REVIEW 3 major objections 4 minor 148 references
Protecting Confidentiality, Privacy and Integrity in Collaborative Learning
T0 review · 3 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read Even n-1 colluding owners can't strip DP privacy
desk verdict Strong TEE-based system with a real privacy hole at the center: the collusion-resistance claim is unproven and a natural mask choice breaks it. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the differentially private masking scheme: masks are drawn so their sum is one Gaussian sample of scale $\sigma C$, matching the central DP-SGD noise; each handler adds its mask before release and the updater aggregates, so the released aggregate is DP-SGD's update. Two supporting mechanisms carry the argument: dynamic gradient clipping, where a noisy histogram of gradient norms selects the clipping bound each round with per-bin $\ell_2$-sensitivity at most $\sqrt{2}$, and DP noise correction, where iteration $t+1$ adds $\xi_{t+1}-\lambda\xi_t$, so short sequences of per-iteration gradients are harder to denoise while the final model's noise is unchanged. The sandbox with network, filesystem, and IPC isolation is what forces the untrusted training code to output only through this barrier.
What would settle it
Construct the adversarial view explicitly: give the colluding parties their masks and all masked gradients, then compute the hockey-stick divergence between neighboring datasets for the remaining owner's contribution. If the released aggregate plus the $n-1$ known masks lets an attacker recover the noise $\xi$, or any function with sensitivity larger than the DP-SGD bound, with better-than-Gaussian accuracy, the collusion claim is false; measuring that divergence numerically for any concrete mask distribution settles it.
Extended reading notes
Core claim
Citadel++'s central claim is that differential privacy for individual data records can be enforced by construction in a collaborative training session, without trusting or inspecting the model owner's code. The construction: a trusted admin component generates $n$ masks $m_1,\ldots,m_n$ whose sum $\sum_i m_i = \xi$ is a single Gaussian draw $\mathcal{N}(0,\sigma^2 C^2 I)$; data handler $i$ sends the masked gradient $g_i + m_i$, and the model updater's aggregate is $\sum_i g_i + \xi$, exactly the DP-SGD update. Consequently each individual masked gradient is uniformly random given the others, and the paper claims that collusion among the model owner and up to $n-1$ dataset owners does not reduce the DP noise protecting the non-colluding owner. Dynamic gradient clipping and a noise-correction step extend the same accounting without changing the final model's privacy-utility trade-off.
Load-bearing premise
The guarantee that a non-colluding data owner stays private when the model owner and $n-1$ dataset owners collude is asserted without a formal proof or a specified mask distribution: the paper does not analyze the adversary who sees all masked gradients and knows the masks of $n-1$ colluding owners.
Editorial extensions
If this is right
- A model owner can offer proprietary training code without showing it to data owners, and data owners can keep their datasets encrypted at rest and in use inside TEEs.
- The final model's accuracy matches central DP-SGD at the same $(\varepsilon,\delta)$ budget, because the aggregate gradient distribution is identical.
- Per-iteration gradients are protected against reconstruction and membership-inference attacks, since each released gradient is individually masked.
- Citadel++ can run on GPU TEEs and match non-confidential federated learning speed, with reported speedups of up to 543x on CPU and 113x on GPU over cryptographic baselines.
Reading between the lines
- If the privacy-under-collusion claim is proved with a concrete mask distribution and composition analysis, the same masking construction could be reused as a drop-in secure-aggregation layer for federated learning without TEEs.
- The noise-correction step is effectively a moving-average filter on the noise, which suggests a family of higher-order correction schemes that shrink per-iteration privacy loss further at the cost of more complex accounting.
- Using the paper's own formulas for bounded-length update sequences, one could tune $\lambda$ adaptively to maximize per-iteration privacy for a fixed final-model privacy budget.
- The sandboxing results imply that the main cost of containing malicious code is the boundary between the trusted service container and the untrusted handler, not the TEE itself.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. Citadel++ is a collaborative ML training system that combines VM-level TEEs (AMD SEV-SNP, Intel TDX, NVIDIA H100) with a DP-based privacy barrier to protect dataset, model, and code confidentiality, and individual privacy. The privacy barrier consists of DP-masking, dynamic gradient clipping, and DP noise correction. The paper also contributes sandboxing of untrusted training code via OS namespaces and integrity enhancements for Confidential Containers. Experiments show the system is competitive with non-confidential FL and much faster than cryptographic baselines.
Significance. The system-level engineering is substantial: the paper demonstrates a full implementation with GPU TEE support, sandboxing, and integrity mechanisms, and the performance evaluation is careful and extensive. If the privacy claims held, Citadel++ would be an important practical step toward confidential collaborative learning with DP guarantees. However, the central privacy claims are not yet rigorously established: the DP-masking scheme is under-specified, the adversary's full view is not modeled, and the noise-correction privacy formulas contain algebraic errors. These issues are load-bearing because the paper's main novelty over prior TEE-based systems is its privacy barrier.
major comments (3)
- [Sec. 4.2, Sec. 7, Sec. 8.2] The DP-masking mechanism is under-specified and the privacy analysis does not model the adversary's actual view. The paper fixes only the sum of masks, Σ_i m_i = ξ ~ N(0, σ²C²I), and Section 7's accounting (with Appendices A.1-A.2) covers only the aggregated output Σ_i g_i + ξ. However, the model updating component receives each per-handler value g_i + m_i individually, and the model owner may collude with up to n-1 dataset owners who can reveal their true gradients g_j and, from the observed g_j + m_j, their masks m_j. Section 8.2 asserts without proof that the non-colluding owner's g_i remains protected by the full DP noise. This is false for a natural instantiation: if m_i = ξ/n for all i, one colluding owner's mask reveals ξ, and then the adversary obtains m_i and solves for g_i exactly from g_i + m_i. If instead the masks are i.i.d. with variance σ²C²/n, each per-handler release carries only noise σC/√n, which is weaker than the claimed DP-SGD noise σC unless the composition of per-handler releases is explicitly accounted for. The paper must specify the exact joint distribution of (m_1,...,m_n) and provide a DP analysis of the entire view (g_1+m_1,...,g_n+m_n, Σ_i(g_i+m_i)), including the colluding-adversary case, before the central privacy claim can be evaluated.
- [Appendix A.3.1, Eq. (6) and Thm. 5] The composition formula for T Gaussian mechanisms is algebraically incorrect. Eq. (6) reads δ(ε) = Φ(-εσ√T + √T/(2σ)) - e^ε Φ(-εσ√T - √T/(2σ)); the correct expression, obtained by composing T mechanisms each with sensitivity 1 and noise scale σ, is Φ(-εσ/√T + √T/(2σ)) - e^ε Φ(-εσ/√T - √T/(2σ)). The same reciprocal error appears in Theorem 5, where σ_total = sqrt(T/\tilde{σ}² + n_g/σ_g²) is defined as the standard deviation of the resulting PLRV but is then used in the Gaussian CDF in place of the reciprocal of the effective noise scale. The resulting formula is dimensionally inconsistent, so the privacy numbers for the noise-correction mechanism (Section 10.1, Figure 8, Appendix A.3.3) are not reliable. The proof of Theorem 5 also does not use the histogram sensitivity √2 stated in Section 4.3, so the σ_total definition is inconsistent with the mechanism's stated sensitivity.
- [Sec. 10.1, Figs. 5 and 8] The abstract and Section 1 claim that Citadel++ 'matches the model utility of standard central DP-SGD mechanisms,' but the experiments never compare against a central DP-SGD baseline. Figure 5 shows accuracy for different ε values against a non-private upper bound only; Figure 8 compares DP-GD with and without noise correction. Without a DP-SGD reference curve and without error bars over multiple runs, the utility-parity claim is not empirically substantiated. Since this is one of the paper's headline contributions, the evaluation should include a direct DP-SGD comparison and report variability across seeds.
minor comments (4)
- [Sec. 4.2] The notation 'Σ_{i=1}^n m_i = N(0, σ²C²I)' is mathematically imprecise; the left-hand side is a random variable, so the expression should read 'Σ_i m_i ~ N(0, σ²C²I)'.
- [Sec. 8.2] The statement that 'Noise correction further prevents attackers from correlating noise across iterations' is not analyzed in the collusion context; Appendix A.3.3 considers sequences of updates but does not connect to the colluding-adversary model of Section 8.2.
- [Appendix B] The text says 'we launched one admin, one model handling, and four data handling components'; for consistency with the rest of the paper, 'model handling' should be 'model updating'.
- [Fig. 5 caption] The legend labels 'ε = 50', etc., should specify that these are privacy budgets; the caption currently does not define the parameter.
Circularity Check
No circular derivation found: the DP-SGD accounting and noise-correction proofs are self-contained, and the only notable gap (the collusion-resistance assertion in Sec. 7 and Sec. 8.2) is a missing proof, not a circular argument.
full rationale
Walking the paper's claimed derivation chain, the DP mechanisms are not circular. (1) The DP-masking construction in Sec. 4.2 is explicitly definitional: the admin generates masks such that the sum is DP noise, "Σ_{i=1}^n m_i = N(0, σ^2 C^2 I) = ξ," and the aggregate becomes "Σ_i g_i + ξ." The paper says "by design" this matches DP-SGD, so the aggregate guarantee is the definition of the construction rather than a derived result that secretly assumes its conclusion. (2) The dynamic-clipping accounting in Theorem 3 is a standard PLRV composition over DP-SGD PLRVs and histogram Gaussian mechanisms with sensitivity √2, citing external numerical accounting works [48, 139] and the Opacus implementation; this is independent support, not a self-citation chain. (3) The noise-correction proof in Appendix A.3 is a self-contained unrolling of the update equations into Gaussian mechanisms with sensitivity at most 1/(1−λ), yielding an effective noise scale eσ = (1−λ)σ; this is a direct sensitivity calculation that does not assume the target DP guarantee. The §4.4 statement that the raw noise level is σ/(1−λ) is consistent with this derivation when σ denotes the target DP-SGD noise scale. The real gap is the collusion claim: Sec. 7 asserts that DP masking "simply extends those guarantees even when the model owner and up to n−1 data owners collude (§8.2)", and Sec. 8.2 concludes that "the non-colluding dataset owners are still protected with the full DP noise." No theorem in the paper analyzes the honest owner's per-owner release g_h + m_h in the view of that colluding adversary; Sec. 4.2 fixes only the sum of the masks, not the joint distribution of (m_1, ..., m_n), so whether the honest owner's marginal mask provides σ-scale noise is unproven (and for the equal-split instantiation m_i = ξ/n it does not). This is a completeness and correctness concern about an asserted security property, not a circularity: the claim is not used as an input to, nor is it equivalent by construction to, the definition of the masking mechanism. The only self-citation is the architectural reference to the predecessor Citadel [134], which is not load-bearing for the new DP claims. Consequently, no specific circular step can be exhibited, and the appropriate circularity score is 0.
Assumptions & free parameters
free parameters (6)
- DP noise scale sigma =
varies per experiment (e.g., 3, 10, 15, 50)
- Noise correction coefficient lambda =
0.7, 0.9
- Histogram noise scale sigma_g =
not reported
- Clipping percentile r =
tested at 1%, 10%, ..., 99%
- Initial clipping bound =
2.0 for MNIST-MLP3
- Subsampling ratio q =
varies with batch size
assumptions (5)
- domain assumption TEEs (AMD SEV-SNP, Intel TDX, NVIDIA H100 Confidential Computing) provide the stated confidentiality and integrity guarantees.
- domain assumption Per-sample gradient clipping bounds the L2 sensitivity of each data point's contribution to C.
- standard math PLRV-based composition theorems from [48,139] are correct.
- standard math Differential privacy is closed under post-processing.
- domain assumption The service code is open-sourced and correctly measured by remote attestation.
Cite this review
Pith. "Pith review of Protecting Confidentiality, Privacy and Integrity in Collaborative Learning." pith.science (2026). https://pith.science/paper/U75ZAZZ4
@misc{pith2026241208534,
author = {Pith},
title = {Pith review of: Protecting Confidentiality, Privacy and Integrity in Collaborative Learning},
year = {2026},
howpublished = {\url{https://pith.science/paper/U75ZAZZ4}},
note = {Machine review of arXiv:2412.08534}
}
read the original abstract
A collaboration between dataset owners and model owners is needed to facilitate effective machine learning (ML) training. During this collaboration, however, dataset owners and model owners want to protect the confidentiality of their respective assets (i.e., datasets, models and training code), with the dataset owners also caring about the privacy of individual users whose data is in their datasets. Existing solutions either provide limited confidentiality for models and training code, or suffer from privacy issues due to collusion. We present Citadel++, a collaborative ML training system designed to simultaneously protect the confidentiality of datasets, models and training code as well as the privacy of individual users. Citadel++ enhances differential privacy mechanisms to safeguard the privacy of individual user data while maintaining model utility. By employing Virtual Machine-level Trusted Execution Environments (TEEs) as well as the improved sandboxing and integrity mechanisms through OS-level techniques, Citadel++ effectively preserves the confidentiality of datasets, models and training code, and enforces our privacy mechanisms even when the models and training code have been maliciously designed. Our experiments show that Citadel++ provides model utility and performance while adhering to the confidentiality and privacy requirements of dataset owners and model owners, outperforming the state-of-the-art privacy-preserving training systems by up to 543x on CPU and 113x on GPU TEEs.
Figures
Figures from the paper (8 more)
Reference graph
Works this paper leans on
-
[1]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. InProceedings of the 2016 ACM SIGSAC conference on computer and communications security . 308–318
2016
-
[2]
https://www.intel.com/content/www/us/en/developer/topic- technology/software-security-guidance/processors-affected- consolidated-product-cpu-model.html
Affected Processors: Guidance for Security Issues on Intel Processors . https://www.intel.com/content/www/us/en/developer/topic- technology/software-security-guidance/processors-affected- consolidated-product-cpu-model.html . Accessed: 2025-04-10
2025
-
[3]
Nitin Agrawal, Ali Shahin Shamsabadi, Matt J Kusner, and Adrià Gascón. 2019. QUOTIENT: Two-party secure neural network training and prediction. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 1231–1247
2019
-
[4]
https://www.kaggle.com/ datasets/amananandrai/ag-news-classification-dataset
AG’s News Topic Classification Dataset . https://www.kaggle.com/ datasets/amananandrai/ag-news-classification-dataset . Accessed: 2025-04-10
2025
-
[5]
Istemi Ekin Akkus and Ivica Rimac. 2024. duet: Combining a Trust- worthy Controller with a Confidential Computing Environment. In 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
2024
-
[6]
Istemi Ekin Akkus, Ivica Rimac, and Ruichuan Chen. 2024. PraaS: Verifiable Proofs of Property as-a-Service with Intel SGX. In2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
2024
-
[7]
Accessed: 2025-04-10
AMD Secure Encrypted Virtualization (SEV) .https://www.amd.com/ en/developer/sev.html. Accessed: 2025-04-10
2025
-
[8]
https://www.amd.com/content/ dam/amd/en/documents/epyc-business-docs/white-papers/SEV- SNP-strengthening-vm-isolation-with-integrity-protection-and- more.pdf
AMD SEV-SNP: Strengthening VM isolation with integrity protection and more 2020. https://www.amd.com/content/ dam/amd/en/documents/epyc-business-docs/white-papers/SEV- SNP-strengthening-vm-isolation-with-integrity-protection-and- more.pdf. Accessed: 2025-04-10
2020
Show all 148 references
-
[9]
Galen Andrew, Om Thakkar, Brendan McMahan, and Swaroop Ra- maswamy. 2021. Differentially private learning with adaptive clip- ping. Advances in Neural Information Processing Systems 34 (2021), 17455–17466
2021
-
[10]
Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, and Shiho Moriai. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE transactions on information forensics and security 13, 5 (2017), 1333–1345
2017
-
[11]
https://security.apple.com/blog/private-cloud-compute/
Apple Private Cloud Compute: A new frontier for AI privacy in the cloud . https://security.apple.com/blog/private-cloud-compute/. Accessed: 2025-04-10
2025
-
[12]
https://www.arm
Arm Confidential Compute Architecture . https://www.arm. com/architecture/security-features/arm-confidential-compute- architecture. Accessed: 2025-04-10
2025
-
[13]
https://aws.amazon.com/ec2/nitro/nitro- enclaves/
AWS Nitro Enclaves . https://aws.amazon.com/ec2/nitro/nitro- enclaves/. Accessed: 2025-04-10
2025
-
[14]
https://azure.microsoft.com/en-us/ solutions/confidential-compute
Azure confidential computing . https://azure.microsoft.com/en-us/ solutions/confidential-compute. Accessed: 2025-04-10
2025
-
[15]
Borja Balle and Yu-Xiang Wang. 2018. Improving the gaussian mech- anism for differential privacy: Analytical calibration and optimal denoising. In International Conference on Machine Learning . PMLR, 394–403
2018
-
[16]
Raphael Bost, Raluca Ada Popa, Stephen Tu, and Shafi Goldwasser
-
[17]
Justin Brickell, Donald E Porter, Vitaly Shmatikov, and Emmett Witchel. 2007. Privacy-preserving remote diagnostics. In Proceed- ings of the 14th ACM conference on Computer and Communications Security. 498–507
2007
-
[18]
https://oag.ca.gov/ privacy/ccpa
California Consumer Privacy Act (CCPA) . https://oag.ca.gov/ privacy/ccpa. Accessed: 2025-04-10
2025
-
[19]
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. In2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 1897–1914
2022
-
[20]
Harsh Chaudhari, Rahul Rachuri, and Ajith Suresh. 2020. Trident: Efficient 4PC Framework for Privacy Preserving Machine Learning. In Proceedings 2020 Network and Distributed System Security Sympo- sium
2020
-
[21]
Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David Oswald, and Flavio D Garcia. 2021. VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID volt- age scaling interface. In 30th USENIX Security Symposium (USENIX Security 21)...
2021
-
[22]
Pau-Chen Cheng, Kevin Eykholt, Zhongshu Gu, Hani Jamjoom, KR Jayaram, Enriquillo Valdez, and Ashish Verma. 2024. DeTA: Min- imizing Data Leaks in Federated Learning via Decentralized and Trustworthy Aggregation. In Proceedings of the Nineteenth European Conference on Computer ...
2024
-
[23]
https: //images.nvidia.com/aem-dam/en-zz/Solutions/data-center/HCC- Whitepaper-v1.0.pdf
Confidential Compute on NVIDIA Hopper H100 . https: //images.nvidia.com/aem-dam/en-zz/Solutions/data-center/HCC- Whitepaper-v1.0.pdf . Accessed: 2025-04-10
2025
-
[24]
https://confidentialcontainers.org/
Confidential Containers . https://confidentialcontainers.org/. Ac- cessed: 2025-04-10
2025
-
[25]
Graeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman, and Raluca Ada Popa. 2024. Secret Key Recovery in a Global-Scale End- to-End Encryption System. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24) . 703–719
2024
-
[26]
Confidential Computing Consortium. 2022. Confidential comput- ing: Hardware-based trusted execution for applications and data. Confidential Computing Consortium Technical Report v1.3 (2022)
2022
-
[27]
Confidential Computing Consortium. 2022. A Technical Analysis of Confidential Computing. Confidential Computing Consortium Technical Report v1.3 (2022)
2022
-
[28]
https://github.com/containerd/ containerd/tree/main/docs/snapshotters
Containerd snapshotter docs . https://github.com/containerd/ containerd/tree/main/docs/snapshotters. Accessed: 2025-04-10
2025
-
[29]
Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016). 13 Dong Chen, Alice Dethise, Istemi Ekin Akkus, Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, Ruichuan Chen
2016
-
[30]
https: //aws.amazon.com/clean-rooms/
Data Collaboration Service - AWS Clean Rooms - AWS . https: //aws.amazon.com/clean-rooms/. Accessed: 2025-04-10
2025
-
[31]
com/data-exchange/
Data Marketplace - AWS Data Exchange - AWS .https://aws.amazon. com/data-exchange/. Accessed: 2025-04-10
2025
-
[32]
https://www.databricks.com/ product/marketplace
Databricks Marketplace | Databricks . https://www.databricks.com/ product/marketplace. Accessed: 2025-04-10
2025
-
[33]
https://datarade.ai/
Datarade | Find the right data, effortlessly . https://datarade.ai/. Accessed: 2025-04-10
2025
-
[34]
Jesse De Meulemeester, Luca Wilke, David Oswald, Thomas Eisen- barth, Ingrid Verbauwhede, and Jo Van Bulck. 2025. BadRAM: Practi- cal Memory Aliasing Attacks on Trusted Execution Environments. In 46th IEEE Symposium on Security and Privacy (S&P)
2025
-
[35]
https://github.com/deepseek-ai
DeepSeek . https://github.com/deepseek-ai. Accessed: 2025-04-10
2025
-
[36]
Sergey Denisov, H Brendan McMahan, John Rush, Adam Smith, and Abhradeep Guha Thakurta. 2022. Improved differential privacy for SGD via optimal private linear operators on adaptive streams. Ad- vances in Neural Information Processing Systems 35 (2022), 5910–5924
2022
-
[37]
https://docs.kernel.org/admin-guide/ device-mapper/verity.html
dm-verity in Linux Kernel . https://docs.kernel.org/admin-guide/ device-mapper/verity.html. Accessed: 2025-04-10
2025
-
[38]
Friedrich Dörmann, Osvald Frisk, Lars Nørvang Andersen, and Chris- tian Fischer Pedersen. 2021. Not all noise is accounted equally: How differentially private learning benefits from large sampling rates. In 2021 IEEE 31st International Workshop on Machine Learning for Signal P...
2021
-
[39]
Cynthia Dwork. 2006. Differential privacy. In International Collo- quium on Automata, Languages, and Programming
2006
-
[40]
https://artificialintelligenceact.eu/
EU Artificial Intelligence Act . https://artificialintelligenceact.eu/. Accessed: 2025-04-10
2025
-
[41]
https://github.com/ facebookresearch/fairseq/tree/main/examples/roberta
fairseq/examples/Roberta - Facebook Research . https://github.com/ facebookresearch/fairseq/tree/main/examples/roberta. Accessed: 2025-04-10
2025
-
[42]
Anna Galanou, Khushboo Bindlish, Luca Preibsch, Yvonne-Anne Pignolet, Christof Fetzer, and Rüdiger Kapitza. 2023. Trustworthy confidential virtual machines for the masses. In Proceedings of the 24th International Middleware Conference . 316–328
2023
-
[43]
Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning? Advances in neural information processing systems (NeurIPS) 33 (2020), 16937–16947
2020
-
[44]
https://gdpr-info.eu/
General Data Protection Regulation (GDPR) . https://gdpr-info.eu/. Accessed: 2025-04-10
2025
-
[45]
Rafael Genés-Durán, Juan Hernández-Serrano, Oscar Esparza, Marta Bellés-Muñoz, and José Luis Muñoz-Tapia. 2021. DEFS—Data Ex- change with Free Sample Protocol. Electronics 10, 12 (2021), 1455
2021
-
[46]
Muñoz-Tapia
Rafael Genés-Durán, Oscar Esparza, Juan Hernández-Serrano, Fer- nando Román-García, Miquel Soriano, Achille Zappa, Martin Serrano, Susanne Stahnke, Birthe Böhm, Edgar Fries, Vasiliki Koniakou, Bruno Michel, and Jose L. Muñoz-Tapia. 2022. Data Marketplaces with a Free Sampling ...
2022
-
[47]
https://cloud.google.com/ security/products/confidential-computing
Google Cloud Confidential Computing . https://cloud.google.com/ security/products/confidential-computing. Accessed: 2025-04-10
2025
-
[48]
Sivakanth Gopi, Yin Tat Lee, and Lukas Wutschitz. 2021. Numerical Composition of Differential Privacy. In Advances in Neural Informa- tion Processing Systems (NeurIPS)
2021
-
[49]
Thore Graepel, Kristin Lauter, and Michael Naehrig. 2012. ML confi- dential: Machine learning on encrypted data. In International confer- ence on information security and cryptology . Springer, 1–21
2012
-
[50]
Marcus Hähnel, Weidong Cui, and Marcus Peinado. 2017. High- Resolution side channels for untrusted operating systems. In 2017 USENIX Annual Technical Conference (USENIX ATC 17) . 299–312
2017
-
[51]
Vivek Haldar, Deepak Chandra, and Michael Franz. 2004. Semantic remote attestation: A virtual machine directed approach to trusted computing. In USENIX Virtual Machine Research and Technology Sym- posium, Vol. 2004. USENIX Association
2004
-
[52]
https://www
Health Insurance Portability and Accountability Act . https://www. hhs.gov/hipaa/index.html. Accessed: 2025-04-10
2025
-
[53]
Ehsan Hesamifard, Hassan Takabi, Mehdi Ghasemi, and Rebecca N Wright. 2018. Privacy-preserving machine learning as a service. Proceedings on Privacy Enhancing Technologies (2018)
2018
-
[54]
Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017. Deep models under the GAN: Information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security . 603–618
2017
-
[55]
Weizhe Hua, Muhammad Umar, Zhiru Zhang, and G Edward Suh. 2022. GuardNN: Secure accelerator architecture for privacy- preserving deep learning. In Proceedings of the 59th ACM/IEEE Design Automation Conference. 349–354
2022
-
[56]
Dzmitry Huba, John Nguyen, Kshitiz Malik, Ruiyu Zhu, Mike Rab- bat, Ashkan Yousefpour, Carole-Jean Wu, Hongyuan Zhan, Pavel Ustinov, Harish Srinivas, Kaikai Wang, Anthony Shoumikhin, Je- sik Min, and Mani Malek. 2022. PAPAYA: Practical, Private, and Scalable Federated Learning...
2022
-
[57]
Tyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely, Yige Hu, Christo- pher J Rossbach, and Emmett Witchel. 2020. Telekine: Secure com- puting with cloud GPUs. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20) . 817–833
2020
-
[58]
Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving machine learning as a service. arXiv preprint arXiv:1803.05961 (2018)
2018 arXiv
-
[59]
Tyler Hunt, Zhiting Zhu, Yuanzhong Xu, Simon Peter, and Emmett Witchel. 2018. Ryoan: A Distributed Sandbox for Untrusted Com- putation on Secret Data. ACM Transactions on Computer Systems (2018)
2018
-
[60]
Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient deep learning on multi-source private data.arXiv preprint arXiv:1807.06689 (2018)
2018 arXiv
-
[61]
https://www.youtube.com/watch?v=Bb9NHtJ_Qnk
Industry Perspectives: The Impact and Future of Confidential Com- puting . https://www.youtube.com/watch?v=Bb9NHtJ_Qnk. Ac- cessed: 2025-04-10
2025
-
[62]
https: //www.intel.com/content/www/us/en/products/docs/accelerator- engines/software-guard-extensions.html
Intel Software Guard Extensions (Intel SGX) . https: //www.intel.com/content/www/us/en/products/docs/accelerator- engines/software-guard-extensions.html. Accessed: 2025-04-10
2025
-
[63]
https: //www.intel.com/content/www/us/en/developer/tools/trust- domain-extensions/overview.html
Intel Trust Domain Extensions (Intel TDX) . https: //www.intel.com/content/www/us/en/developer/tools/trust- domain-extensions/overview.html. Accessed: 2025-04-10
2025
-
[64]
Simon Johnson, Vinnie Scarlata, Carlos Rozas, Ernie Brickell, and Frank Mckeen. 2016. Intel software guard extensions: EPID provi- sioning and attestation services. White Paper 1, 1-10 (2016), 119
2016
-
[65]
Peter Kairouz, H Brendan McMahan, Brendan Avent, Aurélien Bel- let, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al. 2021. Advances and open problems in federated learning. Foundations and trends in machine learning...
2021
-
[66]
Or Kamara. 2020. Hack my mis-configured Kubernetes – priv- ileged pods. https://www.cncf.io/blog/2020/10/16/hack-my-mis- configured-kubernetes-privileged-pods/
2020
-
[67]
https://katacontainers.io/
Kata Container: a secure container runtime with lightweight virtual machines . https://katacontainers.io/. Accessed: 2025-04-10
2025
-
[68]
Helena Klause, Alexander Ziller, Daniel Rueckert, Kerstin Ham- mernik, and Georgios Kaissis. 2022. Differentially private train- ing of residual networks with scale normalisation. arXiv preprint arXiv:2203.00324 (2022). 14 Protecting Confidentiality, Privacy and Integrity in C...
2022 arXiv
-
[69]
Jakub Konečn`y, H Brendan McMahan, Felix X Yu, Peter Richtárik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. arXiv preprint arXiv:1610.05492 (2016)
2016 arXiv
-
[70]
Antti Koskela, Joonas Jälkö, and Antti Honkela. 2020. Computing Tight Differential Privacy Guarantees Using FFT. In International Conference on Artificial Intelligence and Statistics . PMLR, 2560–2569
2020
-
[71]
Nishat Koti, Arpita Patra, Rahul Rachuri, and Ajith Suresh. 2022. Tetrad: Actively Secure 4PC for Secure Training and Inference. In Proceedings 2022 Network and Distributed System Security Symposium
2022
-
[72]
Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. University of Toronto (2009)
2009
-
[73]
Alexey Kurakin, Shuang Song, Steve Chien, Roxana Geambasu, An- dreas Terzis, and Abhradeep Thakurta. 2022. Toward Training at Ima- geNet scale with Differential Privacy. arXiv preprint arXiv:2201.12328 (2022)
2022 arXiv
-
[74]
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner. 1998. Gradient-based learning applied to document recognition. Proc. IEEE 86, 11 (1998), 2278–2324
1998
-
[75]
Dayeol Lee, Dongha Jung, Ian T Fang, Chia-Che Tsai, and Raluca Ada Popa. 2020. An Off-Chip attack on hardware enclaves via the memory bus. In 29th USENIX Security Symposium (USENIX Security 20)
2020
-
[76]
Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In26th USENIX Security Symposium (USENIX Security 17) . 557–574
2017
-
[77]
Taegyeong Lee, Zhiqi Lin, Saumay Pushp, Caihua Li, Yunxin Liu, Youngki Lee, Fengyuan Xu, Chenren Xu, Lintao Zhang, and Junehwa Song. 2019. Occlumency: Privacy-preserving remote deep-learning inference using SGX. In The 25th Annual International Conference on Mobile Computing a...
2019
-
[78]
Mengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth, Radu Teodorescu, and Yinqian Zhang. 2022. A systematic look at ciphertext side channels on AMD SEV-SNP. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 337–351
2022
-
[79]
Ping Li, Jin Li, Zhengan Huang, Tong Li, Chong-Zhi Gao, Siu-Ming Yiu, and Kai Chen. 2017. Multi-key privacy-preserving deep learning in cloud computing. Future Generation Computer Systems 74 (2017), 76–85
2017
-
[80]
Tian Li, Anit Kumar Sahu, Ameet Talwalkar, and Virginia Smith
-
[81]
https://man7.org/linux/man- pages/man7/namespaces.7.html
Linux Namespace kernel documents . https://man7.org/linux/man- pages/man7/namespaces.7.html. Accessed: 2025-04-10
2025
-
[82]
Bo Liu, Ming Ding, Sina Shaham, Wenny Rahayu, Farhad Farokhi, and Zihuai Lin. 2021. When machine learning meets privacy: A survey and outlook. ACM Computing Surveys (CSUR) 54, 2 (2021), 1–36
2021
-
[83]
Xuanqi Liu, Zhuotao Liu, Qi Li, Ke Xu, and Mingwei Xu. 2024. Pen- cil: Private and Extensible Collaborative Learning without the Non- Colluding Assumption. In Network and Distributed System Security (NDSS) Symposium
2024
-
[84]
Haohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao, Zibin Liu, Mingyu Gao, Cong Wang, Huimin Cui, Xiaobing Feng, and Christos Kozyrakis. 2023. Honeycomb: Secure and Efficient GPU Executions via Static Validation. In17th USENIX Symposium on Operating Systems Design and Imple...
2023
-
[85]
Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R Savagaonkar. 2013. Innovative instructions and software model for isolated execution. Hasp@ isca 10, 1 (2013)
2013
-
[86]
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273–1282
2017
-
[87]
H Brendan McMahan, Eider Moore, Daniel Ramage, and Blaise Agüera y Arcas. 2016. Federated learning of deep net- works using model averaging. arXiv preprint arXiv:1602.05629 2, 2 (2016)
2016 arXiv
-
[88]
Benshan Mei, Saisai Xia, Wenhao Wang, and Dongdai Lin. 2024. Cabin: Confining Untrusted Programs within Confidential VMs. In International Conference on Information and Communications Security. Springer, 165–184
2024
-
[89]
https://llama.meta.com/
Meta Llama . https://llama.meta.com/. Accessed: 2025-04-10
2025
-
[90]
https://azure.microsoft.com/en-us/ products/azure-attestation
Microsoft Azure Attestation . https://azure.microsoft.com/en-us/ products/azure-attestation. Accessed: 2025-04-10
2025
-
[91]
https: //techcommunity.microsoft.com/blog/linuxandopensourceblog/ inside-look-how-azure-linux-powers-confidential-containers-on- aks/3981296
Microsoft Confidential Container with Tardev-snapshotter . https: //techcommunity.microsoft.com/blog/linuxandopensourceblog/ inside-look-how-azure-linux-powers-confidential-containers-on- aks/3981296. Accessed: 2025-04-10
2025
-
[92]
https://github.com/microsoft/kata- containers
Microsoft Kata Container . https://github.com/microsoft/kata- containers. Accessed: 2025-04-10
2025
-
[93]
Ilya Mironov. 2017. Rényi Differential Privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF) . 263–275. https: //doi.org/10.1109/CSF.2017.11
2017 doi
-
[94]
Fan Mo, Hamed Haddadi, Kleomenis Katevas, Eduard Marin, Diego Perino, and Nicolas Kourtellis. 2021. PPFL: Privacy-preserving feder- ated learning with trusted execution environments. In Proceedings of the 19th Annual International Conference on Mobile Systems, Applica- tions, ...
2021
-
[95]
Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas, Soteris Demetriou, Ilias Leontiadis, Andrea Cavallaro, and Hamed Haddadi
-
[96]
Payman Mohassel and Peter Rindal. 2018. ABY3: A mixed protocol framework for machine learning. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 35– 52
2018
-
[97]
Payman Mohassel and Yupeng Zhang. 2017. SecureML: A system for scalable privacy-preserving machine learning. In 2017 IEEE Sympo- sium on Security and Privacy (S&P) . IEEE, 19–38
2017
-
[98]
Kit Murdock, David Oswald, Flavio D Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based fault in- jection attacks against Intel SGX. In2020 IEEE Symposium on Security and Privacy (S&P). IEEE, 1466–1482
2020
-
[99]
In Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services
DarkneTZ: Towards model privacy at the edge using Trusted Execution Environments. In Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services . 161–174
-
[100]
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehen- sive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE Symposium on Security and Privacy (S&P) . IEEE, 739–753
2019
-
[101]
Lucien KL Ng and Sherman SM Chow. 2023. SoK: Cryptographic neural-network computation. In 2023 IEEE Symposium on Security and Privacy (S&P). IEEE, 497–514
2023
-
[102]
https://www.nvidia.com/en-us/ data-center/solutions/confidential-computing/
NVIDIA Confidential Computing . https://www.nvidia.com/en-us/ data-center/solutions/confidential-computing/ . Accessed: 2025-04- 10
2025
-
[103]
Karthik Nandakumar, Nalini Ratha, Sharath Pankanti, and Shai Halevi. 2019. Towards deep neural network training on encrypted data. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition workshops
2019
-
[104]
Nicolas Papernot, Andrew Galen, and Steven Chien. 2020. Tensorflow privacy. https://github.com/tensorflow/privacy 15 Dong Chen, Alice Dethise, Istemi Ekin Akkus, Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, Ruichuan Chen
2020
-
[105]
Arpita Patra and Ajith Suresh. 2020. BLAZE: Blazing Fast Privacy- Preserving Machine Learning. In Proceedings 2020 Network and Dis- tributed System Security Symposium
2020
-
[106]
Do Le Quoc and Christof Fetzer. 2021. SecFL: Confidential federated learning using TEEs. arXiv preprint arXiv:2110.00981 (2021)
2021 arXiv
-
[107]
Olga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta, Se- bastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious Multi-Party machine learning on trusted processors. In 25th USENIX Security Symposium (USENIX Security 16) . 619–636
2016
-
[108]
Sinem Sav, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, David Froelicher, Jean-Philippe Bossuat, Joao Sa Sousa, and Jean- Pierre Hubaux. 2021. POSEIDON: Privacy-Preserving Federated Neu- ral Network Learning. In Proceedings 2021 Network and Distributed System Security Symposium
2021
-
[109]
Vinnie Scarlata, Simon Johnson, James Beaney, and Piotr Zmijewski
-
[110]
Benedict Schlüter, Supraja Sridhara, Andrin Bertschi, and Shweta Shinde. 2024. WeSee: using malicious #VC interrupts to break AMD SEV-SNP. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE, 4220–4238
2024
-
[111]
Do Le Quoc, Franz Gregor, Sergei Arnautov, Roland Kunkel, Pramod Bhatotia, and Christof Fetzer. 2020. SecureTF: A Secure TensorFlow Framework. In Proceedings of the 21st International Middleware Con- ference. 44–59
2020
-
[112]
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov
-
[113]
https: //docs.snowflake.com/en/user-guide/cleanrooms/demo- flows/machine-learning
Snowflake Data Clean Room: Machine Learning . https: //docs.snowflake.com/en/user-guide/cleanrooms/demo- flows/machine-learning. Accessed: 2025-04-10
2025
-
[114]
https://www
Snowflake Data Marketplace | Snowflake Data Cloud . https://www. snowflake.com/en/data-cloud/marketplace/. Accessed: 2025-04-10
2025
-
[115]
David M Sommer, Sebastian Meiser, and Esfandiar Mohammadi. 2019. Privacy Loss Classes: The Central Limit Theorem in Differential Privacy. Proceedings on Privacy Enhancing Technologies 2 (2019), 245–269
2019
-
[116]
Ming-Wei Shih, Sangho Lee, Taesoo Kim, and Marcus Peinado. 2017. T-SGX: Eradicating Controlled-Channel Attacks Against Enclave Programs. In NDSS, Vol. 6. 15–43
2017
-
[117]
Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017. CLKSCREW: Exposing the perils of Security-Oblivious energy man- agement. In 26th USENIX Security Symposium (USENIX Security 17) . 1057–1074
2017
-
[118]
https://www.youtube.com/watch?v= BBpxx5JDmcI
The Status Quo of Confidential Computing Panel Discussion with AMD, Azure, Intel, & NVIDIA . https://www.youtube.com/watch?v= BBpxx5JDmcI. Accessed: 2025-04-10
2025
-
[119]
Han Tian, Chaoliang Zeng, Zhenghang Ren, Di Chai, Junxue Zhang, Kai Chen, and Qiang Yang. 2022. Sphinx: Enabling privacy-preserving online learning over the cloud. In 2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 2487–2501
2022
-
[120]
Florian Tramer and Dan Boneh. 2018. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287 (2018)
2018 arXiv
-
[121]
Anna Trikalinou and Dan Lake. 2017. Taking DMA attacks to the next level. BlackHat USA (2017), 22–27
2017
-
[122]
https://stability.ai/stable-image
Stability AI Image Models . https://stability.ai/stable-image. Ac- cessed: 2025-04-10
2025
-
[123]
Jo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens, and Raoul Strackx. 2017. Telling your secrets without page faults: Stealthy page Table-Based attacks on enclaved execution. In 26th USENIX Security Symposium (USENIX Security 17) . 1041–1056
2017
-
[124]
Daan Vanoverloop, Andres Sanchez, Flavio Toffalini, Frank Piessens, Mathias Payer, and Jo Van Bulck. 2025. TLBlur: Compiler-Assisted Automated Hardening against Controlled Channels on Off-the-Shelf Intel SGX Platforms. In 34th USENIX Security Symposium (USENIX Security 25)
2025
-
[125]
Kapil Vaswani, Stavros Volos, Cedric Fournet, Antonio Nino Diaz, Ken Gordon, Balaji Vembu, Sam Webster, David Chisnall, Saurabh Kulkarni, Graham Cunningham, Richard Osborne, and Daniel Wilkin- son. 2023. Confidential Computing within an AI Accelerator. In 2023 USENIX Annual Te...
2023
-
[126]
Sameer Wagh, Divya Gupta, and Nishanth Chandran. 2019. Se- cureNN: 3-party secure computation for neural network training. Proceedings on Privacy Enhancing Technologies (2019)
2019
-
[127]
Sameer Wagh, Shruti Tople, Fabrice Benhamouda, Eyal Kushilevitz, Prateek Mittal, and Tal Rabin. 2021. Falcon: Honest-Majority Mali- ciously Secure Framework for Private Deep Learning. In Proceedings on Privacy Enhancing Technologies
2021
-
[128]
Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the Intel SGX kingdom with transient Out-of-Order execution. In 27th USENIX Secu...
2018
-
[129]
Luca Wilke and Gianluca Scopelliti. 2024. SNPGuard: Remote At- testation of SEV-SNP VMs Using Open Source Tools. arXiv preprint arXiv:2406.01186 (2024)
2024 arXiv
-
[130]
Xinwei Wu, Li Gong, and Deyi Xiong. 2022. Adaptive differential privacy for language model training. In Proceedings of the First Work- shop on Federated Learning for Natural Language Processing (FL4NLP 2022). 21–26
2022
-
[131]
Yuanzhong Xu, Weidong Cui, and Marcus Peinado. 2015. Controlled- channel attacks: Deterministic side channels for untrusted operating systems. In 2015 IEEE Symposium on Security and Privacy . IEEE, 640– 656
2015
-
[132]
Hongxu Yin, Arun Mallya, Arash Vahdat, Jose M Alvarez, Jan Kautz, and Pavlo Molchanov. 2021. See through gradients: Image batch recovery via gradinversion. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 16337–16346
2021
-
[133]
Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Tes- tuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov
-
[134]
Zihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang, John Mitchell, Haixu Tang, and XiaoFeng Wang. 2024. DPAdapter: Improving Differ- entially Private Deep Learning through Noise Tolerance Pre-training. arXiv preprint arXiv:2403.02571 (2024)
2024 arXiv
-
[135]
Shixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang, Yinqian Zhang, and Zhiqiang Lin. 2023. Reusable enclaves for confidential serverless computing. In 32nd USENIX Security Symposium (USENIX Security 23). 4015–4032
2023
-
[136]
Ziqiao Zhou, Weiteng Chen, Sishuai Gong, Chris Hawblitzel, Wei- dong Cui, et al. 2024. VeriSMo: A verified security module for confi- dential VMs. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24) . 599–614
2024
-
[137]
Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems (NeurIPS) 32 (2019)
2019
-
[138]
Ruofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie, and Rui Chang
-
[139]
Yuqing Zhu, Jinshuo Dong, and Yu-Xiang Wang. 2022. Optimal Accounting of Differential Privacy via Characteristic Function. Pro- ceedings of The 25th International Conference on Artificial Intelligence and Statistics (2022). Appendix A Differential Privacy Analysis A.1 Backgrou...
2022
-
[141]
Chengliang Zhang, Junzhe Xia, Baichen Yang, Huancheng Puyang, Wei Wang, Ruichuan Chen, Istemi Ekin Akkus, Paarijaat Aditya, and Feng Yan. 2021. Citadel: Protecting data privacy and model confidentiality for collaborative learning. In Proceedings of the ACM Symposium on Cloud C...
2021
-
[148]
World”, “Sports
and from the fact that the means and vari- ance in the sums of Gaussian random variables sum up, and by plugging in the resulting Gaussian random variable in the formula (3). The analytical form of Eq. (10) for a Gaussian PLRV with noise variance𝜎 2 total is shown, e.g., in [1...
-
[832]
https://proceedings.mlsys.org/paper_files/paper/2022/file/ a8bc4cb14a20f20d1f96188bd61eec87-Paper.pdf
2022
-
[2015]
In Pro- ceedings 2015 Network and Distributed System Security Symposium
Machine Learning Classification over Encrypted Data. In Pro- ceedings 2015 Network and Distributed System Security Symposium
2015
-
[2017]
In 2017 IEEE symposium on security and privacy (S&P)
Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (S&P) . IEEE, 3–18
2017
-
[2018]
White paper 12 (2018)
Supporting third party attestation for Intel SGX with Intel data center attestation primitives. White paper 12 (2018)
2018
-
[2020]
IEEE signal processing magazine 37, 3 (2020), 50–60
Federated learning: Challenges, methods, and future directions. IEEE signal processing magazine 37, 3 (2020), 50–60
2020
-
[2021]
arXiv preprint arXiv:2109.12298 (2021)
Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298 (2021)
2021 arXiv
-
[2025]
In Proceedings of the 2025 IEEE Symposium on Security and Privacy (S&P)
My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (S&P) . IEEE, IEEE. 16 Protecting Confidentiality, Privacy and Integrity in Collaborative Learning
2025
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.