{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T13:38:39Z","timestamp":1769607519669,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":97,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072262"],"award-info":[{"award-number":["62072262"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627145","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"621-635","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Secure MLaaS with Temper: Trusted and Efficient Model Partitioning and Enclave Reuse"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5877-2693","authenticated-orcid":false,"given":"Fabing","family":"Li","sequence":"first","affiliation":[{"name":"Xi'an Jiaotong University, China and Institute for Interdisciplinary Information Core Technology, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8906-0832","authenticated-orcid":false,"given":"Xiang","family":"Li","sequence":"additional","affiliation":[{"name":"Tsinghua University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8433-7281","authenticated-orcid":false,"given":"Mingyu","family":"Gao","sequence":"additional","affiliation":[{"name":"Tsinghua University, China and Shanghai Artificial Intelligence Lab, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"d.]. Alibaba Cloud. https:\/\/ai.aliyun.com\/","year":"2021","unstructured":"[n. d.]. Alibaba Cloud. https:\/\/ai.aliyun.com\/. Accessed: August 2021."},{"key":"e_1_3_2_1_2_1","volume-title":"d.]. AMD Secure Encrypted Virtualization (SEV). https:\/\/developer.amd.com\/sev\/","year":"2021","unstructured":"[n. d.]. AMD Secure Encrypted Virtualization (SEV). https:\/\/developer.amd.com\/sev\/. Accessed: November 2021."},{"key":"e_1_3_2_1_3_1","volume-title":"d.]. Baidu AI cloud. https:\/\/intl.cloud.baidu.com\/","year":"2021","unstructured":"[n. d.]. Baidu AI cloud. https:\/\/intl.cloud.baidu.com\/. Accessed: August 2021."},{"key":"e_1_3_2_1_4_1","volume-title":"d.]. Deep Learning on AWS. https:\/\/aws.amazon.com\/deep-learning\/","year":"2021","unstructured":"[n. d.]. Deep Learning on AWS. https:\/\/aws.amazon.com\/deep-learning\/. Accessed: August 2021."},{"key":"e_1_3_2_1_5_1","volume-title":"Google Cloud. https:\/\/cloud.google.com\/deep-learning-vm\/. Accessed","year":"2021","unstructured":"[n. d.]. Deep Learning VM, Google Cloud. https:\/\/cloud.google.com\/deep-learning-vm\/. Accessed: August 2021."},{"key":"e_1_3_2_1_6_1","volume-title":"d.]. Intel\u00ae Trust Domain Extensions (Intel\u00ae TDX). https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-trust-domain-extensions.html","year":"2021","unstructured":"[n. d.]. Intel\u00ae Trust Domain Extensions (Intel\u00ae TDX). https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-trust-domain-extensions.html. Accessed: November 2021."},{"key":"e_1_3_2_1_7_1","volume-title":"Microsoft Azure. https:\/\/azure.microsoft.com\/en-us\/services\/machine-learning\/. Accessed","year":"2021","unstructured":"[n. d.]. Machine Learning Service, Microsoft Azure. https:\/\/azure.microsoft.com\/en-us\/services\/machine-learning\/. Accessed: August 2021."},{"key":"e_1_3_2_1_8_1","volume-title":"TensorFlow: A System for Large-Scale Machine Learning. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 265\u2013283","author":"Abadi Mart\u00edn","year":"2016","unstructured":"Mart\u00edn Abadi, Paul Barham, Jianmin Chen, Zhifeng Chen, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Geoffrey Irving, Michael Isard, Manjunath Kudlur, Josh Levenberg, Rajat Monga, Sherry Moore, Derek\u00a0G. Murray, Benoit Steiner, Paul Tucker, Vijay Vasudevan, Pete Warden, Martin Wicke, Yuan Yu, and Xiaoqiang Zheng. 2016. TensorFlow: A System for Large-Scale Machine Learning. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 265\u2013283."},{"key":"e_1_3_2_1_9_1","unstructured":"ARM. 2009. ARM Security Technology Building a Secure System using TrustZone Technology. https:\/\/developer.arm.com\/documentation\/genc009492\/c."},{"key":"e_1_3_2_1_10_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 689\u2013703","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O\u2019Keeffe, Mark\u00a0L. Stillwell, David Goltzsche, Dave Eyers, R\u00fcdiger Kapitza, Peter Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 689\u2013703."},{"key":"e_1_3_2_1_11_1","volume-title":"Xiao Nan, Khin Mi\u00a0Mi Aung, and Vijay\u00a0Ramaseshan Chandrasekhar.","author":"Badawi Ahmad\u00a0Al","year":"2018","unstructured":"Ahmad\u00a0Al Badawi, Jin Chao, Jie Lin, Chan\u00a0Fook Mun, Sim\u00a0Jun Jie, Benjamin Hong\u00a0Meng Tan, Xiao Nan, Khin Mi\u00a0Mi Aung, and Vijay\u00a0Ramaseshan Chandrasekhar. 2018. Towards the AlexNet Moment for Homomorphic Encryption: HCNN, the First Homomorphic CNN on Encrypted Data with GPUs. arXiv preprint arXiv:1811.00778 (2018)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3364684"},{"key":"e_1_3_2_1_13_1","unstructured":"Peva Blanchard El\u00a0Mahdi El\u00a0Mhamdi Rachid Guerraoui and Julien Stainer. 2017. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Advances in Neural Information Processing Systems (NeurIPS). 118\u2013128."},{"key":"e_1_3_2_1_14_1","volume-title":"Language Models are Few-Shot Learners. arXiv preprint arXiv:2005.14165","author":"Brown B","year":"2020","unstructured":"Tom\u00a0B Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-Voss, Gretchen Krueger, Tom Henighan, Rewon Child, Aditya Ramesh, Daniel\u00a0M Ziegler, Jeffrey Wu, Clemens Winter, Christopher Hesse, Mark Chen, Eric Sigler, Mateusz Litwin, Scott Gray, Benjamin Chess, Jack Clark, Christopher Berner, Sam McCandlish, Alec Radford, Ilya Sutskever, and Dario Amodei. 2020. Language Models are Few-Shot Learners. arXiv preprint arXiv:2005.14165 (2020)."},{"key":"e_1_3_2_1_15_1","volume-title":"Low Latency Privacy Preserving Inference. In 36th International Conference on Machine Learning (ICML). 812\u2013821","author":"Brutzkus Alon","year":"2019","unstructured":"Alon Brutzkus, Ran Gilad-Bachrach, and Oren Elisha. 2019. Low Latency Privacy Preserving Inference. In 36th International Conference on Machine Learning (ICML). 812\u2013821."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00020"},{"key":"e_1_3_2_1_17_1","volume-title":"MXNet: A Flexible and Efficient Machine Learning Library for Heterogeneous Distributed Systems. arXiv preprint arXiv:1512.01274","author":"Chen Tianqi","year":"2015","unstructured":"Tianqi Chen, Mu Li, Yutian Li, Min Lin, Naiyan Wang, Minjie Wang, Tianjun Xiao, Bing Xu, Chiyuan Zhang, and Zheng Zhang. 2015. MXNet: A Flexible and Efficient Machine Learning Library for Heterogeneous Distributed Systems. arXiv preprint arXiv:1512.01274 (2015)."},{"key":"e_1_3_2_1_18_1","volume-title":"TVM: An Automated End-to-End Optimizing Compiler for Deep Learning. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 578\u2013594","author":"Chen Tianqi","year":"2018","unstructured":"Tianqi Chen, Thierry Moreau, Ziheng Jiang, Lianmin Zheng, Eddie Yan, Haichen Shen, Meghan Cowan, Leyuan Wang, Yuwei Hu, Luis Ceze, Carlos Guestrin, and Arvind Krishnamurthy. 2018. TVM: An Automated End-to-End Optimizing Compiler for Deep Learning. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 578\u2013594."},{"key":"e_1_3_2_1_19_1","volume-title":"SentiNet: Detecting Localized Universal Attacks Against Deep Learning Systems. In 2020 IEEE Security and Privacy Workshops (SPW). IEEE, 48\u201354","author":"Chou Edward","year":"2020","unstructured":"Edward Chou, Florian Tramer, and Giancarlo Pellegrino. 2020. SentiNet: Detecting Localized Universal Attacks Against Deep Learning Systems. In 2020 IEEE Security and Privacy Workshops (SPW). IEEE, 48\u201354."},{"key":"e_1_3_2_1_20_1","first-page":"1","article-title":"Intel SGX Explained","volume":"2016","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained. IACR Cryptology ePrint Archive 2016, 086 (2016), 1\u2013118.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_2_1_21_1","volume-title":"Sanctum: Minimal Hardware Extensions for Strong Software Isolation. In 25th USENIX Security Symposium (USENIX Security). 857\u2013874","author":"Costan Victor","year":"2016","unstructured":"Victor Costan, Ilia Lebedev, and Srinivas Devadas. 2016. Sanctum: Minimal Hardware Extensions for Strong Software Isolation. In 25th USENIX Security Symposium (USENIX Security). 857\u2013874."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541941"},{"key":"e_1_3_2_1_23_1","volume-title":"ImageNet: A Large-Scale Hierarchical Image Database. In 2009 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 248\u2013255","author":"Deng Jia","year":"2009","unstructured":"Jia Deng, Wei Dong, Richard Socher, Li\u00a0Jia Li, and Fei\u00a0Fei Li. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In 2009 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 248\u2013255."},{"key":"e_1_3_2_1_24_1","volume-title":"33rd International Conference on Machine Learning (ICML). 201\u2013210","author":"Dowlin Nathan","year":"2016","unstructured":"Nathan Dowlin, Ran Gilad-Bachrach, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy. In 33rd International Conference on Machine Learning (ICML). 201\u2013210."},{"key":"e_1_3_2_1_25_1","volume-title":"29th USENIX Security Symposium (USENIX Security). 1605\u20131622","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local Model Poisoning Attacks to Byzantine-Robust Federated Learning. In 29th USENIX Security Symposium (USENIX Security). 1605\u20131622."},{"key":"e_1_3_2_1_26_1","volume-title":"Scalable Memory Protection in the PENGLAI Enclave. In 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 275\u2013294","author":"Feng Erhu","year":"2021","unstructured":"Erhu Feng, Xu Lu, Dong Du, Bicheng Yang, Xueqiang Jiang, Yubin Xia, Binyu Zang, and Haibo Chen. 2021. Scalable Memory Protection in the PENGLAI Enclave. In 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 275\u2013294."},{"key":"e_1_3_2_1_27_1","volume-title":"d.]. Fortanix Enclave Development Platform - Rust EDP. https:\/\/edp.fortanix.com\/","year":"2021","unstructured":"Fortanix. [n. d.]. Fortanix Enclave Development Platform - Rust EDP. https:\/\/edp.fortanix.com\/. Accessed: January 2021."},{"key":"e_1_3_2_1_28_1","volume-title":"Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures. In 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS). 1322\u20131333","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures. In 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS). 1322\u20131333."},{"key":"e_1_3_2_1_29_1","volume-title":"Electromagnetic Analysis: Concrete Results. In Cryptographic Hardware and Embedded Systems (CHES)","author":"Gandolfi Karine","year":"2001","unstructured":"Karine Gandolfi, Christophe Mourtel, and Francis Olivier. 2001. Electromagnetic Analysis: Concrete Results. In Cryptographic Hardware and Embedded Systems (CHES). Springer, 251\u2013261."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-015-9224-2"},{"key":"e_1_3_2_1_31_1","volume-title":"Fully Homomorphic Encryption Using Ideal Lattices. In 41st Annual ACM Symposium on Theory of Computing (STOC). 169\u2013178","author":"Gentry Craig","year":"2009","unstructured":"Craig Gentry. 2009. Fully Homomorphic Encryption Using Ideal Lattices. In 41st Annual ACM Symposium on Theory of Computing (STOC). 169\u2013178."},{"key":"e_1_3_2_1_32_1","volume-title":"PRIVADO: Practical and Secure DNN Inference with Enclaves. arXiv preprint arXiv:1810.00602","author":"Grover Karan","year":"2019","unstructured":"Karan Grover, Shruti Tople, Shweta Shinde, Ranjita Bhagwan, and Ramachandran Ramjee. 2019. PRIVADO: Practical and Secure DNN Inference with Enclaves. arXiv preprint arXiv:1810.00602 (2019)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2010.23"},{"key":"e_1_3_2_1_34_1","volume-title":"MLCapsule: Guarded Offline Deployment of Machine Learning as a Service. arXiv preprint arXiv:1808.00590","author":"Hanzlik Lucjan","year":"2018","unstructured":"Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Max Augustin, Michael Backes, and Mario Fritz. 2018. MLCapsule: Guarded Offline Deployment of Machine Learning as a Service. arXiv preprint arXiv:1808.00590 (2018)."},{"key":"e_1_3_2_1_35_1","volume-title":"DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted Hardware. In 54th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 212\u2013224","author":"Hashemi Hanieh","year":"2021","unstructured":"Hanieh Hashemi, Yongqin Wang, and Murali Annavaram. 2021. DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted Hardware. In 54th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 212\u2013224."},{"key":"e_1_3_2_1_36_1","volume-title":"Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770\u2013778","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770\u2013778."},{"key":"e_1_3_2_1_37_1","volume-title":"Mesos: A Platform for Fine-Grained Resource Sharing in the Data Center. In 8th USENIX Symposium on Networked Systems Design and Implementation (NSDI). 295\u2013308","author":"Hindman Benjamin","year":"2011","unstructured":"Benjamin Hindman, Andy Konwinski, Matei Zaharia, Ali Ghodsi, Anthony\u00a0D. Joseph, Randy Katz, Scott Shenker, and Ion Stoica. 2011. Mesos: A Platform for Fine-Grained Resource Sharing in the Data Center. In 8th USENIX Symposium on Networked Systems Design and Implementation (NSDI). 295\u2013308."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488370"},{"key":"e_1_3_2_1_39_1","volume-title":"MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications. arXiv preprint arXiv:1704.04861","author":"Howard G","year":"2017","unstructured":"Andrew\u00a0G Howard, Menglong Zhu, Bo Chen, Dmitry Kalenichenko, Weijun Wang, Tobias Weyand, Marco Andreetto, and Hartwig Adam. 2017. MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications. arXiv preprint arXiv:1704.04861 (2017)."},{"key":"e_1_3_2_1_40_1","volume-title":"Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 4700\u20134708","author":"Huang Gao","year":"2017","unstructured":"Gao Huang, Zhuang Liu, Laurens Van Der\u00a0Maaten, and Kilian\u00a0Q Weinberger. 2017. Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 4700\u20134708."},{"key":"e_1_3_2_1_41_1","unstructured":"Yanping Huang Youlong Cheng Ankur Bapna Orhan Firat Dehao Chen Mia\u00a0Xu Chen HyoukJoong Lee Jiquan Ngiam Quoc\u00a0V Le Yonghui Wu 2019. GPipe: Efficient Training of Giant Neural Networks using Pipeline Parallelism.. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_42_1","volume-title":"Telekine: Secure Computing with Cloud GPUs. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI). 817\u2013833","author":"Hunt Tyler","year":"2020","unstructured":"Tyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely, Yige Hu, Christopher\u00a0J Rossbach, and Emmett Witchel. 2020. Telekine: Secure Computing with Cloud GPUs. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI). 817\u2013833."},{"key":"e_1_3_2_1_43_1","volume-title":"Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961","author":"Hunt Tyler","year":"2018","unstructured":"Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961 (2018)."},{"key":"e_1_3_2_1_44_1","volume-title":"Efficient Deep Learning on Multi-Source Private Data. arXiv preprint arXiv:1807.06689","author":"Hynes Nick","year":"2018","unstructured":"Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient Deep Learning on Multi-Source Private Data. arXiv preprint arXiv:1807.06689 (2018)."},{"key":"e_1_3_2_1_45_1","unstructured":"Intel. 2018. Intel Software Guard Extensions (Intel SGX) Developer Guide. https:\/\/software.intel.com\/content\/www\/us\/en\/develop\/download\/intel-software-guard-extensions-intel-sgx-developer-guide.html."},{"key":"e_1_3_2_1_46_1","volume-title":"Heterogeneous Isolated Execution for Commodity GPUs. In 24th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS). 455\u2013468","author":"Jang Insu","year":"2019","unstructured":"Insu Jang, Adrian Tang, Taehoon Kim, Simha Sethumadhavan, and Jaehyuk Huh. 2019. Heterogeneous Isolated Execution for Commodity GPUs. In 24th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS). 455\u2013468."},{"key":"e_1_3_2_1_47_1","volume-title":"Proceedings of the 2nd Conference on Systems and Machine Learning (MLSys).","author":"Jia Zhihao","year":"2019","unstructured":"Zhihao Jia, Matei Zaharia, and Alex Aiken. 2019. Beyond Data and Model Parallelism for Deep Neural Networks. In Proceedings of the 2nd Conference on Systems and Machine Learning (MLSys)."},{"key":"e_1_3_2_1_48_1","volume-title":"2019 IEEE European Symposium on Security and Privacy (EuroS&P). 512\u2013527","author":"Juuti Mika","unstructured":"Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan. 2019. PRADA: Protecting against DNN Model Stealing Attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P). 512\u2013527."},{"key":"e_1_3_2_1_49_1","volume-title":"GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In 27th USENIX Security Symposium (USENIX Security). 1651\u20131669","author":"Juvekar Chiraag","year":"2018","unstructured":"Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018. GAZELLE: A Low Latency Framework for Secure Neural Network Inference. In 27th USENIX Security Symposium (USENIX Security). 1651\u20131669."},{"key":"e_1_3_2_1_50_1","volume-title":"AMD Memory Encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD Memory Encryption. White paper (2016), 13."},{"key":"e_1_3_2_1_51_1","unstructured":"David Kaplan Jeremy Powell and Tom Woller. 2020. AMD SEV-SNP: Strengthening VM Isolationwith Integrity Protection and More. Technical Report. AMD Inc."},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the ACM Symposium on Cloud Computing (SoCC). 462\u2013476","author":"Kim Kyungtae","unstructured":"Kyungtae Kim, Chung\u00a0Hwan Kim, Junghwan\u00a0\u201cJohn\u201d Rhee, Xiao Yu, Haifeng Chen, Dave Tian, and Byoungyoung Lee. 2020. Vessels: Efficient and Scalable Deep Learning Prediction on Trusted Processors. In Proceedings of the ACM Symposium on Cloud Computing (SoCC). 462\u2013476."},{"key":"e_1_3_2_1_53_1","volume-title":"TensorSCONE: A Secure TensorFlow Framework using Intel SGX. arXiv preprint arXiv:1902.04413","author":"Kunkel Roland","year":"2019","unstructured":"Roland Kunkel, Do\u00a0Le Quoc, Franz Gregor, Sergei Arnautov, Pramod Bhatotia, and Christof Fetzer. 2019. TensorSCONE: A Secure TensorFlow Framework using Intel SGX. arXiv preprint arXiv:1902.04413 (2019)."},{"key":"e_1_3_2_1_54_1","volume-title":"Deep Learning. Nature 521, 7553","author":"LeCun Yann","year":"2015","unstructured":"Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015. Deep Learning. Nature 521, 7553 (2015), 436\u2013444."},{"key":"e_1_3_2_1_55_1","volume-title":"Privacy-Preserving Machine Learning in Untrusted Clouds Made Simple. arXiv preprint arXiv:2009.04390","author":"Lee Dayeol","year":"2020","unstructured":"Dayeol Lee, Dmitrii Kuvaiskii, Anjo Vahldiek-Oberwagner, and Mona Vij. 2020. Privacy-Preserving Machine Learning in Untrusted Clouds Made Simple. arXiv preprint arXiv:2009.04390 (2020)."},{"key":"e_1_3_2_1_56_1","volume-title":"Secure Encrypted Virtualization. In 28th USENIX Security Symposium (USENIX Security). 1257\u20131272","author":"Li Mengyuan","year":"2019","unstructured":"Mengyuan Li, Yinqian Zhang, Zhiqiang Lin, and Yan Solihin. 2019. Exploiting Unprotected I\/O Operations in AMD\u2019s Secure Encrypted Virtualization. In 28th USENIX Security Symposium (USENIX Security). 1257\u20131272."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486988"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2020.3018403"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"e_1_3_2_1_60_1","volume-title":"Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. In International Symposium on Research in Attacks, Intrusions, and Defenses. Springer, 273\u2013294","author":"Liu Kang","year":"2018","unstructured":"Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. In International Symposium on Research in Attacks, Intrusions, and Defenses. Springer, 273\u2013294."},{"key":"e_1_3_2_1_61_1","volume-title":"S3ML: A Secure Serving System for Machine Learning Inference. arXiv preprint arXiv:2010.06212 (October","author":"Ma Junming","year":"2020","unstructured":"Junming Ma, Chaofan Yu, Aihui Zhou, Bingzhe Wu, Xibin Wu, Xingyu Chen, Xiangqun Chen, Lei Wang, and Donggang Cao. 2020. S3ML: A Secure Serving System for Machine Learning Inference. arXiv preprint arXiv:2010.06212 (October 2020)."},{"key":"e_1_3_2_1_62_1","volume-title":"Thermal Covert Channels on Multi-Core Platforms. In 24th USENIX Security Symposium (USENIX Security). 865\u2013880","author":"Masti Ramya\u00a0Jayaram","year":"2015","unstructured":"Ramya\u00a0Jayaram Masti, Devendra Rai, Aanjhan Ranganathan, Christian M\u00fcller, Lothar Thiele, and Srdjan Capkun. 2015. Thermal Covert Channels on Multi-Core Platforms. In 24th USENIX Security Symposium (USENIX Security). 865\u2013880."},{"key":"e_1_3_2_1_63_1","volume-title":"Innovative Instructions and Software Model for Isolated Execution. In 2nd International Workshop on Hardware and Architectural Support for Security and Privacy (HASP).","author":"McKeen Frank","year":"2013","unstructured":"Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos\u00a0V Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday\u00a0R Savagaonkar. 2013. Innovative Instructions and Software Model for Isolated Execution. In 2nd International Workshop on Hardware and Architectural Support for Security and Privacy (HASP)."},{"key":"e_1_3_2_1_64_1","volume-title":"Delphi: A Cryptographic Inference Service for Neural Networks. In 29th USENIX Security Symposium (USENIX Security). 2505\u20132522","author":"Mishra Pratyush","year":"2020","unstructured":"Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca\u00a0Ada Popa. 2020. Delphi: A Cryptographic Inference Service for Neural Networks. In 29th USENIX Security Symposium (USENIX Security). 2505\u20132522."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300022"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3193111.3193112"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359646"},{"key":"e_1_3_2_1_68_1","volume-title":"GForce: GPU-Friendly Oblivious and Rapid Neural Network Inference. In 30th USENIX Security Symposium (USENIX Security). 2147\u20132164","author":"Ng KL","year":"2021","unstructured":"Lucien\u00a0KL Ng and Sherman\u00a0SM Chow. 2021. GForce: GPU-Friendly Oblivious and Rapid Neural Network Inference. In 30th USENIX Security Symposium (USENIX Security). 2147\u20132164."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i17.17746"},{"key":"e_1_3_2_1_70_1","volume-title":"d.]. Open Neural Network Exchange (ONNX). https:\/\/onnx.ai\/","author":"ONNX","year":"2021","unstructured":"ONNX team. [n. d.]. Open Neural Network Exchange (ONNX). https:\/\/onnx.ai\/. Accessed: January 2021."},{"key":"e_1_3_2_1_71_1","volume-title":"PyTorch: An Imperative Style","author":"Paszke Adam","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. 2019. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems (NeurIPS). 8026\u20138037."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"e_1_3_2_1_73_1","volume-title":"d.]. Rust Programming Language. https:\/\/www.rust-lang.org\/","author":"Rust","year":"2021","unstructured":"Rust team. [n. d.]. Rust Programming Language. https:\/\/www.rust-lang.org\/. Accessed: January 2021."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991125"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897885"},{"key":"e_1_3_2_1_77_1","volume-title":"Megatron-LM: Training Multi-Billion Parameter Language Models Using Model Parallelism. arXiv preprint arXiv:1909.08053","author":"Shoeybi Mohammad","year":"2019","unstructured":"Mohammad Shoeybi, Mostofa Patwary, Raul Puri, Patrick LeGresley, Jared Casper, and Bryan Catanzaro. 2019. Megatron-LM: Training Multi-Billion Parameter Language Models Using Model Parallelism. arXiv preprint arXiv:1909.08053 (2019)."},{"key":"e_1_3_2_1_78_1","volume-title":"Membership Inference Attacks Against Machine Learning Models. In 2017 IEEE Symposium on Security and Privacy (S&P). IEEE, 3\u201318","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership Inference Attacks Against Machine Learning Models. In 2017 IEEE Symposium on Security and Privacy (S&P). IEEE, 3\u201318."},{"key":"e_1_3_2_1_79_1","volume-title":"Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv preprint arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3478684.3479257"},{"key":"e_1_3_2_1_81_1","volume-title":"Rethinking the Inception Architecture for Computer Vision. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 2818\u20132826","author":"Szegedy Christian","year":"2016","unstructured":"Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016. Rethinking the Inception Architecture for Computer Vision. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 2818\u20132826."},{"key":"e_1_3_2_1_82_1","volume-title":"Automatic Graph Partitioning for Very Large-scale Deep Learning. arXiv preprint arXiv:2103.16063","author":"Tanaka Masahiro","year":"2021","unstructured":"Masahiro Tanaka, Kenjiro Taura, Toshihiro Hanawa, and Kentaro Torisawa. 2021. Automatic Graph Partitioning for Very Large-scale Deep Learning. arXiv preprint arXiv:2103.16063 (2021)."},{"key":"e_1_3_2_1_83_1","unstructured":"Jakub\u00a0M Tarnawski Amar Phanishayee Nikhil Devanur Divya Mahajan and Fanny Nina\u00a0Paravecino. 2020. Efficient Algorithms for Device Placement of DNN Graph Operators. In Advances in Neural Information Processing Systems (NeurIPS). 15451\u201315463."},{"key":"e_1_3_2_1_84_1","volume-title":"XLA: Optimizing Compiler for Machine Learning. https:\/\/www.tensorflow.org\/xla.","year":"2020","unstructured":"TensorFlow. 2020. XLA: Optimizing Compiler for Machine Learning. https:\/\/www.tensorflow.org\/xla."},{"key":"e_1_3_2_1_85_1","volume-title":"Verifiable and Private Execution of Neural Networks in Trusted Hardware. In 7th International Conference on Learning Representations (ICLR).","author":"Tramer Florian","year":"2019","unstructured":"Florian Tramer and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In 7th International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_86_1","volume-title":"25th USENIX Security Symposium (USENIX Security). 601\u2013618","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael\u00a0K. Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In 25th USENIX Security Symposium (USENIX Security). 601\u2013618."},{"key":"e_1_3_2_1_87_1","volume-title":"Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (ATC). 645\u2013658","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai, Donald\u00a0E Porter, and Mona Vij. 2017. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (ATC). 645\u2013658."},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/2741948.2741964"},{"key":"e_1_3_2_1_89_1","volume-title":"Graviton: Trusted Execution Environments on GPUs. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 681\u2013696","author":"Volos Stavros","year":"2018","unstructured":"Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted Execution Environments on GPUs. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 681\u2013696."},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303953"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274808.3274824"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080208"},{"key":"e_1_3_2_1_93_1","volume-title":"Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems. In 2015 IEEE Symposium on Security and Privacy (S&P). 640\u2013656","author":"Xu Yuanzhong","year":"2015","unstructured":"Yuanzhong Xu, Weidong Cui, and Marcus Peinado. 2015. Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems. In 2015 IEEE Symposium on Security and Privacy (S&P). 640\u2013656."},{"key":"e_1_3_2_1_94_1","volume-title":"Protocols for Secure Computations. In 23rd Annual Symposium on Foundations of Computer Science (SFCS). 160\u2013164","author":"Yao C","year":"1982","unstructured":"Andrew\u00a0C Yao. 1982. Protocols for Secure Computations. In 23rd Annual Symposium on Foundations of Computer Science (SFCS). 160\u2013164."},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486998"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507733"},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00049"}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC '23"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627145","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627145","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:40:43Z","timestamp":1755884443000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627145"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":97,"alternative-id":["10.1145\/3627106.3627145","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627145","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}