Pith. sign in

REVIEW 4 major objections 7 minor 168 references

TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models

T0 review · 4 major / 7 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read TEESlice proposes partitioning a neural network before training so that only small private slices are shielded, matching whole-model protection at a fraction of the computational cost.

desk verdict Partition-before-training is a real step forward, but the security-equivalence claim needs a test the paper doesn't run. read the letter →

arxiv 2411.09945 v1 pith:PG6RYL23 submitted 2024-11-15 cs.CR cs.AIcs.LG

classification cs.CRcs.AIcs.LG
keywords trustedexecutionenvironmentmodelpartitioningstealingmembershipinferencepartition-before-trainingone-timepadlow-rankadaptationlargelanguagemodels
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

TEESlice claims that existing TEE-shielded DNN partitioning (TSDP) schemes break down when the attacker can download public pre-trained models, because the offloaded weights were trained on private data and carry near-white-box information. The paper's fix is to partition before training: keep a public pre-trained backbone running on the GPU and confine all private training to small 'slices' inside the TEE. It reports that this reaches the security level of shielding the entire model at about one-tenth the computational cost. If true, on-device models could get black-box-level protection against model stealing and membership inference while running most inference on an untrusted GPU.

What carries the argument

The carrying object is the hybrid model: a public pre-trained backbone with small private slices inserted between its layers. The carrying mechanism is partition-before-training plus iterative slice pruning, where a densely sliced model is trained so each slice carries an importance scalar (or, for LLMs, is scored by the weight magnitude of its LoRA adapters); slices with the smallest importance are pruned and the model retrained until accuracy falls below a 1% threshold, automatically finding the configuration that minimizes TEE computation. The TEE-GPU channel is protected by one-time-pad encryption of quantized features—valid because the offloaded layers are linear, so the pad can be precomputed—and by Freivalds' algorithm, a probabilistic check that the GPU computed the linear layer correctly. For transformer attention, the inter-feature product cannot be protected by a one-time pad, so the mechanism substitutes linear attention (a weight-feature product) under a trainable interpolation factor, and outsources that instead.

What would settle it

A decisive experiment is to take a TEESlice hybrid model trained on a task close to the backbone's pre-training distribution, drop the slices, and measure the model-stealing accuracy of a surrogate trained from the backbone alone; whenever that accuracy approaches the accuracy of a surrogate trained from the full hybrid model, the claim that the slices are the exclusive carriers of private functionality fails, and with it the 'full model protection' guarantee.

Watch

Extended reading notes

Core claim

Existing TSDP solutions train the whole model on private data before partitioning, so private information is spread across the offloaded weights; when the attacker initializes a surrogate with a public pre-trained model, the paper measures model-stealing accuracy 3.85×–4.56× and membership-inference accuracy 1.16×–1.36× above the black-box baseline. TEESlice reverses the order: it keeps a public pre-trained backbone, trains only small private slices inserted into it, and shields only the slices and the backbone's non-linear layers in the TEE, while the backbone's linear layers run on the GPU under one-time-pad encryption with Freivalds verification. In the paper's evaluation, model-stealing and membership-inference accuracy against TEESlice are statistically indistinguishable from the shielding-whole-model baseline, with an average TEE FLOP cost of 3.44% versus 45.98%–97.02% for prior defenses. The same recipe extends to large models: privacy becomes LoRA adapters pruned by weight magnitude, and attention is replaced by linear attention where needed, yielding TEE FLOP costs around 0.09% for ViT models.

Load-bearing premise

The public backbone, which runs entirely outside the TEE, must not itself be able to perform the private task or leak the private training data, because the paper's security claim rests on the offloaded weights carrying no private information.

Editorial extensions

If this is right

  • On-device CNN models can keep most computation on an untrusted GPU while achieving the same model-stealing and membership-inference resistance as shielding the whole model.
  • The partition-before-training recipe removes the need to search for a security/utility 'sweet spot' per model and dataset, since the private slices are the only sensitive weights by construction.
  • For large language models, the private functionality can be compressed into LoRA slices that consume about 0.09% of the model's FLOPs, with accuracy loss under about 0.24% in the reported ViT experiments.
  • One-time-pad encryption plus Freivalds verification means the GPU not only cannot learn the private features but also cannot silently corrupt the outsourced linear computations.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper: the reported backbone-only accuracies (e.g., 51.32% vs. 52.27% for AlexNet on UTKFace) suggest that when the private task is close to the public pre-training distribution, the backbone may already carry most of the functionality; a natural security metric is the gap between hybrid and backbone-only attack accuracy.
  • Beyond the paper: because the slices are the only components trained on private data, the recipe could be tested against other white-box attacks such as model inversion or training-data extraction, which the paper does not evaluate.
  • Beyond the paper: the linear-attention substitution changes the model's behavior on long-context tasks, so a testable extension is whether TEESlice's security guarantee persists when linear attention materially degrades quality and the interpolation factor must favor the original attention.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. The paper studies TEE-shielded DNN partitioning (TSDP) under an adversary who can use public pre-trained models and public datasets. It first surveys and taxonomizes 17 prior TSDP papers, then empirically evaluates five representative schemes against model stealing (MS) and membership inference (MIA), finding that all leak substantially more than a black-box baseline. The authors then propose TEESlice, a partition-before-training scheme: a public pre-trained backbone is frozen, small private slices are trained on private data and executed inside a TEE, and GPU-communicated features are protected with one-time-pad encryption and Freivalds' verification. They report that TEESlice achieves black-box-level MS/MIA accuracy across 20 CNN settings, with roughly 3.44% of FLOPs inside the TEE on average (about 10x lower than prior TSDP solutions), and they extend the design to ViT-style models via LoRA slices and to BART on NLP tasks. The paper includes a real SGX+GPU prototype and reports latency and memory measurements.

Significance. If the central claim holds, TEESlice is a solid engineering contribution: it gives a principled way to confine private information to TEE-resident slices while offloading the bulk of computation to an untrusted GPU, and it provides the first systematic demonstration that prior training-before-partition TSDP schemes are insecure against a public-information-aware adversary. The evaluation is broad by the standards of this area (5 CNN architectures, 4 datasets, 20 settings, plus ViT and BART experiments), the authors provide artifacts, and the OTP/Freivalds building blocks are standard and appropriate. The main value is not a new cryptographic primitive but a deployment strategy that converts a white-box model-stealing surface into a label-only surface. However, the security-equivalence claim is currently supported only by the construction (all private slices are in the TEE) plus empirical attack results; it is not supported by any formal or empirical bound on what the public backbone itself reveals or already encodes about the private task. That gap, and the ambiguity in how the black-box baseline is defined, are load-bearing for the paper's headline claim.

major comments (4)
  1. [Sec. 6.1, Sec. 7.1, Table 6] The central security assertion is that the public backbone is 'never trained using private data and thus, no information is leaked' (Sec. 6.1). This is load-bearing, yet the paper provides no test of whether the public backbone already performs the private task or can be adapted to it with public data alone. Table 6 shows that a backbone-only surrogate often achieves MS accuracy close to (and sometimes higher than) the hybrid-model surrogate, e.g., AlexNet/UTKFace 51.32% vs. 52.27% and VGG16_BN/UTKFace 52.54% vs. 48.37%. Because the threat model explicitly allows an attacker with public pre-trained models and public datasets (Sec. 2.2), the attacker could fine-tune or linear-probe the public backbone on public data; this quantity is never measured. Without either a formal bound on backbone leakage or an empirical evaluation of adapted-backbone accuracy on the private task, the claim of 'full model protection' is not established.
  2. [Sec. 4.3, Tables 3/4] The security comparison between TEESlice and the black-box baseline is not apples-to-apples. The black-box baseline is defined against the original victim model M_vic, which is trained entirely on private data, while TEESlice protects the hybrid model M_hyb, which combines a public backbone with private slices. These are different models with different accuracies (Table 7), so equal MS/MIA accuracy against them does not demonstrate equivalent protection. The paper should report a black-box baseline against M_hyb itself (i.e., an attacker who queries M_hyb only through labels and cannot see the backbone or slices), and then compare TEESlice's attack accuracy to that baseline. Without this matched comparison, the statement that TEESlice 'achieves a security level equivalent to the shielding-whole-model baseline' is ambiguous.
  3. [Sec. 6.4, Table 11] The 'large language model' scalability claim is not fully supported by the experiments. Section 6.4 and Table 11 evaluate TEESlice on ViT image classifiers (ViT-B/L on CIFAR10/100 and STL10), not on language models; the only NLP evaluation is in Sec. 7.5 with BART, and there the paper reports MS accuracy but no security cost, no TEE/GPU deployment details, and no comparison of private-slice FLOPs against the shielding-whole-model baseline. Since the abstract and introduction claim that TEESlice 'can compress the private functionalities of the large language model to lightweight slices,' the paper should either provide an actual decoder-only LLM evaluation (e.g., with LoRA on a generative task) or substantially soften the claim to cover vision transformers and encoder-only NLP models.
  4. [Sec. 6.2.2, Eq. (3)] Equation (3) as written is not correct over the integers. From h_e = (h + r) % p, the equality g(h_e) - g(r) = g((h+r)%p - r%p) does not equal g(h) in general; for example, with p=256, h=200, r=100, the integer difference is -56, not 200. The identity only holds modulo p, so the decryption must reduce the result modulo p (or the computation must be defined over the field Z_p). The claim that 'the last equation holds as long as p > 2^8' is insufficient; one needs p > 2^8 and a final modular reduction, or a guarantee that h+r never wraps. This is a technical error in the core OTP derivation, although the underlying OTP mechanism is standard and fixable.
minor comments (7)
  1. [Sec. 3, first paragraph] The text says 'Both Membership Inference (MS) and Model Inversion Attacks (MIA) are carried out'; this should read 'Model Stealing (MS) and Membership Inference Attacks (MIA),' since MS is defined as model stealing elsewhere and model inversion is not evaluated.
  2. [Sec. 3.2, Table 1] The text refers to 'Table 2 summarizes the reviewed papers,' but the table in that section is labeled Table 1; please fix the cross-reference.
  3. [Sec. 7.1, paragraph on additional assumptions] The 'victim-knowing' assumption is dismissed as unrealistic, but the discussion of why it sometimes yields lower MS accuracy than backbone-only is speculative and not backed by a hypothesis test; either add a brief analysis or remove the speculation.
  4. [Sec. 7.1, Fig. 9] Figure 9 shows only CIFAR100 for four models, while the text says the conclusion holds 'for all cases'; please either include the full set of datasets in the figure or state the selection criterion explicitly.
  5. [Sec. 10, 'Differential Privacy' paragraph] The sentence 'DP may provide insufficient privacy [97]' cites a TSDP paper, not a DP-specific analysis; consider replacing with a more directly relevant reference.
  6. [Sec. 6.4, Eq. (13)] The dynamic attention interpolation uses a scalar beta_l per layer, but the paper does not specify how beta_l is initialized, whether it is constrained to [0,1], or how the 'small beta' threshold is chosen during pruning; please add these implementation details.
  7. [Sec. 8] The threats-to-validity section does not mention the possibility that the public backbone already encodes the private task, which is the main limitation identified above; adding this to the external-validity discussion would improve the paper's transparency.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: TEESlice's black-box equivalence is empirically validated, not derived solely from its construction.

full rationale

The paper's central claim—that TEESlice provides protection equivalent to shielding the whole model—is not a circular derivation. The construction does place all privacy-related slices in the TEE and encrypts TEE-GPU features with OTP (Sec 6.2.2), which by design reduces the attacker's surface to black-box queries plus the public backbone. However, the load-bearing question is whether the public backbone itself encodes the private task; this is an empirical property, and the paper tests it directly via the backbone-only assumption in Table 6 and the large-query comparison in Fig 9, showing MS accuracies statistically indistinguishable from the black-box baseline (Wilcoxon p=0.81, Sec 7.1). These experiments could have failed if the backbone leaked the private task, so the security claim has independent content. The explanation in Sec 7.1 that MIA is at random-guess level 'because all the feature communications are encrypted, and the TEE shields all the privacy-related slices' is a post-hoc causal account, not a fitted parameter renamed as a prediction or an equation reduced to its inputs. Self-citations [155]-[159] are used for provenance, terminology, and the prior conference version, not as load-bearing evidence for the security guarantee; the OTP and Freivalds components are standard cryptographic primitives applied with their usual assumptions. The paper's admitted weakness is the absence of a formal bound on what a public backbone can reveal after adaptation; that is a correctness/validity risk, not circularity.

Assumptions & free parameters 7 free parameters · 6 assumptions · 0 invented entities

The central claims rest mainly on domain assumptions about TEE security, the information content of public backbones, and the adequacy of standard cryptographic primitives, plus a set of training hyperparameters (importance scalars, pruning step, tolerance, LoRA rank). The paper contributes no new physical or cryptographic entities; the 'model slices' are a deployment construct whose behavior is measured in the evaluation.

free parameters (7)
  • Slice importance scalar alpha_i^p = not reported (learned)
    Each private slice's output is weighted by a learned importance scalar; pruning uses these scalars (Sec 6.2.1).
  • alpha_setup = 0.05
    Heuristic threshold for initial slice pruning, taken from NetTailor (Sec 6.2.1).
  • Pruning step n = not specified
    Number of slices pruned per round in Algorithm 1/2; affects final slice count and utility.
  • Training rounds = not specified
    Total retraining rounds in iterative pruning; affects accuracy and utility.
  • Accuracy tolerance delta = 0.01 (1%)
    Tolerable accuracy loss bound used to define ACC_tol; controls pruning stopping point.
  • LoRA rank r = 4
    Reduced dimension of LoRA slices in LLM experiments (Sec 7.4.1).
  • Attention interpolation beta_l = learned, not reported
    Trainable scalar controlling replacement of softmax attention with linear attention; regularized in loss (Sec 6.4).
assumptions (6)
  • domain assumption TEE provides a secure execution environment and side-channel attacks are out of scope
    Sec 2.1 states data/code inside TEE are secure and side-channel attacks are not considered.
  • domain assumption The public backbone is never trained on private data, so it contains no private information
    Core to partition-before-training security argument; Sec 6.1 states offloaded weights are never trained using private data.
  • standard math One-time pad and Freivalds' algorithm provide confidentiality and integrity for TEE-GPU communication
    Standard cryptographic primitives; underlying security not proven in this paper.
  • standard math The attacker cannot decrypt OTP-encrypted features without the one-time mask
    Standard information-theoretic OTP assumption; Sec 6.2.2.
  • domain assumption Linear attention can replace softmax attention with acceptable accuracy loss
    Empirical assumption validated only on ViT/BART; Sec 6.4.
  • domain assumption Model owner can train private slices using private data without exposing them to GPU
    Training phase is assumed secure; deployment is the focus.

how reviews work

0 comments
Cite this review

Pith. "Pith review of TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models." pith.science (2026). https://pith.science/paper/PG6RYL23

@misc{pith2026241109945,
  author       = {Pith},
  title        = {Pith review of: TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/PG6RYL23}},
  note         = {Machine review of arXiv:2411.09945}
}
read the original abstract

Trusted Execution Environments (TEE) are used to safeguard on-device models. However, directly employing TEEs to secure the entire DNN model is challenging due to the limited computational speed. Utilizing GPU can accelerate DNN's computation speed but commercial widely-available GPUs usually lack security protection. To this end, scholars introduce TSDP, a method that protects privacy-sensitive weights within TEEs and offloads insensitive weights to GPUs. Nevertheless, current methods do not consider the presence of a knowledgeable adversary who can access abundant publicly available pre-trained models and datasets. This paper investigates the security of existing methods against such a knowledgeable adversary and reveals their inability to fulfill their security promises. Consequently, we introduce a novel partition before training strategy, which effectively separates privacy-sensitive weights from other components of the model. Our evaluation demonstrates that our approach can offer full model protection with a computational cost reduced by a factor of 10. In addition to traditional CNN models, we also demonstrate the scalability to large language models. Our approach can compress the private functionalities of the large language model to lightweight slices and achieve the same level of protection as the shielding-whole-model baseline.

Figures

Figures reproduced from arXiv: 2411.09945 by the authors.

Figure 1
Figure 1. An illustration of TSDP solutions. 2.2 Threat Model Defender’s Goal. TSDP solutions (and the defenders) aim to provide a black-box label-only protection against MS/MIA by shielding partial DNN models inside TEEs. The motivation is to reduce inference latency of the straightforward black-box protection that shields the whole model inside TEEs (increase latency by up to 50× [137]). The security goal of TSDP solutions … view at source ↗
Figure 2
Figure 2. Two types of DNN partition. computing, machine learning, and computer systems. We also included the papers that are cited by top-tier papers. In total, we identified and reviewed 17 papers [PITH_FULL_IMAGE:figures/full_fig_p008_2.png] view at source ↗
Figure 3
Figure 3. An illustration of different TSDP solutions on a four-layer DNN. [PITH_FULL_IMAGE:figures/full_fig_p014_3.png] view at source ↗
Figures from the paper (6 more)
Figure 4
Figure 4. Figure 4: A three-phase attack pipeline. Surrogate Model Initialization. Steps in our attack pipeline are automated except for the first step, surrogate model initialization (P𝑖 ). To run the attacks, attackers first need to construct 𝑀init with the exposed knowledge in the publ…
Figure 5
Figure 5. Figure 5: Correlation between %𝐹 𝐿𝑂𝑃𝑠 and inference latency on Occlum [123]. Inference time is averaged over 10 runs. shields shallow layers, we put different amounts of consecutive layers starting from the DNN input layer. For ResNet models, we use the residual layers as the di…
Figure 6
Figure 6. Figure 6: Model stealing results in terms of accuracy, fidelity, and ASR. [PITH_FULL_IMAGE:figures/full_fig_p021_6.png]
Figure 7
Figure 7. Figure 7: Membership inference results of generalization gap, confidence gap, confidence-based membership [PITH_FULL_IMAGE:figures/full_fig_p022_7.png]
Figure 8
Figure 8. Figure 8: The comparison between TEESlice and prior TSDP solutions. For TEESlice, all information generated by private data will be handled in the TEE. 6.1 Approach Overview We propose TEESlice, a novel partitioning strategy that offloads DNN layers with no private information t…
Figure 9
Figure 9. Figure 9: Comparison of TEESlice and the black-box protection against MS attacks with different sizes of queried data. We report the accuracy of 𝑀sur, where the first row represents TEESlice and the second row is for the black-box baseline. The MS attack performance is indisting…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

168 extracted references · 28 canonical work pages

  1. [1]

    Knockoff Nets Demo Code

    2019. Knockoff Nets Demo Code. https://github.com/tribhuvanesh/knockoffnets

  2. [2]

    ML-Doctor Demo Code

    2022. ML-Doctor Demo Code. https://github.com/liuyugeng/ML-Doctor

  3. [3]

    One-time pad

    2022. One-time pad. https://en.wikipedia.org/wiki/One-time_pad

  4. [4]

    Android 7.0 Compatibility Definition

    2023. Android 7.0 Compatibility Definition. https://source.android.com/docs/compatibility/7.0/android-7.0-cdd#9

  5. [5]

    Artifact

    2023. Artifact. https://github.com/ziqi-zhang/TEESlice-artifact

  6. [6]

    Full Supplementary

    2023. Full Supplementary. https://sites.google.com/view/tsdp-teeslice/home

  7. [7]

    OP-TEE documentation Raspberry Pi 3

    2023. OP-TEE documentation Raspberry Pi 3. https://optee.readthedocs.io/en/latest/building/devices/rpi3.html

  8. [8]

    Artifact for LLM

    2024. Artifact for LLM. https://anonymous.4open.science/r/TEESlice_LLM

Show all 168 references
  1. [9]

    Tiago Alves. 2004. Trustzone: Integrated hardware and software security. White paper (2004)

  2. [10]

    Arm. 2021. Introducing Arm Confidential Compute Architecture. https://developer.arm.com/documentation/den0125/ 0200/Arm-CCA-Extensions

  3. [11]

    Aref Asvadishirehjini, Murat Kantarcioglu, and Bradley A. Malin. 2022. GINN: Fast GPU-TEE Based Integrity for Neural Network Training. In CODASPY ’22: Twelveth ACM Conference on Data and Application Security and Privacy, Baltimore, MD, USA, April 24 - 27, 2022 , Anupam Joshi, ...

  4. [12]

    Ahmad Atamli-Reineh and Andrew Martin. 2015. Securing application with software partitioning: A case study using sgx. In International Conference on Security and Privacy in Communication Systems . Springer, 605–621

  5. [13]

    Ahmad Atamli-Reineh, Andrew Paverd, Giuseppe Petracca, and Andrew Martin. 2017. A framework for application partitioning using trusted execution environments. Concurrency and Computation: Practice and Experience 29, 23 (2017), e4130

  6. [14]

    Eugene Bagdasaryan, Omid Poursaeed, and Vitaly Shmatikov. 2019. Differential Privacy Has Disparate Impact on Model Accuracy. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8-14, 2...

  7. [15]

    Soroush Bateni and Cong Liu. 2020. NeuOS: A Latency-Predictable Multi-Dimensional Optimization Framework for DNN-driven Autonomous Systems. In 2020 USENIX Annual Technical Conference, USENIX ATC 2020, July 15-17, 2020 , Ada Gavrilovska and Erez Zadok (Eds.). USENIX Association...

  8. [16]

    Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16, 2019 , Nadia Henin...

  9. [19]

    Nicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks. In 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16, 2019 , Nadia Henin...

  10. [20]

    Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020. Exploring Connections Between Active Learning and Model Extraction. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 , Srdjan Capkun and Franziska Roesner ...

  11. [21]

    Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten-Hwang Lai. 2020. SgxPectre: Stealing Intel Secrets From SGX Enclaves via Speculative Execution. IEEE Secur. Priv. 18, 3 (2020), 28–37. https: //doi.org/10.1109/MSEC.2019.2963021 ACM Trans. Softw. Eng....

  12. [22]

    Guoxing Chen, Wenhao Wang, Tianyu Chen, Sanchuan Chen, Yinqian Zhang, XiaoFeng Wang, Ten-Hwang Lai, and Dongdai Lin. 2018. Racing in Hyperspace: Closing Hyper-Threading Side Channels on SGX with Contrived Data Races. In 2018 IEEE Symposium on Security and Privacy, SP 2018, Pro...

  13. [23]

    Jialuo Chen, Jingyi Wang, Tinglan Peng, Youcheng Sun, Peng Cheng, Shouling Ji, Xingjun Ma, Bo Li, and Dawn Song

  14. [24]

    Min Chen, Zhikun Zhang, Tianhao Wang, Michael Backes, Mathias Humbert, and Yang Zhang. 2021. When Machine Unlearning Jeopardizes Privacy. In CCS ’21: 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, Republic of Korea, November 15 - 19, 2021 , ...

  15. [25]

    Yufei Chen, Chao Shen, Cong Wang, and Yang Zhang. 2022. Teacher Model Fingerprinting Attacks Against Trans- fer Learning. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022 , Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Associatio...

  16. [26]

    Ng, and Honglak Lee

    Adam Coates, Andrew Y. Ng, and Honglak Lee. 2011. An Analysis of Single-Layer Networks in Unsupervised Feature Learning. In Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics, AISTATS 2011, Fort Lauderdale, USA, April 11-13, 2011 (...

  17. [27]

    Papers With Code. 2018. Image Classification on STL-10. https://paperswithcode.com/paper/hybridnet-classification- and-reconstruction

  18. [28]

    Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. ImageNet: A large-scale hierarchical image database. In 2009 IEEE Computer Society Conference on Computer Vision and Pattern Recognition (CVPR 2009), 20-25 June 2009, Miami, Florida, USA . IEEE Comput...

  19. [29]

    Shrey Desai, Geoffrey Goh, Arun Babu, and Ahmed Aly. 2020. Lightweight Convolutional Representations for On-Device Natural Language Processing. ArXiv abs/2002.01535 (2020). https://api.semanticscholar.org/CorpusID: 211032126

  20. [30]

    Wentao Dong and Cong Wang. 2023. Poster: Towards Lightweight TEE-Assisted MPC. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security . 3609–3611

  21. [31]

    Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2021. An Image is Worth 16x16 Words: Transformers for Image Recognit...

  22. [32]

    Utsav Drolia, Katherine Guo, and Priya Narasimhan. 2017. Precog: prefetching for image recognition applications at the edge. In Proceedings of the Second ACM/IEEE Symposium on Edge Computing(San Jose, California)(SEC ’17). Association for Computing Machinery, New York, NY, USA...

  23. [33]

    Cynthia Dwork and Aaron Roth. 2014. The Algorithmic Foundations of Differential Privacy. Found. Trends Theor. Comput. Sci. (2014)

  24. [34]

    Tarek Elgamal and Klara Nahrstedt. 2020. Serdab: An IoT Framework for Partitioning Neural Networks Computation across Multiple Enclaves. In 20th IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGRID 2020, Melbourne, Australia, May 11-14, 2020 . IEEE...

  25. [35]

    Shufan Fei, Zheng Yan, Wenxiu Ding, and Haomeng Xie. 2021. Security vulnerabilities of SGX and countermeasures: A survey. ACM Computing Surveys (CSUR) 54, 6 (2021), 1–36

  26. [36]

    Rusins Freivalds. 1977. Probabilistic Machines Can Use Less Running Time.. In IFIP congress

  27. [37]

    Lauter, Michael Naehrig, and John Wernsing

    Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin E. Lauter, Michael Naehrig, and John Wernsing. 2016. CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy. In Proceedings of the 33nd International Conference on Machine Learning, ICML 20...

  28. [38]

    Google. 2020. Tensorflow Hub. https://www.tensorflow.org/hub

  29. [39]

    Google. 2020. TensorFlow Model Garden. https://github.com/tensorflow/models

  30. [40]

    Google. 2020. Tensorflow Transfer Learning API. https://www.tensorflow.org/tutorials/images/transfer_learning

  31. [41]

    Daniel Gruss, Julian Lettner, Felix Schuster, Olga Ohrimenko, István Haller, and Manuel Costa. 2017. Strong and Efficient Cache Side-Channel Protection using Hardware Transactional Memory. In 26th USENIX Security Symposium, USENIX Security 2017, Vancouver, BC, Canada, August 1...

  32. [42]

    Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Hani Jamjoom, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy. 2018. Confidential inference via ternary model partitioning. arXiv:1807.00969 (2018)

  33. [43]

    Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Maximilian Augustin, Michael Backes, and Mario Fritz

  34. [44]

    Hanieh Hashemi, Yongqin Wang, and Murali Annavaram. 2021. DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted Hardware. In MICRO ’21: 54th Annual IEEE/ACM International Symposium on Microarchitecture, Virtual Event, Greece, Octo...

  35. [45]

    Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016 . IEEE Computer Society, 770–778. https://doi.org/10.1...

  36. [46]

    Jiahui Hou, Huiqi Liu, Yunxin Liu, Yu Wang, Peng-Jun Wan, and Xiang-Yang Li. 2022. Model Protection: Real-Time Privacy-Preserving Inference Service for Model Privacy at the Edge. IEEE Trans. Dependable Secur. Comput. 19, 6 (2022), 4270–4284. https://doi.org/10.1109/TDSC.2021.3126315

  37. [47]

    Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen

    Edward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen

  38. [48]

    Yu, and Xuyun Zhang

    Hongsheng Hu, Zoran Salcic, Lichao Sun, Gillian Dobbie, Philip S. Yu, and Xuyun Zhang. 2022. Membership Inference Attacks on Machine Learning: A Survey. ACM Comput. Surv. 54, 11s (2022), 235:1–235:37. https://doi.org/10.1145/ 3523273

  39. [49]

    Li Hu, Jin Li, Guanbiao Lin, Shiyu Peng, Zhenxin Zhang, Yingying Zhang, and Changyu Dong. 2023. Defending Against Membership Inference Attacks With High Utility by GAN. IEEE Transactions on Dependable and Secure Computing 20, 3 (2023), 2144–2157. https://doi.org/10.1109/TDSC.2...

  40. [50]

    In The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 2022

    LoRA: Low-Rank Adaptation of Large Language Models. In The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 2022 . OpenReview.net. https://openreview.net/forum?id= nZeVKeeFYf9

  41. [51]

    Xing Hu, Ling Liang, Shuangchen Li, Lei Deng, Pengfei Zuo, Yu Ji, Xinfeng Xie, Yufei Ding, Chang Liu, Timothy Sherwood, and Yuan Xie. 2020. DeepSniffer: A DNN Model Extraction Framework Based on Learning Architectural Hints. In ASPLOS ’20: Architectural Support for Programming...

  42. [52]

    Edward Suh

    Weizhe Hua, Muhammad Umar, Zhiru Zhang, and G. Edward Suh. 2020. GuardNN: Secure DNN Accelerator for Privacy-Preserving Deep Learning. CoRR abs/2008.11632 (2020). arXiv:2008.11632 https://arxiv.org/abs/2008.11632

  43. [53]

    Li Hu, Anli Yan, Hongyang Yan, Jin Li, Teng Huang, Yingying Zhang, Changyu Dong, and Chunsheng Yang. 2023. Defenses to Membership Inference Attacks: A Survey. ACM Comput. Surv. 56, 4, Article 92 (nov 2023), 34 pages. https://doi.org/10.1145/3620667

  44. [54]

    Hongwei Huang, Weiqi Luo, Guoqiang Zeng, Jian Weng, Yue Zhang, and Anjia Yang. 2022. DAMIA: Leveraging Domain Adaptation as a Defense Against Membership Inference Attacks. IEEE Transactions on Dependable and Secure Computing 19, 5 (2022), 3183–3199. https://doi.org/10.1109/TDS...

  45. [55]

    Pengzhi Huang, Thang Hoang, Yueying Li, Elaine Shi, and G Edward Suh. 2022. STAMP: Lightweight TEE-Assisted MPC for Efficient Privacy-Preserving Machine Learning. arXiv preprint arXiv:2210.10133 (2022)

  46. [56]

    Edward Suh

    Weizhe Hua, Zhiru Zhang, and G. Edward Suh. 2018. Reverse engineering convolutional neural networks through side-channel information leaks. In Proceedings of the 55th Annual Design Automation Conference, DAC 2018, San Francisco, CA, USA, June 24-29, 2018 . ACM, 4:1–4:6. https:...

  47. [57]

    Intel. 2021. Intel Architecture Memory Encryp- tion Technologies Specification. https://software.intel.com/content/ dam/develop/external/us/en/documents-tps/multi-key-total-memory-encryption-spec.pdf

  48. [58]

    Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. 2020. High Accuracy and High Fidelity Extraction of Neural Networks. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020, Srdjan Capkun and Franziska Roesner (Eds....

  49. [59]

    Wei Huang, Yinggui Wang, Anda Cheng, Aihui Zhou, Chaofan Yu, and Lei Wang. 2024. A Fast, Performant, Secure Distributed Training Framework For LLM. In ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 4800–4804

  50. [60]

    Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan. 2019. PRADA: Protecting Against DNN Model Stealing Attacks. In IEEE European Symposium on Security and Privacy, EuroS&P 2019, Stockholm, Sweden, June 17-19, 2019 . IEEE, 512–527. https://doi.org/10.1109/EuroSP.2019.00044

  51. [61]

    Chandrakasan

    Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha P. Chandrakasan. 2018. GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15-17, 2018 , William Enck and Adrienne Porter Fe...

  52. [62]

    Yuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen, Zhengde Zhai, Shoumeng Yan, and Zhengyu He. 2022. HyperEnclave: An Open and Cross-platform Trusted Execution Environment. In 2022 USENIX Annual Technical Conference, USENIX ATC 2022, Carlsbad, CA, USA, July 11-13, 2022 , Jiri Schin...

  53. [63]

    Angelos Katharopoulos, Apoorv Vyas, Nikolaos Pappas, and François Fleuret. 2020. Transformers are rnns: Fast autoregressive transformers with linear attention. In International conference on machine learning . PMLR, 5156–5165

  54. [64]

    Yigitcan Kaya, Sanghyun Hong, and Tudor Dumitras. 2020. On the Effectiveness of Regularization Against Membership Inference Attacks. ArXiv abs/2006.05336 (2020). https://api.semanticscholar.org/CorpusID:219559068

  55. [65]

    David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD memory encryption. White paper (2016)

  56. [66]

    Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 2019 IEEE Symposium on Security and Privacy,...

  57. [67]

    Alex Krizhevsky, Geoffrey Hinton, et al. 2009. Learning multiple layers of features from tiny images. (2009)

  58. [68]

    Kyungtae Kim, Chung Hwan Kim, Junghwan John Rhee, Xiao Yu, Haifeng Chen, Dave (Jing) Tian, and Byoungyoung Lee. 2020. Vessels: efficient and scalable deep learning prediction on trusted processors. In SoCC ’20: ACM Symposium on Cloud Computing, Virtual Event, USA, October 19-2...

  59. [69]

    kuangliu. 2020. Train CIFAR10 with PyTorch. https://github.com/kuangliu/pytorch-cifar

  60. [70]

    Titouan Lazard, Johannes Götzfried, Tilo Müller, Gianni Santinelli, and Vincent Lefebvre. 2018. TEEshift: Protecting Code Confidentiality by Selectively Shifting Functions into TEEs. In Proceedings of the 3rd Workshop on System Software for Trusted Execution (Toronto, Canada) ...

  61. [71]

    Alex Krizhevsky, Ilya Sutskever, and Geoffrey E. Hinton. 2012. ImageNet Classification with Deep Convolutional Neural Networks. In Advances in Neural Information Processing Systems 25: 26th Annual Conference on Neural Information Processing Systems 2012. Proceedings of a meeti...

  62. [72]

    Molloy, and Dong Su

    Taesung Lee, Benjamin Edwards, Ian M. Molloy, and Dong Su. 2019. Defending Against Neural Network Model Stealing Attacks Using Deceptive Perturbations. In 2019 IEEE Security and Privacy Workshops, SP Workshops 2019, San Francisco, CA, USA, May 19-23, 2019 . IEEE, 43–49. https:...

  63. [73]

    Taegyeong Lee, Zhiqi Lin, Saumay Pushp, Caihua Li, Yunxin Liu, Youngki Lee, Fengyuan Xu, Chenren Xu, Lintao Zhang, and Junehwa Song. 2019. Occlumency: Privacy-preserving Remote Deep-learning Inference Using SGX. In The 25th Annual International Conference on Mobile Computing a...

  64. [74]

    Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing. In 26th USENIX Security Symposium, USENIX Security 2017, Vancouver, BC, Canada, August 16-18, 2017 , Engin ...

  65. [75]

    Mike Lewis, Yinhan Liu, Naman Goyal, Marjan Ghazvininejad, Abdelrahman Mohamed, Omer Levy, Veselin Stoyanov, and Luke Zettlemoyer. 2020. BART: Denoising Sequence-to-Sequence Pre-training for Natural Language Generation, Translation, and Comprehension. In Proceedings of the 58t...

  66. [76]

    Mengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth, Radu Teodorescu, and Yinqian Zhang. 2022. A systematic look at ciphertext side channels on AMD SEV-SNP. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 337–351

  67. [77]

    Klas Leino and Matt Fredrikson. 2020. Stolen Memories: Leveraging Model Memorization for Calibrated White-Box Membership Inference. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 , Srdjan Capkun and Franziska Roesner (Eds.). USENIX Association, 160...

  68. [78]

    Zomaya, and Minyi Guo

    Yuepeng Li, Deze Zeng, Lin Gu, Quan Chen, Song Guo, Albert Y. Zomaya, and Minyi Guo. 2021. Lasagna: Accelerating Secure Deep Learning Inference in SGX-enabled Edge Cloud. In SoCC ’21: ACM Symposium on Cloud Computing, Seattle, W A, USA, November 1 - 4, 2021, Carlo Curino, Geor...

  69. [79]

    Zheng Li and Yang Zhang. 2021. Membership Leakage in Label-Only Exposures. In CCS ’21: 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, Republic of Korea, November 15 - 19, 2021, Yongdae Kim, Jong Kim, Giovanni Vigna, and Elaine Shi (Eds.). AC...

  70. [80]

    Qinfeng Li, Zhiqiang Shen, Zhenghan Qin, Yangfan Xie, Xuhong Zhang, Tianyu Du, and Jianwei Yin. 2024. TransLink- Guard: Safeguarding Transformer Models Against Model Stealing in Edge Deployment.arXiv preprint arXiv:2404.11121 ACM Trans. Softw. Eng. Methodol., Vol. 1, No. 1, Ar...

  71. [81]

    Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Dollár, and C

    Tsung-Yi Lin, Michael Maire, Serge J. Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Dollár, and C. Lawrence Zitnick. 2014. Microsoft COCO: Common Objects in Context. In Computer Vision - ECCV 2014 - 13th European Conference, Zurich, Switzerland, September 6-12, 2014...

  72. [82]

    Joshua Lind, Christian Priebe, Divya Muthukumaran, Dan O’Keeffe, Pierre-Louis Aublin, Florian Kelbert, Tobias Reiher, David Goltzsche, David Eyers, Rüdiger Kapitza, et al. 2017. Glamdring: Automatic application partitioning for intel{SGX}. In 2017 USENIX Annual Technical Confe...

  73. [83]

    Ji Lin, Jiaming Tang, Haotian Tang, Shang Yang, Wei-Ming Chen, Wei-Chen Wang, Guangxuan Xiao, Xingyu Dang, Chuang Gan, and Song Han. 2024. AWQ: Activation-aware Weight Quantization for On-Device LLM Compression and Acceleration. Proceedings of Machine Learning and Systems 6 (2...

  74. [84]

    Chang Liu, Xiao Shaun Wang, Kartik Nayak, Yan Huang, and Elaine Shi. 2015. Oblivm: A programming framework for secure computation. In 2015 IEEE Symposium on Security and Privacy . IEEE, 359–376

  75. [85]

    Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In 31st USENIX Security Symposium, USENIX Security 20...

  76. [86]

    Moritz Lipp, Andreas Kogler, David Oswald, Michael Schwarz, Catherine Easdon, Claudio Canella, and Daniel Gruss

  77. [87]

    In 2021 IEEE Symposium on Security and Privacy (SP)

    PLATYPUS: Software-based power side-channel attacks on x86. In 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 355–371

  78. [88]

    Stefan Mangard. 2016. Cache Attacks and Rowhammer on ARM . Ph. D. Dissertation. Graz University of Technology

  79. [89]

    Sourab Mangrulkar, Sylvain Gugger, Lysandre Debut, Younes Belkada, Sayak Paul, and Benjamin Bossan. 2022. PEFT: State-of-the-art Parameter-Efficient Fine-Tuning methods. https://github.com/huggingface/peft

  80. [90]

    Ziyu Liu, Yukui Luo, Shijin Duan, Tong Zhou, and Xiaolin Xu. 2023. MirrorNet: A TEE-Friendly Framework for Secure On-device DNN Inference. CoRR abs/2311.09489 (2023). https://doi.org/10.48550/ARXIV.2311.09489 arXiv:2311.09489

  81. [91]

    Paolo Maistri, Regis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, J-M Dutertre, and Mathieu Lisart. 2014. Electromagnetic analysis and fault injection onto secure circuits. In 2014 22nd International Conference on Very...

  82. [92]

    Luke Melas. 2020. Pretrained ViT. https://github.com/lukemelas/PyTorch-Pretrained-ViT

  83. [93]

    Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting Unintended Feature Leakage in Collaborative Learning. In 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19-23, 2019. IEEE, 691–706. https://doi.org/10....

  84. [94]

    Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R

    Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V. Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R. Savagaonkar. 2013. Innovative instructions and software model for isolated execution. In HASP 2013, The Second Workshop on Hardware and Architectural Support for Sec...

  85. [95]

    Dibbo, Ehsanul Kabir, Ninghui Li, and Elisa Bertino

    Shagufta Mehnaz, Sayanton V. Dibbo, Ehsanul Kabir, Ninghui Li, and Elisa Bertino. 2022. Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, ...

  86. [96]

    Tullsen, and Hadi Esmaeilzadeh

    Fatemehsadat Mireshghallah, Mohammadkazem Taram, Prakash Ramrakhyani, Ali Jalali, Dean M. Tullsen, and Hadi Esmaeilzadeh. 2020. Shredder: Learning Noise Distributions to Protect Inference Privacy. In ASPLOS ’20: Architectural Support for Programming Languages and Operating Sys...

  87. [97]

    Fan Mo, Hamed Haddadi, Kleomenis Katevas, Eduard Marin, Diego Perino, and Nicolas Kourtellis. 2021. PPFL: privacy- preserving federated learning with trusted execution environments. In MobiSys ’21: The 19th Annual International ACM Trans. Softw. Eng. Methodol., Vol. 1, No. 1, ...

  88. [98]

    Meta. 2020. Pytorch Hub. https://pytorch.org/hub/

  89. [99]

    Meta. 2020. Pytorch Model Zoo. https://pytorch.org/serve/model_zoo.html

  90. [100]

    Antonio Muñoz, Ruben Rios, Rodrigo Román, and Javier López. 2023. A survey on the (in) security of trusted execution environments. Computers & Security 129 (2023), 103180

  91. [101]

    Oswald, Flavio D

    Kit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based Fault Injection Attacks against Intel SGX. In 2020 IEEE Symposium on Security and Privacy, SP 2020, San Francisco, CA, USA, May 18-21, 2020 . IEEE,...

  92. [102]

    Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas, Soteris Demetriou, Ilias Leontiadis, Andrea Cavallaro, and Hamed Haddadi. 2020. DarkneTZ: towards model privacy at the edge using trusted execution environments. In MobiSys ’20: The 18th Annual International Conference on Mobil...

  93. [103]

    Pedro Morgado and Nuno Vasconcelos. 2019. NetTailor: Tuning the Architecture, Not Just the Weights. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2019, Long Beach, CA, USA, June 16-20, 2019 . Computer Vision Foundation / IEEE, 3044–3054. https://doi.org/1...

  94. [104]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning. In 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May ...

  95. [105]

    Lucien K. L. Ng, Sherman S. M. Chow, Anna P. Y. Woo, Donald P. H. Wong, and Yongjun Zhao. 2021. Goten: GPU-Outsourcing Trusted Execution of Neural Network Training. In Thirty-Fifth AAAI Conference on Artificial Intelligence, AAAI 2021, Thirty-Third Conference on Innovative App...

  96. [106]

    Krishna Giri Narra, Zhifeng Lin, Yongqin Wang, Keshav Balasubramaniam, and Murali Annavaram. 2019. Privacy- Preserving Inference in Machine Learning Services Using Trusted Execution Environments. CoRR abs/1912.03485 (2019)

  97. [107]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2018. Machine Learning with Membership Privacy using Adversarial Regularization. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018, Toronto, ON, Canada, October 15-19, 2018 , David L...

  98. [108]

    Yue Niu, Ramy E Ali, and Salman Avestimehr. 2022. 3LegRace: Privacy-Preserving DNN Training over TEEs and GPUs. Proceedings on Privacy Enhancing Technologies 4 (2022), 183–203

  99. [109]

    NVIDIA. 2023. NVIDIA H100 Tensor Core GPU. https://www.nvidia.com/en-us/data-center/h100/

  100. [111]

    Alexander Nilsson, Pegah Nikbakht Bideh, and Joakim Brorsson. 2020. A Survey of Published Attacks on Intel SGX. CoRR abs/2006.13598 (2020)

  101. [112]

    Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2020. Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020. OpenReview.net. https://ope...

  102. [113]

    Shevade, and Vinod Ganapathy

    Soham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade, Shirish K. Shevade, and Vinod Ganapathy. 2019. A framework for the extraction of Deep Neural Networks by leveraging public data. CoRR (2019)

  103. [114]

    Oleksii Oleksenko, Bohdan Trach, Robert Krahn, Mark Silberstein, and Christof Fetzer. 2018. Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks. In 2018 USENIX Annual Technical Conference, USENIX ATC 2018, Boston, MA, USA, July 11-13, 2018 , Haryadi S. Gunawi an...

  104. [115]

    Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019. Knockoff Nets: Stealing Functionality of Black-Box Models. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2019, Long Beach, CA, USA, June 16-20,

  105. [117]

    Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In 26th Annual Network and Distributed System Security Symposium, NDSS 20...

  106. [118]

    Maxim Saplin. 2024. Running Local LLMs, CPU vs. GPU - a Quick Speed Test. https://dev.to/maximsaplin/running- local-llms-cpu-vs-gpu-a-quick-speed-test-2cjn

  107. [119]

    Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael Wellman. 2016. Towards the science of security and privacy in machine learning. arXiv preprint arXiv:1611.03814 (2016)

  108. [120]

    McDaniel, Ian J

    Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami

  109. [121]

    Tianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang, Siyuan Wen, Xusheng Chen, Shixiong Zhao, Sen Wang, Li Chen, Xiapu Luo, Fengwei Zhang, and Heming Cui. 2022. SOTER: Guarding Black-box Inference for General Neural Networks at the Edge. In 2022 USENIX Annual Technical Conference, ...

  110. [122]

    Yun Shen, Xinlei He, Yufei Han, and Yang Zhang. 2022. Model Stealing Attacks Against Inductive Graph Neural Networks. In 43rd IEEE Symposium on Security and Privacy, SP 2022, San Francisco, CA, USA, May 22-26, 2022 . IEEE, 1175–1192. https://doi.org/10.1109/SP46214.2022.9833607

  111. [123]

    Youren Shen, Hongliang Tian, Yu Chen, Kang Chen, Runji Wang, Yi Xu, Yubin Xia, and Shoumeng Yan. 2020. Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX. In ASPLOS ’20: Architectural Support for Programming Languages and Operating Systems, Lausanne...

  112. [124]

    https://www.ndss-symposium.org/ndss-paper/ml-leaks-model-and-data-independent- membership-inference-attacks-and-defenses-on-machine-learning-models/

    The Internet Society. https://www.ndss-symposium.org/ndss-paper/ml-leaks-model-and-data-independent- membership-inference-attacks-and-defenses-on-machine-learning-models/

  113. [125]

    Ming-Wei Shih, Sangho Lee, Taesoo Kim, and Marcus Peinado. 2017. T-SGX: Eradicating Controlled-Channel Attacks Against Enclave Programs.. In NDSS

  114. [126]

    Alexander Schlögl and Rainer Böhme. 2020. eNNclave: Offline Inference with Model Confidentiality. In AISec@CCS 2020: Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security, Virtual Event, USA, 13 November 2020, Jay Ligatti and Xinming Ou (Eds.). ACM, 93–1...

  115. [127]

    Haihao Shen, Hanwen Chang, Bo Dong, Yu Luo, and Hengyu Meng. 2023. Efficient llm inference on cpus. arXiv preprint arXiv:2311.00502 (2023)

  116. [128]

    Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun ...

  117. [129]

    Chawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan, and David Wagner. 2023. Defending Against Transfer Attacks From Public Models. ArXiv abs/2310.17645 (2023). https://api.semanticscholar.org/CorpusID: 264490564

  118. [130]

    Congzheng Song and Ananth Raghunathan. 2020. Information Leakage in Embedding Models. In CCS ’20: 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, USA, November 9-13, 2020 , Jay Ligatti, Xinming Ou, Jonathan Katz, and Giovanni Vigna (Eds.). AC...

  119. [131]

    Zhuoran Shen, Mingyuan Zhang, Haiyu Zhao, Shuai Yi, and Hongsheng Li. 2021. Efficient attention: Attention with linear complexities. In Proceedings of the IEEE/CVF winter conference on applications of computer vision . 3531–3539

  120. [132]

    Pranav Subramani, Nicholas Vadivelu, and Gautam Kamath. 2021. Enabling Fast Differentially Private SGD via Just- in-Time Compilation and Vectorization. In Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, Neu...

  121. [133]

    Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership Inference Attacks Against Machine Learning Models. In 2017 IEEE Symposium on Security and Privacy, SP 2017, San Jose, CA, USA, May 22-26,

  122. [134]

    https://doi.org/10.1109/SP.2017.41

    IEEE Computer Society, 3–18. https://doi.org/10.1109/SP.2017.41

  123. [135]

    SSABBSMK ShwetaShinde. 2023. ACAI: Protecting Accelerator Execution with Arm Confidential Computing Architecture. (2023)

  124. [136]

    Hugo Touvron, Thibaut Lavril, Gautier Izacard, Xavier Martinet, Marie-Anne Lachaux, Timothée Lacroix, Baptiste Rozière, Naman Goyal, Eric Hambro, Faisal Azhar, et al. 2023. Llama: Open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)

  125. [137]

    Florian Tramèr and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6-9,

  126. [138]

    Reiter, and Thomas Ristenpart

    Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10-12, 2016, Thorsten Holz and Stefan Savage (Eds.). USENI...

  127. [139]

    Liwei Song and Prateek Mittal. 2021. Systematic Evaluation of Privacy Risks of Machine Learning Models. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021 , Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 2615–2632. https://www.usenix....

  128. [140]

    Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue In-Flight Data Load. In 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19-23, 2019...

  129. [141]

    Zhichuang Sun, Ruimin Sun, Long Lu, and Somesh Jha. 2020. ShadowNet: A Secure and Efficient System for On-device Model Inference. CoRR abs/2011.05905 (2020)

  130. [142]

    Zhichuang Sun, Ruimin Sun, Long Lu, and Alan Mislove. 2021. Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile Apps. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021 , Michael Bailey and Rachel Greens...

  131. [143]

    2017.{CLKSCREW}: Exposing the perils of{Security- Oblivious} energy management

    Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017.{CLKSCREW}: Exposing the perils of{Security- Oblivious} energy management. In 26th USENIX Security Symposium (USENIX Security 17) . 1057–1074

  132. [144]

    Bolun Wang, Yuanshun Yao, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2018. With Great Training Comes Great Vulnerability: Practical Attacks against Transfer Learning. In27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15-17, 2018 , William ...

  133. [145]

    Chenxu Wang, Yunjie Deng, Zhenyu Ning, Kevin Leach, Jin Li, Shoumeng Yan, Zhengyu He, Jiannong Cao, and Fengwei Zhang. 2023. Building a Lightweight Trusted Execution Environment for Arm GPUs. IEEE Transactions on Dependable and Secure Computing (2023)

  134. [146]

    https://openreview.net/forum?id=rJVorjCcKQ

    OpenReview.net. https://openreview.net/forum?id=rJVorjCcKQ

  135. [147]

    weiaicunzai. 2020. Pytorch-cifar100. https://github.com/weiaicunzai/pytorch-cifar100

  136. [148]

    Chia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey, Raluca Ada Popa, and Donald E Porter. 2020. Civet: An efficient java partitioning framework for hardware enclaves. In 29th USENIX Security Symposium (USENIX Security 20). 505–522

  137. [149]

    Pengfei Wu, Jianting Ning, Jiamin Shen, Hongbing Wang, and Ee-Chien Chang. 2022. Hybrid trust multi-party computation with trusted execution environment. InThe Network and Distributed System Security (NDSS) Symposium

  138. [150]

    Berkeley Vision and Learning Center. 2020. Caffe Model Zoo. https://github.com/BVLC/caffe/wiki/Model-Zoo

  139. [151]

    Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted Execution Environments on GPUs. In 13th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2018, Carlsbad, CA, USA, October 8-10, 2018, Andrea C. Arpaci-Dusseau and Geoff Voelker (Eds.)...

  140. [152]

    Alex Wang, Amanpreet Singh, Julian Michael, Felix Hill, Omer Levy, and Samuel R Bowman. [n. d.]. GLUE: A multi-task benchmark and analysis platform for natural language understanding. arXiv:1804.07461 ([n. d.])

  141. [153]

    Fletcher, and Josep Torrellas

    Mengjia Yan, Christopher W. Fletcher, and Josep Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 , Srdjan Capkun and Franziska Roesner (Eds.). USENIX Ass...

  142. [154]

    Xiaoyong Yuan and Lan Zhang. 2022. Membership Inference Attacks and Defenses in Neural Network Pruning. CoRR (2022). ACM Trans. Softw. Eng. Methodol., Vol. 1, No. 1, Article . Publication date: November 2024. TEESlice: Protecting Sensitive Neural Network Models in Trusted Exec...

  143. [155]

    Wenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang, XiaoFeng Wang, Vincent Bindschaedler, Haixu Tang, and Carl A. Gunter. 2017. Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGX. In Proceedings of the 2017 ACM SIGSAC Conference on Computer an...

  144. [156]

    Ziqi Zhang, Yuanchun Li, Yao Guo, Xiangqun Chen, and Yunxin Liu. 2020. Dynamic slicing for deep neural networks. In ESEC/FSE ’20: 28th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering

  145. [157]

    Frank Wilcoxon. 1992. Individual comparisons by ranking methods. In Breakthroughs in statistics. Springer

  146. [158]

    Ziqi Zhang, Yuanchun Li, Jindong Wang, Bingyan Liu, Ding Li, Yao Guo, Xiangqun Chen, and Yunxin Liu. 2022. ReMoS: Reducing Defect Inheritance in Transfer Learning via Relevant Model Slicing. In 44th IEEE/ACM 44th International Conference on Software Engineering, ICSE 2022

  147. [159]

    Yecheng Xiang, Yidi Wang, Hyunjong Choi, Mohsen Karimi, and Hyoseung Kim. 2021. AegisDNN: Dependable and Timely Execution of DNN Tasks with SGX. In 42nd IEEE Real-Time Systems Symposium, RTSS 2021, Dortmund, Germany, December 7-10, 2021. IEEE, 68–81. https://doi.org/10.1109/RT...

  148. [160]

    Guangxuan Xiao, Ji Lin, Mickael Seznec, Hao Wu, Julien Demouth, and Song Han. 2023. SmoothQuant: Accurate and Efficient Post-Training Quantization for Large Language Models. In Proceedings of the 40th International Conference on Machine Learning

  149. [161]

    Karthikeyan, and T

    Dhanush Kumar Yadlapally, Bhavana Vasireddy, Madhumitha Marimganti, Teja Chowdary, C. Karthikeyan, and T. Vignesh. 2023. A Review on the Potential of AI Voice Assistants for Personalized and Adaptive Learning in Education. In 2023 7th International Conference on Computing Meth...

  150. [162]

    Zixuan Zhou, Xuefei Ning, Ke Hong, Tianyu Fu, Jiaming Xu, Shiyao Li, Yuming Lou, Luning Wang, Zhihang Yuan, Xiuhong Li, et al. 2024. A survey on efficient inference for large language models. arXiv preprint arXiv:2404.14294 (2024)

  151. [163]

    Yuankun Zhu, Yueqiang Cheng, Husheng Zhou, and Yantao Lu. 2021. Hermes Attack: Steal DNN Models with Lossless Inference Accuracy. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021 , Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 1973...

  152. [164]

    Ziqi Zhang, Chen Gong, Yifeng Cai, Yuanyuan Yuan, Bingyan Liu, Ding Li, Yao Guo, and Xiangqun Chen. 2024. No privacy left outside: On the (in-) security of tee-shielded dnn partition for on-device ml. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE, 3327–3345

  153. [166]

    Ziqi Zhang, Yuanchun Li, Bingyan Liu, Yifeng Cai, Ding Li, Yao Guo, and Xiangqun Chen. 2023. FedSlice: Protecting Federated Learning Models from Malicious Participants with Model Slicing. In 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) . IEEE, 460–472

  154. [168]

    Ziqi Zhang, Lucien KL Ng, Bingyan Liu, Yifeng Cai, Ding Li, Yao Guo, and Xiangqun Chen. 2022. TEESlice: slicing DNN models for secure and efficient deployment. In Proceedings of the 2nd ACM International Workshop on AI and Software Testing/Analysis. 1–8

  155. [169]

    Zhifei Zhang, Yang Song, and Hairong Qi. 2017. Age Progression/Regression by Conditional Adversarial Autoencoder. In 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA, July 21-26, 2017 . IEEE Computer Society, 4352–4360. https://doi....

  156. [170]

    Tong Zhou, Yukui Luo, Shaolei Ren, and Xiaolin Xu. 2023. NNSplitter: An Active Defense Solution for DNN Model via Automated Weight Obfuscation. In International Conference on Machine Learning, ICML 2023, 23-29 July 2023, Honolulu, Hawaii, USA (Proceedings of Machine Learning R...

  157. [173]

    Fuzhen Zhuang, Zhiyuan Qi, Keyu Duan, Dongbo Xi, Yongchun Zhu, Hengshu Zhu, Hui Xiong, and Qing He. 2021. A Comprehensive Survey on Transfer Learning. Proc. IEEE 109, 1 (2021), 43–76. https://doi.org/10.1109/JPROC.2020. 3004555 ACM Trans. Softw. Eng. Methodol., Vol. 1, No. 1, ...

  158. [2017]

    Practical Black-Box Attacks against Machine Learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, AsiaCCS 2017, Abu Dhabi, United Arab Emirates, April 2-6, 2017 , Ramesh Karri, Ozgur Sinanoglu, Ahmad-Reza Sadeghi, and Xun Yi (Eds....

  159. [2019]

    https://doi.org/10.1109/CVPR.2019.00509

    Computer Vision Foundation / IEEE, 4954–4963. https://doi.org/10.1109/CVPR.2019.00509

  160. [2021]

    In IEEE Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2021, virtual, June 19-25, 2021

    MLCapsule: Guarded Offline Deployment of Machine Learning as a Service. In IEEE Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2021, virtual, June 19-25, 2021. Computer Vision Foundation / IEEE, 3300–3309. https://doi.org/10.1109/CVPRW53098.2021.00368

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.