Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-12T16:26:48.676389Z
Paper Citation Record · LEDGER
As of 12 August 2026, this Paper Citation Record lists 100 of 183 outbound references and 0 inbound Pith citation observations for arXiv:2411.13459.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-12T16:26:48.676389Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
100 of 183 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 1d17ed6a-3366-4383-8ad2-b54beb828302 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Chatgpt
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f01b204-8f3b-4f9a-be43-d7e34c5f8bf2 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Unresolved cited work
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2fd8c185-aab8-471a-a86f-60564ed38176 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Copilot
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dad5238a-3b3f-4907-9961-e2e0635d5ab3 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Autopilot and full self-driving (supervised) — tesla support
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ec675b08-ab3d-43c3-9bae-8a305dca1ab7 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Ocr software, data extraction tool - amazon textract - aws
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 33ffdc73-91a2-4068-a711-b6652d764da9 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Membership inference attacks against machine learning models,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3623de56-1558-4e47-8628-c21f79548049 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Stealing machine learning models via prediction {APIs},
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 37fbd553-7ace-48c2-8922-aee8964aef4d · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Model recon- struction from model explanations,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 557c188d-75e8-4192-b5e0-51b8f1138795 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures A comprehensive survey on poisoning attacks and countermeasures in machine learning,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 489d4c49-8f46-4ef2-b7b4-a870bbbaa300 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Dnn model theft through trojan side-channel on edge fpga accelerator,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 204e6b4e-8c75-4c38-b125-6446f16503ae · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures SESAME: Software defined Enclaves to Secure Inference Accelerators with Multi-tenant Execution
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 2c803071-fa07-4468-bb83-b674efee5103 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Triton: Software-defined threat model for secure multi-tenant ml inference accelerators,
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ca00561-6bfc-4401-80fb-f35653897198 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Prada: protecting against dnn model stealing attacks,
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 06f9fe30-71ee-46ce-912f-366bea2cf12d · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Machine un- learning,
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a748a3f0-90a9-45c4-a2b9-8bef5c150b0c · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Strong data augmenta- tion sanitizes poisoning and backdoor attacks without an accuracy tradeoff,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 53e21c43-9069-44a0-b7df-cd9616216253 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Privacy side channels in machine learning systems,
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2c529706-eb42-4fc0-8b29-2c301376cffb · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures The shift from models to compound ai systems
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 064ee7b0-6077-426c-a3ee-19a2d482a331 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Langchain framework
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 972d7a8a-8d79-429b-a41d-f7de21be0416 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Pytorch
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3f9d310a-be17-4adc-9b5b-a82a72a97516 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cuda® deep neural network library
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 144b293c-d386-48a3-b195-c7f23c982fbe · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rowhammer: A retrospective,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fe8ce346-3722-45a3-834f-7ae60d1345cf · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures SoK: Memorization in General-Purpose Large Language Models
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0874ad74-5bd5-4f9c-b943-b7db0774799c · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sok: Security and privacy in machine learning,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e34c7f6d-42b0-408c-85b7-09a9c1033435 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sok: Membership inference is harder than previously thought,
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 37c68c4c-db04-40d8-b1e6-8cdc8f5a250e · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 18ceb25b-385e-4548-8858-cd1694413110 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Mitre attack framework
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a2676bbf-b45d-4303-9a01-018f52ee0a50 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures In-datacenter performance analysis of a tensor processing unit,
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0d5effc0-21c5-464e-8b7b-b807ed32fd6d · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Github copilot
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ab437fca-2a7e-42c4-b9ed-6d5ff5885adb · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Amazon q developer
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ebafccad-0762-4dec-a490-eb53f707e950 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Mistral ai
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e4e203ee-f4c4-4588-ab65-ad1fd0c3bdea · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Clip-decoder: Zeroshot multilabel classifica- tion using multimodal clip aligned representations,
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 014c581d-3965-463e-8c94-74954065ef5c · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Mitre att&ck: Design and philosophy,
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 40188ab7-adae-4237-98cb-048d710e886b · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Ev- erywhere all at once: Co-location attacks on public cloud faas,
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1885305f-dbab-4dea-ad1e-20cca475a317 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Theory and practice of finding eviction sets,
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5baa0dc4-8fbb-49d6-9411-86d725c74980 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Flush+ reload: A high resolution, low noise, l3 cache side-channel attack,
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 42911aa2-2358-4345-9d07-06e8d604d882 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cache missing for fun and profit,
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d5ce4d8b-fac2-49fa-93b0-34f971675527 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Confusedpilot: Confused deputy risks in rag-based llms,
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24309597-0288-42a2-ba3c-62f72bca1b5d · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cache telepathy: Lever- aging shared resource attacks to learn dnn architectures,
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d2895b32-7b18-46dc-95a7-5ff23235f0f7 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Hugging face
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 32ac1193-7b6c-47b2-a125-e360f9d160c3 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Google tensorflow
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fb37b1fc-7cc8-4dd4-b43c-df96d2a920d0 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Apache spark
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0356afa5-d899-42e0-9c49-e0015a0aeadf · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Apache hadoop
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e588a361-37a6-492e-a618-2d27f79f663f · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Snowflake
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 54555caf-c53d-4313-8758-7a3e6df3b886 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Bentoml
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 35a17ec1-9088-49a0-9e98-0a7a4e1ab88e · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Kubernetes
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3287ac1d-c9d4-47db-9723-13a9a293099c · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Pyyaml package
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eaae5611-df31-4694-8a1c-cb10e3df3a4a · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cve-2023-31035
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 05c08627-4426-42c2-bcae-3c2d86394343 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cve-2024-3095
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8f73ffd2-41be-4715-9135-217dcd657ac6 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Formal verification methods,
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aaff326a-2956-43c9-86c0-f3811c7b3d37 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Hfl: Hybrid fuzzing on the linux kernel.,
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 108975ce-905a-432a-b103-abebdc116bed · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sok: A defense- oriented evaluation of software supply chain security,
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 25808180-b641-4818-bf05-fe54c4d28a44 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sok: Taxonomy of attacks on open-source software supply chains,
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4bbe68ab-0217-45a0-853d-70ec7a482aa2 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Practical automated detection of ma- licious npm packages,
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 96743c1a-c479-4ad3-a59f-5e6260240558 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Immutability and encapsulation for sound oo information flow control,
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4d9060f9-dd1e-48f5-b94e-b86921103dbc · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Raksha: a flexible information flow architecture for software security,
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ce1b3b7d-370c-4d1e-8df3-dd89c5b0159a · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Mod- ular information flow through ownership,
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3f44c7c0-ecc2-4cd4-a42f-100b5103c820 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rethinking privacy in machine learning pipelines from an information flow control perspective,
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9dc92f20-9424-4a27-a16d-0b2a8d49beca · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rust ai engine
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 550f4880-d673-4bb2-a2b7-bc3dd0588a72 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rusty Linux: Advances in Rust for Linux Kernel Development
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 399c3b4f-0cb8-4282-ba98-7ffcbdc5185f · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Erim: Secure, efficient in-process isolation with memory protection keys,
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b2b57b35-95be-4e5b-ab0b-2cafff4f3ab9 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Securecells: A secure compartmentalized architecture,
Reference 62
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d87f32df-493c-4e33-a896-fd520c9027b9 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Retrofitting fine grain isola- tion in the firefox renderer,
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 190ae8d1-6aaf-46cd-8bd7-a596ccddf4f8 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Going beyond the limits of sfi: Flexible and secure hardware-assisted in-process isolation with hfi,
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 721c84b2-d2fd-4705-8a9f-547fdc9def69 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Cheri: A hybrid capability-system architecture for scalable software compart- mentalization,
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b6683080-c406-4bc5-bdde-41b386c686f3 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Morpheus: A vulnerability-tolerant secure architecture based on ensembles of moving target defenses with churn,
Reference 66
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8476dd99-55c6-43cf-8774-b9ebdf5b0f71 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Boosting microservice resilience: An evaluation of istio’s impact on kubernetes clusters under chaos,
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ceaf804e-5ea7-41c5-b86e-53977a75c8fe · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rethinking system audit architectures for high event coverage and synchronous log availability,
Reference 68
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 58efcf24-36ff-4e47-9516-d195d20c03fa · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Nvidia bluefield dpu
Reference 69
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f5f881b3-bd28-41a3-ab63-c7f2553d0516 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Practical cold boot attack on iot device-case study on raspberry pi,
Reference 70
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 263d8b64-888d-43a9-8239-0266fc06f838 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Warm-boot attack on modern drams,
Reference 71
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c9c62902-f948-41f2-a033-660fd34ce7fa · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Drama: Exploiting dram addressing for cross-cpu attacks,
Reference 72
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f30e256-67bb-4793-8b14-eb6d76ae4b5e · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Dramaqueen: Revisiting side channels in dram,
Reference 73
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 211e7a6c-cbdc-4b01-a0b4-28c5541d576b · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Nvleak:off-chip side-channel attacks via non-volatile mem- ory systems,
Reference 74
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d157c122-07c4-4ec7-a926-7567ffbecda3 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips,
Reference 75
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5ae70405-4990-4f42-95e3-8ff737f8dab4 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Yes, one-bit-flip matters! universal dnn model inference depletion with runtime code fault injection,
Reference 76
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6963e044-0169-4e9f-9ee9-60817fa4a450 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Bit-flip attack: Crushing neural net- work with progressive bit search,
Reference 77
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f8a59798-f740-44a7-8bbb-6a9e4f71bc19 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rambleed: Reading bits in memory without accessing them,
Reference 78
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation da900df5-04ce-4da4-a5a1-d492bb3524e5 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories,
Reference 79
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fb71c962-833f-4c25-8d26-99ef05fc38f0 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Side- channel attack analysis on in-memory computing architectures,
Reference 80
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a2b2078d-11ca-4c38-9a96-f01240882ae7 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Powergan: A machine learning approach for power side-channel attack on compute-in-memory accelerators,
Reference 81
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 61710016-9e82-44dd-87de-56999f9268f7 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Revisiting Main Memory-Based Covert and Side Channel Attacks in the Context of Processing-in-Memory
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation e51fb4c3-a8e1-4683-be93-36b6ece115db · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Understanding error propagation in deep learning neural network (dnn) accelerators and applications,
Reference 84
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d534396-8608-40df-be87-d2cee68c26e6 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Fault injection for tensorflow applications,
Reference 85
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bbf05e1c-e2b6-41a5-9dbe-3c91e0af95fb · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures pcileech
Reference 86
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5d129d9f-d4e8-46c8-99fb-2388081e48db · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Thunderclap: Exploring vulnerabilities in operating system iommu protection via dma from untrustworthy peripherals,
Reference 87
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8a99724b-4896-4c5c-9be6-de8f01817929 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures New Security Challenges on Machine Learning Inference Engine: Chip Cloning and Model Reverse Engineering
Reference 88
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation f0672432-354f-4c0a-91ba-ee28e83f3817 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Reverse engineering convo- lutional neural networks through side-channel information leaks,
Reference 89
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 53bcbfe3-0b18-40b4-8699-c7a40666cf95 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Bandwidth Utilization Side-Channel on ML Inference Accelerators
Reference 90
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation c3ca3481-d1d6-4c0e-9e25-2fe542debe1d · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Chen, “Hmtt.” https://asg.ict.ac.cn/hmtt/, 2019
Reference 91
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3868178d-67b2-431a-a1b9-ccd362399909 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Hermes attack: Steal dnn models with lossless inference accuracy,
Reference 92
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a7d94e91-e12f-42ad-9d1d-303fe9e97597 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Deepsniffer: A dnn model extraction framework based on learning architectural hints,
Reference 93
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5abedf82-125e-468f-a382-743827a267ee · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Rendered insecure: Gpu side channel attacks are practical,
Reference 94
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ed03dd3c-df11-452b-b4d0-a6b0dfda7548 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel,
Reference 95
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 68b595f5-31e1-405a-99cb-af3984fb2cbc · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Huffduff: Stealing pruned dnns from sparse accelerators,
Reference 96
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3978d5cf-f87e-45a7-a3c4-6528d4d6e55c · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Sparsity turns adver- sarial: Energy and latency attacks on deep neural networks,
Reference 97
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c244e5e0-6157-400c-83e3-fbfdb18d94d2 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Beyond the Bridge: Contention-Based Covert and Side Channel Attacks on Multi-GPU Interconnect
Reference 98
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 0a97080f-1d13-4473-96a5-7a6d4b080585 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Invisible probe: Timing attacks with pcie congestion side-channel,
Reference 99
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9f0f7c9c-80b9-4384-90c8-fbd16c6373b0 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Stealing Neural Networks via Timing Side Channels
Reference 100
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1e6eccc7-381f-4f0d-b662-98717b445e92 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Layer sequence extraction of optimized dnns using side-channel information leaks,
Reference 101
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 970cae3d-372a-4c83-933b-495f7cf64523 · outbound
SoK: A Systems Perspective on Compound AI Threats and Countermeasures Practical attacks on deep neural networks by memory trojaning,
Reference 102
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.