquhar et al. , “Prioritized training on points that are learnable, worth learning, and not yet learnt,” in International Conference on Machine Learning . PMLR, 2022, pp. 15 630–15 649
2022
Closest in time.
2022
Closest in time.
M. Li, L. Wilke, J. Wichelmann, T. Eisenbarth, R. Teodorescu, and Y. Zhang, “A systematic look at ciphertext side channels on amd sev-snp,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 2022, pp. 1541–1541
2022
Closest in time.
H. Xia, D. Zhang, W. Liu, I. Haller, B. Sherwin, and D. Chisnall, “A secret-free hypervisor: Rethinking isolation in the age of speculative vulnerabilities,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 2022, pp. 1544–1544
2022
Closest in time.
Y. Jia, S. Liu, W. Wang, Y. Chen, Z. Zhai, S. Yan, and Z. He, “ { \{ HyperEnclave } \} : An open and cross-platform trusted execution environment,” in 2022 USENIX Annual Technical Conference (USENIX ATC 22) , 2022, pp. 437–454
2022
Closest in time.
X. Li, X. Li, C. Dall, R. Gu, J. Nieh, Y. Sait, and G. Stockwell, “Design and verification of the arm confidential compute architecture,” in 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22) , 2022, pp. 465–484
2022
Closest in time.
A. Kumar, R. Tourani, M. Vij, and S. Srikanteswara, “Sclera: A framework for privacy-preserving mlaas at the pervasive edge,” in 2022 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops) . IEEE, 2022, pp. 175–180
2022
Closest in time.
Z. Yang, Z. Yuan, S. Jin, X. Chen, L. Sun, X. Du, W. Li, and H. Zhang, “Fsaflow: Lightweight and fast dynamic path tracking and control for privacy protection on android using hybrid analysis with state-reduction strategy,” in Proceedings of the 43rd IEEE Symposium on Security and Privacy (SP), IEEE, San Francisco, CA, USA , 2022, pp. 23–25
2022
Closest in time.
S. Park, S. Kim, and Y.-s. Lim, “Fairness audit of machine learning models with confidential computing,” in Proceedings of the ACM Web Conference 2022 , 2022, pp. 3488–3499
2022
Closest in time.
W. Hua, M. Umar, Z. Zhang, and G. E. Suh, “Guardnn: secure accelerator architecture for privacy-preserving deep learning,” in Proceedings of the 59th ACM/IEEE Design Automation Conference , 2022, pp. 349–354
2022
Closest in time.
T. Shen, J. Qi, J. Jiang, X. Wang, S. Wen, X. Chen, S. Zhao, S. Wang, L. Chen, X. Luo et al. , “ { \{ SOTER } \} : Guarding black-box inference for general neural networks at the edge,” in 2022 USENIX Annual Technical Conference (USENIX ATC 22) , 2022, pp. 723–738
2022
Closest in time.
Y. Deng, C. Wang, S. Yu, S. Liu, Z. Ning, K. Leach, J. Li, S. Yan, Z. He, J. Cao et al. , “Strongbox: A gpu tee on arm endpoints,” in Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security , 2022, pp. 769–783
2022
Closest in time.
M. F. Babar and M. Hasan, “Real-time scheduling of trustzone-enabled dnn workloads,” in Proceedings of the 4th Workshop on CPS & IoT Security and Privacy , 2022, pp. 63–69
2022
Closest in time.
F. Mo, H. Haddadi, K. Katevas, E. Marin, D. Perino, and N. Kourtellis, “Ppfl: Enhancing privacy in federated learning with confidential computing,” GetMobile: Mobile Computing and Communications , vol. 25, no. 4, pp. 35–38, 2022
2022
Closest in time.
M. Zhao, M. Gao, and C. Kozyrakis, “Shef: shielded enclaves for cloud fpgas,” in Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems , 2022, pp. 1070–1085
2022
Closest in time.
M. Andersch, G. Palmer, R. Krashinsky, N. Stam, V. Mehta, G. Brito, and S. Ramaswamy, “Nvidia hopper architecture in-depth,” 2022
2022
Closest in time.
Z. Tarkhani, “Secure programming with dispersed compartments,” Ph.D. dissertation, University of Cambridge, 2022
2022
Closest in time.
R. Zhang, J. Liu, Y. Ding, Z. Wang, Q. Wu, and K. Ren, ““adversarial examples” for proof-of-learning,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1408–1422
2022
Closest in time.
N. Lukas, E. Jiang, X. Li, and F. Kerschbaum, “Sok: How robust is image classification deep neural network watermarking?” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 787–804
2022
Closest in time.
A. Akram, V. Akella, S. Peisert, and J. Lowe-Power, “Sok: Limitations of confidential computing via tees for high-performance compute systems,” in 2022 IEEE International Symposium on Secure and Private Execution Environment Design (SEED) . IEEE, 2022, pp. 121–132
2022
Closest in time.
S. Zhao, M. Li, Y. Zhangyz, and Z. Lin, “vsgx: Virtualizing sgx enclaves on amd sev,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 321–336
2022
Closest in time.
2022
Closest in time.
H. Hu, Z. Salcic, L. Sun, G. Dobbie, P. S. Yu, and X. Zhang, “Membership inference attacks on machine learning: A survey,” ACM Computing Surveys (CSUR) , vol. 54, no. 11s, pp. 1–37, 2022
2022
Closest in time.
“AI Model Lifecycle Management: Overview,” https://www.ibm.com/cloud/blog/ai-model-lifecycle-management-overview , accessed: 2023-02-23
2023
Closest in time.
“Securing Artificial Intelligence (SAI) Problem Statement,” https://www.etsi.org/deliver/etsi_gr/SAI/001_099/004/01.01.01_60/gr_SAI004v010101p.pdf , accessed: 2023-02-23
2023
Closest in time.
D. Kaplan, “Hardware vm isolation in the cloud: Enabling confidential computing with amd sev-snp technology,” Queue , vol. 21, no. 4, pp. 49–67, 2023
2023
Closest in time.
2023
Closest in time.
R. Sahita, V. Shanbhogue, A. Bresticker, A. Khare, A. Patra, S. Ortiz, D. Reid, and R. Kanwal, “Cove: Towards confidential computing on risc-v platforms,” in Proceedings of the 20th ACM International Conference on Computing Frontiers , 2023, pp. 315–321
2023
Closest in time.
M. Brossard, G. Bryant, B. El Gaabouri, X. Fan, A. Ferreira, E. Grimley-Evans, C. Haster, E. Johnson, D. Miller, F. Mo et al. , “Private delegated computations using strong isolation,” IEEE Transactions on Emerging Topics in Computing , 2023
2023
Closest in time.
M. Poltavtseva and E. Rudnitskaya, “Confidentiality of machine learning models,” Automatic Control and Computer Sciences , vol. 57, no. 8, pp. 975–982, 2023
2023
Closest in time.
2023
Closest in time.
K. Vaswani, S. Volos, C. Fournet, A. N. Diaz, K. Gordon, B. Vembu, S. Webster, D. Chisnall, S. Kulkarni, G. Cunningham et al. , “Confidential computing within an { \{ AI } \} accelerator,” in 2023 USENIX Annual Technical Conference (USENIX ATC 23) , 2023, pp. 501–518
2023
Closest in time.
H. Mai, J. Zhao, H. Zheng, Y. Zhao, Z. Liu, M. Gao, C. Wang, H. Cui, X. Feng, and C. Kozyrakis, “Honeycomb: Secure and efficient { \{ GPU } \} executions via static validation,” in 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23) , 2023, pp. 155–172
2023
Closest in time.
M. S. Islam, M. Zamani, C. H. Kim, L. Khan, and K. W. Hamlen, “Confidential execution of deep learning inference at the untrusted edge with arm trustzone,” in Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy , 2023, pp. 153–164
2023
Closest in time.
J. Wang, Y. Wang, and N. Zhang, “Secure and timely gpu execution in cyber-physical systems,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security , 2023, pp. 2591–2605
2023
Closest in time.
K. Lee, M. Yan, J. Emer, and A. Chandrakasan, “Secureloop: Design space exploration of secure dnn accelerators,” in Proceedings of the 56th Annual IEEE/ACM International Symposium on Microarchitecture , 2023, pp. 194–208
2023
Closest in time.
Z. Tarkhani and A. Madhavapeddy, “Information flow tracking for heterogeneous compartmentalized software,” in Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses , 2023, pp. 564–579
2023
Closest in time.
S. Chen, Z. Lin, and Y. Zhang, “Controlled Data Races in Enclaves: Attacks and Detection,” in 32st USENIX Security Symposium (USENIX Security 23) . USENIX Association, 2023
2023
Closest in time.
2023
Closest in time.
A. Salem, G. Cherubin, D. Evans, B. Köpf, A. Paverd, A. Suri, S. Tople, and S. Zanella-Béguelin, “Sok: Let the privacy games begin! a unified treatment of data inference privacy in machine learning,” in 2023 IEEE Symposium on Security and Privacy (SP) . IEEE, 2023, pp. 327–345
2023
Closest in time.
M. Rigaki and S. Garcia, “A survey of privacy attacks in machine learning,” ACM Computing Surveys , vol. 56, no. 4, pp. 1–34, 2023
2023
Closest in time.
M. F. Babar and M. Hasan, “Trusted deep neural execution—a survey,” IEEE Access , 2023
2023
Closest in time.
A. Vassilev, A. Oprea, A. Fordyce, and H. Andersen, “Adversarial machine learning: A taxonomy and terminology of attacks and mitigations,” 2024
2024
Closest in time.
“Veracruz: Privacy-Preserving Collaborative Compute,” https://veracruz-project.com/ , accessed: 2024-02-07
2024
Closest in time.
“Trusted execution environment: Getting started with op-tee on i.mx processors,” https://www.nxp.com/design/training/trusted-execution-environment-getting-started-with-op-tee-on-i-mx-processors:TIP-TRUSTED-EXECUTION-ENVIRONMENT-GETTING-STARTED , [Accessed 26-02-2024]
2024
Closest in time.
Microsoft, “Deep dive: Secure orchestration of confidential containers on aks,” https://techcommunity.microsoft.com/t5/linux-and-open-source-blog/deep-dive-secure-orchestration-of-confidential-containers-on/ba-p/4137179 , 2024, accessed: 2024-05-19
2024
Closest in time.
“Confidential gke nodes: Encrypting data in use,” https://cloud.google.com/kubernetes-engine/docs/how-to/confidential-gke-nodes , 2024, accessed: 2024-05-19
2024
Closest in time.
Intel, “SGX intel® xeon® scalable processors,” https://www.intel.com/content/www/us/en/architecture-and-technology/software-guard-extensions-processors.html , [Accessed 26-02-2024]
2024
Closest in time.
Lenovo, “Enabling Intel SGX on Lenovo ThinkSystem Servers,” https://lenovopress.lenovo.com/lp1471.pdf , 2023, [Accessed 26-02-2024]
2024
Closest in time.
“Build Secure, Scalable, and Accelerated Machine Learning Pipelines — intel.com,” https://www.intel.com/content/www/us/en/developer/articles/troubleshooting/build-secure-scalable-accelerate-ml-pipelines.html , [Accessed 26-02-2024]
2024
Closest in time.
“Demetics Protects AI-Based Medical Innovation with Intel SGX — intel.com,” https://www.intel.com/content/www/us/en/newsroom/news/demetics-protects-ai-based-medical-innovation-sgx.html , [Accessed 26-02-2024]
2024
Closest in time.
“Alibaba Builds End-to-End PPML Solution — intel.com,” https://www.intel.com/content/www/us/en/customer-spotlight/stories/alibaba-cloud-ppml-customer-story.html , [Accessed 26-02-2024]
2024
Closest in time.
J. Weng, S. Yao, Y. Du, J. Huang, J. Weng, and C. Wang, “Proof of unlearning: Definitions and instantiation,” IEEE Transactions on Information Forensics and Security , 2024
2024
Closest in time.
C. Wang, F. Zhang, Y. Deng, K. Leach, J. Cao, Z. Ning, S. Yan, and Z. He, “Cage: Complementing arm cca with gpu extensions,” in Network and Distributed System Security (NDSS) Symposium 2024 , 2024
2024
Closest in time.
“Intel® tdx full report,” https://services.google.com/fh/files/misc/intel_tdx_-_full_report_041423.pdf , 2023, accessed: 2024-05-19
2024
Closest in time.
“Intel-sa-01036: Intel® tdx module software advisory,” https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html , 2024, accessed: 2024-05-19
2024
Closest in time.
S. Siby, S. Abdollahi, M. Maheri, M. Kogias, and H. Haddadi, “Guarantee: Towards attestable and private ml with cca,” in Proceedings of the 4th Workshop on Machine Learning and Systems , 2024, pp. 1–9
2024
Closest in time.
“Nvidia blackwell platform arrives to power a new era of computing,” https://nvidianews.nvidia.com/news/nvidia-blackwell-platform-arrives-to-power-a-new-era-of-computing , 2024, accessed: 2024-05-19
2024
Closest in time.
P.-C. Cheng, W. Ozga, E. Valdez, S. Ahmed, Z. Gu, H. Jamjoom, H. Franke, and J. Bottomley, “Intel tdx demystified: A top-down approach,” ACM Computing Surveys , vol. 56, no. 9, pp. 1–33, 2024
2024
Closest in time.
“California consumer privacy act (ccpa),” https://oag.ca.gov/privacy/ccpa , 2024
2024
Closest in time.
“The eu artificial intelligence act,” https://artificialintelligenceact.eu/ , 2024
2024
Closest in time.
J. Jia, Y. Liu, and N. Z. Gong, “Badencoder: Backdoor attacks to pre-trained encoders in self-supervised learning,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 2043–2059
2059
Closest in time.