{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T16:03:05Z","timestamp":1781884985876,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":83,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744798","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:37:25Z","timestamp":1763854645000},"page":"1008-1022","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["TensorShield: Safeguarding On-Device Inference by Shielding Critical DNN Tensors with TEE"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9398-6216","authenticated-orcid":false,"given":"Tong","family":"Sun","sequence":"first","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9528-9832","authenticated-orcid":false,"given":"Bowen","family":"Jiang","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8358-3065","authenticated-orcid":false,"given":"Hailong","family":"Lin","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5262-2483","authenticated-orcid":false,"given":"Borui","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6671-6734","authenticated-orcid":false,"given":"Yixiao","family":"Teng","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7897-5965","authenticated-orcid":false,"given":"Yi","family":"Gao","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0498-1494","authenticated-orcid":false,"given":"Wei","family":"Dong","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2016. Raspberry Pi 3 Model B. https:\/\/www.raspberrypi.com\/products\/raspberrypi-3-model-b\/."},{"key":"e_1_3_2_1_2_1","unstructured":"2017. Hikey960. https:\/\/www.96boards.org\/product\/hikey960\/."},{"key":"e_1_3_2_1_3_1","unstructured":"2018. Raspberry Pi 3 Model B. https:\/\/www.raspberrypi.com\/products\/raspberry-pi-3-model-b-plus\/."},{"key":"e_1_3_2_1_4_1","unstructured":"ARM. 2022. TrustZone for Cortex-A. https:\/\/www.arm.com\/technologies\/trustzone-for-cortex-a."},{"key":"e_1_3_2_1_5_1","unstructured":"Arm. 2023. Arm Confidential Compute Architecture . https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture."},{"key":"e_1_3_2_1_6_1","volume-title":"Jean-Louis Lanet, and Axel Legay.","author":"Bukasa Sebanjila Kevin","year":"2017","unstructured":"Sebanjila Kevin Bukasa, Ronan Lashermes, H\u00e9l\u00e8ne Le Bouder, Jean-Louis Lanet, and Axel Legay. 2017. How TrustZone could be bypassed: Side-channel attacks on a modern system-on-chip. In WISTP. Springer."},{"key":"e_1_3_2_1_7_1","volume-title":"A Statistical and Multi-Perspective Revisiting of the Membership Inference Attack in Large Language Models. arXiv preprint arXiv:2412.13475","author":"Chen Bowen","year":"2024","unstructured":"Bowen Chen, Namgi Han, and Yusuke Miyao. 2024. A Statistical and Multi-Perspective Revisiting of the Membership Inference Attack in Large Language Models. arXiv preprint arXiv:2412.13475 (2024)."},{"key":"e_1_3_2_1_8_1","volume-title":"Proc. of ICLR.","author":"Chen Dingfan","year":"2022","unstructured":"Dingfan Chen, Ning Yu, and Mario Fritz. 2022. Relaxloss: Defending membership inference attacks without losing utility. In Proc. of ICLR."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363207"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3570361.3592501"},{"key":"e_1_3_2_1_11_1","volume-title":"Proc. of AISTATS.","author":"Coates Adam","year":"2011","unstructured":"Adam Coates, Andrew Ng, and Honglak Lee. 2011. An analysis of single-layer networks in unsupervised feature learning. In Proc. of AISTATS."},{"key":"e_1_3_2_1_12_1","volume-title":"Proc. of NeurIPS","author":"Deasy Jacob","year":"2020","unstructured":"Jacob Deasy, Nikola Simidjievski, and Pietro Li\u00f2. 2020. Constraining variational inference with geometric jensen-shannon divergence. Proc. of NeurIPS (2020)."},{"key":"e_1_3_2_1_13_1","unstructured":"Deli. 2024. DL333501 Power Monitor. . https:\/\/www.delitoolsglobal.com\/Power-Monitor-DL333501.html."},{"key":"e_1_3_2_1_14_1","unstructured":"Sen Deng Mengyuan Li Yining Tang Shuai Wang Shoumeng Yan and Yinqian Zhang. 2023. CipherH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations. In USENIX Security."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560627"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCGrid49817.2020.00-41"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3241539.3241559"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670267"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519565"},{"key":"e_1_3_2_1_20_1","volume-title":"Proc. of USENIX NSDI. 705--719","author":"Guo Peizhen","year":"2021","unstructured":"Peizhen Guo, Bo Hu, and Wenjun Hu. 2021. Mistify: Automating DNN Model Porting for On-Device Inference at the Edge. In Proc. of USENIX NSDI. 705--719."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3126315"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3523273"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530439"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560551"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3581791.3596852"},{"key":"e_1_3_2_1_27_1","volume-title":"Proc. of USENIX Security.","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. 2020. High accuracy and high fidelity extraction of neural networks. In Proc. of USENIX Security."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498361.3538932"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3261327"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3263631"},{"key":"e_1_3_2_1_33_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_34_1","volume-title":"Tiny imagenet visual recognition challenge. CS 231N 7, 7","author":"Le Ya","year":"2015","unstructured":"Ya Le and Xuan Yang. 2015. Tiny imagenet visual recognition challenge. CS 231N 7, 7 (2015), 3."},{"key":"e_1_3_2_1_35_1","volume-title":"Keystone: A framework for architecting tees. arXiv preprint arXiv:1907.10119","author":"Lee Dayeol","year":"2019","unstructured":"Dayeol Lee, David Kohlbrenner, Shweta Shinde, Dawn Song, and Krste Asanovic. 2019. Keystone: A framework for architecting tees. arXiv preprint arXiv:1907.10119 (2019)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"e_1_3_2_1_37_1","volume-title":"Multi-sensor Data Consistency and Fusion Based on Jensen-Shannon Divergence. In International Conference on Guidance, Navigation and Control. Springer, 5595--5605","author":"Li Duo","year":"2022","unstructured":"Duo Li, Junxiang Bai, and Wenling Li. 2022. Multi-sensor Data Consistency and Fusion Based on Jensen-Shannon Divergence. In International Conference on Guidance, Navigation and Control. Springer, 5595--5605."},{"key":"e_1_3_2_1_38_1","volume-title":"TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models. ACM Transactions on Software Engineering and Methodology","author":"Li Ding","year":"2024","unstructured":"Ding Li, Ziqi Zhang, Mengyu Yao, Yifeng Cai, Yao Guo, and Xiangqun Chen. 2024. TEESlice: Protecting Sensitive Neural Network Models in Trusted Execution Environments When Attackers have Pre-Trained Models. ACM Transactions on Software Engineering and Methodology (2024)."},{"key":"e_1_3_2_1_39_1","volume-title":"CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel. In USENIX Security.","author":"Li Mengyuan","year":"2021","unstructured":"Mengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li, and Yueqiang Cheng. 2021. CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel. In USENIX Security."},{"key":"e_1_3_2_1_40_1","volume-title":"Proc. of USENIX Security.","author":"Liu Yugeng","year":"2022","unstructured":"Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic Risk Assessment of Inference Attacks against Machine Learning Models. In Proc. of USENIX Security."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"e_1_3_2_1_42_1","volume-title":"Machine learning with confidential computing: A systematization of knowledge. ACM computing surveys (CSUR) 56, 11","author":"Mo Fan","year":"2024","unstructured":"Fan Mo, Zahra Tarkhani, and Hamed Haddadi. 2024. Machine learning with confidential computing: A systematization of knowledge. ACM computing surveys (CSUR) 56, 11 (2024), 1--40."},{"key":"e_1_3_2_1_43_1","unstructured":"NVIDIA. 2022. NVIDIA CONFIDENTIAL COMPUTING. https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3552326.3567483"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"key":"e_1_3_2_1_48_1","volume-title":"Fan Yao, and Deliang Fan.","author":"Rakin Adnan Siraj","year":"2022","unstructured":"Adnan Siraj Rakin, Md Hafizul Islam Chowdhuryy, Fan Yao, and Deliang Fan. 2022. Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories. In S&P'22. IEEE, 1157--1174."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354197"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_2_1_53_1","volume-title":"Proc. of USENIX ATC.","author":"Shen Tianxiang","year":"2022","unstructured":"Tianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang, Siyuan Wen, Xusheng Chen, Shixiong Zhao, Sen Wang, Li Chen, Xiapu Luo, et al. 2022. SOTER: Guarding Black-box Inference for General Neural Networks at the Edge. In Proc. of USENIX ATC."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833607"},{"key":"e_1_3_2_1_55_1","volume-title":"Proc. of ICLR.","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-scale Image Recognition. In Proc. of ICLR."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01333"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00021"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/IPSN61024.2024.00021"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00001"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179382"},{"key":"e_1_3_2_1_61_1","volume-title":"Proc. of USENIX Security.","author":"Sun Zhichuang","year":"2021","unstructured":"Zhichuang Sun, Ruimin Sun, Long Lu, and Alan Mislove. 2021. Mind your weight(s): A large-scale study on insufficient machine learning model protection in mobile apps. In Proc. of USENIX Security."},{"key":"e_1_3_2_1_62_1","volume-title":"Proc. of ICML. PMLR, 3319--3328","author":"Sundararajan Mukund","year":"2017","unstructured":"Mukund Sundararajan, Ankur Taly, and Qiqi Yan. 2017. Axiomatic attribution for deep networks. In Proc. of ICML. PMLR, 3319--3328."},{"key":"e_1_3_2_1_63_1","volume-title":"Proc. of USENIX Security.","author":"Tang Xinyu","year":"2022","unstructured":"Xinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar, Milad Nasr, Amir Houmansadr, and Prateek Mittal. 2022. Mitigating membership inference attacks by {Self-Distillation} through a novel ensemble architecture. In Proc. of USENIX Security."},{"key":"e_1_3_2_1_64_1","volume-title":"Proc. of ICLR.","author":"Tramer Florian","year":"2019","unstructured":"Florian Tramer and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In Proc. of ICLR."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"e_1_3_2_1_66_1","volume-title":"Proc. of USENIX OSDI.","author":"Volos Stavros","year":"2018","unstructured":"Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted Execution Environments on GPUs. In Proc. of USENIX OSDI."},{"key":"e_1_3_2_1_67_1","volume-title":"Proc. of NDSS.","author":"Zhang Fengwei","year":"2024","unstructured":"ChenxuWang, Fengwei Zhang, Yunjie Deng, Kevin Leach, Jiannong Cao, Zhenyu Ning, Shoumeng Yan, and Zhengyu He. 2024. CAGE: Complementing Arm CCA with GPU Extensions. In Proc. of NDSS."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623197"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447993.3448625"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.coling-main.529"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00077"},{"key":"e_1_3_2_1_72_1","volume-title":"Memory-Efficient and Secure DNN Inference on TrustZoneenabled Consumer IoT Devices. In INFOCOM'24","author":"Xie Xueshuo","year":"2024","unstructured":"Xueshuo Xie, Haoxu Wang, Zhaolong Jian, Tao Li, Wei Wang, Zhiwei Xu, and Guiling Wang. 2024. Memory-Efficient and Secure DNN Inference on TrustZoneenabled Consumer IoT Devices. In INFOCOM'24."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2008.58"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313591"},{"key":"e_1_3_2_1_75_1","volume-title":"PowerInfer-2: Fast Large Language Model Inference on a Smartphone. arXiv preprint arXiv:2406.06282","author":"Xue Zhenliang","year":"2024","unstructured":"Zhenliang Xue, Yixin Song, Zeyu Mi, Le Chen, Yubin Xia, and Haibo Chen. 2024. PowerInfer-2: Fast Large Language Model Inference on a Smartphone. arXiv preprint arXiv:2406.06282 (2024)."},{"key":"e_1_3_2_1_76_1","volume-title":"Llm as a system service on mobile devices. arXiv preprint arXiv:2403.11805","author":"Yin Wangsong","year":"2024","unstructured":"Wangsong Yin, Mengwei Xu, Yuanchun Li, and Xuanzhe Liu. 2024. Llm as a system service on mobile devices. arXiv preprint arXiv:2403.11805 (2024)."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3517016"},{"key":"e_1_3_2_1_78_1","volume-title":"Proc. of IEEE S&P'25","author":"Yuan Yuanyuan","year":"2024","unstructured":"Yuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen, ShuaiWang, Yinqian Zhang, and Zhendong Su. 2024. CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side Channels. In Proc. of IEEE S&P'25."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690317"},{"key":"e_1_3_2_1_80_1","first-page":"1","article-title":"Are all layers created equal","volume":"23","author":"Zhang Chiyuan","year":"2022","unstructured":"Chiyuan Zhang, Samy Bengio, and Yoram Singer. 2022. Are all layers created equal? Journal of Machine Learning Research 23, 67 (2022), 1--28.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_81_1","volume-title":"A comprehensive deep learning library benchmark and optimal library selection","author":"Zhang Qiyang","year":"2023","unstructured":"Qiyang Zhang, Xiangying Che, Yijie Chen, Xiao Ma, Mengwei Xu, Schahram Dustdar, Xuanzhe Liu, and Shangguang Wang. 2023. A comprehensive deep learning library benchmark and optimal library selection. IEEE Transactions on Mobile Computing (2023)."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00052"},{"key":"e_1_3_2_1_83_1","volume-title":"Proc. of ICML.","author":"Zhang Zheng","year":"2024","unstructured":"Zheng Zhang, Na Wang, Ziqi Zhang, Yao Zhang, Tianyi Zhang, Jianwei Liu, and Ye Wu. 2024. GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEs. In Proc. of ICML."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744798","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:21:46Z","timestamp":1766442106000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744798"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":83,"alternative-id":["10.1145\/3719027.3744798","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744798","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}