{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T15:57:58Z","timestamp":1781539078380,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":34,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T00:00:00Z","timestamp":1781481600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472432"],"award-info":[{"award-number":["62472432"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Natural Science Foundation of China","award":["62306325"],"award-info":[{"award-number":["62306325"]}]},{"name":"Fundamental and Interdisciplinary Disciplines Breakthrough Plan of the Ministry of Education of China","award":["JYB2025XDXM118"],"award-info":[{"award-number":["JYB2025XDXM118"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,16]]},"DOI":"10.1145\/3805622.3810609","type":"proceedings-article","created":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:42:57Z","timestamp":1781534577000},"page":"2059-2067","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["MirageNet: A Secure, Efficient, and Scalable DNN Protection for Edge-Computing Multimedia Retrieval"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5733-8364","authenticated-orcid":false,"given":"Huadi","family":"Zheng","sequence":"first","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4124-0732","authenticated-orcid":false,"given":"Cheng","family":"Li","sequence":"additional","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6358-1621","authenticated-orcid":false,"given":"Xin","family":"Zhou","sequence":"additional","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-3486-642X","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9592-7301","authenticated-orcid":false,"given":"Yuanhang","family":"Yu","sequence":"additional","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4009-6783","authenticated-orcid":false,"given":"Feng","family":"Wang","sequence":"additional","affiliation":[{"name":"Hunan University, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4741-517X","authenticated-orcid":false,"given":"Yan","family":"Ding","sequence":"additional","affiliation":[{"name":"National University of Defense Technology, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,15]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62144-5_4"},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456238"},{"key":"e_1_3_3_1_4_2","first-page":"215","volume-title":"Proceedings of the fourteenth international conference on artificial intelligence and statistics","author":"Coates Adam","year":"2011","unstructured":"Adam Coates, Andrew Ng, and Honglak Lee. 2011. An analysis of single-layer networks in unsupervised feature learning. In Proceedings of the fourteenth international conference on artificial intelligence and statistics. JMLR Workshop and Conference Proceedings, 215\u2013223."},{"key":"e_1_3_3_1_5_2","volume-title":"Intel Software Guard Extensions (Intel SGX) - Key Management on the 3rd Generation Intel Xeon Scalable Processor","author":"Corporation Intel","year":"2021","unstructured":"Intel Corporation. 2021. Intel Software Guard Extensions (Intel SGX) - Key Management on the 3rd Generation Intel Xeon Scalable Processor. Technical Report. Intel Corporation. https:\/\/www.intel.com\/content\/www\/us\/en\/content-details\/706019\/intel-software-guard-extensions-intel-sgx-key-management-on-the-3rd-generation-intel-xeon-scalable-processor.html"},{"key":"e_1_3_3_1_6_2","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016)."},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","unstructured":"Shuiguang Deng Hailiang Zhao Weijia Fang Jianwei Yin Schahram Dustdar and Albert\u00a0Y. Zomaya. 2020. Edge Intelligence: The Confluence of Edge Computing and Artificial Intelligence. IEEE Internet of Things Journal 7 8 (2020) 7457\u20137469. 10.1109\/JIOT.2020.2984887","DOI":"10.1109\/JIOT.2020.2984887"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"crossref","unstructured":"Yan Ding Liaoliao Feng Liantao Song Pan Dong Zihao Guan Wei Wang and Yusong Tan. 2024. A Survey on Trustzone-Based System Security Enhancement Research. Available at SSRN 4697495 (2024).","DOI":"10.2139\/ssrn.4697495"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"Thomas Elsken Jan\u00a0Hendrik Metzen and Frank Hutter. 2019. Neural Architecture Search: A Survey.Journal of Machine Learning Research (2019) 1\u201321. Issue No.30-56.","DOI":"10.1007\/978-3-030-05318-5_11"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"crossref","unstructured":"Jiahui Hou Huiqi Liu Yunxin Liu Yu Wang Peng-Jun Wan and Xiang-Yang Li. 2021. Model protection: Real-time privacy-preserving inference service for model privacy at the edge. IEEE Transactions on Dependable and Secure Computing 19 6 (2021) 4270\u20134284.","DOI":"10.1109\/TDSC.2021.3126315"},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378460"},{"key":"e_1_3_3_1_13_2","unstructured":"David Kaplan Jeremy Powell and Tom Woller. 2016. AMD memory encryption. White paper 13 (2016) 12."},{"key":"e_1_3_3_1_14_2","unstructured":"Alex Krizhevsky Geoffrey Hinton et\u00a0al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"crossref","unstructured":"Alex Krizhevsky Ilya Sutskever and Geoffrey\u00a0E Hinton. 2017. ImageNet classification with deep convolutional neural networks. Commun. ACM 60 6 (2017) 84\u201390.","DOI":"10.1145\/3065386"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Fan Mo Ali\u00a0Shahin Shamsabadi Kleomenis Katevas Soteris Demetriou Ilias Leontiadis Andrea Cavallaro and Hamed Haddadi. 2020. Darknetz: towards model privacy at the edge using trusted execution environments. (2020) 161\u2013174.","DOI":"10.1145\/3386901.3388946"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"crossref","unstructured":"Antonio Mu\u00f1oz Ruben R\u00edos Rodrigo Rom\u00e1n and Javier L\u00f3pez. 2023. A survey on the (in) security of trusted execution environments. Computers & Security 129 (2023) 103180.","DOI":"10.1016\/j.cose.2023.103180"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3600160.3600169"},{"key":"e_1_3_3_1_20_2","unstructured":"N Papemot PD McDaniel A Sinha and MP Wellman. 2016. Towards the science of security and privacy in machine learning. CoRR (2016)."},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"crossref","unstructured":"Sandro Pinto and Nuno Santos. 2019. Demystifying arm trustzone: A comprehensive survey. ACM computing surveys (CSUR) 51 6 (2019) 1\u201336.","DOI":"10.1145\/3291047"},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.357"},{"key":"e_1_3_3_1_23_2","unstructured":"AMD Sev-Snp. 2020. Strengthening VM isolation with integrity protection and more. White Paper January 53 2020 (2020) 1450\u20131465."},{"key":"e_1_3_3_1_24_2","first-page":"723","volume-title":"2022 USENIX Annual Technical Conference (USENIX ATC 22)","author":"Shen Tianxiang","year":"2022","unstructured":"Tianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang, Siyuan Wen, Xusheng Chen, Shixiong Zhao, Sen Wang, Li Chen, Xiapu Luo, et\u00a0al. 2022. SOTER: Guarding black-box inference for general neural networks at the edge. In 2022 USENIX Annual Technical Conference (USENIX ATC 22). 723\u2013738."},{"key":"e_1_3_3_1_25_2","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1409.1556 (2014)."},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICWS62655.2024.00103"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179382"},{"key":"e_1_3_3_1_28_2","first-page":"1955","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Sun Zhichuang","year":"2021","unstructured":"Zhichuang Sun, Ruimin Sun, Long Lu, and Alan Mislove. 2021. Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile Apps. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 1955\u20131972."},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796929"},{"key":"e_1_3_3_1_30_2","unstructured":"Florian Tramer and Dan Boneh. 2018. Slalom: Fast verifiable and private execution of neural networks in trusted hardware. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1806.03287 (2018)."},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS52674.2021.00018"},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00052"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3536168.3543299"},{"key":"e_1_3_3_1_34_2","series-title":"Proceedings of Machine Learning Research","first-page":"59992","volume-title":"Proceedings of the 41st International Conference on Machine Learning","volume":"235","author":"Zhang Zheng","year":"2024","unstructured":"Zheng Zhang, Na Wang, Ziqi Zhang, Yao Zhang, Tianyi Zhang, Jianwei Liu, and Ye Wu. 2024. GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEs. In Proceedings of the 41st International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a0235). PMLR, 59992\u201360003."},{"key":"e_1_3_3_1_35_2","first-page":"42614","volume-title":"International Conference on Machine Learning","author":"Zhou Tong","year":"2023","unstructured":"Tong Zhou, Yukui Luo, Shaolei Ren, and Xiaolin Xu. 2023. NNSplitter: an active defense solution for DNN model via automated weight obfuscation. In International Conference on Machine Learning. PMLR, 42614\u201342624."}],"event":{"name":"ICMR '26: International Conference on Multimedia Retrieval","location":"Amsterdam The Netherlands","acronym":"ICMR '26","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2026 International Conference on Multimedia Retrieval"],"original-title":[],"deposited":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T15:49:00Z","timestamp":1781538540000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3805622.3810609"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,15]]},"references-count":34,"alternative-id":["10.1145\/3805622.3810609","10.1145\/3805622"],"URL":"https:\/\/doi.org\/10.1145\/3805622.3810609","relation":{},"subject":[],"published":{"date-parts":[[2026,6,15]]},"assertion":[{"value":"2026-06-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}