{"id":"https://openalex.org/W4389166734","doi":"https://doi.org/10.1109/iccad57390.2023.10323746","title":"MirrorNet: A TEE-Friendly Framework for Secure On-Device DNN Inference","display_name":"MirrorNet: A TEE-Friendly Framework for Secure On-Device DNN Inference","publication_year":2023,"publication_date":"2023-10-28","ids":{"openalex":"https://openalex.org/W4389166734","doi":"https://doi.org/10.1109/iccad57390.2023.10323746"},"language":"en","primary_location":{"id":"doi:10.1109/iccad57390.2023.10323746","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccad57390.2023.10323746","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100350069","display_name":"Ziyu Liu","orcid":"https://orcid.org/0009-0004-4423-5917"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ziyu Liu","raw_affiliation_strings":["Northeastern University,Boston,MA,USA","Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University,Boston,MA,USA","institution_ids":["https://openalex.org/I12912129"]},{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041001467","display_name":"Yukui Luo","orcid":"https://orcid.org/0000-0002-5852-4195"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yukui Luo.","raw_affiliation_strings":["Northeastern University,Boston,MA,USA","Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University,Boston,MA,USA","institution_ids":["https://openalex.org/I12912129"]},{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023765976","display_name":"Shijin Duan","orcid":"https://orcid.org/0000-0002-4317-1489"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shijin Duan","raw_affiliation_strings":["Northeastern University,Boston,MA,USA","Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University,Boston,MA,USA","institution_ids":["https://openalex.org/I12912129"]},{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101777618","display_name":"Tong Zhou","orcid":"https://orcid.org/0000-0002-8645-5246"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tong Zhou","raw_affiliation_strings":["Northeastern University,Boston,MA,USA","Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University,Boston,MA,USA","institution_ids":["https://openalex.org/I12912129"]},{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5054462808","display_name":"Xiaolin Xu","orcid":"https://orcid.org/0000-0001-8393-2783"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiaolin Xu","raw_affiliation_strings":["Northeastern University,Boston,MA,USA","Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University,Boston,MA,USA","institution_ids":["https://openalex.org/I12912129"]},{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100350069"],"corresponding_institution_ids":["https://openalex.org/I12912129"],"apc_list":null,"apc_paid":null,"fwci":2.4448,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.91316565,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9919999837875366,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8286728858947754},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7524452209472656},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.6116955280303955},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.5725346803665161},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.5421496629714966},{"id":"https://openalex.org/keywords/flexibility","display_name":"Flexibility (engineering)","score":0.5420213341712952},{"id":"https://openalex.org/keywords/latency","display_name":"Latency (audio)","score":0.4874842166900635},{"id":"https://openalex.org/keywords/confidentiality","display_name":"Confidentiality","score":0.463047057390213},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4385581314563751},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.437100887298584},{"id":"https://openalex.org/keywords/inference-engine","display_name":"Inference engine","score":0.4215102195739746},{"id":"https://openalex.org/keywords/edge-computing","display_name":"Edge computing","score":0.4198142886161804},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.41289469599723816},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.4078294038772583},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.34774863719940186},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30243173241615295},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.29826655983924866},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.15555238723754883},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.12695395946502686}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8286728858947754},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7524452209472656},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.6116955280303955},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.5725346803665161},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.5421496629714966},{"id":"https://openalex.org/C2780598303","wikidata":"https://www.wikidata.org/wiki/Q65921492","display_name":"Flexibility (engineering)","level":2,"score":0.5420213341712952},{"id":"https://openalex.org/C82876162","wikidata":"https://www.wikidata.org/wiki/Q17096504","display_name":"Latency (audio)","level":2,"score":0.4874842166900635},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.463047057390213},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4385581314563751},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.437100887298584},{"id":"https://openalex.org/C46743427","wikidata":"https://www.wikidata.org/wiki/Q1341685","display_name":"Inference engine","level":3,"score":0.4215102195739746},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.4198142886161804},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.41289469599723816},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4078294038772583},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.34774863719940186},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30243173241615295},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29826655983924866},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.15555238723754883},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.12695395946502686},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/iccad57390.2023.10323746","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccad57390.2023.10323746","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.6800000071525574,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1131590049","display_name":null,"funder_award_id":"OAC-2319962,CNS-2239672,CNS-2153690,CNS-2326597,CNS-2247892","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W1522301498","https://openalex.org/W1686810756","https://openalex.org/W2112796928","https://openalex.org/W2117539524","https://openalex.org/W2132083787","https://openalex.org/W2194775991","https://openalex.org/W2463516579","https://openalex.org/W2750384547","https://openalex.org/W2789304371","https://openalex.org/W2789758093","https://openalex.org/W2805074088","https://openalex.org/W2886754822","https://openalex.org/W2899435347","https://openalex.org/W2903650079","https://openalex.org/W2913096406","https://openalex.org/W2914223029","https://openalex.org/W2951245151","https://openalex.org/W2963844355","https://openalex.org/W2964318098","https://openalex.org/W2970731090","https://openalex.org/W2999711171","https://openalex.org/W3000280594","https://openalex.org/W3006136119","https://openalex.org/W3011082615","https://openalex.org/W3016075089","https://openalex.org/W3097924569","https://openalex.org/W3097981673","https://openalex.org/W3105904792","https://openalex.org/W3118608800","https://openalex.org/W3135347465","https://openalex.org/W3171718976","https://openalex.org/W3185788529","https://openalex.org/W4200287842","https://openalex.org/W4281693361","https://openalex.org/W4285490414","https://openalex.org/W4287120058","https://openalex.org/W4287600281","https://openalex.org/W4312121099","https://openalex.org/W6631190155","https://openalex.org/W6637373629","https://openalex.org/W6712237015","https://openalex.org/W6719314992","https://openalex.org/W6743688258","https://openalex.org/W6751922297","https://openalex.org/W6755958147","https://openalex.org/W6759402996","https://openalex.org/W6767246738","https://openalex.org/W6773658961","https://openalex.org/W6786144789","https://openalex.org/W6840496522","https://openalex.org/W6840499532","https://openalex.org/W6842266614"],"related_works":["https://openalex.org/W4322761281","https://openalex.org/W4238233472","https://openalex.org/W3111395152","https://openalex.org/W4313526662","https://openalex.org/W4313463218","https://openalex.org/W3106131444","https://openalex.org/W3216099748","https://openalex.org/W4205963435","https://openalex.org/W4312996489","https://openalex.org/W3214037210"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"network":[2],"(DNN)":[3],"models":[4],"have":[5],"become":[6],"prevalent":[7],"in":[8,37,100,120,187],"edge":[9],"devices":[10],"for":[11,66,203],"real-time":[12],"inference.":[13,60,207],"However,":[14],"they":[15],"are":[16],"vulnerable":[17],"to":[18,30,55,71,143],"model":[19,33,70,74,95,125],"extraction":[20],"attacks":[21],"and":[22,81,109,138,163,174,200,220],"require":[23],"protection.":[24],"Existing":[25],"defense":[26],"approaches":[27],"either":[28],"fail":[29],"fully":[31],"safeguard":[32],"confidentiality":[34],"or":[35],"result":[36],"significant":[38],"latency":[39],"issues.":[40],"To":[41,147],"overcome":[42],"these":[43],"challenges,":[44],"this":[45],"paper":[46],"presents":[47],"MirrorNet,":[48],"which":[49,97,158,167],"leverages":[50],"Trusted":[51],"Execution":[52],"Environment":[53],"(TEE)":[54],"enable":[56],"secure":[57,122,204],"on-device":[58,205],"DNN":[59,69,206],"It":[61],"generates":[62,159],"a":[63,115,198,214],"TEE-friendly":[64],"implementation":[65],"any":[67],"given":[68],"protect":[72],"the":[73,78,93,101,110,121,129,132,136,140,154,164,169,176,183,209],"confidentiality,":[75],"while":[76,191,223],"meeting":[77],"stringent":[79],"computation":[80,194],"storage":[82],"constraints":[83],"of":[84,89,171,185],"TEE.":[85],"The":[86],"framework":[87],"consists":[88],"two":[90,152],"key":[91],"components:":[92],"backbone":[94],"(BackboneNet),":[96],"is":[98],"stored":[99,119],"normal":[102],"world":[103],"but":[104],"achieves":[105],"lower":[106],"inference":[107],"accuracy,":[108],"Companion":[111],"Partial":[112],"Monitor":[113],"(CPM),":[114],"lightweight":[116],"mirrored":[117],"branch":[118],"world,":[123],"preserving":[124],"confidentiality.":[126],"During":[127],"inference,":[128],"CPM":[130,155],"monitors":[131],"intermediate":[133],"results":[134],"from":[135],"BackboneNet":[137],"rectifies":[139],"classification":[141],"output":[142],"achieve":[144,213],"higher":[145],"accuracy.":[146],"enhance":[148],"flexibility,":[149],"MirrorNet":[150,186,197,211],"incorporates":[151],"modules:":[153],"Strategy":[156],"Generator,":[157],"various":[160],"protection":[161],"strategies,":[162],"Performance":[165],"Emulator,":[166],"estimates":[168],"performance":[170],"each":[172],"strategy":[173],"selects":[175],"most":[177],"optimal":[178],"one.":[179],"Extensive":[180],"experiments":[181],"demonstrate":[182],"effectiveness":[184],"providing":[188],"security":[189],"guarantees":[190],"maintaining":[192],"low":[193],"latency,":[195],"making":[196],"practical":[199],"promising":[201],"solution":[202],"For":[208],"evaluation,":[210],"can":[212],"18.6%":[215],"accuracy":[216],"gap":[217],"between":[218],"authenticated":[219],"illegal":[221],"use,":[222],"only":[224],"introducing":[225],"0.99%":[226],"hardware":[227],"overhead.":[228]},"counts_by_year":[{"year":2025,"cited_by_count":10},{"year":2024,"cited_by_count":4}],"updated_date":"2026-02-25T23:00:34.991745","created_date":"2025-10-10T00:00:00"}
