{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,28]],"date-time":"2026-03-28T16:59:59Z","timestamp":1774717199498,"version":"3.50.1"},"reference-count":48,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,3]]},"DOI":"10.23919\/date48585.2020.9116560","type":"proceedings-article","created":{"date-parts":[[2020,6,15]],"date-time":"2020-06-15T19:28:37Z","timestamp":1592249317000},"page":"460-465","source":"Crossref","is-referenced-by-count":32,"title":["Offline Model Guard: Secure and Private ML on Mobile Devices"],"prefix":"10.23919","author":[{"given":"Sebastian P.","family":"Bayerl","sequence":"first","affiliation":[{"name":"Technische Hochschule N&#x00FC;rnberg,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tommaso","family":"Frassetto","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Patrick","family":"Jauernig","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Korbinian","family":"Riedhammer","sequence":"additional","affiliation":[{"name":"Technische Hochschule N&#x00FC;rnberg,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmad-Reza","family":"Sadeghi","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Schneider","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emmanuel","family":"Stapf","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Weinert","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"IMIX: InProcess Memory Isolation EXtension","author":"frassetto","year":"2018","journal-title":"Usenix Security"},{"key":"ref38","article-title":"Intel SGX Explained","volume":"2016 86","author":"costan","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref33","article-title":"Efficient Deep Learning on MultiSource Private Data","volume":"abs 1807 6689","author":"hynes","year":"2018","journal-title":"CoRR"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3231594"},{"key":"ref31","article-title":"Chiron: Privacy-preserving Machine Learning as a Service","volume":"abs 1803 5961","author":"hunt","year":"2018","journal-title":"CoRR"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"ref37","article-title":"MLCapsule: Guarded Offline Deployment of Machine Learning as a Service","volume":"abs 1808 590","author":"hanzlik","year":"2018","journal-title":"CoRR"},{"key":"ref36","article-title":"Prch: A System for Privacy-Preserving Speech Transcription","volume":"abs 1909 4198","author":"ahmed","year":"2019","journal-title":"CoRR"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2018-2032"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66402-6_21"},{"key":"ref10","article-title":"TensorFlow Lite for Microcontrollers","year":"0"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23068"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23448"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1186\/1687-417X-2007-037343"},{"key":"ref15","article-title":"Generalized Universal Circuits for Secure Evaluation of Private Functions with Application to Data Classification","author":"sadeghi","year":"2008","journal-title":"International Conference on Information Security and Cryptology (ICISC)"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2108650"},{"key":"ref17","article-title":"CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy","author":"dowlin","year":"2016","journal-title":"ICML"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref28","article-title":"Oblivious Multi-Party Machine Learning on Trusted Processors","author":"ohrimenko","year":"2016","journal-title":"Usenix Security"},{"key":"ref4","article-title":"Major breach found in biometrics system used by banks, UK police and defence firms","year":"2019"},{"key":"ref27","article-title":"Slalom: Fast, Verifiable and Private Execution` of Neural Networks in Trusted Hardware","author":"tramer","year":"2019","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref3","article-title":"Apple contractors &#x2019;regularly hear confidential details&#x2019; on Siri recordings","year":"2019"},{"key":"ref6","article-title":"An All-Neural On-Device Speech Recognizer","author":"schalkwyk","year":"2019"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682336"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref7","article-title":"CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel","author":"batina","year":"2019","journal-title":"Usenix Security"},{"key":"ref2","article-title":"Amazon Ordered to Give Alexa Evidence in Double Murder Case","year":"2018"},{"key":"ref9","article-title":"The Secret Sharer: Measuring Unintended Neural Network Memorization & Extracting Secrets","volume":"abs 1802 8232","author":"carlini","year":"2018","journal-title":"CoRR"},{"key":"ref1","article-title":"Amazon Alexa User Receives 1,700 Audio Recordings of a Stranger through &#x2018;Human Error&#x2019;","year":"2018"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref45","article-title":"Zircon Microkernel","year":"0"},{"key":"ref48","article-title":"Convolutional Neural Networks for SmallFootprint Keyword Spotting","author":"sainath","year":"2015","journal-title":"InterSpeech"},{"key":"ref22","article-title":"XONN: XNOR-based Oblivious Deep Neural Network Inference","author":"riazi","year":"2019","journal-title":"Usenix Security"},{"key":"ref47","article-title":"Speech Commands: A Dataset for Limited-Vocabulary Speech Recognition","volume":"abs 1804 3209","author":"warden","year":"2018","journal-title":"CoRR"},{"key":"ref21","article-title":"GAZELLE: A Low Latency Framework for Secure Neural Network Inference","author":"juvekar","year":"2018","journal-title":"Usenix Security"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.17"},{"key":"ref24","article-title":"Private Machine Learning in TensorFlow using Secure Computation","volume":"abs 1810 8130","author":"dahl","year":"2018","journal-title":"CoRR"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.52"},{"key":"ref23","article-title":"SEALion: A Framework for Neural Network Inference on Encrypted Data","volume":"abs 1904 12840","author":"van elsloo","year":"2019","journal-title":"CoRR"},{"key":"ref44","article-title":"Trust Issues: Exploiting TrustZone TEEs","year":"2017"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2230222"},{"key":"ref43","article-title":"ARM Security Technology - Building a Secure System using TrustZone Technology","year":"2009"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3338469.3358944"}],"event":{"name":"2020 Design, Automation & Test in Europe Conference & Exhibition (DATE)","location":"Grenoble, France","start":{"date-parts":[[2020,3,9]]},"end":{"date-parts":[[2020,3,13]]}},"container-title":["2020 Design, Automation &amp; Test in Europe Conference &amp; Exhibition (DATE)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9112295\/9116186\/09116560.pdf?arnumber=9116560","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T19:48:09Z","timestamp":1659469689000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9116560\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3]]},"references-count":48,"URL":"https:\/\/doi.org\/10.23919\/date48585.2020.9116560","relation":{},"subject":[],"published":{"date-parts":[[2020,3]]}}}