{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T01:01:59Z","timestamp":1784595719095,"version":"3.55.0"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030816445","type":"print"},{"value":"9783030816452","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-81645-2_10","type":"book-chapter","created":{"date-parts":[[2021,7,21]],"date-time":"2021-07-21T17:02:52Z","timestamp":1626886972000},"page":"151-168","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Towards Trained Model Confidentiality and Integrity Using Trusted Execution Environments"],"prefix":"10.1007","author":[{"given":"Tsunato","family":"Nakai","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daisuke","family":"Suzuki","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takeshi","family":"Fujino","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,7,22]]},"reference":[{"key":"10_CR1","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv:1312.6199 (2014)"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Isakov, M., Gadepally, V., Gettings, K., Kinsy, M.: Survey of attacks and defenses on edge-deployed neural networks. In: IEEE High Performance Extreme Computing Conference (HPEC), pp. 1\u20138 (2019)","DOI":"10.1109\/HPEC.2019.8916519"},{"key":"10_CR4","unstructured":"Ohrimenko, O., et al.: Oblivious multi-party machine learning on trusted processors. In: Proceedings of the 25th USENIX Security Symposium, pp. 619\u2013636 (2016)"},{"key":"10_CR5","unstructured":"Tramer, F., Boneh, D.: Slalom: fast, verifiable and private execution of neural networks in trusted hardware. In: International Conference on Learning Representations (ICML) (2019)"},{"key":"10_CR6","unstructured":"Hanzlik, L., et al.: MLCapsule: guarded offline deployment of machine learning as a service. arXiv:1808.00590 (2018)"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"Schl\u00f6gl, A., B\u00f6hme, R.: eNNclave: offline inference with model confidentiality. In: Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security (AISec), pp. 93\u2013104 (2020)","DOI":"10.1145\/3411508.3421376"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Bayerl, S., et al..: Offline model guard: secure and private ML on mobile devices. In: Design, Automation & Test in Europe Conference & Exhibition (DATE), pp. 460\u2013465 (2020)","DOI":"10.23919\/DATE48585.2020.9116560"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Mo, F., et al.: DarkneTZ: towards model privacy at the edge using trusted execution environments. In: Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services (MobiSys), pp. 161\u2013174 (2020)","DOI":"10.1145\/3386901.3388946"},{"key":"10_CR10","unstructured":"VanNostrand, P., Kyriazis, I., Cheng, M., Guo, T., Walls, R.: Confidential deep learning: executing proprietary models on untrusted devices. arXiv:1908.10730 (2019)"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Amacher, J., Schiavoni, V.: On the performance of ARM TrustZone (practical experience report). In: IFIP International Conference on Distributed Applications and Interoperable Systems (DAIS), pp. 133\u2013151 (2019)","DOI":"10.1007\/978-3-030-22496-7_9"},{"key":"10_CR12","unstructured":"Zhao, S., Zhang, Q., Qin, Y., Feng, W., Feng, D.: Minimal kernel: an operating system architecture for TEE to resist board level physical attacks. In: Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID) (2019)"},{"key":"10_CR13","unstructured":"Linaro OP-TEE. https:\/\/www.op-tee.org"},{"key":"10_CR14","unstructured":"Darknet: Open Source Neural Networks in C. https:\/\/pjreddie.com\/darknet"},{"key":"10_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/3-540-46805-6_19","volume-title":"Shape, Contour and Grouping in Computer Vision","author":"Y LeCun","year":"1999","unstructured":"LeCun, Y., Haffner, P., Bottou, L., Bengio, Y.: Object recognition with gradient-based learning. In: Shape, Contour and Grouping in Computer Vision. LNCS, vol. 1681, pp. 319\u2013345. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-46805-6_19"},{"key":"10_CR16","unstructured":"LeCun, Y., Cortes, C.: MNIST handwritten digit database (2010)"},{"key":"10_CR17","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. arXiv:1409.1556 (2014)"},{"key":"10_CR18","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images (2009)"},{"issue":"3","key":"10_CR19","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky, O., et al.: ImageNet large scale visual recognition challenge. Int. J. Comput. Vis. 115(3), 211\u2013252 (2015). https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"Int. J. Comput. Vis."},{"key":"10_CR20","unstructured":"Mbed TLS. https:\/\/tls.mbed.org"},{"key":"10_CR21","unstructured":"Google Trusty TEE. https:\/\/source.android.google.cn\/security\/trusty"},{"key":"10_CR22","unstructured":"NVIDIA Jetson Linux Developer Guide 32.5 Release. https:\/\/docs.nvidia.com\/jetson\/l4t\/index.html"},{"key":"10_CR23","unstructured":"Karan, G., Shruti, T., Shweta, S., Ranjita, B., Ramachandran, R.: Privado: practical and secure DNN inference with enclaves. arXiv:1810.00602 (2018)"},{"key":"10_CR24","unstructured":"Dowlin, N., Gilad-Bachrach, R., Laine, K., Lauter, K., Naehrig, M., Wernsing, J.: CryptoNets: applying neural networks to encrypted data with high throughput and accuracy. In: Proceedings of the 33rd International Conference on International Conference on Machine Learning (ICML), vol. 48, pp. 201\u2013210 (2016)"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Mohassel, P., Zhang, Y.: SecureML: a system for scalable privacy-preserving machine learning. In: IEEE Symposium on Security and Privacy (S&P), pp. 19\u201338 (2017)","DOI":"10.1109\/SP.2017.12"},{"key":"10_CR26","unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., Keshet, J.: Turning your weakness into a strength: watermarking deep neural networks by backdooring. In: Proceedings of the 27th USENIX Security Symposium, pp. 1615\u20131631 (2018)"},{"key":"10_CR27","doi-asserted-by":"crossref","unstructured":"Dubey, A., Cammarota, R., Aysu, A.: MaskedNet: the first hardware inference engine aiming power side-channel protection. arXiv:1910.13063 (2019)","DOI":"10.1109\/HOST45689.2020.9300276"},{"key":"10_CR28","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M., Ristenpart, T.: Stealing machine learning models via prediction APIs. In: Proceedings of the 25th USENIX Conference on Security Symposium, pp. 601\u2013618 (2016)"},{"key":"10_CR29","unstructured":"Huawei Technologies Co., Ltd.: Thinking ahead about AI security and privacy protection. In: Protecting Personal Data & Advancing Technology Capabilities (2019)"},{"key":"10_CR30","unstructured":"ETSI GR SAI 004: GROUP REPORT V1.1.1 Securing Artificial Intelligence (SAI); Problem Statement (2020)"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-81645-2_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T00:05:40Z","timestamp":1784592340000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-81645-2_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030816445","9783030816452"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-81645-2_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"22 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kamakura","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 June 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 June 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"186","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"37","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.89","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7.81","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Due to the COVID-19 pandemic the conference took place virtually.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}