{"id":"https://openalex.org/W3205334056","doi":"https://doi.org/10.1145/3466752.3480112","title":"DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted Hardware","display_name":"DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted Hardware","publication_year":2021,"publication_date":"2021-10-17","ids":{"openalex":"https://openalex.org/W3205334056","doi":"https://doi.org/10.1145/3466752.3480112","mag":"3205334056"},"language":"en","primary_location":{"id":"doi:10.1145/3466752.3480112","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3466752.3480112","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3466752.3480112","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3466752.3480112","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5070386139","display_name":"Hanieh Hashemi","orcid":null},"institutions":[{"id":"https://openalex.org/I2800817003","display_name":"Southern California University for Professional Studies","ror":"https://ror.org/058zz0t50","country_code":"US","type":"education","lineage":["https://openalex.org/I2800817003"]},{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Hanieh Hashemi","raw_affiliation_strings":["University of Southern California"],"affiliations":[{"raw_affiliation_string":"University of Southern California","institution_ids":["https://openalex.org/I2800817003","https://openalex.org/I1174212"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103063936","display_name":"Yongqin Wang","orcid":"https://orcid.org/0009-0005-5076-7706"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]},{"id":"https://openalex.org/I2800817003","display_name":"Southern California University for Professional Studies","ror":"https://ror.org/058zz0t50","country_code":"US","type":"education","lineage":["https://openalex.org/I2800817003"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yongqin Wang","raw_affiliation_strings":["University of Southern California, United States of America"],"affiliations":[{"raw_affiliation_string":"University of Southern California, United States of America","institution_ids":["https://openalex.org/I2800817003","https://openalex.org/I1174212"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5018033573","display_name":"Murali Annavaram","orcid":"https://orcid.org/0000-0002-4633-6867"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]},{"id":"https://openalex.org/I2800817003","display_name":"Southern California University for Professional Studies","ror":"https://ror.org/058zz0t50","country_code":"US","type":"education","lineage":["https://openalex.org/I2800817003"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Murali Annavaram","raw_affiliation_strings":["University of Southern California, United States of America"],"affiliations":[{"raw_affiliation_string":"University of Southern California, United States of America","institution_ids":["https://openalex.org/I2800817003","https://openalex.org/I1174212"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5070386139"],"corresponding_institution_ids":["https://openalex.org/I1174212","https://openalex.org/I2800817003"],"apc_list":null,"apc_paid":null,"fwci":4.6199,"has_fulltext":true,"cited_by_count":49,"citation_normalized_percentile":{"value":0.95587917,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"212","last_page":"224"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.852482795715332},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.7924736738204956},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.7143760919570923},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.6412678956985474},{"id":"https://openalex.org/keywords/data-integrity","display_name":"Data integrity","score":0.5531854629516602},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5459827184677124},{"id":"https://openalex.org/keywords/masking","display_name":"Masking (illustration)","score":0.5449404716491699},{"id":"https://openalex.org/keywords/encoding","display_name":"Encoding (memory)","score":0.47259148955345154},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.4522581100463867},{"id":"https://openalex.org/keywords/trusted-computing","display_name":"Trusted Computing","score":0.4275680482387543},{"id":"https://openalex.org/keywords/hardware-security-module","display_name":"Hardware security module","score":0.42315560579299927},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.4118429720401764},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.41171154379844666},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.3689020276069641},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.21879342198371887},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.18238642811775208},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.15372934937477112},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.11087596416473389}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.852482795715332},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.7924736738204956},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.7143760919570923},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.6412678956985474},{"id":"https://openalex.org/C33762810","wikidata":"https://www.wikidata.org/wiki/Q461671","display_name":"Data integrity","level":2,"score":0.5531854629516602},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5459827184677124},{"id":"https://openalex.org/C2777402240","wikidata":"https://www.wikidata.org/wiki/Q6783436","display_name":"Masking (illustration)","level":2,"score":0.5449404716491699},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.47259148955345154},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.4522581100463867},{"id":"https://openalex.org/C2776831232","wikidata":"https://www.wikidata.org/wiki/Q966812","display_name":"Trusted Computing","level":2,"score":0.4275680482387543},{"id":"https://openalex.org/C39217717","wikidata":"https://www.wikidata.org/wiki/Q1432354","display_name":"Hardware security module","level":3,"score":0.42315560579299927},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.4118429720401764},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.41171154379844666},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.3689020276069641},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.21879342198371887},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.18238642811775208},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.15372934937477112},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.11087596416473389},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3466752.3480112","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3466752.3480112","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3466752.3480112","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3466752.3480112","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3466752.3480112","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3466752.3480112","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.5799999833106995,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1555293057","display_name":null,"funder_award_id":"HR001120C0088","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G4842797379","display_name":null,"funder_award_id":"HR001117C0053","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G606531454","display_name":null,"funder_award_id":"5345039074","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320306078","display_name":"U.S. Department of Defense","ror":"https://ror.org/0447fe631"},{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"},{"id":"https://openalex.org/F4320332815","display_name":"Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3205334056.pdf","grobid_xml":"https://content.openalex.org/works/W3205334056.grobid-xml"},"referenced_works_count":70,"referenced_works":["https://openalex.org/W72012145","https://openalex.org/W381682963","https://openalex.org/W1247015877","https://openalex.org/W1686810756","https://openalex.org/W1904114845","https://openalex.org/W1981029888","https://openalex.org/W1993931385","https://openalex.org/W2023401109","https://openalex.org/W2031533839","https://openalex.org/W2053637704","https://openalex.org/W2093144089","https://openalex.org/W2099111195","https://openalex.org/W2117539524","https://openalex.org/W2150620897","https://openalex.org/W2187244164","https://openalex.org/W2194775991","https://openalex.org/W2259324379","https://openalex.org/W2286365479","https://openalex.org/W2397423248","https://openalex.org/W2435473771","https://openalex.org/W2463516579","https://openalex.org/W2473418344","https://openalex.org/W2478708596","https://openalex.org/W2586702902","https://openalex.org/W2606774910","https://openalex.org/W2607255160","https://openalex.org/W2616901112","https://openalex.org/W2701059868","https://openalex.org/W2765200655","https://openalex.org/W2767079719","https://openalex.org/W2805074088","https://openalex.org/W2886636392","https://openalex.org/W2895865029","https://openalex.org/W2899435347","https://openalex.org/W2940542208","https://openalex.org/W2950321888","https://openalex.org/W2953150480","https://openalex.org/W2963000099","https://openalex.org/W2963163009","https://openalex.org/W2963374099","https://openalex.org/W2963733194","https://openalex.org/W2963752132","https://openalex.org/W2964299589","https://openalex.org/W2966325922","https://openalex.org/W2969388332","https://openalex.org/W2970408908","https://openalex.org/W2975828523","https://openalex.org/W2979832172","https://openalex.org/W2985805285","https://openalex.org/W2992389096","https://openalex.org/W3011434423","https://openalex.org/W3014541599","https://openalex.org/W3016075089","https://openalex.org/W3021878953","https://openalex.org/W3024430195","https://openalex.org/W3036349229","https://openalex.org/W3043192809","https://openalex.org/W3043791176","https://openalex.org/W3080934051","https://openalex.org/W3093385444","https://openalex.org/W3097981673","https://openalex.org/W3102407811","https://openalex.org/W3153868986","https://openalex.org/W3157084143","https://openalex.org/W3175329822","https://openalex.org/W3176786489","https://openalex.org/W3181552337","https://openalex.org/W4232172926","https://openalex.org/W4239982965","https://openalex.org/W4289038676"],"related_works":["https://openalex.org/W3186150091","https://openalex.org/W2759901721","https://openalex.org/W4321192641","https://openalex.org/W2566543615","https://openalex.org/W2911286527","https://openalex.org/W4311080747","https://openalex.org/W4378501452","https://openalex.org/W2957985992","https://openalex.org/W4230279121","https://openalex.org/W2887002521"],"abstract_inverted_index":{"Privacy":[0],"and":[1,48,79,92,99,157,170,185],"security-related":[2],"concerns":[3],"are":[4,31,38],"growing":[5],"as":[6,28],"machine":[7],"learning":[8],"reaches":[9],"diverse":[10],"application":[11],"domains.":[12],"The":[13,136],"data":[14,23,47,122,138,150,155],"holders":[15],"want":[16],"to":[17,40,112,129,142,181],"train":[18],"or":[19],"infer":[20],"with":[21,61],"private":[22],"while":[24,75,102],"exploiting":[25],"accelerators,":[26,93],"such":[27,53],"GPUs,":[29],"that":[30,42],"hosted":[32],"in":[33,160],"the":[34,44,95,105,108,114,161],"cloud.":[35],"Cloud":[36],"systems":[37],"vulnerable":[39],"attackers":[41],"compromise":[43],"privacy":[45,59,78,98,156,169],"of":[46,50,107],"integrity":[49,100,159],"computations.":[51],"Tackling":[52],"a":[54,69,120,134],"challenge":[55],"requires":[56],"unifying":[57],"theoretical":[58],"algorithms":[60],"hardware":[62],"security":[63],"capabilities.":[64],"This":[65],"paper":[66],"presents":[67],"DarKnight,":[68],"framework":[70],"for":[71,144,174],"large":[72],"DNN":[73],"training":[74,184],"protecting":[76],"input":[77,131],"computation":[80,111,158],"integrity.":[81],"DarKnight":[82,118],"relies":[83],"on":[84,126],"cooperative":[85],"execution":[86,89],"between":[87],"trusted":[88],"environments":[90],"(TEE)":[91],"where":[94],"TEE":[96],"provides":[97,153],"verification,":[101],"accelerators":[103],"perform":[104],"bulk":[106],"linear":[109,146],"algebraic":[110,147],"optimize":[113],"performance.":[115],"In":[116],"particular,":[117],"uses":[119],"customized":[121],"encoding":[123,177],"strategy":[124,152],"based":[125],"matrix":[127],"masking":[128],"create":[130],"obfuscation":[132,151],"within":[133],"TEE.":[135],"obfuscated":[137],"is":[139,179],"then":[140],"offloaded":[141],"GPUs":[143],"fast":[145],"computation.":[148],"DarKnight\u2019s":[149,176],"provable":[154],"cloud":[162],"servers.":[163],"While":[164],"prior":[165],"works":[166],"tackle":[167],"inference":[168],"cannot":[171],"be":[172],"utilized":[173],"training,":[175],"scheme":[178],"designed":[180],"support":[182],"both":[183],"inference.":[186]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":13},{"year":2024,"cited_by_count":13},{"year":2023,"cited_by_count":13},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":2}],"updated_date":"2026-04-23T09:07:50.710637","created_date":"2025-10-10T00:00:00"}
