{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T15:58:31Z","timestamp":1773849511422,"version":"3.50.1"},"reference-count":59,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T00:00:00Z","timestamp":1736121600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T00:00:00Z","timestamp":1736121600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,1,6]]},"DOI":"10.1109\/comsnets63942.2025.10885734","type":"proceedings-article","created":{"date-parts":[[2025,2,20]],"date-time":"2025-02-20T20:05:58Z","timestamp":1740081958000},"page":"207-216","source":"Crossref","is-referenced-by-count":1,"title":["Secured and Privacy-Preserving GPU-Based Machine Learning Inference in Trusted Execution Environment: A Comprehensive Survey"],"prefix":"10.1109","author":[{"given":"Arunava","family":"Chaudhuri","sequence":"first","affiliation":[{"name":"Indian Institute of Technology, Kharagpur,Department of Computer Science and Engineering,Kharagpur,India"}]},{"given":"Shubhi","family":"Shukla","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology, Kharagpur,Centre for Computational and Data Sciences,Kharagpur,India"}]},{"given":"Sarani","family":"Bhattacharya","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology, Kharagpur,Department of Computer Science and Engineering,Kharagpur,India"}]},{"given":"Debdeep","family":"Mukhopadhyay","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology, Kharagpur,Department of Computer Science and Engineering,Kharagpur,India"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3295500.3356177"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2018.00024"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-51935-3_30"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516686"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.357"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3308755.3308761"},{"key":"ref8","first-page":"86","article-title":"Intel sgx explained","volume":"2016","author":"Costan","year":"2016","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-0377-4_5"},{"key":"ref10","volume-title":"Deep Learning.","author":"Goodfellow","year":"2016"},{"key":"ref11","article-title":"Privado: Practical and secure dnn inference with enclaves","author":"Grover","year":"2019"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23239"},{"key":"ref13","first-page":"431","article-title":"Raccoon: Closing digital Side-Channels through obfuscated execution","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Rane"},{"key":"ref14","first-page":"619","article-title":"Oblivious Multi-Party machine learning on trusted processors","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Ohrimenko"},{"key":"ref15","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"Tram\u00e8r","year":"2019"},{"key":"ref16","article-title":"Probabilistic machines can use less running time","volume-title":"IFIP Congress","author":"Freivalds"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS52674.2021.00018"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/AsianHOST51057.2020.9358260"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CCGrid49817.2020.00-41"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.5555\/3291168.3291219"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304021"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00054"},{"key":"ref24","first-page":"155","article-title":"Honeycomb: Secure and efficient GPU executions via static validation","volume-title":"17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23)","author":"Mai"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1002\/9780470959152.ch88"},{"key":"ref26","article-title":"Confidential computing solutions","year":"2024"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3707453"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560627"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00019"},{"key":"ref30","article-title":"Cage: Complementing arm cca with gpu extensions","volume-title":"Proceedings of the 31st Annual Network and Distributed System Security Symposium","author":"Wang"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3472634.3472652"},{"key":"ref32","article-title":"Confidential deep learning: Executing proprietary models on untrusted devices","author":"VanNostrand","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3560826.3563386"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3577923.3583648"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3450268.3453524"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3097983.3098158"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00669"},{"key":"ref39","article-title":"Featurized bidirectional gan: Adversarial defense via adversarially learned semantic inference","author":"Bao","year":"2018"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2940533"},{"key":"ref41","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2017"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/415"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01171"},{"key":"ref44","article-title":"Blocking transferability of adversarial examples in black-box learning systems","author":"Hosseini","year":"2017"},{"key":"ref45","article-title":"Stateful detection of black-box adversarial attacks","author":"Chen","year":"2019"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11828"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2874243"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10165"},{"key":"ref50","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"Papernot","year":"2017"},{"key":"ref51","first-page":"35","article-title":"Privacy-preserving classification on deep neural network","volume":"2017","author":"Chabanne","year":"2017","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref52","first-page":"201","article-title":"Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"Proceedings of The 33rd International Conference on Machine Learning","volume":"48","author":"Gilad-Bachrach"},{"key":"ref53","article-title":"Cryptodl: Deep neural networks over encrypted data","author":"Hesamifard","year":"2017"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96878-0_17"},{"key":"ref55","article-title":"Tapas: Tricks to accelerate (encrypted) prediction as a service","author":"Sanyal","year":"2018"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/dac.2018.8465894"},{"key":"ref59","article-title":"SecureNN: Efficient and private neural network training","author":"Wagh","year":"2018"}],"event":{"name":"2025 17th International Conference on COMmunication Systems and NETworks (COMSNETS)","location":"Bengaluru, India","start":{"date-parts":[[2025,1,6]]},"end":{"date-parts":[[2025,1,10]]}},"container-title":["2025 17th International Conference on COMmunication Systems and NETworks (COMSNETS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10885406\/10885547\/10885734.pdf?arnumber=10885734","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:11:12Z","timestamp":1740121872000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10885734\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,6]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/comsnets63942.2025.10885734","relation":{},"subject":[],"published":{"date-parts":[[2025,1,6]]}}}