{"id":"https://openalex.org/W3097924569","doi":"https://doi.org/10.1145/3411508.3421376","title":"eNNclave","display_name":"eNNclave","publication_year":2020,"publication_date":"2020-11-02","ids":{"openalex":"https://openalex.org/W3097924569","doi":"https://doi.org/10.1145/3411508.3421376","mag":"3097924569"},"language":"en","primary_location":{"id":"doi:10.1145/3411508.3421376","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3411508.3421376","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5075251080","display_name":"Alexander Schl\u00f6gl","orcid":null},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Alexander Schl\u00f6gl","raw_affiliation_strings":["University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029455813","display_name":"Rainer B\u00f6hme","orcid":"https://orcid.org/0000-0003-4518-6227"},"institutions":[{"id":"https://openalex.org/I190249584","display_name":"Universit\u00e4t Innsbruck","ror":"https://ror.org/054pv6659","country_code":"AT","type":"education","lineage":["https://openalex.org/I190249584"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Rainer B\u00f6hme","raw_affiliation_strings":["University of Innsbruck, Innsbruck, Austria"],"affiliations":[{"raw_affiliation_string":"University of Innsbruck, Innsbruck, Austria","institution_ids":["https://openalex.org/I190249584"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5075251080"],"corresponding_institution_ids":["https://openalex.org/I190249584"],"apc_list":null,"apc_paid":null,"fwci":1.0605,"has_fulltext":false,"cited_by_count":23,"citation_normalized_percentile":{"value":0.82486299,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"93","last_page":"104"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8205280303955078},{"id":"https://openalex.org/keywords/homomorphic-encryption","display_name":"Homomorphic encryption","score":0.7621982097625732},{"id":"https://openalex.org/keywords/confidentiality","display_name":"Confidentiality","score":0.7150183916091919},{"id":"https://openalex.org/keywords/toolchain","display_name":"Toolchain","score":0.7044206857681274},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5923543572425842},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.5471502542495728},{"id":"https://openalex.org/keywords/outsourcing","display_name":"Outsourcing","score":0.5330613255500793},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4778059124946594},{"id":"https://openalex.org/keywords/dilemma","display_name":"Dilemma","score":0.47233691811561584},{"id":"https://openalex.org/keywords/layer","display_name":"Layer (electronics)","score":0.4653886556625366},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.4561275243759155},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41897130012512207},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3767935335636139},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.37596333026885986},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2599351406097412},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.24345022439956665},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2159704864025116}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8205280303955078},{"id":"https://openalex.org/C158338273","wikidata":"https://www.wikidata.org/wiki/Q2154943","display_name":"Homomorphic encryption","level":3,"score":0.7621982097625732},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.7150183916091919},{"id":"https://openalex.org/C2777062904","wikidata":"https://www.wikidata.org/wiki/Q545406","display_name":"Toolchain","level":3,"score":0.7044206857681274},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5923543572425842},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.5471502542495728},{"id":"https://openalex.org/C46934059","wikidata":"https://www.wikidata.org/wiki/Q61515","display_name":"Outsourcing","level":2,"score":0.5330613255500793},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4778059124946594},{"id":"https://openalex.org/C2778496695","wikidata":"https://www.wikidata.org/wiki/Q254128","display_name":"Dilemma","level":2,"score":0.47233691811561584},{"id":"https://openalex.org/C2779227376","wikidata":"https://www.wikidata.org/wiki/Q6505497","display_name":"Layer (electronics)","level":2,"score":0.4653886556625366},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.4561275243759155},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41897130012512207},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3767935335636139},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.37596333026885986},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2599351406097412},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.24345022439956665},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2159704864025116},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C178790620","wikidata":"https://www.wikidata.org/wiki/Q11351","display_name":"Organic chemistry","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3411508.3421376","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3411508.3421376","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.5299999713897705}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W47137029","https://openalex.org/W133884053","https://openalex.org/W398859631","https://openalex.org/W569478347","https://openalex.org/W1686810756","https://openalex.org/W1851422430","https://openalex.org/W2051267297","https://openalex.org/W2117539524","https://openalex.org/W2134670479","https://openalex.org/W2139750209","https://openalex.org/W2152161678","https://openalex.org/W2165698076","https://openalex.org/W2168231600","https://openalex.org/W2194775991","https://openalex.org/W2295464403","https://openalex.org/W2325939864","https://openalex.org/W2435473771","https://openalex.org/W2460441129","https://openalex.org/W2535690855","https://openalex.org/W2565439473","https://openalex.org/W2593390416","https://openalex.org/W2603766943","https://openalex.org/W2701059868","https://openalex.org/W2732026016","https://openalex.org/W2750990141","https://openalex.org/W2774510177","https://openalex.org/W2794357950","https://openalex.org/W2805074088","https://openalex.org/W2807403537","https://openalex.org/W2883613460","https://openalex.org/W2886576854","https://openalex.org/W2888798936","https://openalex.org/W2911433949","https://openalex.org/W2947718647","https://openalex.org/W2962883027","https://openalex.org/W2963311060","https://openalex.org/W2963844355","https://openalex.org/W2963857521","https://openalex.org/W2964318098","https://openalex.org/W2964590009","https://openalex.org/W2971196067","https://openalex.org/W2973232880","https://openalex.org/W3015806656","https://openalex.org/W3015844221","https://openalex.org/W4212774754","https://openalex.org/W4300072878"],"related_works":["https://openalex.org/W4387497383","https://openalex.org/W3183948672","https://openalex.org/W3173606202","https://openalex.org/W3110381201","https://openalex.org/W2948807893","https://openalex.org/W2935909890","https://openalex.org/W2778153218","https://openalex.org/W2758277628","https://openalex.org/W1531601525","https://openalex.org/W2013037783"],"abstract_inverted_index":{"Outsourcing":[0],"machine":[1,144],"learning":[2,145],"inference":[3,153],"creates":[4],"a":[5,44,95],"confidentiality":[6],"dilemma:":[7],"either":[8],"the":[9,14,22,40,73,86,90,99,104,134,137,158,168],"client":[10,100],"has":[11,24],"to":[12,25,66,84,107,167],"trust":[13],"server":[15,23],"with":[16],"potentially":[17],"sensitive":[18,159,174],"input":[19],"data,":[20],"or":[21,38],"share":[26],"his":[27],"commercially":[28],"valuable":[29],"model.":[30],"Known":[31],"remedies":[32],"include":[33],"homomorphic":[34],"encryption,":[35],"multi-party":[36],"computation,":[37],"placing":[39],"entire":[41],"model":[42,70,87,160],"in":[43,72],"trusted":[45,96],"enclave.":[46],"None":[47],"of":[48,77,136],"these":[49],"are":[50,165],"suitable":[51],"for":[52,129],"large":[53],"models.":[54],"For":[55],"two":[56],"relevant":[57],"use":[58],"cases,":[59],"we":[60],"show":[61,150],"that":[62,89,151],"it":[63],"is":[64,154,180],"possible":[65,155],"keep":[67],"all":[68,171],"confidential":[69,91],"parameters":[71,135,161],"last":[74],"(dense)":[75],"layers":[76,139,172],"deep":[78],"neural":[79],"networks.":[80],"This":[81,121],"allows":[82],"us":[83],"split":[85],"such":[88],"parts":[92],"fit":[93],"into":[94,116],"enclave":[97],"on":[98,142],"side.":[101],"We":[102],"present":[103],"eNNclave":[105],"toolchain":[106],"cut":[108],"TensorFlow":[109],"models":[110],"at":[111],"any":[112],"layer,":[113],"splitting":[114],"them":[115],"public":[117,130],"and":[118,126,176],"enclaved":[119,138],"layers.":[120],"preserves":[122],"TensorFlow's":[123],"performance":[124],"optimizations":[125],"hardware":[127],"support":[128],"layers,":[131],"while":[132,156],"keeping":[133,157],"private.":[140],"Evaluations":[141],"several":[143],"tasks":[146],"spanning":[147],"multiple":[148],"domains":[149],"fast":[152],"confidential.":[162],"Accuracy":[163],"results":[164],"close":[166],"baseline":[169],"where":[170],"carry":[173],"information":[175],"confirm":[177],"our":[178],"approach":[179],"practical.":[181]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":5}],"updated_date":"2026-02-26T08:16:20.718346","created_date":"2020-11-09T00:00:00"}
