{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T22:10:47Z","timestamp":1784239847403,"version":"3.55.0"},"reference-count":76,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Smart Grid-National Science and Technology Major Project","award":["2024ZD0803000"],"award-info":[{"award-number":["2024ZD0803000"]}]},{"name":"Key R&amp;D projects in Hubei Province","award":["2023BAB165"],"award-info":[{"award-number":["2023BAB165"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1109\/tdsc.2026.3694706","type":"journal-article","created":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T19:52:15Z","timestamp":1779220335000},"page":"9649-9663","source":"Crossref","is-referenced-by-count":0,"title":["Palladium: Guarding Neural Network Training With Confidential Computing"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1096-2505","authenticated-orcid":false,"given":"Wenzhe","family":"Yi","sequence":"first","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7808-852X","authenticated-orcid":false,"given":"Mengda","family":"Yang","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8813-7842","authenticated-orcid":false,"given":"Juan","family":"Wang","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8710-247X","authenticated-orcid":false,"given":"Hongxin","family":"Hu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University at Buffalo, Buffalo, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1015-5594","authenticated-orcid":false,"given":"Ziang","family":"Li","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2672-9145","authenticated-orcid":false,"given":"Xiaoyang","family":"Xu","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/7068349"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3285029"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-024-20016-1"},{"key":"ref4","article-title":"Google cloud AI","year":"2024"},{"key":"ref5","article-title":"Microsoft azure machine learning","year":"2024"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2018.2809624"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486998"},{"key":"ref8","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Gilad-Bachrach"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00121"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"ref11","article-title":"Chiron: Privacy-preserving machine learning as a service","author":"Hunt","year":"2018"},{"key":"ref12","article-title":"Efficient deep learning on multi-source private data","author":"Hynes","year":"2018"},{"key":"ref13","article-title":"Tensorscone: A secure tensorflow framework using intel SGX","author":"Kunkel","year":"2019"},{"key":"ref14","article-title":"Tf encrypted","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"ref16","first-page":"18","article-title":"Trustzone: Integrated hardware and software security","volume":"3","author":"Alves","year":"2004","journal-title":"Inf. Quart."},{"key":"ref17","first-page":"1450","article-title":"Strengthening vm isolation with integrity protection and more","volume":"53","author":"Sev-Snp","year":"2020","journal-title":"White Paper"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i17.17746"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480112"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46766-1_34"},{"key":"ref21","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Paszke"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"ref23","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref27","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref28","article-title":"ImageNette: A smaller subset of 10 easily classified classes from imageNet","author":"Howard","year":"2019"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/0925-2312(93)90006-O"},{"key":"ref32","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW53098.2021.00368"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"ref35","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"Tramer","year":"2018"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3126315"},{"key":"ref37","first-page":"723","article-title":"$\\lbrace${SOTER$\\rbrace$}: Guarding black-box inference for general neural networks at the edge","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Shen"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179382"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00052"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"ref41","first-page":"1","article-title":"TBNet: A neural architectural defense framework facilitating DNN model protection in trusted execution environments","volume-title":"Proc. 61st ACM\/IEEE Des. Automat. Conf.","author":"Liu"},{"key":"ref42","article-title":"Probabilistic machines can use less running time","volume-title":"Proc. IFIP Congr.","author":"Freivalds"},{"key":"ref43","article-title":"Intel SGX explained","author":"Costan","year":"2016","journal-title":"Cryptol. ePrint Arch."},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/791"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM41043.2020.9155414"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3508398.3511503"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1515\/mcma-2020-2076"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-09526-8_5"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_18"},{"key":"ref50","article-title":"Pytorch custom modules","year":"2024"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421282"},{"key":"ref52","first-page":"59992","article-title":"GROUPCOVER: A secure, efficient and scalable inference framework for on-device model protection based on tees","volume-title":"Proc. 41st Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690335"},{"key":"ref58","first-page":"5465","article-title":"Enhanced label-only membership inference attacks with fewer queries","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Li"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.21236\/ADA273556"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134038"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66787-4_4"},{"key":"ref62","first-page":"5699","article-title":"Relocate-vote: Using sparsity information to exploit ciphertext side-channels","volume-title":"Proc. 34th USENIX Conf. Secur. Symp.","author":"Yan"},{"key":"ref63","first-page":"717","article-title":"$\\lbrace${CIPHERLEAKS $\\rbrace$}: Breaking constant-time cryptography on $\\lbrace${ AMD$\\rbrace$}$\\lbrace${SEV$\\rbrace$} via the ciphertext side channel","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Li"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833768"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00250"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690317"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00079"},{"key":"ref68","first-page":"227","article-title":"Varys: Protecting $\\lbrace${SGX $\\rbrace$} enclaves from practical $\\lbrace${ Side-Channel$\\rbrace$} attacks","volume-title":"Proc. Usenix Annu. Tech. Conf.","author":"Oleksenko"},{"key":"ref69","first-page":"788","article-title":"DR SGX: Automated and adjustable side-channel protection for SGX using data location randomization","volume-title":"Proc. 35th Annu. Comput. Secur. Appl. Conf.","author":"Brasser"},{"key":"ref70","first-page":"6789","article-title":"CipherFix: Mitigating ciphertext $\\lbrace${Side-Channel$\\rbrace$} attacks in software","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Wichelmann"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00261"},{"key":"ref72","first-page":"681","article-title":"Graviton: Trusted execution environments on $\\lbrace${GPUs$\\rbrace$}","volume-title":"Proc. 13th USENIX Symp. Operating Syst. Des. Implementation","author":"Volos"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560627"},{"key":"ref74","article-title":"CAGE: Complementing arm CCA with GPU extensions","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Wang"},{"key":"ref75","article-title":"NVIDIA h100 tensor core GPU architecture","volume-title":"NVIDIA, Tech. Rep.","year":"2023"},{"key":"ref76","article-title":"NVIDIA secure AI with blackwell and Hopper GPUs","volume-title":"NVIDIA, Tech. Rep.","year":"2025"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11603880\/11524063.pdf?arnumber=11524063","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:46:50Z","timestamp":1784238410000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11524063\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":76,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3694706","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7]]}}}