Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
4 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

DarkneTZ: Towards Model Privacy at the Edge using Trusted Execution Environments (2004.05703v1)

Published 12 Apr 2020 in cs.LG, cs.CR, and stat.ML

Abstract: We present DarkneTZ, a framework that uses an edge device's Trusted Execution Environment (TEE) in conjunction with model partitioning to limit the attack surface against Deep Neural Networks (DNNs). Increasingly, edge devices (smartphones and consumer IoT devices) are equipped with pre-trained DNNs for a variety of applications. This trend comes with privacy risks as models can leak information about their training data through effective membership inference attacks (MIAs). We evaluate the performance of DarkneTZ, including CPU execution time, memory usage, and accurate power consumption, using two small and six large image classification models. Due to the limited memory of the edge device's TEE, we partition model layers into more sensitive layers (to be executed inside the device TEE), and a set of layers to be executed in the untrusted part of the operating system. Our results show that even if a single layer is hidden, we can provide reliable model privacy and defend against state of the art MIAs, with only 3% performance overhead. When fully utilizing the TEE, DarkneTZ provides model protections with up to 10% overhead.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (7)
  1. Fan Mo (17 papers)
  2. Ali Shahin Shamsabadi (27 papers)
  3. Kleomenis Katevas (20 papers)
  4. Soteris Demetriou (17 papers)
  5. Ilias Leontiadis (29 papers)
  6. Andrea Cavallaro (59 papers)
  7. Hamed Haddadi (131 papers)
Citations (158)

Summary

We haven't generated a summary for this paper yet.