{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T00:49:58Z","timestamp":1743036598989,"version":"3.40.3"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031168147"},{"type":"electronic","value":"9783031168154"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-16815-4_12","type":"book-chapter","created":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T20:19:35Z","timestamp":1663964375000},"page":"200-217","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Towards Isolated AI Accelerators with\u00a0OP-TEE on\u00a0SoC-FPGAs"],"prefix":"10.1007","author":[{"given":"Tsunato","family":"Nakai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daisuke","family":"Suzuki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"Fujino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,24]]},"reference":[{"unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)","key":"12_CR1"},{"doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","key":"12_CR2","DOI":"10.1145\/2810103.2813677"},{"doi-asserted-by":"crossref","unstructured":"Isakov, M., Gadepally, V., Gettings, K.M., Kinsy, M.A.: Survey of attacks and defenses on edge-deployed neural networks. In: 2019 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1\u20138. IEEE (2019)","key":"12_CR3","DOI":"10.1109\/HPEC.2019.8916519"},{"key":"12_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/978-3-030-81645-2_10","volume-title":"Applied Cryptography and Network Security Workshops","author":"T Nakai","year":"2021","unstructured":"Nakai, T., Suzuki, D., Fujino, T.: Towards trained model confidentiality and integrity using trusted execution environments. In: Zhou, J., et al. (eds.) ACNS 2021. LNCS, vol. 12809, pp. 151\u2013168. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81645-2_10"},{"unstructured":"ETSI GR SAI 004.: GROUP REPORT V1.1.1 Securing Artificial Intelligence (SAI); Problem Statement (2020). https:\/\/www.etsi.org\/deliver\/etsi_gr\/SAI\/001_099\/004\/01.01.01_60\/gr_SAI004v010101p.pdf","key":"12_CR5"},{"unstructured":"Apple Secure Enclave. https:\/\/support.apple.com\/ja-jp\/guide\/security\/sec59b0b31ff\/1\/web\/1","key":"12_CR6"},{"unstructured":"Xilinx CHaiDNN-v2. https:\/\/github.com\/Xilinx\/CHaiDNN","key":"12_CR7"},{"unstructured":"Hua, W., Umar, M., Zhang, Z., Edward Suh, G.: GuardNN: secure DNN accelerator for privacy-preserving deep learning. arXiv preprint arXiv:2008.11632 (2020)","key":"12_CR8"},{"issue":"5","key":"12_CR9","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1109\/MM.2019.2928962","volume":"39","author":"T Moreau","year":"2019","unstructured":"Moreau, T., et al.: A hardware-software blueprint for flexible deep learning specialization. IEEE Micro 39(5), 8\u201316 (2019)","journal-title":"IEEE Micro"},{"unstructured":"Xie, P., Ren, X., Sun, G.: Customizing trusted AI accelerators for efficient privacy-preserving machine learning. arXiv preprint arXiv:2011.06376 (2020)","key":"12_CR10"},{"unstructured":"Linaro OP-TEE. https:\/\/www.op-tee.org","key":"12_CR11"},{"unstructured":"NVIDIA Deep Learning Accelerator. https:\/\/nvdla.org","key":"12_CR12"},{"unstructured":"Isolation Design Example for the Zynq UltraScale+ MPSoC. https:\/\/japan.xilinx.com\/support\/documentation\/application_notes\/xapp1336-isolation-design-flow-example-mpsoc.pdf","key":"12_CR13"},{"unstructured":"Jouppi, N.P., et al.: In-datacenter performance analysis of a tensor processing unit. In: Proceedings of the 44th Annual International Symposium on Computer Architecture, pp. 1\u201312 (2017)","key":"12_CR14"},{"unstructured":"Park, H., Lin, F.X.: Safe and practical GPU acceleration in trustzone. arXiv preprint arXiv:2111.03065 (2021)","key":"12_CR15"},{"unstructured":"Hashemi, H., Wang, Y., Annavaram, M.: Privacy and integrity preserving training using trusted hardware. CoRR, abs\/2105.00334 (2021)","key":"12_CR16"},{"unstructured":"NVIDIA H100 Tensor Core GPU Architecture, Exceptional Performance, Scalability, and Security for the Data Center. https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/","key":"12_CR17"},{"issue":"8","key":"12_CR18","doi-asserted-by":"publisher","first-page":"1238","DOI":"10.1109\/TC.2019.2900235","volume":"68","author":"EM Benhani","year":"2019","unstructured":"Benhani, E.M., Bossuet, L., Aubert, A.: The security of ARM TrustZone in a FPGA-based SoC. IEEE Trans. Comput. 68(8), 1238\u20131248 (2019)","journal-title":"IEEE Trans. Comput."},{"doi-asserted-by":"crossref","unstructured":"Jia, Y., et al.: Caffe: convolutional architecture for fast feature embedding. arXiv preprint arXiv:1408.5093 (2014)","key":"12_CR19","DOI":"10.1145\/2647868.2654889"},{"unstructured":"Zynq UltraScale+ MPSoC ZCU102. https:\/\/japan.xilinx.com\/products\/boards-and-kits\/ek-u1-zcu102-g.html","key":"12_CR20"},{"key":"12_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/3-540-46805-6_19","volume-title":"Shape, Contour and Grouping in Computer Vision","author":"Y LeCun","year":"1999","unstructured":"LeCun, Y., Haffner, P., Bottou, L., Bengio, Y.: Object recognition with gradient-based learning. In: Shape, Contour and Grouping in Computer Vision. LNCS, vol. 1681, pp. 319\u2013345. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-46805-6_19"},{"doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","key":"12_CR22","DOI":"10.1109\/CVPR.2016.90"},{"issue":"11","key":"12_CR23","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y Lecun","year":"1998","unstructured":"Lecun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278\u20132324 (1998)","journal-title":"Proc. IEEE"},{"unstructured":"Krizhevsky, A., Hinton, G., et al.: Learning multiple layers of features from tiny images (2009)","key":"12_CR24"},{"doi-asserted-by":"crossref","unstructured":"Xu, Q., Arafin, Md.T., Qu, G.: Security of neural networks from hardware perspective: a survey and beyond. In: 2021 26th Asia and South Pacific Design Automation Conference (ASP-DAC), pp. 449\u2013454 (2021)","key":"12_CR25","DOI":"10.1145\/3394885.3431639"},{"doi-asserted-by":"crossref","unstructured":"Wang, X., Hou, R., Zhu, Y., Zhang, J., Meng, D.: NPUFort: a secure architecture of DNN accelerator against model inversion attack. In: Proceedings of the 16th ACM International Conference on Computing Frontiers, pp. 190\u2013196 (2019)","key":"12_CR26","DOI":"10.1145\/3310273.3323070"},{"doi-asserted-by":"crossref","unstructured":"Gross, M., Jacob, N., Zankl, A., Sigl, G.: Breaking TrustZone memory isolation through malicious hardware on a modern FPGA-SoC. In: Proceedings of the 3rd ACM Workshop on Attacks and Solutions in Hardware Security Workshop, pp. 3\u201312 (2019)","key":"12_CR27","DOI":"10.1145\/3338508.3359568"},{"doi-asserted-by":"crossref","unstructured":"Stajnrod, R., Yehuda, R.B., Zaidenberg, N.J.: Attacking TrustZone on devices lacking memory protection. J. Comput. Virol. Hacking Tech. 1\u201311 (2021)","key":"12_CR28","DOI":"10.1007\/s11416-021-00413-y"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-16815-4_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,15]],"date-time":"2025-03-15T13:09:09Z","timestamp":1742044149000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-16815-4_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031168147","9783031168154"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-16815-4_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 June 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/sites.google.com\/di.uniroma1.it\/acns2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}