{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:5C4D3ZDH6WAAAOLNBIF3WCZUF7","short_pith_number":"pith:5C4D3ZDH","schema_version":"1.0","canonical_sha256":"e8b83de467f58000396d0a0bbb0b342febce70938ff1232836b7c8b8fb60d900","source":{"kind":"arxiv","id":"1908.10730","version":1},"attestation_state":"computed","paper":{"title":"Confidential Deep Learning: Executing Proprietary Models on Untrusted Devices","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Ioannis Kyriazis, Michelle Cheng, Peter M. VanNostrand, Robert J. Walls, Tian Guo","submitted_at":"2019-08-28T14:02:59Z","abstract_excerpt":"Performing deep learning on end-user devices provides fast offline inference results and can help protect the user's privacy. However, running models on untrusted client devices reveals model information which may be proprietary, i.e., the operating system or other applications on end-user devices may be manipulated to copy and redistribute this information, infringing on the model provider's intellectual property. We propose the use of ARM TrustZone, a hardware-based security feature present in most phones, to confidentially run a proprietary model on an untrusted end-user device. We explore "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1908.10730","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-08-28T14:02:59Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"9309270132a2f1fc4507859f24327fa09819b0cb4902519b675e192c670ed1b5","abstract_canon_sha256":"b4ebdb31f8710e6d8cae954fbccf03e354f0e602b9812a34fc038187afa45e89"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:00:20.703700Z","signature_b64":"7vpCp0zMBv6GJHl8otMPAg+lyeWHY6GxwoP/SlfYap0OgTK3iZm2WayA+jTJKD4o8fOtDYY0q6yJttXWKTp0Ag==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e8b83de467f58000396d0a0bbb0b342febce70938ff1232836b7c8b8fb60d900","last_reissued_at":"2026-07-05T00:00:20.700928Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:00:20.700928Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Confidential Deep Learning: Executing Proprietary Models on Untrusted Devices","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Ioannis Kyriazis, Michelle Cheng, Peter M. VanNostrand, Robert J. Walls, Tian Guo","submitted_at":"2019-08-28T14:02:59Z","abstract_excerpt":"Performing deep learning on end-user devices provides fast offline inference results and can help protect the user's privacy. However, running models on untrusted client devices reveals model information which may be proprietary, i.e., the operating system or other applications on end-user devices may be manipulated to copy and redistribute this information, infringing on the model provider's intellectual property. We propose the use of ARM TrustZone, a hardware-based security feature present in most phones, to confidentially run a proprietary model on an untrusted end-user device. We explore "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1908.10730","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1908.10730/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1908.10730","created_at":"2026-07-05T00:00:20.700981+00:00"},{"alias_kind":"arxiv_version","alias_value":"1908.10730v1","created_at":"2026-07-05T00:00:20.700981+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1908.10730","created_at":"2026-07-05T00:00:20.700981+00:00"},{"alias_kind":"pith_short_12","alias_value":"5C4D3ZDH6WAA","created_at":"2026-07-05T00:00:20.700981+00:00"},{"alias_kind":"pith_short_16","alias_value":"5C4D3ZDH6WAAAOLN","created_at":"2026-07-05T00:00:20.700981+00:00"},{"alias_kind":"pith_short_8","alias_value":"5C4D3ZDH","created_at":"2026-07-05T00:00:20.700981+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.29450","citing_title":"Protecting On-Device AI Inference: A Systematic Review of Attacks and Defence Mechanisms","ref_index":58,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7","json":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7.json","graph_json":"https://pith.science/api/pith-number/5C4D3ZDH6WAAAOLNBIF3WCZUF7/graph.json","events_json":"https://pith.science/api/pith-number/5C4D3ZDH6WAAAOLNBIF3WCZUF7/events.json","paper":"https://pith.science/paper/5C4D3ZDH"},"agent_actions":{"view_html":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7","download_json":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7.json","view_paper":"https://pith.science/paper/5C4D3ZDH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1908.10730&json=true","fetch_graph":"https://pith.science/api/pith-number/5C4D3ZDH6WAAAOLNBIF3WCZUF7/graph.json","fetch_events":"https://pith.science/api/pith-number/5C4D3ZDH6WAAAOLNBIF3WCZUF7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7/action/storage_attestation","attest_author":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7/action/author_attestation","sign_citation":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7/action/citation_signature","submit_replication":"https://pith.science/pith/5C4D3ZDH6WAAAOLNBIF3WCZUF7/action/replication_record"}},"created_at":"2026-07-05T00:00:20.700981+00:00","updated_at":"2026-07-05T00:00:20.700981+00:00"}