{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T10:37:35Z","timestamp":1779359855536,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":3,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["2112471, 2207202"],"award-info":[{"award-number":["2112471, 2207202"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765029","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:33:16Z","timestamp":1763854396000},"page":"2653-2667","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["GPU Travelling: Efficient Confidential Collaborative Training with TEE-Enabled GPUs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2992-3434","authenticated-orcid":false,"given":"Shixuan","family":"Zhao","sequence":"first","affiliation":[{"name":"The Ohio State University, Columbus, OH, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9624-2669","authenticated-orcid":false,"given":"Zhongshu","family":"Gu","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0290-5367","authenticated-orcid":false,"given":"Salman","family":"Ahmed","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4674-3384","authenticated-orcid":false,"given":"Enriquillo","family":"Valdez","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6143-1064","authenticated-orcid":false,"given":"Hani","family":"Jamjoom","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6527-5994","authenticated-orcid":false,"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[{"name":"The Ohio State University, Columbus, OH, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Amazon. 2023. Amazon EC2 now supports AMD SEV-SNP. https:\/\/aws.amazon.com\/about-aws\/whats-new\/2023\/04\/amazon-ec2-amd-sev-snp\/."},{"key":"e_1_3_2_1_2_1","volume-title":"AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. White paper","author":"AMD.","year":"2020","unstructured":"AMD. 2020. AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. White paper (2020)."},{"key":"e_1_3_2_1_3_1","unstructured":"Andrej Karpathy. [n.d.]. karpathy\/llm.c: LLM training in simple raw C\/CUDA. https:\/\/github.com\/karpathy\/llm.c."},{"key":"e_1_3_2_1_4_1","volume-title":"Preview: Introducing DCesv5 and ECesv5-series Confidential VMs with Intel TDX. https:\/\/azure.microsoft.com\/en-us\/updates\/confidential-vms-with-intel-tdx-dcesv5-ecesv5\/.","year":"2023","unstructured":"Azure. 2023. Preview: Introducing DCesv5 and ECesv5-series Confidential VMs with Intel TDX. https:\/\/azure.microsoft.com\/en-us\/updates\/confidential-vms-with-intel-tdx-dcesv5-ecesv5\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Felix Brakel Uraz Odyurt and Ana-Lucia Varbanescu. 2024. Model Parallelism on Distributed Infrastructure: A Literature Review from Theory to LLM Case-Studies. arXiv:2403.03699 [cs.DC] https:\/\/arxiv.org\/abs\/2403.03699"},{"key":"e_1_3_2_1_6_1","volume-title":"Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, and Ruichuan Chen.","author":"Chen Dong","year":"2024","unstructured":"Dong Chen, Alice Dethise, Istemi Ekin Akkus, Ivica Rimac, Klaus Satzke, Antti Koskela, Marco Canini, Wei Wang, and Ruichuan Chen. 2024. Protecting Confidentiality, Privacy and Integrity in Collaborative Learning. arXiv:2412.08534 [cs.DC] https:\/\/arxiv.org\/abs\/2412.08534"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650082"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3652597","article-title":"Intel TDX Demystified","volume":"56","author":"Cheng Pau-Chen","year":"2024","unstructured":"Pau-Chen Cheng, Wojciech Ozga, Enriquillo Valdez, Salman Ahmed, Zhongshu Gu, Hani Jamjoom, Hubertus Franke, and James Bottomley. 2024b. Intel TDX Demystified: A Top-Down Approach. Comput. Surveys, Vol. 56, 9 (2024), 1-33.","journal-title":"A Top-Down Approach. Comput. Surveys"},{"key":"e_1_3_2_1_9_1","unstructured":"Christopher A. Choquette-Choo Natalie Dullerud Adam Dziedzic Yunxiang Zhang Somesh Jha Nicolas Papernot and Xiao Wang. 2021. CaPC Learning: Confidential and Private Collaborative Learning. arXiv:2102.05188 [cs.LG] https:\/\/arxiv.org\/abs\/2102.05188"},{"key":"e_1_3_2_1_10_1","unstructured":"Katharine Daly Hubert Eichner Peter Kairouz H. Brendan McMahan Daniel Ramage and Zheng Xu. 2025. Federated Learning in Practice: Reflections and Projections. arXiv:2410.08892 [cs.LG] https:\/\/arxiv.org\/abs\/2410.08892"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626827"},{"key":"e_1_3_2_1_12_1","unstructured":"DMTF. [n.d.]. SPDM | DMTF. https:\/\/www.dmtf.org\/standards\/spdm."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_14_1","volume-title":"Nova Fallen, Peter Kairouz, Albert Cheu, et al.","author":"Eichner Hubert","year":"2024","unstructured":"Hubert Eichner, Daniel Ramage, Kallista Bonawitz, Dzmitry Huba, Tiziano Santoro, Brett McLarnon, Timon Van Overveldt, Nova Fallen, Peter Kairouz, Albert Cheu, et al., 2024. Confidential federated computations. arXiv preprint arXiv:2404.10764 (2024)."},{"key":"e_1_3_2_1_15_1","unstructured":"Hugging Face. 2020. OpenAI GPT2. https:\/\/huggingface.co\/docs\/transformers\/model_doc\/gpt2."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPS53621.2022.00077"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"key":"e_1_3_2_1_18_1","volume-title":"AI Training, and LLMs. https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=4963711.","author":"Gervais Daniel J","year":"2024","unstructured":"Daniel J Gervais, Noam Shemtov, HARALAMBOS MARMANIS, and CATHERINE ZALLER ROWLAND. 2024. The Heart of the Matter: Copyright, AI Training, and LLMs. https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=4963711. (2024)."},{"key":"e_1_3_2_1_19_1","unstructured":"Google. 2020. Introducing Google Cloud Confidential Computing with Confidential VMs. https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-confidential-computing-with-confidential-vms."},{"key":"e_1_3_2_1_20_1","volume-title":"Michael Le, Hani Jamjoom, Shixuan Zhao, and Zhiqiang Lin.","author":"Gu Zhongshu","year":"2025","unstructured":"Zhongshu Gu, Enriquillo Valdez, Salman Ahmed, Julian James Stephen, Michael Le, Hani Jamjoom, Shixuan Zhao, and Zhiqiang Lin. 2025. NVIDIA GPU Confidential Computing Demystified. arXiv:2507.02770 [cs.CR] https:\/\/arxiv.org\/abs\/2507.02770"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCEM48484.2019.000-5"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3665220"},{"key":"e_1_3_2_1_23_1","unstructured":"Pankaj Gupta and Tom Lendacky. 2023. SEV-SNP Live Migration and VMM\/KVM API Implications. https:\/\/lpc.events\/event\/17\/contributions\/1532\/attachments\/1369\/2974\/06%20LPC-SNP-Live-Migration.pdf"},{"key":"e_1_3_2_1_24_1","first-page":"297","volume-title":"Understanding Routable PCIe Performance for Composable Infrastructures. In 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 24)","author":"Hou Wentao","year":"2024","unstructured":"Wentao Hou, Jie Zhang, Zeke Wang, and Ming Liu. 2024. Understanding Routable PCIe Performance for Composable Infrastructures. In 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 24). USENIX Association, Santa Clara, CA, 297-312. https:\/\/www.usenix.org\/conference\/nsdi24\/presentation\/hou"},{"key":"e_1_3_2_1_25_1","unstructured":"IBM. 2025. Confidential computing solutions. https:\/\/www.ibm.com\/confidential-computing."},{"key":"e_1_3_2_1_26_1","unstructured":"Intel. 2020. Intel Trust Domain Extensions Whitepaper. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/tdx-whitepaper-final9-17.pdf."},{"key":"e_1_3_2_1_27_1","unstructured":"Jinda Jia Cong Xie Hanlin Lu Daoce Wang Hao Feng Chengming Zhang Baixi Sun Haibin Lin Zhi Zhang Xin Liu and Dingwen Tao. 2024. SDP4Bit: Toward 4-bit Communication Quantization in Sharded Data Parallelism for LLM Training. arXiv:2410.15526 [cs.LG] https:\/\/arxiv.org\/abs\/2410.15526"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2024.3355010"},{"key":"e_1_3_2_1_29_1","volume-title":"Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al.","author":"Kairouz Peter","year":"2021","unstructured":"Peter Kairouz, H Brendan McMahan, Brendan Avent, Aur\u00e9lien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al., 2021. Advances and open problems in federated learning. Foundations and trends\u00ae in machine learning, Vol. 14, 1-2 (2021), 1-210."},{"key":"e_1_3_2_1_30_1","volume-title":"Protecting VM register state with SEV-ES. White paper","author":"Kaplan David","year":"2017","unstructured":"David Kaplan. 2017. Protecting VM register state with SEV-ES. White paper (2017)."},{"key":"e_1_3_2_1_31_1","volume-title":"AMD memory encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD memory encryption. White paper (2016)."},{"key":"e_1_3_2_1_32_1","volume-title":"Ananda Theertha Suresh, and Dave Bacon","author":"Konen\u00fd Jakub","year":"2017","unstructured":"Jakub Konen\u00fd, H. Brendan McMahan, Felix X. Yu, Peter Richt\u00e1rik, Ananda Theertha Suresh, and Dave Bacon. 2017. Federated Learning: Strategies for Improving Communication Efficiency. arXiv:1610.05492 [cs.LG] https:\/\/arxiv.org\/abs\/1610.05492"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/LANMAN52105.2021.9478813"},{"key":"e_1_3_2_1_34_1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273-1282.","journal-title":"PMLR"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1093\/jlb\/lsaa002"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3529706.3529715"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD62652.2024.00028"},{"key":"e_1_3_2_1_38_1","unstructured":"NVIDIA. [n.d.]. NVIDIA\/open-gpu-kernel-modules: NVIDIA Linux open GPU kernel module source. https:\/\/github.com\/NVIDIA\/open-gpu-kernel-modules."},{"key":"e_1_3_2_1_39_1","unstructured":"NVIDIA. 2024a. Confidential Computing | NVIDIA. https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/."},{"key":"e_1_3_2_1_40_1","unstructured":"NVIDIA. 2024b. Confidential Computing Deployment Guide - (Intel TDX & KVM). https:\/\/docs.nvidia.com\/cc-deployment-guide-tdx.pdf."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_1_42_1","unstructured":"PCI-SIG. [n.d.]. IDE and TDISP: An Overview of PCIe\u00ae Technology Security Features | PCI-SIG. https:\/\/pcisig.com\/blog\/ide-and-tdisp-overview-pcie\u00ae-technology-security-features."},{"key":"e_1_3_2_1_43_1","volume-title":"Secfl: Confidential federated learning using tees. arXiv preprint arXiv:2110.00981","author":"Quoc Do Le","year":"2021","unstructured":"Do Le Quoc and Christof Fetzer. 2021. Secfl: Confidential federated learning using tees. arXiv preprint arXiv:2110.00981 (2021)."},{"key":"e_1_3_2_1_44_1","unstructured":"Wolfram Ravenwolf. 2025. LLM Comparison\/Test: DeepSeek-V3 QVQ-72B-Preview Falcon3 10B Llama 3.3 70B Nemotron 70B in my updated MMLU-Pro CS benchmark. https:\/\/huggingface.co\/blog\/wolfram\/llm-comparison-test-2025-01-02."},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310-1321","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310-1321."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Jiajun Song Jiajun Luo Rongwei Lu Shuzhao Xie Bin Chen and Zhi Wang. 2024. A Joint Approach to Local Updating and Gradient Compression for Efficient Asynchronous Federated Learning. arXiv:2407.05125 [cs.DC] https:\/\/arxiv.org\/abs\/2407.05125","DOI":"10.1007\/978-3-031-69583-4_14"},{"key":"e_1_3_2_1_47_1","unstructured":"Haijian Sun Xiang Ma and Rose Qingyang Hu. 2020. Adaptive Federated Learning With Gradient Compression in Uplink NOMA. arXiv:2003.01344 [cs.NI] https:\/\/arxiv.org\/abs\/2003.01344"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME58846.2023.00027"},{"key":"e_1_3_2_1_49_1","unstructured":"Andrew S. Tanenbaum. 1989. Computer Networks. (1989) 57."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"crossref","unstructured":"Stacey Truex Nathalie Baracaldo Ali Anwar Thomas Steinke Heiko Ludwig Rui Zhang and Yi Zhou. 2019. A Hybrid Approach to Privacy-Preserving Federated Learning. arXiv:1812.03224 [cs.LG] https:\/\/arxiv.org\/abs\/1812.03224","DOI":"10.1145\/3338501.3357370"},{"key":"e_1_3_2_1_51_1","unstructured":"Wei Wang. 2021. TDX Live Migration. https:\/\/lpc.events\/event\/11\/contributions\/960\/attachments\/839\/1586\/TDX%20Live%20Migration_Wei%20Wang.pdf"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2025.100300"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3689031.3717464"},{"key":"e_1_3_2_1_55_1","volume-title":"Paarijaat Aditya, and Feng Yan.","author":"Zhang Chengliang","year":"2021","unstructured":"Chengliang Zhang, Junzhe Xia, Baichen Yang, Huancheng Puyang, Wei Wang, Ruichuan Chen, Istemi Ekin Akkus, Paarijaat Aditya, and Feng Yan. 2021. Citadel: Protecting Data Privacy and Model Confidentiality for Collaborative Learning with SGX. arXiv:2105.01281 [cs.CR] https:\/\/arxiv.org\/abs\/2105.01281"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.632"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833694"},{"key":"e_1_3_2_1_58_1","first-page":"4015","volume-title":"Reusable Enclaves for Confidential Serverless Computing. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Zhao Shixuan","year":"2023","unstructured":"Shixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang, Yinqian Zhang, and Zhiqiang Lin. 2023. Reusable Enclaves for Confidential Serverless Computing. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 4015-4032. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/zhao-shixuan"},{"key":"e_1_3_2_1_59_1","unstructured":"Mingwei Zheng Chengpeng Wang Xuwei Liu Jinyao Guo Shiwei Feng and Xiangyu Zhang. 2025. An LLM Agent for Functional Bug Detection in Network Protocols. arXiv:2506.00714 [cs.SE] https:\/\/arxiv.org\/abs\/2506.00714"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765029","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765029","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:19:26Z","timestamp":1766441966000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765029"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":59,"alternative-id":["10.1145\/3719027.3765029","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765029","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}