{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T03:37:43Z","timestamp":1772077063750,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,13]]},"DOI":"10.1145\/3411508.3421376","type":"proceedings-article","created":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T21:16:40Z","timestamp":1604351800000},"page":"93-104","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["eNNclave"],"prefix":"10.1145","author":[{"given":"Alexander","family":"Schl\u00f6gl","sequence":"first","affiliation":[{"name":"University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Amazon. 2016. Amazon reknognition. https:\/\/aws.amazon.com\/rekognition\/. Accessed on 2020-04--15.  Amazon. 2016. Amazon reknognition. https:\/\/aws.amazon.com\/rekognition\/. Accessed on 2020-04--15."},{"key":"e_1_3_2_1_2_1","unstructured":"Kairos AR. 2012. Kairos face recognition. https:\/\/kairos.com\/. Accessed on 2020-04--15.  Kairos AR. 2012. Kairos face recognition. https:\/\/kairos.com\/. Accessed on 2020-04--15."},{"key":"e_1_3_2_1_3_1","volume-title":"USENIX Security Symposium. USENIX, 249--266","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella , Jo Van Bulck , Michael Schwarz , Moritz Lipp , Benjamin von Berg , Philipp Ortner , Frank Piessens , Dmitry Evtyushkin , and Daniel Gruss . 2019 . A systematic evaluation of transient execution attacks and defenses . In USENIX Security Symposium. USENIX, 249--266 . Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A systematic evaluation of transient execution attacks and defenses. In USENIX Security Symposium. USENIX, 249--266."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2016.2516039"},{"key":"e_1_3_2_1_6_1","volume-title":"IEEE European Symposium on Security and Privacy (EuroS&P). 142--157","author":"Chen Guoxing","unstructured":"Guoxing Chen , Sanchuan Chen , Yuan Xiao , Yinqian Zhang , Zhiqiang Lin , and Ten H. Lai . 2019. SgxPectre Attacks: Stealing Intel secrets from SGX enclaves via speculative execution . In IEEE European Symposium on Security and Privacy (EuroS&P). 142--157 . Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H. Lai. 2019. SgxPectre Attacks: Stealing Intel secrets from SGX enclaves via speculative execution. In IEEE European Symposium on Security and Privacy (EuroS&P). 142--157."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-015-0029-9"},{"key":"e_1_3_2_1_8_1","unstructured":"Darktrace. 2013. Darktrace email security. https:\/\/www.darktrace.com\/en\/technology\/#email-security . Accessed on 2020-04--15.  Darktrace. 2013. Darktrace email security. https:\/\/www.darktrace.com\/en\/technology\/#email-security . Accessed on 2020-04--15."},{"key":"e_1_3_2_1_9_1","volume-title":"Ng","author":"Dean Jeffrey","year":"2012","unstructured":"Jeffrey Dean , Greg Corrado , Rajat Monga , Kai Chen , Matthieu Devin , Mark Mao , Marc'aurelio Ranzato , Andrew Senior , Paul Tucker , Ke Yang , Quoc V. Le , and Andrew Y . Ng . 2012 . Large scale distributed deep networks. In Advances in Neural Information Processing Systems. Vol. 25 . Curran Associates , 1223--1231. Jeffrey Dean, Greg Corrado, Rajat Monga, Kai Chen, Matthieu Devin, Mark Mao, Marc'aurelio Ranzato, Andrew Senior, Paul Tucker, Ke Yang, Quoc V. Le, and Andrew Y. Ng. 2012. Large scale distributed deep networks. In Advances in Neural Information Processing Systems. Vol. 25. Curran Associates, 1223--1231."},{"key":"e_1_3_2_1_10_1","unstructured":"Python Software Foundation. 2020. Python C API . https:\/\/docs.python.org\/3.7\/c-api\/index.html . Accessed on 2020-09--10.  Python Software Foundation. 2020. Python C API . https:\/\/docs.python.org\/3.7\/c-api\/index.html . Accessed on 2020-09--10."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_12_1","volume-title":"IFIP Congress , , Bruce Gilchrist (Ed.). 839--842","author":"Freivalds Rusins","year":"1977","unstructured":"Rusins Freivalds . 1977 . Probabilistic machines can use less running time . In IFIP Congress , , Bruce Gilchrist (Ed.). 839--842 . Rusins Freivalds. 1977. Probabilistic machines can use less running time. In IFIP Congress , , Bruce Gilchrist (Ed.). 839--842."},{"key":"e_1_3_2_1_13_1","volume-title":"International Conference on Machine Learning (ICML)","volume":"48","author":"Gilad-Bachrach Ran","year":"2016","unstructured":"Ran Gilad-Bachrach , Nathan Dowlin , Kim Laine , Kristin Lauter , Michael Naehrig , and John Wernsing . 2016 . CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy . In International Conference on Machine Learning (ICML) , Vol. 48 . 201--210. Ran Gilad-Bachrach , Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy. In International Conference on Machine Learning (ICML), Vol. 48. 201--210."},{"key":"e_1_3_2_1_14_1","volume-title":"Information Security and Cryptology (ICISC), Han Dong-Guk Lee Hyang-Sook (Ed.)","author":"Graepel Thore","unstructured":"Thore Graepel , Kristin Lauter , and Michael Naehrig . 2013. ML Confidential: Machine learning on encrypted data . In Information Security and Cryptology (ICISC), Han Dong-Guk Lee Hyang-Sook (Ed.) . Springer , 1--21. Thore Graepel, Kristin Lauter, and Michael Naehrig. 2013. ML Confidential: Machine learning on encrypted data. In Information Security and Cryptology (ICISC), Han Dong-Guk Lee Hyang-Sook (Ed.). Springer, 1--21."},{"key":"e_1_3_2_1_15_1","unstructured":"HDF Group. 1998. HDF5 file format. https:\/\/portal.hdfgroup.org\/display\/HDF5\/HDF5 . Accessed on 2020-04--23.  HDF Group. 1998. HDF5 file format. https:\/\/portal.hdfgroup.org\/display\/HDF5\/HDF5 . Accessed on 2020-04--23."},{"key":"e_1_3_2_1_16_1","unstructured":"Lucjan Hanzlik Yang Zhang Kathrin Grosse Ahmed Salem Max Augustin Michael Backes and Mario Fritz. 2019. MLCapsule: Guarded offline deployment of machine learning as a service. https:\/\/publications.cispa.saarland\/2751\/.  Lucjan Hanzlik Yang Zhang Kathrin Grosse Ahmed Salem Max Augustin Michael Backes and Mario Fritz. 2019. MLCapsule: Guarded offline deployment of machine learning as a service. https:\/\/publications.cispa.saarland\/2751\/."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_18_1","unstructured":"Intel. 2018. Intel software guard extensions (Intel SGX) SDK for Linux OS Developer Reference. https:\/\/download.01.org\/intel-sgx\/linux-2.2\/docs\/Intel_SGX_Developer_Reference_Linux_2.2_Open_Source.pdf . Accessed on 2020-04-01.  Intel. 2018. Intel software guard extensions (Intel SGX) SDK for Linux OS Developer Reference. https:\/\/download.01.org\/intel-sgx\/linux-2.2\/docs\/Intel_SGX_Developer_Reference_Linux_2.2_Open_Source.pdf . Accessed on 2020-04-01."},{"key":"e_1_3_2_1_19_1","unstructured":"Intel. 2019 a. Intel SGX driver for Linux. https:\/\/github.com\/intel\/linux-sgx-driver . Accessed on 2020-04--22.  Intel. 2019 a. Intel SGX driver for Linux. https:\/\/github.com\/intel\/linux-sgx-driver . Accessed on 2020-04--22."},{"key":"e_1_3_2_1_20_1","unstructured":"Intel. 2019 b. Intel SGX monotonic counters. https:\/\/software.intel.com\/en-us\/dal-developer-guide-features-monotonic-counters . Accessed on 2020-04--15.  Intel. 2019 b. Intel SGX monotonic counters. https:\/\/software.intel.com\/en-us\/dal-developer-guide-features-monotonic-counters . Accessed on 2020-04--15."},{"key":"e_1_3_2_1_21_1","unstructured":"Ironscales. 2014. Ironscales email security. https:\/\/ironscales.com\/anti-phishing-solutions\/. Accessed on 2020-04--22.  Ironscales. 2014. Ironscales email security. https:\/\/ironscales.com\/anti-phishing-solutions\/. Accessed on 2020-04--22."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Gabriel Kaptchuk Ian Miers and Matthew Green. 2019. Giving state to the stateless: Augmenting trustworthy computation with ledgers. In Network and Distributed Systems Security (NDSS) .  Gabriel Kaptchuk Ian Miers and Matthew Green. 2019. Giving state to the stateless: Augmenting trustworthy computation with ledgers. In Network and Distributed Systems Security (NDSS) .","DOI":"10.14722\/ndss.2019.23060"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_1_24_1","volume-title":"Franz Gregor, Sergei Arnautov, Pramod Bhatotia, and Christof Fetzer.","author":"Kunkel Roland","year":"2019","unstructured":"Roland Kunkel , Do Le Quoc , Franz Gregor, Sergei Arnautov, Pramod Bhatotia, and Christof Fetzer. 2019 . Tensorscone : A secure TensorFlow framework using Intel SGX . arXiv preprint arXiv:1902.04413 (2019). Roland Kunkel, Do Le Quoc, Franz Gregor, Sergei Arnautov, Pramod Bhatotia, and Christof Fetzer. 2019. Tensorscone: A secure TensorFlow framework using Intel SGX . arXiv preprint arXiv:1902.04413 (2019)."},{"key":"e_1_3_2_1_25_1","volume-title":"USENIX Security Symposium . USENIX, 973--990","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading kernel memory from user space . In USENIX Security Symposium . USENIX, 973--990 . Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading kernel memory from user space. In USENIX Security Symposium . USENIX, 973--990."},{"key":"e_1_3_2_1_26_1","unstructured":"Alexander Mamaev. 2018. Kaggle flower classification challenge. https:\/\/www.kaggle.com\/alxmamaev\/flowers-recognition\/data . Accessed on 2020-04--21.  Alexander Mamaev. 2018. Kaggle flower classification challenge. https:\/\/www.kaggle.com\/alxmamaev\/flowers-recognition\/data . Accessed on 2020-04--21."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00057"},{"key":"e_1_3_2_1_29_1","volume-title":"USENIX Security Symposium . USENIX, 619--636","author":"Ohrimenko Olga","year":"2016","unstructured":"Olga Ohrimenko , Felix Schuster , C\u00e9dric Fournet , Aastha Mehta , Sebastian Nowozin , Kapil Vaswani , and Manuel Costa . 2016 . Oblivious multi-party machine learning on trusted processors . In USENIX Security Symposium . USENIX, 619--636 . Olga Ohrimenko, Felix Schuster, C\u00e9dric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious multi-party machine learning on trusted processors. In USENIX Security Symposium . USENIX, 619--636."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2009.191"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_32_1","volume-title":"IEEE European Symposium on Security and Privacy (EuroS&P). 399--414","author":"Papernot Nicolas","unstructured":"Nicolas Papernot , Patrick McDaniel , Arunesh Sinha , and Michael P. Wellman . 2018. SoK: Security and privacy in machine learning . In IEEE European Symposium on Security and Privacy (EuroS&P). 399--414 . Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P. Wellman. 2018. SoK: Security and privacy in machine learning. In IEEE European Symposium on Security and Privacy (EuroS&P). 399--414."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206537"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_36_1","unstructured":"Alexander Schl\u00f6gl. 2020 a. eNNclave framework. https:\/\/github.com\/alxshine\/eNNclave\/tree\/aisec . Accessed on 2020-09--10.  Alexander Schl\u00f6gl. 2020 a. eNNclave framework. https:\/\/github.com\/alxshine\/eNNclave\/tree\/aisec . Accessed on 2020-09--10."},{"key":"e_1_3_2_1_37_1","unstructured":"Alexander Schl\u00f6gl. 2020 b. eNNclave paper experiments. https:\/\/github.com\/alxshine\/eNNclave\/tree\/aisec . Accessed on 2020-09--10.  Alexander Schl\u00f6gl. 2020 b. eNNclave paper experiments. https:\/\/github.com\/alxshine\/eNNclave\/tree\/aisec . Accessed on 2020-09--10."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_39_1","volume-title":"International Conference on Learning Representations (ICLR) .","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman . 2015 . Very deep convolutional networks for large-scale image recognition . In International Conference on Learning Representations (ICLR) . Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00021"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3177155"},{"key":"e_1_3_2_1_42_1","volume-title":"CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In USENIX Security Symposium. USENIX , 1057--1074","author":"Tang Adrian","year":"2017","unstructured":"Adrian Tang , Simha Sethumadhavan , and Salvatore Stolfo . 2017 . CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In USENIX Security Symposium. USENIX , 1057--1074 . Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017. CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In USENIX Security Symposium. USENIX , 1057--1074."},{"key":"e_1_3_2_1_43_1","volume-title":"IEEE International Conference on Distributed Computing Systems (ICDCS) . 328--339","author":"Teerapittayanon Surat","unstructured":"Surat Teerapittayanon , Bradley McDanel , and H.T. Kung . 2017. Distributed deep neural networks over the cloud, the edge and end devices . In IEEE International Conference on Distributed Computing Systems (ICDCS) . 328--339 . Surat Teerapittayanon, Bradley McDanel, and H.T. Kung. 2017. Distributed deep neural networks over the cloud, the edge and end devices. In IEEE International Conference on Distributed Computing Systems (ICDCS) . 328--339."},{"key":"e_1_3_2_1_44_1","volume-title":"International Conference on Learning Representations (ICLR) .","author":"Tram\u00e8r Florian","year":"2019","unstructured":"Florian Tram\u00e8r and Dan Boneh . 2019 . Slalom: Fast, verifiable and private execution of neural networks in trusted hardware .. In International Conference on Learning Representations (ICLR) . Florian Tram\u00e8r and Dan Boneh. 2019. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware.. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_1_45_1","volume-title":"USENIX Security Symposium . USENIX, 601--618","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r , Fan Zhang , Ari Juels , Michael Reiter , and Thomas Ristenpart . 2016 . Stealing machine learning models via prediction APIs . In USENIX Security Symposium . USENIX, 601--618 . Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In USENIX Security Symposium . USENIX, 601--618."},{"key":"e_1_3_2_1_46_1","volume-title":"IFIP international workshop on information security theory and practices , , Olivier Markowitch, Angelos Bilas, Jaap-Henk Hoepman, Chris J","author":"Tunstall Michael","unstructured":"Michael Tunstall and Debdeep Mukhopadhyay . 2009. Differential fault analysis of the advanced encryption standard using a single fault . In IFIP international workshop on information security theory and practices , , Olivier Markowitch, Angelos Bilas, Jaap-Henk Hoepman, Chris J . Mitchell, and Jean-Jacques Quisquater (Eds.). Springer , 224--233. Michael Tunstall and Debdeep Mukhopadhyay. 2009. Differential fault analysis of the advanced encryption standard using a single fault. In IFIP international workshop on information security theory and practices , , Olivier Markowitch, Angelos Bilas, Jaap-Henk Hoepman, Chris J. Mitchell, and Jean-Jacques Quisquater (Eds.). Springer, 224--233."},{"key":"e_1_3_2_1_47_1","unstructured":"Justifying Recommendations using Distantly-Labeled Reviews and Fine-Grained Aspects. 2019. Jianmo Ni and Jiacheng Li and Julian McAuley. In Empirical Methods in Natural Language Processing (EMLNP). ACL.  Justifying Recommendations using Distantly-Labeled Reviews and Fine-Grained Aspects. 2019. Jianmo Ni and Jiacheng Li and Julian McAuley. In Empirical Methods in Natural Language Processing (EMLNP). ACL."},{"key":"e_1_3_2_1_48_1","volume-title":"USENIX Security Symposium . USENIX, 991--1008","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck , Marina Minkin , Ofir Weisse , Daniel Genkin , Baris Kasikci , Frank Piessens , Mark Silberstein , Thomas F. Wenisch , Yuval Yarom , and Raoul Strackx . 2018 . Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution . In USENIX Security Symposium . USENIX, 991--1008 . Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F. Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution. In USENIX Security Symposium . USENIX, 991--1008."},{"key":"e_1_3_2_1_49_1","volume-title":"IEEE Symposium on Security and Privacy (S&P) .","author":"Bulck Jo Van","year":"2020","unstructured":"Jo Van Bulck , Daniel Moghimi , Michael Schwarz , Moritz Lipp , Marina Minkin , Daniel Genkin , Yarom Yuval , Berk Sunar , Daniel Gruss , and Frank Piessens . 2020 . LVI: Hijacking transient execution through microarchitectural load value injection . In IEEE Symposium on Security and Privacy (S&P) . Jo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp, Marina Minkin, Daniel Genkin, Yarom Yuval, Berk Sunar, Daniel Gruss, and Frank Piessens. 2020. LVI: Hijacking transient execution through microarchitectural load value injection. In IEEE Symposium on Security and Privacy (S&P) ."},{"key":"e_1_3_2_1_50_1","volume-title":"IEEE Symposium on Security and Privacy (S&P) . 36--52","author":"Wang Binghui","unstructured":"Binghui Wang and Neil Z. Gong . 2018. Stealing hyperparameters in machine learning . In IEEE Symposium on Security and Privacy (S&P) . 36--52 . Binghui Wang and Neil Z. Gong. 2018. Stealing hyperparameters in machine learning. In IEEE Symposium on Security and Privacy (S&P) . 36--52."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3014812.3014815"},{"key":"e_1_3_2_1_52_1","volume-title":"Places: A 10 million image database for scene recognition","author":"Zhou Bolei","year":"2017","unstructured":"Bolei Zhou , Agata Lapedriza , Aditya Khosla , Aude Oliva , and Antonio Torralba . 2017 . Places: A 10 million image database for scene recognition . IEEE Transactions on Pattern Analysis and Machine Intelligence ( 2017). Bolei Zhou, Agata Lapedriza, Aditya Khosla, Aude Oliva, and Antonio Torralba. 2017. Places: A 10 million image database for scene recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence (2017)."},{"key":"e_1_3_2_1_53_1","volume-title":"Advances in Neural Information Processing Systems.","author":"Zhou Bolei","unstructured":"Bolei Zhou , Agata Lapedriza , Jianxiong Xiao , Antonio Torralba , and Aude Oliva . 2014. Learning deep features for scene recognition using Places database . In Advances in Neural Information Processing Systems. Vol. 27 . Curran Associates , 487--495. Bolei Zhou, Agata Lapedriza, Jianxiong Xiao, Antonio Torralba, and Aude Oliva. 2014. Learning deep features for scene recognition using Places database. In Advances in Neural Information Processing Systems. Vol. 27. Curran Associates, 487--495."}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411508.3421376","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3411508.3421376","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:37Z","timestamp":1750197757000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411508.3421376"}},"subtitle":["Offline Inference with Model Confidentiality"],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":53,"alternative-id":["10.1145\/3411508.3421376","10.1145\/3411508"],"URL":"https:\/\/doi.org\/10.1145\/3411508.3421376","relation":{},"subject":[],"published":{"date-parts":[[2020,11,9]]},"assertion":[{"value":"2020-11-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}