SearcharxivSearch

arXiv subjects

Felix Maurer

Publications and source records attributed to Felix Maurer.

4 recordsLinked to original sources

TrEEStealer: Stealing Decision Trees via Enclave Side Channels

Today, machine learning is widely applied in sensitive, security-related, and financially lucrative applications. Model extraction attacks undermine current business models where a model owner sells model access, e.g., via MLaaS APIs. Additionally, stolen models can enable powerful white-box attacks, facilitating privacy attacks on sensitive training data, and model evasion. In this paper, we focus on Decision Trees (DT), which are widely deployed in practice. Existing black-box extraction attacks for DTs are either query-intensive, make strong assumptions about the DT structure, or rely on rich API information. To limit attacks to the black-box setting, CPU vendors introduced Trusted Execution Environments (TEE) that use hardware-mechanisms to isolate workloads from external parties, e.g., MLaaS providers. We introduce TrEEStealer, a high-fidelity extraction attack for stealing TEE-protected DTs. TrEEStealer exploits TEE-specific side-channels to steal DTs efficiently and without strong assumptions about the API output or DT structure. The extraction efficacy stems from a novel algorithm that maximizes the information derived from each query by coupling Control-Flow Information (CFI) with passive information tracking. We use two primitives to acquire CFI: for AMD SEV, we follow previous work using the SEV-Step framework and performance counters. For Intel SGX, we reproduce prior findings on current Xeon 6 CPUs and construct a new primitive to efficiently extract the branch history of inference runs through the Branch-History-Register. We found corresponding vulnerabilities in three popular libraries: OpenCV, mlpack, and emlearn. We show that TrEEStealer achieves superior efficiency and extraction fidelity compared to prior attacks. Our work establishes a new state-of-the-art for DT extraction and confirms that TEEs fail to protect against control-flow leakage.

cs.CR

ReDASH: Fast and efficient Scaling in Arithmetic Garbled Circuits for Secure Outsourced Inference

ReDash extends Dash's arithmetic garbled circuits to provide a more flexible and efficient framework for secure outsourced inference. By introducing a novel garbled scaling gadget based on a generalized base extension for the residue number system, ReDash removes Dash's limitation of scaling exclusively by powers of two. This enables arbitrary scaling factors drawn from the residue number system's modular base, allowing for tailored quantization schemes and more efficient model evaluation. Through the new $\text{ScaleQuant}^+$ quantization mechanism, ReDash supports optimized modular bases that can significantly reduce the overhead of arithmetic operations during convolutional neural network inference. ReDash achieves up to a 33-fold speedup in overall inference time compared to Dash Despite these enhancements, ReDash preserves the robust security guarantees of arithmetic garbling. By delivering both performance gains and quantization flexibility, ReDash expands the practicality of garbled convolutional neural network inference.

cs.CR

Competing aggregation and iso-density equilibrium lead to band pattern formation in density gradients

Centrifugation of biological matter in density gradient solutions is a standard method for separating cell types or components. It is also used to separate red blood cells (RBCs) by age, as they lose water and become denser over their lifespan. When the density gradient is prepared with Percoll, discrete bands of RBCs are systematically observed along the gradient, despite the continuous density distribution of RBCs. Early studies suggested that cell aggregation might influence spatial distribution, but it remains debated whether a continuous density population can form discrete bands. We developed a continuity equation incorporating cell aggregation to describe the macroscopic evolution of RBC volume fraction in a density gradient, considering a continuous RBC density distribution. Numerical solutions demonstrate that the competition between isodensity distribution and aggregation is sufficient to create band patterns. Our model reproduces the temporal evolution observed in experiments, but also predicts several types of bifurcation-like behaviors for the steady-state patterns in constant gradients, depending on RBC volume fraction and aggregation energy. This demonstrates that the competition between RBC aggregation and iso-density distribution is a novel mechanism driving pattern formation.

cond-mat.soft

Deposit of Red Blood Cells at low concentrations in evaporating droplets: central edge growth and potential applications

Evaporation of blood droplets and diluted blood samples is a topic of intensive research, as it is seen as a possible low-cost tool for diagnosis. So far, samples with volume fraction down to a few percents of Red Blood Cells (RBCs) have been studied, and those were reportedly dominated by a ``coffee-ring'' deposit. In this study, samples with lower volume fractions have been used in order to study the growth of the evaporative deposit from sessile droplets more in details. We observed that blood samples and salt solutions with less than 1\% volume fraction of RBCs are dominated by a central deposit. We characterized the growth process of this central deposit by evaporating elongated drops, and determined that it is consistent with the Kardar-Parisi-Zhang process in the presence of quenched disorder. Our results showed a sensitivity of this deposit size to the fibrinogen concentration and shape of the RBCs, meaning that this parameter could be used to develop a new and cost-effective clinical marker for inflammation and RBC deformation.

cond-mat.soft