{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,10]],"date-time":"2025-11-10T13:05:10Z","timestamp":1762779910209,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T00:00:00Z","timestamp":1635724800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"General Research Fund","award":["No. 152221\/19E and 15220320\/20E"],"award-info":[{"award-number":["No. 152221\/19E and 15220320\/20E"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772480, 61972171, 61872310"],"award-info":[{"award-number":["61772480, 61972171, 61872310"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Hong Kong RGC Research Impact Fund","award":["R5060-19"],"award-info":[{"award-number":["R5060-19"]}]},{"name":"Shenzhen Science and Technology Innovation Commission","award":["R2020A045"],"award-info":[{"award-number":["R2020A045"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11]]},"DOI":"10.1145\/3472883.3486988","type":"proceedings-article","created":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T10:48:16Z","timestamp":1635331696000},"page":"533-545","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Lasagna"],"prefix":"10.1145","author":[{"given":"Yuepeng","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Science, China, University of Geosciences, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Deze","family":"Zeng","sequence":"additional","affiliation":[{"name":"School of Computer Science, China, University of Geosciences, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lin","family":"Gu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Huazhong University of Science and Technology Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quan","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Song","family":"Guo","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Albert","family":"Zomaya","sequence":"additional","affiliation":[{"name":"Centre for Distributed and High Performance Computing School of Information Technologies, The University of Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minyi","family":"Guo","sequence":"additional","affiliation":[{"name":"Department of Computing, Shanghai Jiao Tong University Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,11]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Proceedings of USENIX Symposium on Operating Systems Design and Implementations (OSDI). 689--703","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , Andre Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O'keeffe , Mark L Stillwell , 2016 . SCONE: Secure linux containers with intel SGX . In Proceedings of USENIX Symposium on Operating Systems Design and Implementations (OSDI). 689--703 . Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'keeffe, Mark L Stillwell, et al. 2016. SCONE: Secure linux containers with intel SGX. In Proceedings of USENIX Symposium on Operating Systems Design and Implementations (OSDI). 689--703."},{"key":"e_1_3_2_2_2_1","volume-title":"Proceedings of Usenix Security Symposium (USENIX Security). 2255--2272","author":"Azizi Ahmadreza","year":"2021","unstructured":"Ahmadreza Azizi , Ibrahim Asadullah Tahmid , Asim Waheed , Neal Mangaokar , Jiameng Pu , Mobin Javed , Chandan K Reddy , and Bimal Viswanath . 2021 . T-Miner: A generative approach to defend against trojan attacks on DNN-based text classification . In Proceedings of Usenix Security Symposium (USENIX Security). 2255--2272 . Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K Reddy, and Bimal Viswanath. 2021. T-Miner: A generative approach to defend against trojan attacks on DNN-based text classification. In Proceedings of Usenix Security Symposium (USENIX Security). 2255--2272."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6256"},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of IEEE International Conference on Data Engineering (ICDE). 1242--1244","author":"Condie Tyson","year":"2013","unstructured":"Tyson Condie , Paul Mineiro , Neoklis Polyzotis , and Markus Weimer . 2013 . Machine learning on big data . In Proceedings of IEEE International Conference on Data Engineering (ICDE). 1242--1244 . Tyson Condie, Paul Mineiro, Neoklis Polyzotis, and Markus Weimer. 2013. Machine learning on big data. In Proceedings of IEEE International Conference on Data Engineering (ICDE). 1242--1244."},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"crossref","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. In IACR Cryptol. ePrint Arch. 1--118.  Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. In IACR Cryptol. ePrint Arch. 1--118.","DOI":"10.1561\/1000000051"},{"key":"e_1_3_2_2_6_1","volume-title":"Proceedings of International Conference on Machine Learning (ICML). 201--210","author":"Gilad-Bachrach Ran","year":"2016","unstructured":"Ran Gilad-Bachrach , Nathan Dowlin , Kim Laine , Kristin Lauter , Michael Naehrig , and John Wernsing . 2016 . Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy . In Proceedings of International Conference on Machine Learning (ICML). 201--210 . Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In Proceedings of International Conference on Machine Learning (ICML). 201--210."},{"key":"e_1_3_2_2_7_1","volume-title":"Proceedings of Computing Research Repository.","author":"Gu Zhongshu","year":"2018","unstructured":"Zhongshu Gu , Heqing Huang , Jialong Zhang , Dong Su , Ankita Lamba , Dimitrios Pendarakis , and Ian Molloy . 2018 . Securing input data of deep learning inference systems via partitioned enclave execution . In Proceedings of Computing Research Repository. Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy. 2018. Securing input data of deep learning inference systems via partitioned enclave execution. In Proceedings of Computing Research Repository."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33016538"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2013.6400435"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081360"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3092050"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_3_2_2_15_1","volume-title":"Caffe model zoo. UC Berkeley","author":"Jia Yangqing","year":"2015","unstructured":"Yangqing Jia and Evan Shelhamer . 2015. Caffe model zoo. UC Berkeley ( 2015 ). Yangqing Jia and Evan Shelhamer. 2015. Caffe model zoo. UC Berkeley (2015)."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421282"},{"key":"e_1_3_2_2_18_1","volume-title":"Proceedings of Annual Conference on Neural Information Processing Systems (NeurIPS)","volume":"25","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky , Ilya Sutskever , and Geoffrey E Hinton . 2012 . Imagenet classification with deep convolutional neural networks . In Proceedings of Annual Conference on Neural Information Processing Systems (NeurIPS) , Vol. 25 . 1097--1105. Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. In Proceedings of Annual Conference on Neural Information Processing Systems (NeurIPS), Vol. 25. 1097--1105."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2925452"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/IPSN.2016.7460664"},{"key":"e_1_3_2_2_21_1","volume-title":"Proceedings of Usenix Security Symposium (USENIX Security). 557--574","author":"Lee Sangho","year":"2017","unstructured":"Sangho Lee , Ming-Wei Shih , Prasun Gera , Taesoo Kim , Hyesoon Kim , and Marcus Peinado . 2017 . Inferring fine-grained control flow inside SGX enclaves with branch shadowing . In Proceedings of Usenix Security Symposium (USENIX Security). 557--574 . Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In Proceedings of Usenix Security Symposium (USENIX Security). 557--574."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2021.3076123"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3423211.3425687"},{"key":"e_1_3_2_2_26_1","unstructured":"Joseph Redmon. 2013--2016. Darknet: Open Source Neural Networks in C. http:\/\/pjreddie.com\/darknet\/.  Joseph Redmon. 2013--2016. Darknet: Open Source Neural Networks in C. http:\/\/pjreddie.com\/darknet\/."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_2_28_1","volume-title":"Proceedings of International Conference on Computer Vision (ICCV)","volume":"2","author":"Rhinehart Nicholas","year":"2019","unstructured":"Nicholas Rhinehart , Rowan McAllister , Kris Kitani , and Sergey Levine . 2019 . PRECOG: Predictions conditioned on goals in visual multi-agent scenarios . In Proceedings of International Conference on Computer Vision (ICCV) , Vol. 2 . 4. Nicholas Rhinehart, Rowan McAllister, Kris Kitani, and Sergey Levine. 2019. PRECOG: Predictions conditioned on goals in visual multi-agent scenarios. In Proceedings of International Conference on Computer Vision (ICCV), Vol. 2. 4."},{"key":"e_1_3_2_2_29_1","volume-title":"Proceedings of International Conference on Learning Representations (ICLR).","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman . 2015 . Very deep convolutional networks for large-scale image recognition . In Proceedings of International Conference on Learning Representations (ICLR). Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In Proceedings of International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_30_1","volume-title":"Proceedings of Usenix Security Symposium (USENIX Security). 1299--1316","author":"Suciu Octavian","year":"2018","unstructured":"Octavian Suciu , Radu Marginean , Yigitcan Kaya , Hal Daume III, and Tudor Dumitras . 2018 . When does machine learning FAIL? generalized transferability for evasion and poisoning attacks . In Proceedings of Usenix Security Symposium (USENIX Security). 1299--1316 . Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daume III, and Tudor Dumitras. 2018. When does machine learning FAIL? generalized transferability for evasion and poisoning attacks. In Proceedings of Usenix Security Symposium (USENIX Security). 1299--1316."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_2_32_1","volume-title":"Proceedings of USENIX Annul Technical Conference (USENIX ATC). 645--658","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai , Donald E Porter , and Mona Vij . 2017 . Graphene-SGX: A practical library OS for unmodified applications on SGX . In Proceedings of USENIX Annul Technical Conference (USENIX ATC). 645--658 . Chia-Che Tsai, Donald E Porter, and Mona Vij. 2017. Graphene-SGX: A practical library OS for unmodified applications on SGX. In Proceedings of USENIX Annul Technical Conference (USENIX ATC). 645--658."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413820"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900091"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3241539.3241563"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2019.2918951"}],"event":{"name":"SoCC '21: ACM Symposium on Cloud Computing","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGOPS ACM Special Interest Group on Operating Systems"],"location":"Seattle WA USA","acronym":"SoCC '21"},"container-title":["Proceedings of the ACM Symposium on Cloud Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3472883.3486988","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3472883.3486988","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:11:57Z","timestamp":1750191117000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3472883.3486988"}},"subtitle":["Accelerating Secure Deep Learning Inference in SGX-enabled Edge Cloud"],"short-title":[],"issued":{"date-parts":[[2021,11]]},"references-count":38,"alternative-id":["10.1145\/3472883.3486988","10.1145\/3472883"],"URL":"https:\/\/doi.org\/10.1145\/3472883.3486988","relation":{},"subject":[],"published":{"date-parts":[[2021,11]]},"assertion":[{"value":"2021-11-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}