{"id":"https://openalex.org/W3213975728","doi":"https://doi.org/10.1109/tdsc.2021.3126315","title":"Model Protection: Real-Time Privacy-Preserving Inference Service for Model Privacy at the Edge","display_name":"Model Protection: Real-Time Privacy-Preserving Inference Service for Model Privacy at the Edge","publication_year":2021,"publication_date":"2021-11-09","ids":{"openalex":"https://openalex.org/W3213975728","doi":"https://doi.org/10.1109/tdsc.2021.3126315","mag":"3213975728"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2021.3126315","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2021.3126315","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033759584","display_name":"Jiahui Hou","orcid":"https://orcid.org/0000-0002-3340-8585"},"institutions":[{"id":"https://openalex.org/I180949307","display_name":"Illinois Institute of Technology","ror":"https://ror.org/037t3ry66","country_code":"US","type":"education","lineage":["https://openalex.org/I180949307"]},{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN","US"],"is_corresponding":true,"raw_author_name":"Jiahui Hou","raw_affiliation_strings":["School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China","Department of Computer Science, Illinois Institute of Technology, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"Department of Computer Science, Illinois Institute of Technology, Chicago, IL, USA","institution_ids":["https://openalex.org/I180949307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013444021","display_name":"Huiqi Liu","orcid":"https://orcid.org/0000-0003-1879-0779"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huiqi Liu","raw_affiliation_strings":["School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102880548","display_name":"Yunxin Liu","orcid":"https://orcid.org/0000-0001-7352-8955"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunxin Liu","raw_affiliation_strings":["Institute for AI Industry Research (AIR), Tsinghua University, China"],"affiliations":[{"raw_affiliation_string":"Institute for AI Industry Research (AIR), Tsinghua University, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100445368","display_name":"Yu Wang","orcid":"https://orcid.org/0000-0003-3511-0288"},"institutions":[{"id":"https://openalex.org/I84392919","display_name":"Temple University","ror":"https://ror.org/00kx1jb78","country_code":"US","type":"education","lineage":["https://openalex.org/I84392919"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yu Wang","raw_affiliation_strings":["Department of Computer and Information Sciences, Temple University, Philadelphia, PA, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer and Information Sciences, Temple University, Philadelphia, PA, USA","institution_ids":["https://openalex.org/I84392919"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036031118","display_name":"Peng\u2010Jun Wan","orcid":"https://orcid.org/0000-0001-7926-5711"},"institutions":[{"id":"https://openalex.org/I180949307","display_name":"Illinois Institute of Technology","ror":"https://ror.org/037t3ry66","country_code":"US","type":"education","lineage":["https://openalex.org/I180949307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Peng-Jun Wan","raw_affiliation_strings":["Department of Computer Science, Illinois Institute of Technology, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Illinois Institute of Technology, Chicago, IL, USA","institution_ids":["https://openalex.org/I180949307"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100341802","display_name":"Xiang\u2010Yang Li","orcid":"https://orcid.org/0000-0002-6070-6625"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiang-Yang Li","raw_affiliation_strings":["School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5033759584"],"corresponding_institution_ids":["https://openalex.org/I126520041","https://openalex.org/I180949307"],"apc_list":null,"apc_paid":null,"fwci":3.7733,"has_fulltext":false,"cited_by_count":47,"citation_normalized_percentile":{"value":0.94351394,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":"19","issue":"6","first_page":"4270","last_page":"4284"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7425798177719116},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.7048277854919434},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6093595623970032},{"id":"https://openalex.org/keywords/notation","display_name":"Notation","score":0.5753911137580872},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.543941080570221},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.5192261338233948},{"id":"https://openalex.org/keywords/edge-computing","display_name":"Edge computing","score":0.4664095640182495},{"id":"https://openalex.org/keywords/service","display_name":"Service (business)","score":0.4366002380847931},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.4116484820842743},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.37481260299682617},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37417301535606384},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3465750217437744},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.24647241830825806},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.12758073210716248}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7425798177719116},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.7048277854919434},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6093595623970032},{"id":"https://openalex.org/C45357846","wikidata":"https://www.wikidata.org/wiki/Q2001982","display_name":"Notation","level":2,"score":0.5753911137580872},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.543941080570221},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.5192261338233948},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.4664095640182495},{"id":"https://openalex.org/C2780378061","wikidata":"https://www.wikidata.org/wiki/Q25351891","display_name":"Service (business)","level":2,"score":0.4366002380847931},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.4116484820842743},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.37481260299682617},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37417301535606384},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3465750217437744},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.24647241830825806},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.12758073210716248},{"id":"https://openalex.org/C136264566","wikidata":"https://www.wikidata.org/wiki/Q159810","display_name":"Economy","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C94375191","wikidata":"https://www.wikidata.org/wiki/Q11205","display_name":"Arithmetic","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2021.3126315","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2021.3126315","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6600000262260437,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[{"id":"https://openalex.org/G3930769006","display_name":null,"funder_award_id":"61625205","funder_id":"https://openalex.org/F4320334953","funder_display_name":"China National Funds for Distinguished Young Scientists"},{"id":"https://openalex.org/G5814277799","display_name":null,"funder_award_id":"61520106007","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5894582779","display_name":null,"funder_award_id":"62132018","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6551229856","display_name":null,"funder_award_id":"CNS-1526638","funder_id":"https://openalex.org/F4320335353","funder_display_name":"National Science Foundation of Sri Lanka"},{"id":"https://openalex.org/G7899093858","display_name":null,"funder_award_id":"61751211","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7949432300","display_name":null,"funder_award_id":"61572347","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320334953","display_name":"China National Funds for Distinguished Young Scientists","ror":"https://ror.org/01pab2602"},{"id":"https://openalex.org/F4320335353","display_name":"National Science Foundation of Sri Lanka","ror":"https://ror.org/010xaa060"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":75,"referenced_works":["https://openalex.org/W1873763122","https://openalex.org/W2011777324","https://openalex.org/W2031533839","https://openalex.org/W2031738616","https://openalex.org/W2035476608","https://openalex.org/W2051267297","https://openalex.org/W2108598243","https://openalex.org/W2119144962","https://openalex.org/W2271840356","https://openalex.org/W2296719434","https://openalex.org/W2435473771","https://openalex.org/W2460441129","https://openalex.org/W2461943168","https://openalex.org/W2535690855","https://openalex.org/W2616901112","https://openalex.org/W2701059868","https://openalex.org/W2741623780","https://openalex.org/W2757528734","https://openalex.org/W2765200655","https://openalex.org/W2805074088","https://openalex.org/W2806082141","https://openalex.org/W2807403537","https://openalex.org/W2888798936","https://openalex.org/W2922429109","https://openalex.org/W2928726480","https://openalex.org/W2934399013","https://openalex.org/W2946622848","https://openalex.org/W2947898397","https://openalex.org/W2950168363","https://openalex.org/W2952653175","https://openalex.org/W2955425717","https://openalex.org/W2962965870","https://openalex.org/W2963378725","https://openalex.org/W2964318098","https://openalex.org/W2970731090","https://openalex.org/W2971687264","https://openalex.org/W2979832172","https://openalex.org/W2983140679","https://openalex.org/W2992389096","https://openalex.org/W3013583651","https://openalex.org/W3015806656","https://openalex.org/W3016075089","https://openalex.org/W3097924569","https://openalex.org/W3097981673","https://openalex.org/W3099866101","https://openalex.org/W3100860658","https://openalex.org/W3112409568","https://openalex.org/W3118608800","https://openalex.org/W3180257170","https://openalex.org/W3217809002","https://openalex.org/W4288117700","https://openalex.org/W4288593403","https://openalex.org/W4289729785","https://openalex.org/W4297799122","https://openalex.org/W4297952240","https://openalex.org/W6677580257","https://openalex.org/W6694517276","https://openalex.org/W6712237015","https://openalex.org/W6718865826","https://openalex.org/W6726275242","https://openalex.org/W6728897251","https://openalex.org/W6729667700","https://openalex.org/W6741779227","https://openalex.org/W6748082217","https://openalex.org/W6751922297","https://openalex.org/W6753172360","https://openalex.org/W6758686700","https://openalex.org/W6762718338","https://openalex.org/W6763242850","https://openalex.org/W6767246738","https://openalex.org/W6767247158","https://openalex.org/W6771063358","https://openalex.org/W6775078712","https://openalex.org/W6776906142","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W3211931762","https://openalex.org/W2942586735","https://openalex.org/W4225757241","https://openalex.org/W4385414328","https://openalex.org/W2534668683","https://openalex.org/W4375928818","https://openalex.org/W3013760193","https://openalex.org/W4307482744","https://openalex.org/W4385586765","https://openalex.org/W3009018976"],"abstract_inverted_index":{"Major":[0],"cloud":[1],"service":[2,159],"providers":[3],"with":[4,29],"well-equipped":[5],"infrastructure,":[6],"experienced":[7],"machine":[8],"learning":[9],"(ML)":[10],"expertise,":[11],"and":[12,46,102,184],"enriched":[13],"training":[14],"datasets":[15],"are":[16],"building":[17],"ML-as-a-Service":[18],"(MLaaS)":[19],"systems,":[20],"in":[21,40,182,189],"which":[22],"clients":[23,72],"can":[24,84,174],"query":[25],"ML-based":[26],"prediction":[27],"services":[28],"their":[30],"data.":[31],"Instead":[32],"of":[33,148,155],"moving":[34],"private":[35],"data":[36],"to":[37,53,70,99,118,136,151,177,193],"the":[38,61,71,110,125,153,161,194],"cloud,":[39],"this":[41],"work,":[42],"we":[43,92,144],"design,":[44],"implement,":[45],"evaluate":[47],"a":[48,75,94,129,137,146,178,185],"novel":[49,149],"secure":[50,95,156,170],"ML":[51,63,82,126],"system":[52],"enable":[54],"MLaaS":[55],"on":[56,65,142],"edge":[57,66,162],"devices.":[58],"To":[59],"protect":[60],"proprietary":[62],"models":[64],"devices":[67],"from":[68],"revealing":[69],"while":[73],"maintaining":[74],"real-time":[76,87,115],"inference":[77,158],"is":[78],"challenging.":[79],"Existing":[80],"privacy-preserving":[81],"techniques":[83],"hardly":[85],"satisfy":[86],"requirements.":[88],"In":[89],"our":[90],"solution,":[91],"employ":[93],"enclave":[96,111],"(e.g.,":[97],"SGX)":[98],"offer":[100],"security":[101],"provide":[103],"better":[104],"efficiency":[105,183],"than":[106],"cryptographic":[107],"techniques.":[108],"However,":[109],"alone":[112],"cannot":[113],"achieve":[114,175],"capability":[116],"due":[117],"its":[119],"limited":[120],"capacity.":[121],"We":[122],"observe":[123],"that":[124],"model":[127,139],"imposes":[128],"severe":[130],"accuracy":[131],"degradation":[132],"when":[133],"adding":[134],"noise":[135],"few":[138],"weights.":[140],"Based":[141],"this,":[143],"design":[145],"suite":[147],"solutions":[150],"optimize":[152],"performance":[154],"enclave-based":[157],"at":[160],"by":[163],"enclosing":[164],"only":[165],"<inline-formula><tex-math":[166,179,186],"notation=\"LaTeX\">$1\\%$</tex-math></inline-formula>":[167],"computation":[168],"within":[169],"enclaves.":[171],"Our":[172],"work":[173],"up":[176],"notation=\"LaTeX\">$7.8\\times$</tex-math></inline-formula>":[180],"increase":[181],"notation=\"LaTeX\">$27\\times$</tex-math></inline-formula>":[187],"reduction":[188],"memory":[190],"usage":[191],"compared":[192],"state-of-the-art.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":16},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":2}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
