Confidential Machine Learning Computation in Untrusted Environments: A Systems Security Perspective
arXiv:2111.03308 · doi:10.1109/ACCESS.2021.3136889
Abstract
As machine learning (ML) technologies and applications are rapidly changing many computing domains, security issues associated with ML are also emerging. In the domain of systems security, many endeavors have been made to ensure ML model and data confidentiality. ML computations are often inevitably performed in untrusted environments and entail complex multi-party security requirements. Hence, researchers have leveraged the Trusted Execution Environments (TEEs) to build confidential ML computation systems. We conduct a systematic and comprehensive survey by classifying attack vectors and mitigation in confidential ML computation in untrusted environments, analyzing the complex security requirements in multi-party scenarios, and summarizing engineering challenges in confidential ML implementation. Lastly, we suggest future research directions based on our study.
Published to IEEE Access, URL: https://ieeexplore.ieee.org/document/9656734
References in corpus (19)
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- Stealing Machine Learning Models via Prediction APIs
- Software Grand Exposure: SGX Cache Attacks Are Practical
- Differential Privacy and Machine Learning: a Survey and Review
- Practical Secure Aggregation for Federated Learning on User-Held Data
- DarkneTZ: Towards Model Privacy at the Edge using Trusted Execution Environments
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX
- SGXIO: Generic Trusted I/O Path for Intel SGX
- Twine: An Embedded Trusted Runtime for WebAssembly
- PPFL: Privacy-preserving Federated Learning with Trusted Execution Environments
- Stealing Links from Graph Neural Networks
- secureTF: A Secure TensorFlow Framework
- TensorSCONE: A Secure TensorFlow Framework using Intel SGX
- Offline Model Guard: Secure and Private ML on Mobile Devices
- Privacy-Preserving Inference in Machine Learning Services Using Trusted Execution Environments
- Enabling Privacy-Preserving, Compute- and Data-Intensive Computing using Heterogeneous Trusted Execution Environment
- DeepPeep: Exploiting Design Ramifications to Decipher the Architecture of Compact DNNs
- Perun: Secure Multi-Stakeholder Machine Learning Framework with GPU Support
- Citadel: Protecting Data Privacy and Model Confidentiality for Collaborative Learning with SGX