Pith. sign in

REVIEW 3 major objections 4 minor 148 references

Protecting Confidentiality, Privacy and Integrity in Collaborative Learning

T0 review · 3 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read Even n-1 colluding owners can't strip DP privacy

desk verdict Strong TEE-based system with a real privacy hole at the center: the collusion-resistance claim is unproven and a natural mask choice breaks it. read the letter →

arxiv 2412.08534 v2 pith:U75ZAZZ4 submitted 2024-12-11 cs.DC cs.CRcs.LG

classification cs.DCcs.CRcs.LG
keywords differentialprivacyDP-SGDtrustedexecutionenvironmentconfidentialcomputinggradientmaskingcollaborativelearningfederatedsandboxing
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that collaborative machine learning can simultaneously protect three things that are usually in tension: the confidentiality of the training data, the confidentiality of the model and its training code, and the differential privacy of individual users whose data appears in the dataset. The proposed system, Citadel++, runs each party's component inside VM-level trusted execution environments and inserts a privacy barrier between data handling and model updating. The barrier adds random masks whose sum is exactly the Gaussian noise of DP-SGD, so the aggregated update carries the same privacy guarantee as central DP-SGD. The paper further claims that this guarantee survives worst-case collusion: even if the model owner and up to $n-1$ dataset owners share everything they see, the remaining dataset owner's data is still protected by the full noise.

What carries the argument

The load-bearing object is the differentially private masking scheme: masks are drawn so their sum is one Gaussian sample of scale $\sigma C$, matching the central DP-SGD noise; each handler adds its mask before release and the updater aggregates, so the released aggregate is DP-SGD's update. Two supporting mechanisms carry the argument: dynamic gradient clipping, where a noisy histogram of gradient norms selects the clipping bound each round with per-bin $\ell_2$-sensitivity at most $\sqrt{2}$, and DP noise correction, where iteration $t+1$ adds $\xi_{t+1}-\lambda\xi_t$, so short sequences of per-iteration gradients are harder to denoise while the final model's noise is unchanged. The sandbox with network, filesystem, and IPC isolation is what forces the untrusted training code to output only through this barrier.

What would settle it

Construct the adversarial view explicitly: give the colluding parties their masks and all masked gradients, then compute the hockey-stick divergence between neighboring datasets for the remaining owner's contribution. If the released aggregate plus the $n-1$ known masks lets an attacker recover the noise $\xi$, or any function with sensitivity larger than the DP-SGD bound, with better-than-Gaussian accuracy, the collusion claim is false; measuring that divergence numerically for any concrete mask distribution settles it.

Watch

Extended reading notes

Core claim

Citadel++'s central claim is that differential privacy for individual data records can be enforced by construction in a collaborative training session, without trusting or inspecting the model owner's code. The construction: a trusted admin component generates $n$ masks $m_1,\ldots,m_n$ whose sum $\sum_i m_i = \xi$ is a single Gaussian draw $\mathcal{N}(0,\sigma^2 C^2 I)$; data handler $i$ sends the masked gradient $g_i + m_i$, and the model updater's aggregate is $\sum_i g_i + \xi$, exactly the DP-SGD update. Consequently each individual masked gradient is uniformly random given the others, and the paper claims that collusion among the model owner and up to $n-1$ dataset owners does not reduce the DP noise protecting the non-colluding owner. Dynamic gradient clipping and a noise-correction step extend the same accounting without changing the final model's privacy-utility trade-off.

Load-bearing premise

The guarantee that a non-colluding data owner stays private when the model owner and $n-1$ dataset owners collude is asserted without a formal proof or a specified mask distribution: the paper does not analyze the adversary who sees all masked gradients and knows the masks of $n-1$ colluding owners.

Editorial extensions

If this is right

  • A model owner can offer proprietary training code without showing it to data owners, and data owners can keep their datasets encrypted at rest and in use inside TEEs.
  • The final model's accuracy matches central DP-SGD at the same $(\varepsilon,\delta)$ budget, because the aggregate gradient distribution is identical.
  • Per-iteration gradients are protected against reconstruction and membership-inference attacks, since each released gradient is individually masked.
  • Citadel++ can run on GPU TEEs and match non-confidential federated learning speed, with reported speedups of up to 543x on CPU and 113x on GPU over cryptographic baselines.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the privacy-under-collusion claim is proved with a concrete mask distribution and composition analysis, the same masking construction could be reused as a drop-in secure-aggregation layer for federated learning without TEEs.
  • The noise-correction step is effectively a moving-average filter on the noise, which suggests a family of higher-order correction schemes that shrink per-iteration privacy loss further at the cost of more complex accounting.
  • Using the paper's own formulas for bounded-length update sequences, one could tune $\lambda$ adaptively to maximize per-iteration privacy for a fixed final-model privacy budget.
  • The sandboxing results imply that the main cost of containing malicious code is the boundary between the trusted service container and the untrusted handler, not the TEE itself.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. Citadel++ is a collaborative ML training system that combines VM-level TEEs (AMD SEV-SNP, Intel TDX, NVIDIA H100) with a DP-based privacy barrier to protect dataset, model, and code confidentiality, and individual privacy. The privacy barrier consists of DP-masking, dynamic gradient clipping, and DP noise correction. The paper also contributes sandboxing of untrusted training code via OS namespaces and integrity enhancements for Confidential Containers. Experiments show the system is competitive with non-confidential FL and much faster than cryptographic baselines.

Significance. The system-level engineering is substantial: the paper demonstrates a full implementation with GPU TEE support, sandboxing, and integrity mechanisms, and the performance evaluation is careful and extensive. If the privacy claims held, Citadel++ would be an important practical step toward confidential collaborative learning with DP guarantees. However, the central privacy claims are not yet rigorously established: the DP-masking scheme is under-specified, the adversary's full view is not modeled, and the noise-correction privacy formulas contain algebraic errors. These issues are load-bearing because the paper's main novelty over prior TEE-based systems is its privacy barrier.

major comments (3)
  1. [Sec. 4.2, Sec. 7, Sec. 8.2] The DP-masking mechanism is under-specified and the privacy analysis does not model the adversary's actual view. The paper fixes only the sum of masks, Σ_i m_i = ξ ~ N(0, σ²C²I), and Section 7's accounting (with Appendices A.1-A.2) covers only the aggregated output Σ_i g_i + ξ. However, the model updating component receives each per-handler value g_i + m_i individually, and the model owner may collude with up to n-1 dataset owners who can reveal their true gradients g_j and, from the observed g_j + m_j, their masks m_j. Section 8.2 asserts without proof that the non-colluding owner's g_i remains protected by the full DP noise. This is false for a natural instantiation: if m_i = ξ/n for all i, one colluding owner's mask reveals ξ, and then the adversary obtains m_i and solves for g_i exactly from g_i + m_i. If instead the masks are i.i.d. with variance σ²C²/n, each per-handler release carries only noise σC/√n, which is weaker than the claimed DP-SGD noise σC unless the composition of per-handler releases is explicitly accounted for. The paper must specify the exact joint distribution of (m_1,...,m_n) and provide a DP analysis of the entire view (g_1+m_1,...,g_n+m_n, Σ_i(g_i+m_i)), including the colluding-adversary case, before the central privacy claim can be evaluated.
  2. [Appendix A.3.1, Eq. (6) and Thm. 5] The composition formula for T Gaussian mechanisms is algebraically incorrect. Eq. (6) reads δ(ε) = Φ(-εσ√T + √T/(2σ)) - e^ε Φ(-εσ√T - √T/(2σ)); the correct expression, obtained by composing T mechanisms each with sensitivity 1 and noise scale σ, is Φ(-εσ/√T + √T/(2σ)) - e^ε Φ(-εσ/√T - √T/(2σ)). The same reciprocal error appears in Theorem 5, where σ_total = sqrt(T/\tilde{σ}² + n_g/σ_g²) is defined as the standard deviation of the resulting PLRV but is then used in the Gaussian CDF in place of the reciprocal of the effective noise scale. The resulting formula is dimensionally inconsistent, so the privacy numbers for the noise-correction mechanism (Section 10.1, Figure 8, Appendix A.3.3) are not reliable. The proof of Theorem 5 also does not use the histogram sensitivity √2 stated in Section 4.3, so the σ_total definition is inconsistent with the mechanism's stated sensitivity.
  3. [Sec. 10.1, Figs. 5 and 8] The abstract and Section 1 claim that Citadel++ 'matches the model utility of standard central DP-SGD mechanisms,' but the experiments never compare against a central DP-SGD baseline. Figure 5 shows accuracy for different ε values against a non-private upper bound only; Figure 8 compares DP-GD with and without noise correction. Without a DP-SGD reference curve and without error bars over multiple runs, the utility-parity claim is not empirically substantiated. Since this is one of the paper's headline contributions, the evaluation should include a direct DP-SGD comparison and report variability across seeds.
minor comments (4)
  1. [Sec. 4.2] The notation 'Σ_{i=1}^n m_i = N(0, σ²C²I)' is mathematically imprecise; the left-hand side is a random variable, so the expression should read 'Σ_i m_i ~ N(0, σ²C²I)'.
  2. [Sec. 8.2] The statement that 'Noise correction further prevents attackers from correlating noise across iterations' is not analyzed in the collusion context; Appendix A.3.3 considers sequences of updates but does not connect to the colluding-adversary model of Section 8.2.
  3. [Appendix B] The text says 'we launched one admin, one model handling, and four data handling components'; for consistency with the rest of the paper, 'model handling' should be 'model updating'.
  4. [Fig. 5 caption] The legend labels 'ε = 50', etc., should specify that these are privacy budgets; the caption currently does not define the parameter.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation found: the DP-SGD accounting and noise-correction proofs are self-contained, and the only notable gap (the collusion-resistance assertion in Sec. 7 and Sec. 8.2) is a missing proof, not a circular argument.

full rationale

Walking the paper's claimed derivation chain, the DP mechanisms are not circular. (1) The DP-masking construction in Sec. 4.2 is explicitly definitional: the admin generates masks such that the sum is DP noise, "Σ_{i=1}^n m_i = N(0, σ^2 C^2 I) = ξ," and the aggregate becomes "Σ_i g_i + ξ." The paper says "by design" this matches DP-SGD, so the aggregate guarantee is the definition of the construction rather than a derived result that secretly assumes its conclusion. (2) The dynamic-clipping accounting in Theorem 3 is a standard PLRV composition over DP-SGD PLRVs and histogram Gaussian mechanisms with sensitivity √2, citing external numerical accounting works [48, 139] and the Opacus implementation; this is independent support, not a self-citation chain. (3) The noise-correction proof in Appendix A.3 is a self-contained unrolling of the update equations into Gaussian mechanisms with sensitivity at most 1/(1−λ), yielding an effective noise scale eσ = (1−λ)σ; this is a direct sensitivity calculation that does not assume the target DP guarantee. The §4.4 statement that the raw noise level is σ/(1−λ) is consistent with this derivation when σ denotes the target DP-SGD noise scale. The real gap is the collusion claim: Sec. 7 asserts that DP masking "simply extends those guarantees even when the model owner and up to n−1 data owners collude (§8.2)", and Sec. 8.2 concludes that "the non-colluding dataset owners are still protected with the full DP noise." No theorem in the paper analyzes the honest owner's per-owner release g_h + m_h in the view of that colluding adversary; Sec. 4.2 fixes only the sum of the masks, not the joint distribution of (m_1, ..., m_n), so whether the honest owner's marginal mask provides σ-scale noise is unproven (and for the equal-split instantiation m_i = ξ/n it does not). This is a completeness and correctness concern about an asserted security property, not a circularity: the claim is not used as an input to, nor is it equivalent by construction to, the definition of the masking mechanism. The only self-citation is the architectural reference to the predecessor Citadel [134], which is not load-bearing for the new DP claims. Consequently, no specific circular step can be exhibited, and the appropriate circularity score is 0.

Assumptions & free parameters 6 free parameters · 5 assumptions · 0 invented entities

The paper introduces no new physical or cryptographic entities. Its mechanisms (DP masking, dynamic clipping, noise correction, sandboxing) are built from standard TEE, DP, and OS primitives. The free parameters are configuration choices for the DP mechanisms, not fitted constants. The key unstated premise is the mask distribution that would make the collusion-resilience claim hold.

free parameters (6)
  • DP noise scale sigma = varies per experiment (e.g., 3, 10, 15, 50)
    Chosen by hand to meet privacy budgets; not fitted to data.
  • Noise correction coefficient lambda = 0.7, 0.9
    Chosen for evaluation; affects per-iteration privacy.
  • Histogram noise scale sigma_g = not reported
    Used in dynamic gradient clipping; value not specified in evaluation.
  • Clipping percentile r = tested at 1%, 10%, ..., 99%
    Dynamic clipping parameter chosen in experiments.
  • Initial clipping bound = 2.0 for MNIST-MLP3
    Starting bound for dynamic clipping.
  • Subsampling ratio q = varies with batch size
    DP-SGD subsampling; part of accounting.
assumptions (5)
  • domain assumption TEEs (AMD SEV-SNP, Intel TDX, NVIDIA H100 Confidential Computing) provide the stated confidentiality and integrity guarantees.
    The threat model in Sec 2.2 explicitly excludes side-channel and physical attacks and assumes TEE guarantees are intact.
  • domain assumption Per-sample gradient clipping bounds the L2 sensitivity of each data point's contribution to C.
    Standard DP-SGD assumption, used throughout Sec 4 and 7; the untrusted data handling code is assumed to produce clipped gradients.
  • standard math PLRV-based composition theorems from [48,139] are correct.
    Used in Theorem 3 and Appendix A.2 for DP accounting.
  • standard math Differential privacy is closed under post-processing.
    Used in the noise correction proof in Appendix A.3.1 to discard previously released mechanisms.
  • domain assumption The service code is open-sourced and correctly measured by remote attestation.
    Needed for integrity guarantees in Sec 6; assumes the attested code is the code that runs.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Protecting Confidentiality, Privacy and Integrity in Collaborative Learning." pith.science (2026). https://pith.science/paper/U75ZAZZ4

@misc{pith2026241208534,
  author       = {Pith},
  title        = {Pith review of: Protecting Confidentiality, Privacy and Integrity in Collaborative Learning},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/U75ZAZZ4}},
  note         = {Machine review of arXiv:2412.08534}
}
read the original abstract

A collaboration between dataset owners and model owners is needed to facilitate effective machine learning (ML) training. During this collaboration, however, dataset owners and model owners want to protect the confidentiality of their respective assets (i.e., datasets, models and training code), with the dataset owners also caring about the privacy of individual users whose data is in their datasets. Existing solutions either provide limited confidentiality for models and training code, or suffer from privacy issues due to collusion. We present Citadel++, a collaborative ML training system designed to simultaneously protect the confidentiality of datasets, models and training code as well as the privacy of individual users. Citadel++ enhances differential privacy mechanisms to safeguard the privacy of individual user data while maintaining model utility. By employing Virtual Machine-level Trusted Execution Environments (TEEs) as well as the improved sandboxing and integrity mechanisms through OS-level techniques, Citadel++ effectively preserves the confidentiality of datasets, models and training code, and enforces our privacy mechanisms even when the models and training code have been maliciously designed. Our experiments show that Citadel++ provides model utility and performance while adhering to the confidentiality and privacy requirements of dataset owners and model owners, outperforming the state-of-the-art privacy-preserving training systems by up to 543x on CPU and 113x on GPU TEEs.

Figures

Figures reproduced from arXiv: 2412.08534 by the authors.

Figure 1
Figure 1. High-level overview of Citadel++. §5 and §6), and is crucial for achieving our confidentiality and privacy goals for datasets, models and training code. Performance: The protection mechanisms in Citadel++ should not affect the training performance. Citadel++ should achieve no worse (often better) results for model accuracy and training time, compared to the state-of-the-art confiden￾tial training systems with weaker… view at source ↗
Figure 2
Figure 2. Differential-private masking. 4.2 Differentially-Private Masking The potentially malicious model updating code (provided by a model owner) can utilize the received gradients to infer sensitive information about the training datasets [19, 43, 54, 100, 112, 132, 137]. Therefore, the gradients sent from data handling components need to be privacy-protected. We design a differentially-private masking mechanism, where ra… view at source ↗
Figure 4
Figure 4. Citadel++ service integrity mechanisms. endpoints for communication purposes. For instance, the policy can set ExecProcessRequest as false to disable the kubectl exec commands to login into a container, or em￾bed information about the container image integrity (§6.3). A default policy along with a policy manager is embedded in the initrd, whose integrity is covered by the CVM attes￾tation report. Using a default pol… view at source ↗
Figures from the paper (8 more)
Figure 5
Figure 5. Figure 5: Model accuracy and convergence over time, compared with the non-private baselines. for covert-, side-channel and physical attacks, Citadel++ does not completely address them, as stated in our threat model (§2). We note, however, that Citadel++’ modular de￾sign allows t…
Figure 8
Figure 8. Figure 8: MNIST classification problem and a feed-forward neural network, trained using DP Gradient Descent (DP-GD) with and without DP Noise Correction, 𝜆 = 0.7. Execution Environment Overhead [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]
Figure 7
Figure 7. Figure 7: Latency per iteration with and without DP dy￾namic gradient clipping (DP-dyn). component in Citadel++ ensures that no further training is allowed because the full privacy budget is spent (§3.3). With a fixed privacy budget, a longer training time (i.e., more it￾eration…
Figure 9
Figure 9. Figure 9: Latency per iteration for different execution environments. QVM: Kata containers [67], CCT: CoCo with tardev-snapshotter. NS: no sandbox, SB: with sandbox. All evaluations use 12 vCPUs. FL+DP(CPU) Pencil(CPU) Pencil(GPU) Citadel(CPU) Citadel++(CPU) Citadel++(GPU) 10 0 …
Figure 10
Figure 10. Figure 10: Latency per iteration for Citadel++ and the state-of-the-art systems. Missing bars for Pencil are due to out-of￾memory errors (CIFAR10-CNN6 with the batch size of 1024) or unsupported model layers (attention layers in AGNEWS￾Roberta-base). All CPU-based evaluations us…
Figure 11
Figure 11. Figure 11: Latency per iteration for AGNEWS-Roberta-base with CPU only and GPU TEE (H100 in TEE mode). NS: no sandbox, SB: with sandbox. 12/40: number of vCPUs. layers for larger models and batch sizes, while Citadel++ (GPU) outperforms Pencil (GPU) up to 113× in other cases. Th…
Figure 12
Figure 12. Figure 12: MNIST classification problem and a two hidden layers feedforward neural network, trained using the DP Gradient Descent and using the DP Gradient Descent with Noise Correction [PITH_FULL_IMAGE:figures/full_fig_p020_12.png]
Figure 13
Figure 13. Figure 13: 𝜀 values for sequences of subsequent updates for the DP Gradient Descent with and without noise correction, 𝛿 = 10−5 . A.4 Noise Correction as a Matrix Mechanism The proposed noise correction given in Eq. (4) and Eq. (5) can also be seen as a so-called matrix mechanis…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

148 extracted references · 64 canonical work pages

  1. [1]

    Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. InProceedings of the 2016 ACM SIGSAC conference on computer and communications security . 308–318

  2. [2]

    https://www.intel.com/content/www/us/en/developer/topic- technology/software-security-guidance/processors-affected- consolidated-product-cpu-model.html

    Affected Processors: Guidance for Security Issues on Intel Processors . https://www.intel.com/content/www/us/en/developer/topic- technology/software-security-guidance/processors-affected- consolidated-product-cpu-model.html . Accessed: 2025-04-10

  3. [3]

    Nitin Agrawal, Ali Shahin Shamsabadi, Matt J Kusner, and Adrià Gascón. 2019. QUOTIENT: Two-party secure neural network training and prediction. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 1231–1247

  4. [4]

    https://www.kaggle.com/ datasets/amananandrai/ag-news-classification-dataset

    AG’s News Topic Classification Dataset . https://www.kaggle.com/ datasets/amananandrai/ag-news-classification-dataset . Accessed: 2025-04-10

  5. [5]

    Istemi Ekin Akkus and Ivica Rimac. 2024. duet: Combining a Trust- worthy Controller with a Confidential Computing Environment. In 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)

  6. [6]

    Istemi Ekin Akkus, Ivica Rimac, and Ruichuan Chen. 2024. PraaS: Verifiable Proofs of Property as-a-Service with Intel SGX. In2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)

  7. [7]

    Accessed: 2025-04-10

    AMD Secure Encrypted Virtualization (SEV) .https://www.amd.com/ en/developer/sev.html. Accessed: 2025-04-10

  8. [8]

    https://www.amd.com/content/ dam/amd/en/documents/epyc-business-docs/white-papers/SEV- SNP-strengthening-vm-isolation-with-integrity-protection-and- more.pdf

    AMD SEV-SNP: Strengthening VM isolation with integrity protection and more 2020. https://www.amd.com/content/ dam/amd/en/documents/epyc-business-docs/white-papers/SEV- SNP-strengthening-vm-isolation-with-integrity-protection-and- more.pdf. Accessed: 2025-04-10

Show all 148 references
  1. [9]

    Galen Andrew, Om Thakkar, Brendan McMahan, and Swaroop Ra- maswamy. 2021. Differentially private learning with adaptive clip- ping. Advances in Neural Information Processing Systems 34 (2021), 17455–17466

  2. [10]

    Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, and Shiho Moriai. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE transactions on information forensics and security 13, 5 (2017), 1333–1345

  3. [11]

    https://security.apple.com/blog/private-cloud-compute/

    Apple Private Cloud Compute: A new frontier for AI privacy in the cloud . https://security.apple.com/blog/private-cloud-compute/. Accessed: 2025-04-10

  4. [12]

    https://www.arm

    Arm Confidential Compute Architecture . https://www.arm. com/architecture/security-features/arm-confidential-compute- architecture. Accessed: 2025-04-10

  5. [13]

    https://aws.amazon.com/ec2/nitro/nitro- enclaves/

    AWS Nitro Enclaves . https://aws.amazon.com/ec2/nitro/nitro- enclaves/. Accessed: 2025-04-10

  6. [14]

    https://azure.microsoft.com/en-us/ solutions/confidential-compute

    Azure confidential computing . https://azure.microsoft.com/en-us/ solutions/confidential-compute. Accessed: 2025-04-10

  7. [15]

    Borja Balle and Yu-Xiang Wang. 2018. Improving the gaussian mech- anism for differential privacy: Analytical calibration and optimal denoising. In International Conference on Machine Learning . PMLR, 394–403

  8. [16]

    Raphael Bost, Raluca Ada Popa, Stephen Tu, and Shafi Goldwasser

  9. [17]

    Justin Brickell, Donald E Porter, Vitaly Shmatikov, and Emmett Witchel. 2007. Privacy-preserving remote diagnostics. In Proceed- ings of the 14th ACM conference on Computer and Communications Security. 498–507

  10. [18]

    https://oag.ca.gov/ privacy/ccpa

    California Consumer Privacy Act (CCPA) . https://oag.ca.gov/ privacy/ccpa. Accessed: 2025-04-10

  11. [19]

    Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. In2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 1897–1914

  12. [20]

    Harsh Chaudhari, Rahul Rachuri, and Ajith Suresh. 2020. Trident: Efficient 4PC Framework for Privacy Preserving Machine Learning. In Proceedings 2020 Network and Distributed System Security Sympo- sium

  13. [21]

    Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David Oswald, and Flavio D Garcia. 2021. VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID volt- age scaling interface. In 30th USENIX Security Symposium (USENIX Security 21)...

  14. [22]

    Pau-Chen Cheng, Kevin Eykholt, Zhongshu Gu, Hani Jamjoom, KR Jayaram, Enriquillo Valdez, and Ashish Verma. 2024. DeTA: Min- imizing Data Leaks in Federated Learning via Decentralized and Trustworthy Aggregation. In Proceedings of the Nineteenth European Conference on Computer ...

  15. [23]

    https: //images.nvidia.com/aem-dam/en-zz/Solutions/data-center/HCC- Whitepaper-v1.0.pdf

    Confidential Compute on NVIDIA Hopper H100 . https: //images.nvidia.com/aem-dam/en-zz/Solutions/data-center/HCC- Whitepaper-v1.0.pdf . Accessed: 2025-04-10

  16. [24]

    https://confidentialcontainers.org/

    Confidential Containers . https://confidentialcontainers.org/. Ac- cessed: 2025-04-10

  17. [25]

    Graeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman, and Raluca Ada Popa. 2024. Secret Key Recovery in a Global-Scale End- to-End Encryption System. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24) . 703–719

  18. [26]

    Confidential Computing Consortium. 2022. Confidential comput- ing: Hardware-based trusted execution for applications and data. Confidential Computing Consortium Technical Report v1.3 (2022)

  19. [27]

    Confidential Computing Consortium. 2022. A Technical Analysis of Confidential Computing. Confidential Computing Consortium Technical Report v1.3 (2022)

  20. [28]

    https://github.com/containerd/ containerd/tree/main/docs/snapshotters

    Containerd snapshotter docs . https://github.com/containerd/ containerd/tree/main/docs/snapshotters. Accessed: 2025-04-10

  21. [29]

    Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016). 13 Dong Chen, Alice Dethise, Istemi Ekin Akkus, Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, Ruichuan Chen

  22. [30]

    https: //aws.amazon.com/clean-rooms/

    Data Collaboration Service - AWS Clean Rooms - AWS . https: //aws.amazon.com/clean-rooms/. Accessed: 2025-04-10

  23. [31]

    com/data-exchange/

    Data Marketplace - AWS Data Exchange - AWS .https://aws.amazon. com/data-exchange/. Accessed: 2025-04-10

  24. [32]

    https://www.databricks.com/ product/marketplace

    Databricks Marketplace | Databricks . https://www.databricks.com/ product/marketplace. Accessed: 2025-04-10

  25. [33]

    https://datarade.ai/

    Datarade | Find the right data, effortlessly . https://datarade.ai/. Accessed: 2025-04-10

  26. [34]

    Jesse De Meulemeester, Luca Wilke, David Oswald, Thomas Eisen- barth, Ingrid Verbauwhede, and Jo Van Bulck. 2025. BadRAM: Practi- cal Memory Aliasing Attacks on Trusted Execution Environments. In 46th IEEE Symposium on Security and Privacy (S&P)

  27. [35]

    https://github.com/deepseek-ai

    DeepSeek . https://github.com/deepseek-ai. Accessed: 2025-04-10

  28. [36]

    Sergey Denisov, H Brendan McMahan, John Rush, Adam Smith, and Abhradeep Guha Thakurta. 2022. Improved differential privacy for SGD via optimal private linear operators on adaptive streams. Ad- vances in Neural Information Processing Systems 35 (2022), 5910–5924

  29. [37]

    https://docs.kernel.org/admin-guide/ device-mapper/verity.html

    dm-verity in Linux Kernel . https://docs.kernel.org/admin-guide/ device-mapper/verity.html. Accessed: 2025-04-10

  30. [38]

    Friedrich Dörmann, Osvald Frisk, Lars Nørvang Andersen, and Chris- tian Fischer Pedersen. 2021. Not all noise is accounted equally: How differentially private learning benefits from large sampling rates. In 2021 IEEE 31st International Workshop on Machine Learning for Signal P...

  31. [39]

    Cynthia Dwork. 2006. Differential privacy. In International Collo- quium on Automata, Languages, and Programming

  32. [40]

    https://artificialintelligenceact.eu/

    EU Artificial Intelligence Act . https://artificialintelligenceact.eu/. Accessed: 2025-04-10

  33. [41]

    https://github.com/ facebookresearch/fairseq/tree/main/examples/roberta

    fairseq/examples/Roberta - Facebook Research . https://github.com/ facebookresearch/fairseq/tree/main/examples/roberta. Accessed: 2025-04-10

  34. [42]

    Anna Galanou, Khushboo Bindlish, Luca Preibsch, Yvonne-Anne Pignolet, Christof Fetzer, and Rüdiger Kapitza. 2023. Trustworthy confidential virtual machines for the masses. In Proceedings of the 24th International Middleware Conference . 316–328

  35. [43]

    Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning? Advances in neural information processing systems (NeurIPS) 33 (2020), 16937–16947

  36. [44]

    https://gdpr-info.eu/

    General Data Protection Regulation (GDPR) . https://gdpr-info.eu/. Accessed: 2025-04-10

  37. [45]

    Rafael Genés-Durán, Juan Hernández-Serrano, Oscar Esparza, Marta Bellés-Muñoz, and José Luis Muñoz-Tapia. 2021. DEFS—Data Ex- change with Free Sample Protocol. Electronics 10, 12 (2021), 1455

  38. [46]

    Muñoz-Tapia

    Rafael Genés-Durán, Oscar Esparza, Juan Hernández-Serrano, Fer- nando Román-García, Miquel Soriano, Achille Zappa, Martin Serrano, Susanne Stahnke, Birthe Böhm, Edgar Fries, Vasiliki Koniakou, Bruno Michel, and Jose L. Muñoz-Tapia. 2022. Data Marketplaces with a Free Sampling ...

  39. [47]

    https://cloud.google.com/ security/products/confidential-computing

    Google Cloud Confidential Computing . https://cloud.google.com/ security/products/confidential-computing. Accessed: 2025-04-10

  40. [48]

    Sivakanth Gopi, Yin Tat Lee, and Lukas Wutschitz. 2021. Numerical Composition of Differential Privacy. In Advances in Neural Informa- tion Processing Systems (NeurIPS)

  41. [49]

    Thore Graepel, Kristin Lauter, and Michael Naehrig. 2012. ML confi- dential: Machine learning on encrypted data. In International confer- ence on information security and cryptology . Springer, 1–21

  42. [50]

    Marcus Hähnel, Weidong Cui, and Marcus Peinado. 2017. High- Resolution side channels for untrusted operating systems. In 2017 USENIX Annual Technical Conference (USENIX ATC 17) . 299–312

  43. [51]

    Vivek Haldar, Deepak Chandra, and Michael Franz. 2004. Semantic remote attestation: A virtual machine directed approach to trusted computing. In USENIX Virtual Machine Research and Technology Sym- posium, Vol. 2004. USENIX Association

  44. [52]

    https://www

    Health Insurance Portability and Accountability Act . https://www. hhs.gov/hipaa/index.html. Accessed: 2025-04-10

  45. [53]

    Ehsan Hesamifard, Hassan Takabi, Mehdi Ghasemi, and Rebecca N Wright. 2018. Privacy-preserving machine learning as a service. Proceedings on Privacy Enhancing Technologies (2018)

  46. [54]

    Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017. Deep models under the GAN: Information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security . 603–618

  47. [55]

    Weizhe Hua, Muhammad Umar, Zhiru Zhang, and G Edward Suh. 2022. GuardNN: Secure accelerator architecture for privacy- preserving deep learning. In Proceedings of the 59th ACM/IEEE Design Automation Conference. 349–354

  48. [56]

    Dzmitry Huba, John Nguyen, Kshitiz Malik, Ruiyu Zhu, Mike Rab- bat, Ashkan Yousefpour, Carole-Jean Wu, Hongyuan Zhan, Pavel Ustinov, Harish Srinivas, Kaikai Wang, Anthony Shoumikhin, Je- sik Min, and Mani Malek. 2022. PAPAYA: Practical, Private, and Scalable Federated Learning...

  49. [57]

    Tyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely, Yige Hu, Christo- pher J Rossbach, and Emmett Witchel. 2020. Telekine: Secure com- puting with cloud GPUs. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20) . 817–833

  50. [58]

    Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving machine learning as a service. arXiv preprint arXiv:1803.05961 (2018)

  51. [59]

    Tyler Hunt, Zhiting Zhu, Yuanzhong Xu, Simon Peter, and Emmett Witchel. 2018. Ryoan: A Distributed Sandbox for Untrusted Com- putation on Secret Data. ACM Transactions on Computer Systems (2018)

  52. [60]

    Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient deep learning on multi-source private data.arXiv preprint arXiv:1807.06689 (2018)

  53. [61]

    https://www.youtube.com/watch?v=Bb9NHtJ_Qnk

    Industry Perspectives: The Impact and Future of Confidential Com- puting . https://www.youtube.com/watch?v=Bb9NHtJ_Qnk. Ac- cessed: 2025-04-10

  54. [62]

    https: //www.intel.com/content/www/us/en/products/docs/accelerator- engines/software-guard-extensions.html

    Intel Software Guard Extensions (Intel SGX) . https: //www.intel.com/content/www/us/en/products/docs/accelerator- engines/software-guard-extensions.html. Accessed: 2025-04-10

  55. [63]

    https: //www.intel.com/content/www/us/en/developer/tools/trust- domain-extensions/overview.html

    Intel Trust Domain Extensions (Intel TDX) . https: //www.intel.com/content/www/us/en/developer/tools/trust- domain-extensions/overview.html. Accessed: 2025-04-10

  56. [64]

    Simon Johnson, Vinnie Scarlata, Carlos Rozas, Ernie Brickell, and Frank Mckeen. 2016. Intel software guard extensions: EPID provi- sioning and attestation services. White Paper 1, 1-10 (2016), 119

  57. [65]

    Peter Kairouz, H Brendan McMahan, Brendan Avent, Aurélien Bel- let, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al. 2021. Advances and open problems in federated learning. Foundations and trends in machine learning...

  58. [66]

    Or Kamara. 2020. Hack my mis-configured Kubernetes – priv- ileged pods. https://www.cncf.io/blog/2020/10/16/hack-my-mis- configured-kubernetes-privileged-pods/

  59. [67]

    https://katacontainers.io/

    Kata Container: a secure container runtime with lightweight virtual machines . https://katacontainers.io/. Accessed: 2025-04-10

  60. [68]

    Helena Klause, Alexander Ziller, Daniel Rueckert, Kerstin Ham- mernik, and Georgios Kaissis. 2022. Differentially private train- ing of residual networks with scale normalisation. arXiv preprint arXiv:2203.00324 (2022). 14 Protecting Confidentiality, Privacy and Integrity in C...

  61. [69]

    Jakub Konečn`y, H Brendan McMahan, Felix X Yu, Peter Richtárik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. arXiv preprint arXiv:1610.05492 (2016)

  62. [70]

    Antti Koskela, Joonas Jälkö, and Antti Honkela. 2020. Computing Tight Differential Privacy Guarantees Using FFT. In International Conference on Artificial Intelligence and Statistics . PMLR, 2560–2569

  63. [71]

    Nishat Koti, Arpita Patra, Rahul Rachuri, and Ajith Suresh. 2022. Tetrad: Actively Secure 4PC for Secure Training and Inference. In Proceedings 2022 Network and Distributed System Security Symposium

  64. [72]

    Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. University of Toronto (2009)

  65. [73]

    Alexey Kurakin, Shuang Song, Steve Chien, Roxana Geambasu, An- dreas Terzis, and Abhradeep Thakurta. 2022. Toward Training at Ima- geNet scale with Differential Privacy. arXiv preprint arXiv:2201.12328 (2022)

  66. [74]

    Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner. 1998. Gradient-based learning applied to document recognition. Proc. IEEE 86, 11 (1998), 2278–2324

  67. [75]

    Dayeol Lee, Dongha Jung, Ian T Fang, Chia-Che Tsai, and Raluca Ada Popa. 2020. An Off-Chip attack on hardware enclaves via the memory bus. In 29th USENIX Security Symposium (USENIX Security 20)

  68. [76]

    Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In26th USENIX Security Symposium (USENIX Security 17) . 557–574

  69. [77]

    Taegyeong Lee, Zhiqi Lin, Saumay Pushp, Caihua Li, Yunxin Liu, Youngki Lee, Fengyuan Xu, Chenren Xu, Lintao Zhang, and Junehwa Song. 2019. Occlumency: Privacy-preserving remote deep-learning inference using SGX. In The 25th Annual International Conference on Mobile Computing a...

  70. [78]

    Mengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth, Radu Teodorescu, and Yinqian Zhang. 2022. A systematic look at ciphertext side channels on AMD SEV-SNP. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 337–351

  71. [79]

    Ping Li, Jin Li, Zhengan Huang, Tong Li, Chong-Zhi Gao, Siu-Ming Yiu, and Kai Chen. 2017. Multi-key privacy-preserving deep learning in cloud computing. Future Generation Computer Systems 74 (2017), 76–85

  72. [80]

    Tian Li, Anit Kumar Sahu, Ameet Talwalkar, and Virginia Smith

  73. [81]

    https://man7.org/linux/man- pages/man7/namespaces.7.html

    Linux Namespace kernel documents . https://man7.org/linux/man- pages/man7/namespaces.7.html. Accessed: 2025-04-10

  74. [82]

    Bo Liu, Ming Ding, Sina Shaham, Wenny Rahayu, Farhad Farokhi, and Zihuai Lin. 2021. When machine learning meets privacy: A survey and outlook. ACM Computing Surveys (CSUR) 54, 2 (2021), 1–36

  75. [83]

    Xuanqi Liu, Zhuotao Liu, Qi Li, Ke Xu, and Mingwei Xu. 2024. Pen- cil: Private and Extensible Collaborative Learning without the Non- Colluding Assumption. In Network and Distributed System Security (NDSS) Symposium

  76. [84]

    Haohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao, Zibin Liu, Mingyu Gao, Cong Wang, Huimin Cui, Xiaobing Feng, and Christos Kozyrakis. 2023. Honeycomb: Secure and Efficient GPU Executions via Static Validation. In17th USENIX Symposium on Operating Systems Design and Imple...

  77. [85]

    Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R Savagaonkar. 2013. Innovative instructions and software model for isolated execution. Hasp@ isca 10, 1 (2013)

  78. [86]

    Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273–1282

  79. [87]

    H Brendan McMahan, Eider Moore, Daniel Ramage, and Blaise Agüera y Arcas. 2016. Federated learning of deep net- works using model averaging. arXiv preprint arXiv:1602.05629 2, 2 (2016)

  80. [88]

    Benshan Mei, Saisai Xia, Wenhao Wang, and Dongdai Lin. 2024. Cabin: Confining Untrusted Programs within Confidential VMs. In International Conference on Information and Communications Security. Springer, 165–184

  81. [89]

    https://llama.meta.com/

    Meta Llama . https://llama.meta.com/. Accessed: 2025-04-10

  82. [90]

    https://azure.microsoft.com/en-us/ products/azure-attestation

    Microsoft Azure Attestation . https://azure.microsoft.com/en-us/ products/azure-attestation. Accessed: 2025-04-10

  83. [91]

    https: //techcommunity.microsoft.com/blog/linuxandopensourceblog/ inside-look-how-azure-linux-powers-confidential-containers-on- aks/3981296

    Microsoft Confidential Container with Tardev-snapshotter . https: //techcommunity.microsoft.com/blog/linuxandopensourceblog/ inside-look-how-azure-linux-powers-confidential-containers-on- aks/3981296. Accessed: 2025-04-10

  84. [92]

    https://github.com/microsoft/kata- containers

    Microsoft Kata Container . https://github.com/microsoft/kata- containers. Accessed: 2025-04-10

  85. [93]

    Ilya Mironov. 2017. Rényi Differential Privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF) . 263–275. https: //doi.org/10.1109/CSF.2017.11

  86. [94]

    Fan Mo, Hamed Haddadi, Kleomenis Katevas, Eduard Marin, Diego Perino, and Nicolas Kourtellis. 2021. PPFL: Privacy-preserving feder- ated learning with trusted execution environments. In Proceedings of the 19th Annual International Conference on Mobile Systems, Applica- tions, ...

  87. [95]

    Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas, Soteris Demetriou, Ilias Leontiadis, Andrea Cavallaro, and Hamed Haddadi

  88. [96]

    Payman Mohassel and Peter Rindal. 2018. ABY3: A mixed protocol framework for machine learning. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 35– 52

  89. [97]

    Payman Mohassel and Yupeng Zhang. 2017. SecureML: A system for scalable privacy-preserving machine learning. In 2017 IEEE Sympo- sium on Security and Privacy (S&P) . IEEE, 19–38

  90. [98]

    Kit Murdock, David Oswald, Flavio D Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based fault in- jection attacks against Intel SGX. In2020 IEEE Symposium on Security and Privacy (S&P). IEEE, 1466–1482

  91. [99]

    In Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services

    DarkneTZ: Towards model privacy at the edge using Trusted Execution Environments. In Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services . 161–174

  92. [100]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehen- sive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE Symposium on Security and Privacy (S&P) . IEEE, 739–753

  93. [101]

    Lucien KL Ng and Sherman SM Chow. 2023. SoK: Cryptographic neural-network computation. In 2023 IEEE Symposium on Security and Privacy (S&P). IEEE, 497–514

  94. [102]

    https://www.nvidia.com/en-us/ data-center/solutions/confidential-computing/

    NVIDIA Confidential Computing . https://www.nvidia.com/en-us/ data-center/solutions/confidential-computing/ . Accessed: 2025-04- 10

  95. [103]

    Karthik Nandakumar, Nalini Ratha, Sharath Pankanti, and Shai Halevi. 2019. Towards deep neural network training on encrypted data. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition workshops

  96. [104]

    Nicolas Papernot, Andrew Galen, and Steven Chien. 2020. Tensorflow privacy. https://github.com/tensorflow/privacy 15 Dong Chen, Alice Dethise, Istemi Ekin Akkus, Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, Ruichuan Chen

  97. [105]

    Arpita Patra and Ajith Suresh. 2020. BLAZE: Blazing Fast Privacy- Preserving Machine Learning. In Proceedings 2020 Network and Dis- tributed System Security Symposium

  98. [106]

    Do Le Quoc and Christof Fetzer. 2021. SecFL: Confidential federated learning using TEEs. arXiv preprint arXiv:2110.00981 (2021)

  99. [107]

    Olga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta, Se- bastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious Multi-Party machine learning on trusted processors. In 25th USENIX Security Symposium (USENIX Security 16) . 619–636

  100. [108]

    Sinem Sav, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, David Froelicher, Jean-Philippe Bossuat, Joao Sa Sousa, and Jean- Pierre Hubaux. 2021. POSEIDON: Privacy-Preserving Federated Neu- ral Network Learning. In Proceedings 2021 Network and Distributed System Security Symposium

  101. [109]

    Vinnie Scarlata, Simon Johnson, James Beaney, and Piotr Zmijewski

  102. [110]

    Benedict Schlüter, Supraja Sridhara, Andrin Bertschi, and Shweta Shinde. 2024. WeSee: using malicious #VC interrupts to break AMD SEV-SNP. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE, 4220–4238

  103. [111]

    Do Le Quoc, Franz Gregor, Sergei Arnautov, Roland Kunkel, Pramod Bhatotia, and Christof Fetzer. 2020. SecureTF: A Secure TensorFlow Framework. In Proceedings of the 21st International Middleware Con- ference. 44–59

  104. [112]

    Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov

  105. [113]

    https: //docs.snowflake.com/en/user-guide/cleanrooms/demo- flows/machine-learning

    Snowflake Data Clean Room: Machine Learning . https: //docs.snowflake.com/en/user-guide/cleanrooms/demo- flows/machine-learning. Accessed: 2025-04-10

  106. [114]

    https://www

    Snowflake Data Marketplace | Snowflake Data Cloud . https://www. snowflake.com/en/data-cloud/marketplace/. Accessed: 2025-04-10

  107. [115]

    David M Sommer, Sebastian Meiser, and Esfandiar Mohammadi. 2019. Privacy Loss Classes: The Central Limit Theorem in Differential Privacy. Proceedings on Privacy Enhancing Technologies 2 (2019), 245–269

  108. [116]

    Ming-Wei Shih, Sangho Lee, Taesoo Kim, and Marcus Peinado. 2017. T-SGX: Eradicating Controlled-Channel Attacks Against Enclave Programs. In NDSS, Vol. 6. 15–43

  109. [117]

    Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017. CLKSCREW: Exposing the perils of Security-Oblivious energy man- agement. In 26th USENIX Security Symposium (USENIX Security 17) . 1057–1074

  110. [118]

    https://www.youtube.com/watch?v= BBpxx5JDmcI

    The Status Quo of Confidential Computing Panel Discussion with AMD, Azure, Intel, & NVIDIA . https://www.youtube.com/watch?v= BBpxx5JDmcI. Accessed: 2025-04-10

  111. [119]

    Han Tian, Chaoliang Zeng, Zhenghang Ren, Di Chai, Junxue Zhang, Kai Chen, and Qiang Yang. 2022. Sphinx: Enabling privacy-preserving online learning over the cloud. In 2022 IEEE Symposium on Security and Privacy (S&P). IEEE, 2487–2501

  112. [120]

    Florian Tramer and Dan Boneh. 2018. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287 (2018)

  113. [121]

    Anna Trikalinou and Dan Lake. 2017. Taking DMA attacks to the next level. BlackHat USA (2017), 22–27

  114. [122]

    https://stability.ai/stable-image

    Stability AI Image Models . https://stability.ai/stable-image. Ac- cessed: 2025-04-10

  115. [123]

    Jo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens, and Raoul Strackx. 2017. Telling your secrets without page faults: Stealthy page Table-Based attacks on enclaved execution. In 26th USENIX Security Symposium (USENIX Security 17) . 1041–1056

  116. [124]

    Daan Vanoverloop, Andres Sanchez, Flavio Toffalini, Frank Piessens, Mathias Payer, and Jo Van Bulck. 2025. TLBlur: Compiler-Assisted Automated Hardening against Controlled Channels on Off-the-Shelf Intel SGX Platforms. In 34th USENIX Security Symposium (USENIX Security 25)

  117. [125]

    Kapil Vaswani, Stavros Volos, Cedric Fournet, Antonio Nino Diaz, Ken Gordon, Balaji Vembu, Sam Webster, David Chisnall, Saurabh Kulkarni, Graham Cunningham, Richard Osborne, and Daniel Wilkin- son. 2023. Confidential Computing within an AI Accelerator. In 2023 USENIX Annual Te...

  118. [126]

    Sameer Wagh, Divya Gupta, and Nishanth Chandran. 2019. Se- cureNN: 3-party secure computation for neural network training. Proceedings on Privacy Enhancing Technologies (2019)

  119. [127]

    Sameer Wagh, Shruti Tople, Fabrice Benhamouda, Eyal Kushilevitz, Prateek Mittal, and Tal Rabin. 2021. Falcon: Honest-Majority Mali- ciously Secure Framework for Private Deep Learning. In Proceedings on Privacy Enhancing Technologies

  120. [128]

    Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the Intel SGX kingdom with transient Out-of-Order execution. In 27th USENIX Secu...

  121. [129]

    Luca Wilke and Gianluca Scopelliti. 2024. SNPGuard: Remote At- testation of SEV-SNP VMs Using Open Source Tools. arXiv preprint arXiv:2406.01186 (2024)

  122. [130]

    Xinwei Wu, Li Gong, and Deyi Xiong. 2022. Adaptive differential privacy for language model training. In Proceedings of the First Work- shop on Federated Learning for Natural Language Processing (FL4NLP 2022). 21–26

  123. [131]

    Yuanzhong Xu, Weidong Cui, and Marcus Peinado. 2015. Controlled- channel attacks: Deterministic side channels for untrusted operating systems. In 2015 IEEE Symposium on Security and Privacy . IEEE, 640– 656

  124. [132]

    Hongxu Yin, Arun Mallya, Arash Vahdat, Jose M Alvarez, Jan Kautz, and Pavlo Molchanov. 2021. See through gradients: Image batch recovery via gradinversion. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 16337–16346

  125. [133]

    Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Tes- tuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov

  126. [134]

    Zihao Wang, Rui Zhu, Dongruo Zhou, Zhikun Zhang, John Mitchell, Haixu Tang, and XiaoFeng Wang. 2024. DPAdapter: Improving Differ- entially Private Deep Learning through Noise Tolerance Pre-training. arXiv preprint arXiv:2403.02571 (2024)

  127. [135]

    Shixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang, Yinqian Zhang, and Zhiqiang Lin. 2023. Reusable enclaves for confidential serverless computing. In 32nd USENIX Security Symposium (USENIX Security 23). 4015–4032

  128. [136]

    Ziqiao Zhou, Weiteng Chen, Sishuai Gong, Chris Hawblitzel, Wei- dong Cui, et al. 2024. VeriSMo: A verified security module for confi- dential VMs. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24) . 599–614

  129. [137]

    Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems (NeurIPS) 32 (2019)

  130. [138]

    Ruofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie, and Rui Chang

  131. [139]

    Yuqing Zhu, Jinshuo Dong, and Yu-Xiang Wang. 2022. Optimal Accounting of Differential Privacy via Characteristic Function. Pro- ceedings of The 25th International Conference on Artificial Intelligence and Statistics (2022). Appendix A Differential Privacy Analysis A.1 Backgrou...

  132. [141]

    Chengliang Zhang, Junzhe Xia, Baichen Yang, Huancheng Puyang, Wei Wang, Ruichuan Chen, Istemi Ekin Akkus, Paarijaat Aditya, and Feng Yan. 2021. Citadel: Protecting data privacy and model confidentiality for collaborative learning. In Proceedings of the ACM Symposium on Cloud C...

  133. [148]

    World”, “Sports

    and from the fact that the means and vari- ance in the sums of Gaussian random variables sum up, and by plugging in the resulting Gaussian random variable in the formula (3). The analytical form of Eq. (10) for a Gaussian PLRV with noise variance𝜎 2 total is shown, e.g., in [1...

  134. [832]

    https://proceedings.mlsys.org/paper_files/paper/2022/file/ a8bc4cb14a20f20d1f96188bd61eec87-Paper.pdf

  135. [2015]

    In Pro- ceedings 2015 Network and Distributed System Security Symposium

    Machine Learning Classification over Encrypted Data. In Pro- ceedings 2015 Network and Distributed System Security Symposium

  136. [2017]

    In 2017 IEEE symposium on security and privacy (S&P)

    Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (S&P) . IEEE, 3–18

  137. [2018]

    White paper 12 (2018)

    Supporting third party attestation for Intel SGX with Intel data center attestation primitives. White paper 12 (2018)

  138. [2020]

    IEEE signal processing magazine 37, 3 (2020), 50–60

    Federated learning: Challenges, methods, and future directions. IEEE signal processing magazine 37, 3 (2020), 50–60

  139. [2021]

    arXiv preprint arXiv:2109.12298 (2021)

    Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298 (2021)

  140. [2025]

    In Proceedings of the 2025 IEEE Symposium on Security and Privacy (S&P)

    My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (S&P) . IEEE, IEEE. 16 Protecting Confidentiality, Privacy and Integrity in Collaborative Learning

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.