{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:19:27Z","timestamp":1784996367252,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,24]],"date-time":"2023-04-24T00:00:00Z","timestamp":1682294400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"ONR","award":["N00014-21-1-2654, N00014-17-1-2995, N00014-20-1-2738"],"award-info":[{"award-number":["N00014-21-1-2654, N00014-17-1-2995, N00014-20-1-2738"]}]},{"name":"DARPA","award":["FA8750-19-C-0006, N6600121C4024"],"award-info":[{"award-number":["FA8750-19-C-0006, N6600121C4024"]}]},{"name":"NSF","award":["DMS-1737978, DGE-2039542, OAC-1828467, OAC-1931541, DGE-1906630"],"award-info":[{"award-number":["DMS-1737978, DGE-2039542, OAC-1828467, OAC-1931541, DGE-1906630"]}]},{"name":"ARO","award":["W911NF2110032"],"award-info":[{"award-number":["W911NF2110032"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,24]]},"DOI":"10.1145\/3577923.3583648","type":"proceedings-article","created":{"date-parts":[[2023,4,20]],"date-time":"2023-04-20T10:57:59Z","timestamp":1681988279000},"page":"153-164","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["Confidential Execution of Deep Learning Inference at the Untrusted Edge with ARM TrustZone"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8929-3003","authenticated-orcid":false,"given":"Md Shihabul","family":"Islam","sequence":"first","affiliation":[{"name":"The University of Texas at Dallas, Richardson, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1239-8162","authenticated-orcid":false,"given":"Mahmoud","family":"Zamani","sequence":"additional","affiliation":[{"name":"The University of Texas at Dallas, Richardson, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0985-8439","authenticated-orcid":false,"given":"Chung Hwan","family":"Kim","sequence":"additional","affiliation":[{"name":"The University of Texas at Dallas, Richardson, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9300-1576","authenticated-orcid":false,"given":"Latifur","family":"Khan","sequence":"additional","affiliation":[{"name":"The University of Texas at Dallas, Richardson, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0479-6280","authenticated-orcid":false,"given":"Kevin W.","family":"Hamlen","sequence":"additional","affiliation":[{"name":"The University of Texas at Dallas, Richardson, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,24]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22496-7_9"},{"key":"e_1_3_2_1_2_1","volume-title":"Low-memory Gemm-based Convolution Algorithms for Deep Neural Networks. arXiv Preprint 1709.03395","author":"Anderson Andrew","year":"2017","unstructured":"Andrew Anderson, Aravind Vasudevan, Cormac Keane, and David Gregg. 2017. Low-memory Gemm-based Convolution Algorithms for Deep Neural Networks. arXiv Preprint 1709.03395 (2017)."},{"key":"e_1_3_2_1_3_1","unstructured":"ARM. 2009. ARM Security Technology: Building a Secure System using TrustZone Technology. White paper PRD29-GENC-009492C. ARM."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCA.2007.904781"},{"key":"e_1_3_2_1_5_1","volume-title":"Proc. Machine Learning and Systems nymMLSys.","author":"Bonawitz Keith","year":"2019","unstructured":"Keith Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chlo\u00e9 Kiddon, Jakub Konevc n\u1ef3, Stefano Mazzocchi, Brendan McMahan, Timon Van Overveldt, David Petrou, Daniel Ramage, and Jason Roselander. 2019. Towards Federated Learning at Scale: System Design. In Proc. Machine Learning and Systems nymMLSys."},{"key":"e_1_3_2_1_6_1","volume-title":"IACR Cryptology ePrint Archive","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained. IACR Cryptology ePrint Archive , Vol. 2016, 086 (2016)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.522"},{"key":"e_1_3_2_1_9_1","volume-title":"The Indirect Convolution Algorithm. arXiv Preprint","author":"Dukhan Marat","year":"1907","unstructured":"Marat Dukhan. 2019. The Indirect Convolution Algorithm. arXiv Preprint 1907.02129 (2019)."},{"key":"e_1_3_2_1_10_1","volume-title":"Differential Privacy: Issues for Policymakers. White paper","author":"Feldman Vitaly","year":"2020","unstructured":"Vitaly Feldman, Konstantin Kakaes, Katrina Ligett, Kobbi Nissim, Aleksandra Slavkovic, and Adam Smith. 2020. Differential Privacy: Issues for Policymakers. White paper. Simons Institute Theory of Computing, University of California at Berkeley."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_12_1","volume-title":"Confidential Inference Via Ternary Model Partitioning. arXiv Preprint","author":"Gu Zhongshu","year":"1807","unstructured":"Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Hani Jamjoom, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy. 2018. Confidential Inference Via Ternary Model Partitioning. arXiv Preprint 1807.00969 (2018)."},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. cnum4th Int. Conf. Learning Representations nymICLR.","author":"Han Song","unstructured":"Song Han, Huizi Mao, and William J. Dally. 2016. Deep Compression: Compressing Deep Neural Networks with Pruning, Trained Quantization and Huffman Coding. In Proc. cnum4th Int. Conf. Learning Representations nymICLR."},{"key":"e_1_3_2_1_14_1","unstructured":"IBM X-Forcetextsuperscript\u00ae Research. 2017. The Weaponization of IoT Devices. www.ibm.com\/downloads\/cas\/6MLEALKV."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD49709.2020.00020"},{"key":"e_1_3_2_1_16_1","volume-title":"Secure real-time heterogeneous iot data management system. In 2019 first IEEE international conference on trust, privacy and security in intelligent systems and applications (TPS-ISA)","author":"Islam Md Shihabul","unstructured":"Md Shihabul Islam, Harsh Verma, Latifur Khan, and Murat Kantarcioglu. 2019. Secure real-time heterogeneous iot data management system. In 2019 first IEEE international conference on trust, privacy and security in intelligent systems and applications (TPS-ISA). IEEE, 228--235."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"e_1_3_2_1_18_1","volume-title":"Junghwan \u201cJohn","author":"Kim Kyungtae","year":"2020","unstructured":"Kyungtae Kim, Chung Hwan Kim, Junghwan \u201cJohn\u201d Rhee, Xiao Yu, Haifeng Chen, Dave Tian, and Byoungyoung Lee. 2020. Vessels: Efficient and Scalable Deep Learning Prediction on Trusted Processors. In Proc. cnum11th ACM Sym. Cloud Computing nymSoCC. 462--476."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411504.3421208"},{"key":"e_1_3_2_1_20_1","volume-title":"One Weird Trick for Parallelizing Convolutional Neural Networks. arXiv Preprint 1404.5997","author":"Krizhevsky Alex","year":"2014","unstructured":"Alex Krizhevsky. 2014. One Weird Trick for Parallelizing Convolutional Neural Networks. arXiv Preprint 1404.5997 (2014)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"e_1_3_2_1_24_1","unstructured":"Linaro. 2022a. OP-TEE Architecture. https:\/\/optee.readthedocs.io\/en\/latest\/architecture\/index.html."},{"key":"e_1_3_2_1_25_1","unstructured":"Linaro. 2022b. Open Portable Trusted Execution Environment. www.op-tee.org."},{"key":"e_1_3_2_1_26_1","volume-title":"Proc. cnum25th USENIX Security Sym. 549--564","author":"Lipp Moritz","year":"2016","unstructured":"Moritz Lipp, Daniel Gruss, Raphael Spreitzer, Cl\u00e9mentine Maurice, and Stefan Mangard. 2016. Armageddon: Cache Attacks on Mobile Devices. In Proc. cnum25th USENIX Security Sym. 549--564."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299155"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"e_1_3_2_1_29_1","volume-title":"Proc. cnum25th USENIX Security Sym. 619--636","author":"Ohrimenko Olga","year":"2016","unstructured":"Olga Ohrimenko, Felix Schuster, C\u00e9dric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious Multi-party Machine Learning on Trusted Processors. In Proc. cnum25th USENIX Security Sym. 619--636."},{"key":"e_1_3_2_1_30_1","volume-title":"Proc. USENIX Annual Technical Conf. nymATC. 537--554","author":"Park Heejin","year":"2019","unstructured":"Heejin Park, Shuang Zhai, Long Lu, and Felix Xiaozhu Lin. 2019. StreamBox-TZ: Secure Stream Analytics at the Edge with TrustZone. In Proc. USENIX Annual Technical Conf. nymATC. 537--554."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"key":"e_1_3_2_1_33_1","unstructured":"Qualcomm. 2020. We Are Making AI Ubiquitous. www.qualcomm.com\/news\/onq\/2020\/06\/we-are-making-ai-ubiquitous."},{"key":"e_1_3_2_1_34_1","unstructured":"Raspberry Pi. 2022. Raspberry Pi 3 Model B. https:\/\/www.raspberrypi.com\/products\/raspberry-pi-3-model-b\/."},{"key":"e_1_3_2_1_35_1","unstructured":"Joseph Redmon. 2013--2016. Darknet: Open Source Neural Networks in C. pjreddie.com\/darknet."},{"key":"e_1_3_2_1_36_1","unstructured":"Joseph Redmon. 2022. Tiny Darknet. pjreddie.com\/darknet\/tiny-darknet."},{"key":"e_1_3_2_1_37_1","volume-title":"YOLOv3: An Incremental Improvement. arXiv Preprint","author":"Redmon Joseph","year":"1804","unstructured":"Joseph Redmon and Ali Farhadi. 2018. YOLOv3: An Incremental Improvement. arXiv Preprint 1804.02767 (2018)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_39_1","volume-title":"Proc. cnum3rd Int. Conf. Learning Representations nymICLR.","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-scale Image Recognition. In Proc. cnum3rd Int. Conf. Learning Representations nymICLR."},{"key":"e_1_3_2_1_40_1","unstructured":"ST Microelectronics. 2022. Discovery Kit with STM32MP157C MPU. www.st.com\/en\/evaluation-tools\/stm32mp157c-dk2.html."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_1_43_1","unstructured":"TensorFlow. 2022. TensorFlow Lite. www.tensorflow.org\/lite."},{"key":"e_1_3_2_1_44_1","volume-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287","author":"Tramer Florian","year":"2018","unstructured":"Florian Tramer and Dan Boneh. 2018. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:1806.03287 (2018)."},{"key":"e_1_3_2_1_45_1","volume-title":"Walls","author":"VanNostrand Peter M.","year":"2019","unstructured":"Peter M. VanNostrand, Ioannis Kyriazis, Michelle Cheng, Tian Guo, and Robert J. Walls. 2019. Confidential Deep Learning: Executing Proprietary Models on Untrusted Devices. arXiv Preprint 1908.10730 (2019)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456455.1456460"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.521"},{"key":"e_1_3_2_1_48_1","volume-title":"Proceedings Fifth IEEE International Symposium on Object-Oriented Real-Time Distributed Computing. ISIRC","author":"Yen Ling","year":"2002","unstructured":"I-Ling Yen, Jayabharath Goluguri, Farokh Bastani, Latifur Khan, and John Linn. 2002. A component-based approach for embedded software development. In Proceedings Fifth IEEE International Symposium on Object-Oriented Real-Time Distributed Computing. ISIRC 2002. IEEE, 402--410."},{"key":"e_1_3_2_1_49_1","volume-title":"Mehmet Emre Gursoy, and Stacey Truex","author":"Yu Lei","year":"2019","unstructured":"Lei Yu, Ling Liu, Calton Pu, Mehmet Emre Gursoy, and Stacey Truex. 2019. Differentially Private Model Publishing for Deep Learning. In Proc. cnum40th IEEE Sym. Security & Privacy nymS&P. 332--349."},{"key":"e_1_3_2_1_50_1","volume-title":"TruSpy: Cache Side-channel Information Leakage From the Secure World on ARM Devices. IACR Cryptology ePrint Archive","author":"Zhang Ning","year":"2016","unstructured":"Ning Zhang, Kun Sun, Deborah Shands, Wenjing Lou, and Y. Thomas Hou. 2016. TruSpy: Cache Side-channel Information Leakage From the Secure World on ARM Devices. IACR Cryptology ePrint Archive , Vol. 2016 (2016)."},{"key":"e_1_3_2_1_51_1","volume-title":"Proc. cnum22nd Int. Sym. Recent Advances in Intrusion Detection nymRAID. 105--120","author":"Zhao Shijun","year":"2019","unstructured":"Shijun Zhao, Qianying Zhang, Yu Qin, Wei Feng, and Dengguo Feng. 2019a. Minimal Kernel: An Operating System Architecture for TEE to Resist Board Level Physical Attacks. In Proc. cnum22nd Int. Sym. Recent Advances in Intrusion Detection nymRAID. 105--120."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363205"},{"key":"e_1_3_2_1_53_1","volume-title":"Proc. cnum2nd USENIX Workshop Hot Topics in Edge Computing nymHotEdge. io","author":"Zhou Li","year":"2019","unstructured":"Li Zhou, Hao Wen, Radu Teodorescu, and David HC Du. 2019. Distributing Deep Neural Networks with Containerized Partitions at the Edge. In Proc. cnum2nd USENIX Workshop Hot Topics in Edge Computing nymHotEdge. io"}],"event":{"name":"CODASPY '23: Thirteenth ACM Conference on Data and Application Security and Privacy","location":"Charlotte NC USA","acronym":"CODASPY '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3577923.3583648","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3577923.3583648","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3577923.3583648","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3577923.3583648","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:08:41Z","timestamp":1750183721000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3577923.3583648"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,24]]},"references-count":52,"alternative-id":["10.1145\/3577923.3583648","10.1145\/3577923"],"URL":"https:\/\/doi.org\/10.1145\/3577923.3583648","relation":{},"subject":[],"published":{"date-parts":[[2023,4,24]]},"assertion":[{"value":"2023-04-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}