{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:29:50Z","timestamp":1786112990984,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":68,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,15]],"date-time":"2020-06-15T00:00:00Z","timestamp":1592179200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EPSRC Databox","award":["EP\/N028260\/1"],"award-info":[{"award-number":["EP\/N028260\/1"]}]},{"name":"EPSRC DADA","award":["EP\/R03351X\/1"],"award-info":[{"award-number":["EP\/R03351X\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,15]]},"DOI":"10.1145\/3386901.3388946","type":"proceedings-article","created":{"date-parts":[[2020,6,7]],"date-time":"2020-06-07T01:27:30Z","timestamp":1591493250000},"page":"161-174","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":166,"title":["DarkneTZ"],"prefix":"10.1145","author":[{"given":"Fan","family":"Mo","sequence":"first","affiliation":[{"name":"Imperial College London"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali Shahin","family":"Shamsabadi","sequence":"additional","affiliation":[{"name":"Queen Mary University of London"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kleomenis","family":"Katevas","sequence":"additional","affiliation":[{"name":"Telef\u00f3nica Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Soteris","family":"Demetriou","sequence":"additional","affiliation":[{"name":"Imperial College London"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ilias","family":"Leontiadis","sequence":"additional","affiliation":[{"name":"Samsung AI"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrea","family":"Cavallaro","sequence":"additional","affiliation":[{"name":"Queen Mary University of London"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hamed","family":"Haddadi","sequence":"additional","affiliation":[{"name":"Imperial College London"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,6,15]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Tukey's honestly significant difference (HSD) test. Encyclopedia of Research Design","author":"Abdi Herv\u00e9","year":"2010","unstructured":"Herv\u00e9 Abdi and Lynne J Williams . 2010. Tukey's honestly significant difference (HSD) test. Encyclopedia of Research Design . Thousand Oaks, CA : Sage ( 2010 ), 1--5. Herv\u00e9 Abdi and Lynne J Williams. 2010. Tukey's honestly significant difference (HSD) test. Encyclopedia of Research Design. Thousand Oaks, CA: Sage (2010), 1--5."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3214303"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, 227--233","author":"Akowuah Francis","year":"2018","unstructured":"Francis Akowuah , Amit Ahlawat , and Wenliang Du . 2018 . Protecting Sensitive Data in Android SQLite Databases Using TrustZone . In Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, 227--233 . Francis Akowuah, Amit Ahlawat, and Wenliang Du. 2018. Protecting Sensitive Data in Android SQLite Databases Using TrustZone. In Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, 227--233."},{"key":"e_1_3_2_1_5_1","unstructured":"Galen Andrew Steve Chien and Nicolas Papernot. 2019. TensorFlow Privacy. https:\/\/github.com\/tensorflow\/privacy  Galen Andrew Steve Chien and Nicolas Papernot. 2019. TensorFlow Privacy. https:\/\/github.com\/tensorflow\/privacy"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"e_1_3_2_1_7_1","volume-title":"Security technology-building a secure system using TrustZone technology. ARM Technical White Paper","author":"Arm A","year":"2009","unstructured":"A Arm . 2009. Security technology-building a secure system using TrustZone technology. ARM Technical White Paper ( 2009 ). A Arm. 2009. Security technology-building a secure system using TrustZone technology. ARM Technical White Paper (2009)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23448"},{"key":"e_1_3_2_1_9_1","unstructured":"Rich Caruana Steve Lawrence and C Lee Giles. 2001. Overfitting in neural nets: Backpropagation conjugate gradient and early stopping. In Advances in Neural Information Processing Systems. 402--408.  Rich Caruana Steve Lawrence and C Lee Giles. 2001. Overfitting in neural nets: Backpropagation conjugate gradient and early stopping. In Advances in Neural Information Processing Systems. 402--408."},{"key":"e_1_3_2_1_10_1","first-page":"1","article-title":"Intel SGX Explained","volume":"2016","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas . 2016 . Intel SGX Explained . IACR Cryptology ePrint Archive 2016 , 086 (2016), 1 -- 118 . Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained. IACR Cryptology ePrint Archive 2016, 086 (2016), 1--118.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_12_1","volume-title":"TZDKS: A New TrustZone-Based Dual-Criticality System with Balanced Performance. In 2018 IEEE 24th International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA)","author":"Dong Pan","year":"2018","unstructured":"Pan Dong , Alan Burns , Zhe Jiang , and Xiangke Liao . 2018 . TZDKS: A New TrustZone-Based Dual-Criticality System with Balanced Performance. In 2018 IEEE 24th International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA) . IEEE , 59--64. Pan Dong, Alan Burns, Zhe Jiang, and Xiangke Liao. 2018. TZDKS: A New TrustZone-Based Dual-Criticality System with Balanced Performance. In 2018 IEEE 24th International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA). IEEE, 59--64."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.522"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork Aaron Roth etal 2014. The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9 3-4 (2014) 211--407.  Cynthia Dwork Aaron Roth et al. 2014. The algorithmic foundations of differential privacy. Foundations and Trends \u00ae in Theoretical Computer Science 9 3-4 (2014) 211--407.","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.38"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_17_1","volume-title":"YerbaBuena: Securing Deep Learning Inference Data via Enclave-based Ternary Model Partitioning. arXiv preprint arXiv:1807.00969","author":"Gu Zhongshu","year":"2018","unstructured":"Zhongshu Gu , Heqing Huang , Jialong Zhang , Dong Su , Hani Jamjoom , Ankita Lamba , Dimitrios Pendarakis , and Ian Molloy . 2018. YerbaBuena: Securing Deep Learning Inference Data via Enclave-based Ternary Model Partitioning. arXiv preprint arXiv:1807.00969 ( 2018 ). Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Hani Jamjoom, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy. 2018. YerbaBuena: Securing Deep Learning Inference Data via Enclave-based Ternary Model Partitioning. arXiv preprint arXiv:1807.00969 (2018)."},{"key":"e_1_3_2_1_18_1","volume-title":"International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1510","author":"Han Song","year":"2015","unstructured":"Song Han , Huizi Mao , and William J Dally . 2015 . Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding. arXiv preprint arXiv:1510.00149 . In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1510 .00149 Song Han, Huizi Mao, and William J Dally. 2015. Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding. arXiv preprint arXiv:1510.00149. In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1510.00149"},{"key":"e_1_3_2_1_19_1","volume-title":"Mlcapsule: Guarded offline deployment of machine learning as a service. arXiv preprint arXiv:1808.00590","author":"Hanzlik Lucjan","year":"2018","unstructured":"Lucjan Hanzlik , Yang Zhang , Kathrin Grosse , Ahmed Salem , Max Augustin , Michael Backes , and Mario Fritz . 2018 . Mlcapsule: Guarded offline deployment of machine learning as a service. arXiv preprint arXiv:1808.00590 (2018). Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Max Augustin, Michael Backes, and Mario Fritz. 2018. Mlcapsule: Guarded offline deployment of machine learning as a service. arXiv preprint arXiv:1808.00590 (2018)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_2_1_22_1","volume-title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861","author":"Howard Andrew G","year":"2017","unstructured":"Andrew G Howard , Menglong Zhu , Bo Chen , Dmitry Kalenichenko , Weijun Wang , Tobias Weyand , Marco Andreetto , and Hartwig Adam . 2017 . Mobilenets: Efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861 (2017). Andrew G Howard, Menglong Zhu, Bo Chen, Dmitry Kalenichenko, Weijun Wang, Tobias Weyand, Marco Andreetto, and Hartwig Adam. 2017. Mobilenets: Efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861 (2017)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_1_24_1","volume-title":"Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961","author":"Hunt Tyler","year":"2018","unstructured":"Tyler Hunt , Congzheng Song , Reza Shokri , Vitaly Shmatikov , and Emmett Witchel . 2018 . Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961 (2018). Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961 (2018)."},{"key":"e_1_3_2_1_25_1","volume-title":"Efficient deep learning on multi-source private data. arXiv preprint arXiv:1807.06689","author":"Hynes Nick","year":"2018","unstructured":"Nick Hynes , Raymond Cheng , and Dawn Song . 2018. Efficient deep learning on multi-source private data. arXiv preprint arXiv:1807.06689 ( 2018 ). Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient deep learning on multi-source private data. arXiv preprint arXiv:1807.06689 (2018)."},{"key":"e_1_3_2_1_26_1","volume-title":"SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and &lt","author":"Iandola Forrest N","year":"2016","unstructured":"Forrest N Iandola , Song Han , Matthew W Moskewicz , Khalid Ashraf , William J Dally , and Kurt Keutzer . 2016. SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and &lt ; 0.5 MB model size. arXiv preprint arXiv:1602.07360 ( 2016 ). Forrest N Iandola, Song Han, Matthew W Moskewicz, Khalid Ashraf, William J Dally, and Kurt Keutzer. 2016. SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and &lt; 0.5 MB model size. arXiv preprint arXiv:1602.07360 (2016)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"e_1_3_2_1_28_1","volume-title":"Evaluating Differentially Private Machine Learning in Practice. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans . 2019 . Evaluating Differentially Private Machine Learning in Practice. In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Association, Santa Clara, CA , 1895--1912. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/jayaraman Bargav Jayaraman and David Evans. 2019. Evaluating Differentially Private Machine Learning in Practice. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 1895--1912. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/jayaraman"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_24"},{"key":"e_1_3_2_1_31_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-100 (Canadian Institute for Advanced Research). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html  Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-100 (Canadian Institute for Advanced Research). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html"},{"key":"e_1_3_2_1_32_1","volume-title":"Deep learning. nature 521, 7553","author":"LeCun Yann","year":"2015","unstructured":"Yann LeCun , Yoshua Bengio , and Geoffrey Hinton . 2015. Deep learning. nature 521, 7553 ( 2015 ), 436--444. Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015. Deep learning. nature 521, 7553 (2015), 436--444."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516686"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363279"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046682"},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of 40th IEEE Symposium on Security & Privacy. IEEE.","author":"Nasr Milad","year":"2019","unstructured":"Milad Nasr , Reza Shokri , and Amir Houmansadr . 2019 . Comprehensive Privacy Analysis of Deep Learning: Stand-alone and Federated Learning under Passive and Active White-box Inference Attacks . In Proceedings of 40th IEEE Symposium on Security & Privacy. IEEE. Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive Privacy Analysis of Deep Learning: Stand-alone and Federated Learning under Passive and Active White-box Inference Attacks. In Proceedings of 40th IEEE Symposium on Security & Privacy. IEEE."},{"key":"e_1_3_2_1_39_1","volume-title":"Oblivious Multi-Party Machine Learning on Trusted Processors. In 25th USENIX Security Symposium (USENIX Security 16)","author":"Ohrimenko Olga","year":"2016","unstructured":"Olga Ohrimenko , Felix Schuster , Cedric Fournet , Aastha Mehta , Sebastian Nowozin , Kapil Vaswani , and Manuel Costa . 2016 . Oblivious Multi-Party Machine Learning on Trusted Processors. In 25th USENIX Security Symposium (USENIX Security 16) . USENIX Association, Austin, TX, 619--636. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/ohrimenko Olga Ohrimenko, Felix Schuster, Cedric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious Multi-Party Machine Learning on Trusted Processors. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 619--636. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/ohrimenko"},{"key":"e_1_3_2_1_40_1","volume-title":"Ali Taheri, Kleomenis Katevas, Sina Sajadmanesh, Hamid R Rabiee, Nicholas D Lane, and Hamed Haddadi.","author":"Osia Seyed Ali","year":"2020","unstructured":"Seyed Ali Osia , Ali Shahin Shamsabadi , Ali Taheri, Kleomenis Katevas, Sina Sajadmanesh, Hamid R Rabiee, Nicholas D Lane, and Hamed Haddadi. 2020 . A hybrid deep learning architecture for privacy-preserving mobile analytics. IEEE Internet of Things Journal ( 2020). Seyed Ali Osia, Ali Shahin Shamsabadi, Ali Taheri, Kleomenis Katevas, Sina Sajadmanesh, Hamid R Rabiee, Nicholas D Lane, and Hamed Haddadi. 2020. A hybrid deep learning architecture for privacy-preserving mobile analytics. IEEE Internet of Things Journal (2020)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2018.2381113"},{"key":"e_1_3_2_1_42_1","unstructured":"Heejin Park Shuang Zhai Long Lu and Felix Xiaozhu Lin. 2019. StreamBox-TZ: secure stream analytics at the edge with TrustZone. In 2019 {USENIX} Annual Technical Conference 19. 537--554.  Heejin Park Shuang Zhai Long Lu and Felix Xiaozhu Lin. 2019. StreamBox-TZ: secure stream analytics at the edge with TrustZone. In 2019 { USENIX } Annual Technical Conference 19. 537--554."},{"key":"e_1_3_2_1_43_1","volume-title":"Automatic Differentiation in PyTorch. In NIPS Autodiff Workshop.","author":"Paszke Adam","year":"2017","unstructured":"Adam Paszke , Sam Gross , Soumith Chintala , Gregory Chanan , Edward Yang , Zachary DeVito , Zeming Lin , Alban Desmaison , Luca Antiga , and Adam Lerer . 2017 . Automatic Differentiation in PyTorch. In NIPS Autodiff Workshop. Adam Paszke, Sam Gross, Soumith Chintala, Gregory Chanan, Edward Yang, Zachary DeVito, Zeming Lin, Alban Desmaison, Luca Antiga, and Adam Lerer. 2017. Automatic Differentiation in PyTorch. In NIPS Autodiff Workshop."},{"key":"e_1_3_2_1_44_1","volume-title":"Downsampling leads to Image Memorization in Convolutional Autoencoders. arXiv preprint arXiv:1810.10333","author":"Radhakrishnan Adityanarayanan","year":"2018","unstructured":"Adityanarayanan Radhakrishnan , Mikhail Belkin , and Caroline Uhler . 2018. Downsampling leads to Image Memorization in Convolutional Autoencoders. arXiv preprint arXiv:1810.10333 ( 2018 ). Adityanarayanan Radhakrishnan, Mikhail Belkin, and Caroline Uhler. 2018. Downsampling leads to Image Memorization in Convolutional Autoencoders. arXiv preprint arXiv:1810.10333 (2018)."},{"key":"e_1_3_2_1_45_1","first-page":"61","article-title":"Membership Inference Attack against Differentially Private Deep Learning Model","volume":"11","author":"Rahman Md Atiqur","year":"2018","unstructured":"Md Atiqur Rahman , Tanzila Rahman , Robert Lagani\u00e8re , Noman Mohammed , and Yang Wang . 2018 . Membership Inference Attack against Differentially Private Deep Learning Model . Transactions on Data Privacy 11 , 1 (2018), 61 -- 79 . Md Atiqur Rahman, Tanzila Rahman, Robert Lagani\u00e8re, Noman Mohammed, and Yang Wang. 2018. Membership Inference Attack against Differentially Private Deep Learning Model. Transactions on Data Privacy 11, 1 (2018), 61--79.","journal-title":"Transactions on Data Privacy"},{"key":"e_1_3_2_1_46_1","unstructured":"Joseph Redmon. 2013--2016. Darknet: Open Source Neural Networks in C. http:\/\/pjreddie.com\/darknet\/.  Joseph Redmon. 2013--2016. Darknet: Open Source Neural Networks in C. http:\/\/pjreddie.com\/darknet\/."},{"key":"e_1_3_2_1_47_1","volume-title":"Network and Distributed Systems Security (NDSS) Symposium 2018","author":"Salem Ahmed","year":"2018","unstructured":"Ahmed Salem , Yang Zhang , Mathias Humbert , Pascal Berrang , Mario Fritz , and Michael Backes . 2018 . Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246 . In Network and Distributed Systems Security (NDSS) Symposium 2018 . https:\/\/arxiv.org\/abs\/1806.01246 Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2018. Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246. In Network and Distributed Systems Security (NDSS) Symposium 2018. https:\/\/arxiv.org\/abs\/1806.01246"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_50_1","volume-title":"Privado: Practical and secure DNN inference. arXiv preprint arXiv:1810.00602","author":"Tople Shruti","year":"2018","unstructured":"Shruti Tople , Karan Grover , Shweta Shinde , Ranjita Bhagwan , and Ramachandran Ramjee . 2018 . Privado: Practical and secure DNN inference. arXiv preprint arXiv:1810.00602 (2018). Shruti Tople, Karan Grover, Shweta Shinde, Ranjita Bhagwan, and Ramachandran Ramjee. 2018. Privado: Practical and secure DNN inference. arXiv preprint arXiv:1810.00602 (2018)."},{"key":"e_1_3_2_1_51_1","volume-title":"International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1806","author":"Tram\u00e8r Florian","year":"2019","unstructured":"Florian Tram\u00e8r and Dan Boneh . 2019 . Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. arXiv preprint arXiv:1806.03287 . In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1806 .03287 Florian Tram\u00e8r and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. arXiv preprint arXiv:1806.03287. In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1806.03287"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00881"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134038"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2897874"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313591"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3210240.3210338"},{"key":"e_1_3_2_1_59_1","unstructured":"Jason Yosinski Jeff Clune Yoshua Bengio and Hod Lipson. 2014. How transferable are features in deep neural networks?. In Advances in Neural Information Processing Systems. 3320--3328.  Jason Yosinski Jeff Clune Yoshua Bengio and Hod Lipson. 2014. How transferable are features in deep neural networks?. In Advances in Neural Information Processing Systems. 3320--3328."},{"key":"e_1_3_2_1_60_1","volume-title":"Deep Learning Workshop in International Conference on Machine Learning. https:\/\/arxiv.org\/abs\/1506","author":"Yosinski Jason","year":"2015","unstructured":"Jason Yosinski , Jeff Clune , Anh Nguyen , Thomas Fuchs , and Hod Lipson . 2015 . Understanding neural networks through deep visualization. arXiv preprint arXiv:1506.06579 . In Deep Learning Workshop in International Conference on Machine Learning. https:\/\/arxiv.org\/abs\/1506 .06579 Jason Yosinski, Jeff Clune, Anh Nguyen, Thomas Fuchs, and Hod Lipson. 2015. Understanding neural networks through deep visualization. arXiv preprint arXiv:1506.06579. In Deep Learning Workshop in International Conference on Machine Learning. https:\/\/arxiv.org\/abs\/1506.06579"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00019"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"e_1_3_2_1_63_1","volume-title":"International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1611","author":"Zhang Chiyuan","year":"2017","unstructured":"Chiyuan Zhang , Samy Bengio , Moritz Hardt , Benjamin Recht , and Oriol Vinyals . 2017 . Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530 . In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1611 .03530 Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals. 2017. Understanding deep learning requires rethinking generalization. arXiv preprint arXiv:1611.03530. In International Conference on Learning Representations (ICLR). https:\/\/arxiv.org\/abs\/1611.03530"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2904897"},{"key":"e_1_3_2_1_65_1","volume-title":"International Conference on Machine Learning. 4091--4099","author":"Zhao Shengjia","year":"2017","unstructured":"Shengjia Zhao , Jiaming Song , and Stefano Ermon . 2017 . Learning hierarchical features from deep generative models . In International Conference on Machine Learning. 4091--4099 . Shengjia Zhao, Jiaming Song, and Stefano Ermon. 2017. Learning hierarchical features from deep generative models. In International Conference on Machine Learning. 4091--4099."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363205"},{"key":"e_1_3_2_1_67_1","unstructured":"Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems. 14747--14756.  Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems. 14747--14756."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"}],"event":{"name":"MobiSys '20: The 18th Annual International Conference on Mobile Systems, Applications, and Services","location":"Toronto Ontario Canada","acronym":"MobiSys '20","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"]},"container-title":["Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386901.3388946","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3386901.3388946","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:33:26Z","timestamp":1750199606000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386901.3388946"}},"subtitle":["towards model privacy at the edge using trusted execution environments"],"short-title":[],"issued":{"date-parts":[[2020,6,15]]},"references-count":68,"alternative-id":["10.1145\/3386901.3388946","10.1145\/3386901"],"URL":"https:\/\/doi.org\/10.1145\/3386901.3388946","relation":{},"subject":[],"published":{"date-parts":[[2020,6,15]]},"assertion":[{"value":"2020-06-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}