{"id":"https://openalex.org/W7134928687","doi":"https://doi.org/10.1145/3779212.3790247","title":"<scp>Wave</scp> : Leveraging Architecture Observation for Privacy-Preserving Model Oversight","display_name":"<scp>Wave</scp> : Leveraging Architecture Observation for Privacy-Preserving Model Oversight","publication_year":2026,"publication_date":"2026-03-10","ids":{"openalex":"https://openalex.org/W7134928687","doi":"https://doi.org/10.1145/3779212.3790247"},"language":null,"primary_location":{"id":"doi:10.1145/3779212.3790247","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779212.3790247","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3779212.3790247","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Haoxuan Xu","orcid":"https://orcid.org/0009-0006-0252-3376"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Haoxuan Xu","raw_affiliation_strings":["University of Southern California, Los Angeles, CA, USA"],"raw_orcid":"https://orcid.org/0009-0006-0252-3376","affiliations":[{"raw_affiliation_string":"University of Southern California, Los Angeles, CA, USA","institution_ids":["https://openalex.org/I1174212"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Chen Gong","orcid":"https://orcid.org/0009-0001-9573-3041"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chen Gong","raw_affiliation_strings":["University of Southern California, Los Angeles, CA, USA"],"raw_orcid":"https://orcid.org/0009-0001-9573-3041","affiliations":[{"raw_affiliation_string":"University of Southern California, Los Angeles, CA, USA","institution_ids":["https://openalex.org/I1174212"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Beijie Liu","orcid":"https://orcid.org/0009-0005-7218-8844"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Beijie Liu","raw_affiliation_strings":["University of Southern California, Los Angeles, CA, USA"],"raw_orcid":"https://orcid.org/0009-0005-7218-8844","affiliations":[{"raw_affiliation_string":"University of Southern California, Los Angeles, CA, USA","institution_ids":["https://openalex.org/I1174212"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126656877","display_name":"Haizhong Zheng","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Haizhong Zheng","raw_affiliation_strings":["Carnegie Mellon University, Pittsburgh, PA, USA"],"raw_orcid":"https://orcid.org/0000-0003-0478-4028","affiliations":[{"raw_affiliation_string":"Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073845046","display_name":"Beidi Chen","orcid":"https://orcid.org/0009-0009-9166-6476"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Beidi Chen","raw_affiliation_strings":["Carnegie Mellon University, Pittsburgh, CA, USA"],"raw_orcid":"https://orcid.org/0009-0009-9166-6476","affiliations":[{"raw_affiliation_string":"Carnegie Mellon University, Pittsburgh, CA, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5005336771","display_name":"M. H. Li","orcid":null},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mengyuan Li","raw_affiliation_strings":["University of Southern California, Los Angeles, CA, USA"],"raw_orcid":"https://orcid.org/0009-0008-2721-4021","affiliations":[{"raw_affiliation_string":"University of Southern California, Los Angeles, CA, USA","institution_ids":["https://openalex.org/I1174212"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I1174212"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.48882474,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2212","last_page":"2231"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.20880000293254852,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.20880000293254852,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.20829999446868896,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11986","display_name":"Scientific Computing and Data Management","score":0.09619999676942825,"subfield":{"id":"https://openalex.org/subfields/1802","display_name":"Information Systems and Management"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.6010000109672546},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5569999814033508},{"id":"https://openalex.org/keywords/visibility","display_name":"Visibility","score":0.5564000010490417},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.487199991941452},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.48089998960494995},{"id":"https://openalex.org/keywords/provisioning","display_name":"Provisioning","score":0.4555000066757202}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8253999948501587},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.6010000109672546},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5569999814033508},{"id":"https://openalex.org/C123403432","wikidata":"https://www.wikidata.org/wiki/Q654068","display_name":"Visibility","level":2,"score":0.5564000010490417},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.487199991941452},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.48089998960494995},{"id":"https://openalex.org/C172191483","wikidata":"https://www.wikidata.org/wiki/Q1071806","display_name":"Provisioning","level":2,"score":0.4555000066757202},{"id":"https://openalex.org/C44210515","wikidata":"https://www.wikidata.org/wiki/Q16968978","display_name":"Bespoke","level":2,"score":0.43050000071525574},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.4244999885559082},{"id":"https://openalex.org/C37279795","wikidata":"https://www.wikidata.org/wiki/Q2492305","display_name":"Consistency model","level":3,"score":0.38530001044273376},{"id":"https://openalex.org/C110251889","wikidata":"https://www.wikidata.org/wiki/Q1569697","display_name":"Model checking","level":2,"score":0.3582000136375427},{"id":"https://openalex.org/C2779227376","wikidata":"https://www.wikidata.org/wiki/Q6505497","display_name":"Layer (electronics)","level":2,"score":0.28450000286102295},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2816999852657318},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.2784999907016754},{"id":"https://openalex.org/C103088060","wikidata":"https://www.wikidata.org/wiki/Q1062839","display_name":"Error detection and correction","level":2,"score":0.2587999999523163},{"id":"https://openalex.org/C82029504","wikidata":"https://www.wikidata.org/wiki/Q4373882","display_name":"Sequential consistency","level":4,"score":0.2554999887943268},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.2547000050544739}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3779212.3790247","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779212.3790247","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3779212.3790247","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779212.3790247","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":17,"referenced_works":["https://openalex.org/W2083350792","https://openalex.org/W2806442079","https://openalex.org/W2891810898","https://openalex.org/W2897213586","https://openalex.org/W2979340153","https://openalex.org/W2991603322","https://openalex.org/W3102836279","https://openalex.org/W3128479244","https://openalex.org/W3210673560","https://openalex.org/W4210613944","https://openalex.org/W4233819588","https://openalex.org/W4297677511","https://openalex.org/W4387321091","https://openalex.org/W4394907743","https://openalex.org/W4394944658","https://openalex.org/W4405183082","https://openalex.org/W4406266037"],"related_works":[],"abstract_inverted_index":{"Large":[0],"Language":[1],"Models":[2],"(LLMs)":[3],"inference":[4],"increasingly":[5],"require":[6],"mechanisms":[7],"that":[8,30,46,148],"provide":[9],"runtime":[10,181],"visibility":[11],"into":[12],"what":[13],"is":[14,41],"actually":[15],"executing,":[16],"without":[17],"exposing":[18],"model":[19,52,152],"weights":[20],"or":[21],"code.":[22],"We":[23,121],"present":[24],"WAVE,":[25],"a":[26,50,79,175],"hardware-grounded":[27],"monitoring":[28,182],"framework":[29],"leverages":[31],"GPU":[32,137],"performance":[33],"counters":[34],"(PMCs)":[35],"to":[36,106],"observe":[37],"LLM":[38,127,184],"inference.":[39],"WAVE":[40,72,123,149,173],"built":[42],"on":[43,124],"the":[44,68,96,109,113,117],"insight":[45],"legitimate":[47],"executions":[48,163],"of":[49,158,183],"given":[51],"must":[53],"satisfy":[54],"hardware-constrained":[55],"invariants,":[56,172],"such":[57,129],"as":[58,130],"memory":[59],"accesses,":[60],"instruction":[61],"mix,":[62],"and":[63,77,99,116,133,144,160],"tensor-core":[64],"utilization,":[65],"induced":[66],"by":[67],"model's":[69,119],"linear-algebraic":[70],"structure.":[71],"collects":[73],"lightweight":[74],"PMC":[75],"traces":[76],"applies":[78],"two-stage":[80],"pipeline:":[81],"(1)":[82],"inferring":[83],"architectural":[84],"properties":[85],"(e.g.,":[86],"parameter":[87],"count,":[88],"layer":[89],"depth,":[90],"hidden":[91],"dimension,":[92],"batch":[93],"size)":[94],"from":[95],"observed":[97],"traces;":[98],"(2)":[100],"using":[101],"an":[102,155],"SMT-based":[103],"consistency":[104],"checker":[105],"assess":[107],"whether":[108],"execution":[110],"aligns":[111],"with":[112,154],"provisioned":[114],"compute":[115],"claimed":[118],"constraints.":[120],"evaluate":[122],"common":[125],"open-source":[126],"architectures,":[128,138],"LLaMA,":[131],"GPT,":[132],"Qwen,":[134],"across":[135],"multiple":[136],"including":[139],"NVIDIA":[140],"Ada":[141],"Lovelace,":[142],"Hopper,":[143],"Blackwell.":[145],"Results":[146],"show":[147],"recovers":[150],"key":[151],"parameters":[153],"average":[156],"error":[157],"6.8%":[159],"identifies":[161],"disguised":[162],"under":[164],"realistic":[165],"perturbations.":[166],"By":[167],"grounding":[168],"oversight":[169],"in":[170],"hardware":[171],"provides":[174],"practical":[176],"avenue":[177],"for":[178],"continuous,":[179],"privacy-preserving":[180],"services.":[185]},"counts_by_year":[],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2026-03-12T00:00:00"}
