11 papers
MOSAIC: Masked Outsourcing of Secure AI Computations
James Hsin-yu Chiang, Sheila Zingg, Kari Kostiainen +1
We address the challenge of securely and efficiently outsourcing AI computations from a trusted but computationally weak client to an untrusted but powerful server, in the setting…
Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations
Sheila Zingg, Daniele Lain, Yoshimichi Nakatsuka +3
The European Union will introduce the EUDI Wallet by late 2026, which allows users to hold digital credentials (i.e., representations of physical official identity documents) on th…
Security Analysis of Time-of-Arrival Estimation via Cross-Correlation under Narrow-Band Conditions
Claudio Anliker, Daniele Coppola, Giovanni Camurati +1
Time-of-arrival (ToA) estimation via cross-correlation is an essential building block of time-of-flight ranging. However, in narrowband systems, it is notoriously difficult to prot…
Can LLMs Make (Personalized) Access Control Decisions?
Friederike Groschupp, Daniele Lain, Aritra Dhar +2
Precise access control decisions are crucial for the security of both traditional applications and emerging agent-based systems. Typically, these decisions are made by users during…
Gyokuro: Source-assisted Private Membership Testing using Trusted Execution Environments
Yoshimichi Nakatsuka, Nicolas Dutly, Kari Kostiainen +1
Private Membership Testing (PMT) protocols enable clients to verify whether a certain data item is included in a database without revealing the item to the database operator or oth…
Devlore: Device Interrupt Protection for Confidential VMs
Andrin Bertschi, Supraja Sridhara, Mark Kuhne +8
Modern confidential computing executes sensitive computation in an abstraction called confidential VMs and protects from the hypervisor, host OS, and other co-resident VMs. It has…