{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T13:01:09Z","timestamp":1780664469220,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,26]],"date-time":"2026-04-26T00:00:00Z","timestamp":1777161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2530909"],"award-info":[{"award-number":["2530909"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NEUTC","doi-asserted-by":"publisher","award":["-"],"award-info":[{"award-number":["-"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,27]]},"DOI":"10.1145\/3767295.3803586","type":"proceedings-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T20:20:04Z","timestamp":1777062004000},"page":"641-656","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["TrustWeave: Integrity Measurement and Attestation For Multi-Cloud LLMs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4089-8316","authenticated-orcid":false,"given":"Jianchang","family":"Su","sequence":"first","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3768-1917","authenticated-orcid":false,"given":"Wenhui","family":"Zhang","sequence":"additional","affiliation":[{"name":"Roblox, San Mateo, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6403-2161","authenticated-orcid":false,"given":"Yifan","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0303-6699","authenticated-orcid":false,"given":"Kexin","family":"Chu","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4819-5786","authenticated-orcid":false,"given":"Hao","family":"Guo","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6214-5390","authenticated-orcid":false,"given":"Youyou","family":"Lu","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9512-4192","authenticated-orcid":false,"given":"Wei","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Aeala. 2023. ShareGPT Vicuna Unfiltered. https:\/\/huggingface.co\/datasets\/Aeala\/ShareGPT_Vicuna_unfiltered. Hugging Face dataset."},{"key":"e_1_3_2_1_2_1","unstructured":"ARM ARM. 2004. TrustZone Technology."},{"key":"e_1_3_2_1_3_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Chen Qi Alfred","year":"2014","unstructured":"Qi Alfred Chen, Zhiyun Qian, and Z Morley Mao. 2014. Peeking into your app without actually seeing it:{UI} state inference and novel android attacks. In 23rd USENIX Security Symposium (USENIX Security 14). 1037\u20131052."},{"key":"e_1_3_2_1_4_1","volume-title":"Intel TDX Demystified: A Top-Down Approach. arXiv preprint arXiv:2303.15540","author":"Cheng Pau-Chen","year":"2023","unstructured":"Pau-Chen Cheng, Wojciech Ozga, Enriquillo Valdez, Salman Ahmed, Zhongshu Gu, Hani Jamjoom, Hubertus Franke, and James Bottomley. 2023. Intel TDX Demystified: A Top-Down Approach. arXiv preprint arXiv:2303.15540 (2023)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516758"},{"key":"e_1_3_2_1_6_1","volume-title":"From llm reasoning to autonomous ai agents: A comprehensive review. arXiv preprint arXiv:2504.19678","author":"Ferrag Mohamed Amine","year":"2025","unstructured":"Mohamed Amine Ferrag, Norbert Tihanyi, and Merouane Debbah. 2025. From llm reasoning to autonomous ai agents: A comprehensive review. arXiv preprint arXiv:2504.19678 (2025)."},{"key":"e_1_3_2_1_7_1","volume-title":"Model equality testing: Which model is this api serving? arXiv preprint arXiv:2410.20247","author":"Gao Irena","year":"2024","unstructured":"Irena Gao, Percy Liang, and Carlos Guestrin. 2024. Model equality testing: Which model is this api serving? arXiv preprint arXiv:2410.20247 (2024)."},{"key":"e_1_3_2_1_8_1","volume-title":"International Conference on Learning Representations, ICLR.","author":"Hong Sirui","year":"2024","unstructured":"Sirui Hong, Mingchen Zhuge, Jonathan Chen, Xiawu Zheng, Yuheng Cheng, Ceyao Zhang, Jinlin Wang, Zili Wang, Steven Ka Shing Yau, Zijuan Lin, et al. 2024. MetaGPT: Meta programming for a multiagent collaborative framework. International Conference on Learning Representations, ICLR."},{"key":"e_1_3_2_1_9_1","volume-title":"Aurora Gonz\u00e1lez Vidal, KR Jayaram, and Antonio Fernando Skarmeta G\u00f3mez.","author":"Ibarra Antonio Mart\u00ednez","year":"2025","unstructured":"Antonio Mart\u00ednez Ibarra, Julian James Stephen, Aurora Gonz\u00e1lez Vidal, KR Jayaram, and Antonio Fernando Skarmeta G\u00f3mez. 2025. Performance of Confidential Computing GPUs. arXiv preprint arXiv:2505.16501 (2025)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133058.1133063"},{"key":"e_1_3_2_1_11_1","volume-title":"USENIX Security Symposium","volume":"12","author":"Jaeger Trent","year":"2003","unstructured":"Trent Jaeger, Reiner Sailer, and Xiaolan Zhang. 2003. Analyzing Integrity Protection in the SELinux Example Policy.. In USENIX Security Symposium, Vol. 12. 5."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.19"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2947124"},{"key":"e_1_3_2_1_14_1","volume-title":"AMD memory encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD memory encryption. White paper (2016), 13."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.14445\/22312803\/IJCTT-V72I11P112"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_3_2_1_18_1","volume-title":"Agentbench: Evaluating llms as agents. arXiv preprint arXiv:2308.03688","author":"Liu Xiao","year":"2023","unstructured":"Xiao Liu, Hao Yu, Hanchen Zhang, Yifan Xu, Xuanyu Lei, Hanyu Lai, Yu Gu, Hangliang Ding, Kaiwen Men, Kejuan Yang, et al. 2023. Agentbench: Evaluating llms as agents. arXiv preprint arXiv:2308.03688 (2023)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2948618.2954331"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD62652.2024.00028"},{"key":"e_1_3_2_1_21_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Narayan Shravan","year":"2021","unstructured":"Shravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi, Evan Johnson, Zhao Gang, Anjo Vahldiek-Oberwagner, Ravi Sahita, Hovav Shacham, Dean Tullsen, et al. 2021. Swivel: Hardening {WebAssembly} against spectre. In 30th USENIX Security Symposium (USENIX Security 21)."},{"key":"e_1_3_2_1_22_1","unstructured":"OWASP Foundation Inc. 2025. OWASP Top 10 for Large Language Model Applications. https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/"},{"key":"e_1_3_2_1_23_1","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Pasquini Dario","year":"2025","unstructured":"Dario Pasquini, Evgenios M Kornaropoulos, and Giuseppe Ateniese. 2025. {LLMmap}: Fingerprinting for large language models. In 34th USENIX Security Symposium (USENIX Security 25). 299\u2013318."},{"key":"e_1_3_2_1_24_1","volume-title":"Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527","author":"Perez F\u00e1bio","year":"2022","unstructured":"F\u00e1bio Perez and Ian Ribeiro. 2022. Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527 (2022)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00025"},{"key":"e_1_3_2_1_26_1","volume-title":"Compromised PyTorch-nightly dependency chain between December 25th and December 30th","author":"Foundation PyTorch","year":"2022","unstructured":"PyTorch Foundation. 2022. Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022. https:\/\/pytorch.org\/blog\/compromised-nightly-dependency\/ PyTorch Blog (page shows an update date of Nov 14, 2024)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEED51797.2021.00024"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 13th Conference on USENIX Security Symposium -","volume":"13","author":"Sailer Reiner","year":"2004","unstructured":"Reiner Sailer, Xiaolan Zhang, Trent Jaeger, and Leendert van Doorn. 2004. Design and Implementation of a TCG-Based Integrity Measurement Architecture. In Proceedings of the 13th Conference on USENIX Security Symposium - Volume 13 (San Diego, CA) (SSYM'04). USENIX Association, USA, 16."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3087421"},{"key":"e_1_3_2_1_30_1","first-page":"1450","article-title":"Strengthening VM isolation with integrity protection and more","volume":"53","author":"Sev-Snp AMD","year":"2020","unstructured":"AMD Sev-Snp. 2020. Strengthening VM isolation with integrity protection and more. White Paper, January 53 (2020), 1450\u20131465.","journal-title":"White Paper"},{"key":"e_1_3_2_1_31_1","volume-title":"Prompt Stealing Attacks Against Large Language Models. arXiv preprint arXiv:2402.12959","author":"Sha Zeyang","year":"2024","unstructured":"Zeyang Sha and Yang Zhang. 2024. Prompt Stealing Attacks Against Large Language Models. arXiv preprint arXiv:2402.12959 (2024)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"e_1_3_2_1_33_1","volume-title":"The Role of Autonomous Agents in Agent-as-a-Service Cloud Service Model. In 2025 International Conference on Computing and Communication Technologies (ICCCT). IEEE, 1\u20136.","author":"Su Muthu Aanand","year":"2025","unstructured":"Muthu Aanand Su and GLK Niharika. 2025. The Role of Autonomous Agents in Agent-as-a-Service Cloud Service Model. In 2025 International Conference on Computing and Communication Technologies (ICCCT). IEEE, 1\u20136."},{"key":"e_1_3_2_1_34_1","volume-title":"SecScale: A Scalable and Secure Trusted Execution Environment for Servers. arXiv preprint arXiv:2407.13572","author":"Sunny Ani","year":"2024","unstructured":"Ani Sunny, Nivedita Shrivastava, and Smruti R Sarangi. 2024. SecScale: A Scalable and Secure Trusted Execution Environment for Servers. arXiv preprint arXiv:2407.13572 (2024)."},{"key":"e_1_3_2_1_35_1","volume-title":"2025 IEEE International Parallel and Distributed Processing Symposium Workshops (IPDPSW). IEEE, 1003\u20131010","author":"Krishna Anand Tokal Shiva Sai","year":"2025","unstructured":"Shiva Sai Krishna Anand Tokal, Vaibhav Jha, Anand Eswaran, Praveen Jayachandran, and Yogesh Simmhan. 2025. Towards Orchestrating Agentic Applications as FaaS Workflows. In 2025 IEEE International Parallel and Distributed Processing Symposium Workshops (IPDPSW). IEEE, 1003\u20131010."},{"key":"e_1_3_2_1_36_1","volume-title":"Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17)","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai, Donald E Porter, and Mona Vij. 2017. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17). 645\u2013658."},{"key":"e_1_3_2_1_37_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Varadarajan Venkatanathan","year":"2015","unstructured":"Venkatanathan Varadarajan, Yinqian Zhang, Thomas Ristenpart, and Michael Swift. 2015. A placement vulnerability study in {Multi-Tenant} public clouds. In 24th USENIX Security Symposium (USENIX Security 15)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0052"},{"key":"e_1_3_2_1_39_1","volume-title":"13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18)","author":"Volos Stavros","year":"2018","unstructured":"Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted execution environments on {GPUs}. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18). 681\u2013696."},{"key":"e_1_3_2_1_40_1","volume-title":"SvTPM: SGX-based Virtual Trusted Platform Modules for Cloud Computing","author":"Wang Juan","year":"2023","unstructured":"Juan Wang, Jie Wang, Chengyang Fan, Fei Yan, Yueqiang Cheng, Yinqian Zhang, Wenhui Zhang, Mengda Yang, and Hongxin Hu. 2023. SvTPM: SGX-based Virtual Trusted Platform Modules for Cloud Computing. IEEE Transactions on Cloud Computing (2023)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10515-024-00471-8"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616655"},{"key":"e_1_3_2_1_43_1","volume-title":"Ottawa Linux Symposium","volume":"8032","author":"Wright Chris","year":"2002","unstructured":"Chris Wright, Crispin Cowan, James Morris, Stephen Smalley, and Greg Kroah-Hartman. 2002. Linux security module framework. In Ottawa Linux Symposium, Vol. 8032. 6\u201316."},{"key":"e_1_3_2_1_44_1","volume-title":"First Conference on Language Modeling.","author":"Wu Qingyun","year":"2024","unstructured":"Qingyun Wu, Gagan Bansal, Jieyu Zhang, Yiran Wu, Beibin Li, Erkang Zhu, Li Jiang, Xiaoyun Zhang, Shaokun Zhang, Jiale Liu, et al. 2024. Autogen: Enabling next-gen LLM applications via multi-agent conversations. In First Conference on Language Modeling."},{"key":"e_1_3_2_1_45_1","volume-title":"25th USENIX security symposium (USENIX Security 16).","author":"Xiao Yuan","unstructured":"Yuan Xiao, Xiaokuan Zhang, Yinqian Zhang, and Radu Teodorescu. 2016. One bit flips, one cloud flops:{Cross-VM} row hammer attacks and privilege escalation. In 25th USENIX security symposium (USENIX Security 16)."},{"key":"e_1_3_2_1_46_1","volume-title":"PRSA: Prompt Reverse Stealing Attacks against Large Language Models. arXiv preprint arXiv:2402.19200","author":"Yang Yong","year":"2024","unstructured":"Yong Yang, Xuhong Zhang, Yi Jiang, Xi Chen, Haoyu Wang, Shouling Ji, and Zonghui Wang. 2024. PRSA: Prompt Reverse Stealing Attacks against Large Language Models. arXiv preprint arXiv:2402.19200 (2024)."},{"key":"e_1_3_2_1_47_1","volume-title":"USENIX Security Symposium.","author":"Zhang Kehuan","year":"2009","unstructured":"Kehuan Zhang and XiaoFeng Wang. 2009. Peeping Tom in the Neighborhood: Keystroke Eavesdropping on Multi-User Systems.. In USENIX Security Symposium."},{"key":"e_1_3_2_1_48_1","volume-title":"Proceedings of the Symposium on Network and Distributed System Security.","author":"Zhang Xiaokuan","year":"2018","unstructured":"Xiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang, and XiaoFeng Wang. 2018. Os-level side channels without procfs: Exploring cross-app information leakage on ios. In Proceedings of the Symposium on Network and Distributed System Security."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978360"},{"key":"e_1_3_2_1_50_1","volume-title":"SHELTER: Extending Arm CCA with Isolation in User Space. In 32nd USENIX Security Symposium (USENIX Security'23)","author":"Zhang Yiming","year":"2023","unstructured":"Yiming Zhang, Yuxin Hu, Zhenyu Ning, Fengwei Zhang, Xiapu Luo, Haoyang Huang, Shoumeng Yan, and Zhengyu He. 2023. SHELTER: Extending Arm CCA with Isolation in User Space. In 32nd USENIX Security Symposium (USENIX Security'23)."},{"key":"e_1_3_2_1_51_1","volume-title":"Prompts should not be seen as secrets: Systematically measuring prompt extraction attack success. arXiv preprint arXiv:2307.06865","author":"Zhang Yiming","year":"2023","unstructured":"Yiming Zhang and Daphne Ippolito. 2023. Prompts should not be seen as secrets: Systematically measuring prompt extraction attack success. arXiv preprint arXiv:2307.06865 (2023)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382230"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660356"},{"key":"e_1_3_2_1_54_1","volume-title":"Blocka2a: Towards secure and verifiable agent-to-agent interoperability. arXiv preprint arXiv:2508.01332","author":"Zou Zhenhua","year":"2025","unstructured":"Zhenhua Zou, Zhuotao Liu, Lepeng Zhao, and Qiuyang Zhan. 2025. Blocka2a: Towards secure and verifiable agent-to-agent interoperability. arXiv preprint arXiv:2508.01332 (2025)."}],"event":{"name":"EUROSYS '26: 21st European Conference on Computer Systems","location":"McEwan Hall\/The University of Edinburgh Edinburgh Scotland UK","acronym":"EUROSYS '26","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 21st European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3767295.3803586","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3767295.3803586","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3767295.3803586","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T12:06:23Z","timestamp":1780661183000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3767295.3803586"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,26]]},"references-count":54,"alternative-id":["10.1145\/3767295.3803586","10.1145\/3767295"],"URL":"https:\/\/doi.org\/10.1145\/3767295.3803586","relation":{},"subject":[],"published":{"date-parts":[[2026,4,26]]},"assertion":[{"value":"2026-04-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}