{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T06:07:05Z","timestamp":1781762825354,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":88,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,22]],"date-time":"2024-04-22T00:00:00Z","timestamp":1713744000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,22]]},"DOI":"10.1145\/3627703.3650082","type":"proceedings-article","created":{"date-parts":[[2024,4,18]],"date-time":"2024-04-18T06:28:28Z","timestamp":1713421708000},"page":"219-235","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["DeTA: Minimizing Data Leaks in Federated Learning via Decentralized and Trustworthy Aggregation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-8234-2260","authenticated-orcid":false,"given":"Pau-Chen","family":"Cheng","sequence":"first","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7040-1657","authenticated-orcid":false,"given":"Kevin","family":"Eykholt","sequence":"additional","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9624-2669","authenticated-orcid":false,"given":"Zhongshu","family":"Gu","sequence":"additional","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6143-1064","authenticated-orcid":false,"given":"Hani","family":"Jamjoom","sequence":"additional","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5382-276X","authenticated-orcid":false,"given":"K. R.","family":"Jayaram","sequence":"additional","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4674-3384","authenticated-orcid":false,"given":"Enriquillo","family":"Valdez","sequence":"additional","affiliation":[{"name":"IBM Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5222-1702","authenticated-orcid":false,"given":"Ashish","family":"Verma","sequence":"additional","affiliation":[{"name":"Amazon Inc., New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security 13, 5 (2017), 1333--1345.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_2_1_2_1","volume-title":"International conference on artificial intelligence and statistics. PMLR, 2938--2948","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International conference on artificial intelligence and statistics. PMLR, 2938--2948."},{"key":"e_1_3_2_1_3_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 473--481","author":"Bellet Aur\u00e9lien","year":"2018","unstructured":"Aur\u00e9lien Bellet, Rachid Guerraoui, Mahsa Taziki, and Marc Tommasi. 2018. Personalized and private peer-to-peer machine learning. In International Conference on Artificial Intelligence and Statistics. PMLR, 473--481."},{"key":"e_1_3_2_1_4_1","volume-title":"International Conference on Machine Learning. PMLR, 634--643","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In International Conference on Machine Learning. PMLR, 634--643."},{"key":"e_1_3_2_1_5_1","volume-title":"Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984","author":"Bhowmick Abhishek","year":"2018","unstructured":"Abhishek Bhowmick, John Duchi, Julien Freudiger, Gaurav Kapoor, and Ryan Rogers. 2018. Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984 (2018)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132769"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems. 118--128","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In Proceedings of the 31st International Conference on Neural Information Processing Systems. 118--128."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00020"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354216"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_2_1_12_1","volume-title":"Intel TDX Demystified: A Top-Down Approach. arXiv preprint arXiv:2303.15540","author":"Cheng Pau-Chen","year":"2023","unstructured":"Pau-Chen Cheng, Wojciech Ozga, Enriquillo Valdez, Salman Ahmed, Zhongshu Gu, Hani Jamjoom, Hubertus Franke, and James Bottomley. 2023. Intel TDX Demystified: A Top-Down Approach. arXiv preprint arXiv:2303.15540 (2023)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387552"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626827"},{"key":"e_1_3_2_1_15_1","unstructured":"Apple Differential Privacy Team. 2017. Learning with Privacy at Scale. (2017). https:\/\/docs-assets.developer.apple.com\/ml-research\/papers\/learning-with-privacy-at-scale.pdf"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433638"},{"key":"e_1_3_2_1_17_1","unstructured":"fedml 2024. Federated learning for Cross-Silo. https:\/\/www.fedml.ai\/federate\/octopus\/index."},{"key":"e_1_3_2_1_18_1","unstructured":"Tobin Feldman-Fitzthum. 2020. sev: add sev-inject-launch-secret. https:\/\/lists.gnu.org\/archive\/html\/qemu-devel\/2020-10\/msg04361.html."},{"key":"e_1_3_2_1_19_1","unstructured":"flower 2024. Flower A Friendly Federated Learning Framework. https:\/\/flower.ai\/."},{"key":"e_1_3_2_1_20_1","volume-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models. arXiv preprint arXiv:2110.13057","author":"Fowl Liam","year":"2021","unstructured":"Liam Fowl, Jonas Geiping, Wojtek Czaja, Micah Goldblum, and Tom Goldstein. 2021. Robbing the fed: Directly obtaining private data in federated learning with modified models. arXiv preprint arXiv:2110.13057 (2021)."},{"key":"e_1_3_2_1_21_1","volume-title":"Chris JM Yoon, and Ivan Beschastnikh","author":"Fung Clement","year":"2018","unstructured":"Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2018. Mitigating sybils in federated learning poisoning. arXiv preprint arXiv:1808.04866 (2018)."},{"key":"e_1_3_2_1_22_1","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning","volume":"33","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning? Advances in Neural Information Processing Systems 33 (2020), 16937--16947.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_23_1","volume-title":"Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557","author":"Geyer Robin C","year":"2017","unstructured":"Robin C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017)."},{"key":"e_1_3_2_1_24_1","unstructured":"gRPC 2021. A high performance open source universal RPC framework. https:\/\/grpc.io\/."},{"key":"e_1_3_2_1_25_1","volume-title":"Confidential Inference via Ternary Model Partitioning. arXiv preprint arXiv:1807.00969","author":"Gu Zhongshu","year":"2018","unstructured":"Zhongshu Gu, Heqing Huang, Jialong Zhang, Dong Su, Hani Jamjoom, Ankita Lamba, Dimitrios Pendarakis, and Ian Molloy. 2018. Confidential Inference via Ternary Model Partitioning. arXiv preprint arXiv:1807.00969 (2018)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00044"},{"key":"e_1_3_2_1_27_1","volume-title":"Memfhe: End-to-end computing with fully homomorphic encryption in memory. ACM Transactions on Embedded Computing Systems","author":"Gupta Saransh","year":"2022","unstructured":"Saransh Gupta, Rosario Cammarota, and Tajana \u0160imuni\u0107 Rosing. 2022. Memfhe: End-to-end computing with fully homomorphic encryption in memory. ACM Transactions on Embedded Computing Systems (2022)."},{"key":"e_1_3_2_1_28_1","volume-title":"Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604","author":"Hard Andrew","year":"2018","unstructured":"Andrew Hard, Kanishka Rao, Rajiv Mathews, Swaroop Ramaswamy, Fran\u00e7oise Beaufays, Sean Augenstein, Hubert Eichner, Chlo\u00e9 Kiddon, and Daniel Ramage. 2018. Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604 (2018)."},{"key":"e_1_3_2_1_29_1","volume-title":"Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. arXiv preprint arXiv:1711.10677","author":"Hardy Stephen","year":"2017","unstructured":"Stephen Hardy, Wilko Henecka, Hamish Ivey-Law, Richard Nock, Giorgio Patrini, Guillaume Smith, and Brian Thorne. 2017. Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. arXiv preprint arXiv:1711.10677 (2017)."},{"key":"e_1_3_2_1_30_1","volume-title":"Evaluation of Deep Convolutional Nets for Document Image Classification and Retrieval. In International Conference on Document Analysis and Recognition. IEEE, 991--995","author":"Harley Adam W","year":"2015","unstructured":"Adam W Harley, Alex Ufkes, and Konstantinos G Derpanis. 2015. Evaluation of Deep Convolutional Nets for Document Image Classification and Retrieval. In International Conference on Document Analysis and Recognition. IEEE, 991--995."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456243"},{"key":"e_1_3_2_1_32_1","volume-title":"Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961","author":"Hunt Tyler","year":"2018","unstructured":"Tyler Hunt, Congzheng Song, Reza Shokri, Vitaly Shmatikov, and Emmett Witchel. 2018. Chiron: Privacy-preserving Machine Learning as a Service. arXiv preprint arXiv:1803.05961 (2018)."},{"key":"e_1_3_2_1_33_1","volume-title":"Efficient Deep Learning on Multi-Source Private Data. arXiv preprint arXiv:1807.06689","author":"Hynes Nick","year":"2018","unstructured":"Nick Hynes, Raymond Cheng, and Dawn Song. 2018. Efficient Deep Learning on Multi-Source Private Data. arXiv preprint arXiv:1807.06689 (2018)."},{"key":"e_1_3_2_1_34_1","unstructured":"IBM. 2022. Introducing IBM Secure Execution for Linux 1.3.0. https:\/\/www.ibm.com\/docs\/en\/linuxonibm\/pdf\/l130se03.pdf. (2022)."},{"key":"e_1_3_2_1_35_1","unstructured":"Intel. 2021. Intel\u00ae Trust Domain Extensions. https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/690419. (2021)."},{"key":"e_1_3_2_1_36_1","volume-title":"Federated Gradient Descent. In 2020 IEEE 13th International Conference on Cloud Computing (CLOUD). IEEE, 201--210","author":"Jayaram K. R.","year":"2020","unstructured":"K. R. Jayaram, Archit Verma, Ashish Verma, Gegi Thomas, and Colin Sutcher-Shepard. 2020. MYSTIKO: Cloud-Mediated, Private, Federated Gradient Descent. In 2020 IEEE 13th International Conference on Cloud Computing (CLOUD). IEEE, 201--210."},{"key":"e_1_3_2_1_37_1","unstructured":"Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji K. A. Bonawitz Zachary Charles Graham Cormode Rachel Cummings Rafael G.L. D'Oliveira Salim El Rouayheb David Evans Josh Gardner Zachary Garrett Adri\u00e0 Gasc\u00f3n Badih Ghazi Phillip B. Gibbons Marco Gruteser Zaid Harchaoui Chaoyang He Lie He Zhouyuan Huo Ben Hutchinson Justin Hsu Martin Jaggi Tara Javidi Gauri Joshi Mikhail Khodak Jakub Kone\u010dn\u00fd Aleksandra Korolova Farinaz Koushanfar Sanmi Koyejo Tancr\u00e8de Lepoint Yang Liu Prateek Mittal Mehryar Mohri Richard Nock Ayfer \u00d6zg\u00fcr Rasmus Pagh Mariana Raykova Hang Qi Daniel Ramage Ramesh Raskar Dawn Song Weikang Song Sebastian U. Stich Ziteng Sun Ananda Theertha Suresh Florian Tram\u00e8r Praneeth Vepakomma Jianyu Wang Li Xiong Zheng Xu Qiang Yang Felix X. Yu Han Yu and Sen Zhao. 2019. Advances and Open Problems in Federated Learning. https:\/\/arxiv.org\/abs\/1912.04977"},{"key":"e_1_3_2_1_38_1","volume-title":"Protecting vm register state with sev-es. White paper","author":"Kaplan David","year":"2017","unstructured":"David Kaplan. 2017. Protecting vm register state with sev-es. White paper (2017)."},{"key":"e_1_3_2_1_39_1","volume-title":"AMD memory encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD memory encryption. White paper (2016)."},{"key":"e_1_3_2_1_40_1","unstructured":"Kata Containers 2021. The speed of containers the security of VMs. https:\/\/katacontainers.io."},{"key":"e_1_3_2_1_41_1","volume-title":"International Conference on Machine Learning. PMLR, 3478--3487","author":"Koloskova Anastasia","year":"2019","unstructured":"Anastasia Koloskova, Sebastian Stich, and Martin Jaggi. 2019. Decentralized stochastic optimization and gossip algorithms with compressed communication. In International Conference on Machine Learning. PMLR, 3478--3487."},{"key":"e_1_3_2_1_42_1","volume-title":"Tara Javidi, and Farinaz Koushanfar.","author":"Lalitha Anusha","year":"2019","unstructured":"Anusha Lalitha, Osman Cihan Kilinc, Tara Javidi, and Farinaz Koushanfar. 2019. Peer-to-peer federated learning on graphs. arXiv preprint arXiv:1901.11173 (2019)."},{"key":"e_1_3_2_1_43_1","volume-title":"CROSSLINE: Breaking \"Security-by-Crash\" based Memory Isolation in AMD SEV. arXiv preprint arXiv:2008.00146","author":"Li Mengyuan","year":"2020","unstructured":"Mengyuan Li, Yinqian Zhang, and Zhiqiang Lin. 2020. CROSSLINE: Breaking \"Security-by-Crash\" based Memory Isolation in AMD SEV. arXiv preprint arXiv:2008.00146 (2020)."},{"key":"e_1_3_2_1_44_1","volume-title":"28th USENIX Security Symposium. USENIX, 1257--1272","author":"Li Mengyuan","year":"2019","unstructured":"Mengyuan Li, Yinqian Zhang, Zhiqiang Lin, and Yan Solihin. 2019. Exploiting unprotected I\/O operations in AMD's Secure Encrypted Virtualization. In 28th USENIX Security Symposium. USENIX, 1257--1272."},{"key":"e_1_3_2_1_45_1","volume-title":"Design and Verification of the Arm Confidential Compute Architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22)","author":"Li Xupeng","year":"2022","unstructured":"Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. 2022. Design and Verification of the Arm Confidential Compute Architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22). 465--484."},{"key":"e_1_3_2_1_46_1","volume-title":"Policy-Based Autonomic Data Governance","author":"Liu Changchang","unstructured":"Changchang Liu, Supriyo Chakraborty, and Dinesh Verma. 2019. Secure model fusion for distributed learning using partial homomorphic encryption. In Policy-Based Autonomic Data Governance. Springer, 154--179."},{"key":"e_1_3_2_1_47_1","volume-title":"IBM Federated Learning: an Enterprise Framework White Paper V0.1. arXiv preprint arXiv:2007.10987","author":"Ludwig Heiko","year":"2020","unstructured":"Heiko Ludwig, Nathalie Baracaldo, Gegi Thomas, Yi Zhou, Ali Anwar, Shashank Rajamoni, Yuya Ong, Jayaram Radhakrishnan, Ashish Verma, Mathieu Sinn, Mark Purcell, Ambrish Rawat, Tran Minh, Naoise Holohan, Supriyo Chakraborty, Shalisha Whitherspoon, Dean Steuer, Laura Wynter, Hifaz Hassan, Sean Laguna, Mikhail Yurochkin, Mayank Agarwal, Ebube Chuba, and Annie Abay. 2020. IBM Federated Learning: an Enterprise Framework White Paper V0.1. arXiv preprint arXiv:2007.10987 (2020)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"e_1_3_2_1_49_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics. PMLR 1273--1282."},{"key":"e_1_3_2_1_50_1","volume-title":"Learning differentially private recurrent language models. arXiv preprint arXiv:1710.06963","author":"McMahan H Brendan","year":"2017","unstructured":"H Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2017. Learning differentially private recurrent language models. arXiv preprint arXiv:1710.06963 (2017)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3458864.3466628"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00054"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00057"},{"key":"e_1_3_2_1_56_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Bj\u00f6rn B Brandenburg, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al. 2022. {FLAME}: Taming backdoors in federated learning. In 31st USENIX Security Symposium (USENIX Security 22). 1415--1432."},{"key":"e_1_3_2_1_57_1","volume-title":"25th USENIX Security Symposium. USENIX, 619--636","author":"Ohrimenko Olga","year":"2016","unstructured":"Olga Ohrimenko, Felix Schuster, C\u00e9dric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious Multi-Party Machine Learning on Trusted Processors.. In 25th USENIX Security Symposium. USENIX, 619--636."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.5555\/1756123.1756146"},{"key":"e_1_3_2_1_59_1","volume-title":"30th USENIX Security Symposium. USENIX.","author":"Poddar Rishabh","year":"2021","unstructured":"Rishabh Poddar, Sukrit Kalra, Avishay Yanai, Ryan Deng, Raluca Ada Popa, and Joseph M Hellerstein. 2021. Senate: A Maliciously-Secure {MPC} Platform for Collaborative Analytics. In 30th USENIX Security Symposium. USENIX."},{"key":"e_1_3_2_1_60_1","volume-title":"Secfl: Confidential federated learning using tees. arXiv preprint arXiv:2110.00981","author":"Quoc Do Le","year":"2021","unstructured":"Do Le Quoc and Christof Fetzer. 2021. Secfl: Confidential federated learning using tees. arXiv preprint arXiv:2110.00981 (2021)."},{"key":"e_1_3_2_1_61_1","volume-title":"Markus Miettinen, and Ahmad-Reza Sadeghi.","author":"Rieger Phillip","year":"2022","unstructured":"Phillip Rieger, Thien Duc Nguyen, Markus Miettinen, and Ahmad-Reza Sadeghi. 2022. Deepsight: Mitigating backdoor attacks in federated learning through deep model inspection. arXiv preprint arXiv:2201.00763 (2022)."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3587135.3592168"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.10"},{"key":"e_1_3_2_1_64_1","volume-title":"API","author":"SEV","year":"2019","unstructured":"SEV API 2019. Secure Encrypted Virtualization API Version 0.22. https:\/\/developer.amd.com\/wp-content\/resources\/55766.PDF."},{"key":"e_1_3_2_1_65_1","volume-title":"Strengthening VM isolation with integrity protection and more. White Paper","author":"AMD SEV-SNP.","year":"2020","unstructured":"AMD SEV-SNP. 2020. Strengthening VM isolation with integrity protection and more. White Paper (2020)."},{"key":"e_1_3_2_1_66_1","unstructured":"SEV-Tool 2019. SEV-Tool. https:\/\/github.com\/AMDESE\/sev-tool."},{"key":"e_1_3_2_1_67_1","volume-title":"Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. ACM, 1310--1321","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. ACM, 1310--1321."},{"key":"e_1_3_2_1_68_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_1_69_1","volume-title":"ESORICS 2020, Guildford, UK, September 14-18, 2020, Proceedings, Part I 25","author":"Tolpegin Vale","year":"2020","unstructured":"Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data poisoning attacks against federated learning systems. In Computer Security-ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14-18, 2020, Proceedings, Part I 25. Springer, 480--501."},{"key":"e_1_3_2_1_70_1","volume-title":"Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. arXiv preprint arXiv:1806.03287","author":"Tramer Florian","year":"2018","unstructured":"Florian Tramer and Dan Boneh. 2018. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. arXiv preprint arXiv:1806.03287 (2018)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"e_1_3_2_1_72_1","volume-title":"27th USENIX Security Symposium. USENIX, 991--1008","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel { SGX} kingdom with transient out-of-order execution. In 27th USENIX Security Symposium. USENIX, 991--1008."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"e_1_3_2_1_74_1","unstructured":"Stephan van Schaik Andrew Kwong Daniel Genkin and Yuval Yarom. 2020. SGAxe: How SGX fails in practice."},{"key":"e_1_3_2_1_75_1","volume-title":"CacheOut: Leaking data on Intel CPUs via cache evictions. arXiv preprint arXiv:2006.13353","author":"van Schaik Stephan","year":"2020","unstructured":"Stephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin, and Yuval Yarom. 2020. CacheOut: Leaking data on Intel CPUs via cache evictions. arXiv preprint arXiv:2006.13353 (2020)."},{"key":"e_1_3_2_1_76_1","unstructured":"Paul Vanhaesebrouck Aur\u00e9lien Bellet and Marc Tommasi. 2017. Decentralized collaborative learning of personalized models over networks. In Artificial Intelligence and Statistics. PMLR 509--517."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329820"},{"key":"e_1_3_2_1_78_1","volume-title":"SEVurity: No Security Without Integrity-Breaking Integrity-Free Memory Encryption with Minimal Assumptions. arXiv preprint arXiv:2004.11071","author":"Wilke Luca","year":"2020","unstructured":"Luca Wilke, Jan Wichelmann, Mathias Morbitzer, and Thomas Eisenbarth. 2020. SEVurity: No Security Without Integrity-Breaking Integrity-Free Memory Encryption with Minimal Assumptions. arXiv preprint arXiv:2004.11071 (2020)."},{"key":"e_1_3_2_1_79_1","volume-title":"Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767","author":"Wu Chen","year":"2020","unstructured":"Chen Wu, Xian Yang, Sencun Zhu, and Prasenjit Mitra. 2020. Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767 (2020)."},{"key":"e_1_3_2_1_80_1","volume-title":"International Conference on Machine Learning. PMLR, 11372--11382","author":"Xie Chulin","year":"2021","unstructured":"Chulin Xie, Minghao Chen, Pin-Yu Chen, and Bo Li. 2021. Crfl: Certifiably robust federated learning against backdoor attacks. In International Conference on Machine Learning. PMLR, 11372--11382."},{"key":"e_1_3_2_1_81_1","volume-title":"International Conference on Machine Learning. PMLR, 5650--5659","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In International Conference on Machine Learning. PMLR, 5650--5659."},{"key":"e_1_3_2_1_82_1","volume-title":"See through Gradients: Image Batch Recovery via GradInversion. arXiv preprint arXiv:2104.07586","author":"Yin Hongxu","year":"2021","unstructured":"Hongxu Yin, Arun Mallya, Arash Vahdat, Jose M Alvarez, Jan Kautz, and Pavlo Molchanov. 2021. See through Gradients: Image Batch Recovery via GradInversion. arXiv preprint arXiv:2104.07586 (2021)."},{"key":"e_1_3_2_1_83_1","volume-title":"Decentralized Federated Learning: A Survey and Perspective. arXiv preprint arXiv:2306.01603","author":"Yuan Liangqi","year":"2023","unstructured":"Liangqi Yuan, Lichao Sun, Philip S Yu, and Ziran Wang. 2023. Decentralized Federated Learning: A Survey and Perspective. arXiv preprint arXiv:2306.01603 (2023)."},{"key":"e_1_3_2_1_84_1","volume-title":"Konda Reddy Mopuri, and Hakan Bilen","author":"Zhao Bo","year":"2020","unstructured":"Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. iDLG: Improved Deep Leakage from Gradients. arXiv preprint arXiv:2001.02610 (2020)."},{"key":"e_1_3_2_1_85_1","volume-title":"14th USENIX Symposium on Networked Systems Design and Implementation. USENIX, 283--298","author":"Zheng Wenting","year":"2017","unstructured":"Wenting Zheng, Ankur Dave, Jethro G Beekman, Raluca Ada Popa, Joseph E Gonzalez, and Ion Stoica. 2017. Opaque: An oblivious and encrypted distributed analytics platform. In 14th USENIX Symposium on Networked Systems Design and Implementation. USENIX, 283--298."},{"key":"e_1_3_2_1_86_1","volume-title":"Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning. In 30th USENIX Security Symposium. USENIX.","author":"Zheng Wenting","year":"2021","unstructured":"Wenting Zheng, Ryan Deng, Weikeng Chen, Raluca Ada Popa, Aurojit Panda, and Ion Stoica. 2021. Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning. In 30th USENIX Security Symposium. USENIX."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00045"},{"key":"e_1_3_2_1_88_1","unstructured":"Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems. 14774--14784."}],"event":{"name":"EuroSys '24: Nineteenth European Conference on Computer Systems","location":"Athens Greece","acronym":"EuroSys '24","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Nineteenth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627703.3650082","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627703.3650082","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T01:09:16Z","timestamp":1755824956000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627703.3650082"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,22]]},"references-count":88,"alternative-id":["10.1145\/3627703.3650082","10.1145\/3627703"],"URL":"https:\/\/doi.org\/10.1145\/3627703.3650082","relation":{},"subject":[],"published":{"date-parts":[[2024,4,22]]},"assertion":[{"value":"2024-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}