[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-116913-en":3,"doc-seo-116913-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},116913,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Trusted Execution Environments in Protecting Machine Learning Models - Master of Science Thesis","Adoption of machine learning across industries has amplified concern over protecting intellectual property and sensitive information embedded in ML models. This thesis investigates Trusted Execution Environments (TEEs), focusing on Intel Software Guard Extensions (Intel SGX), as a way to execute ML-related workloads in isolated settings even when software must be distributed to clients or run in untrusted infrastructure. It analyzes how TEEs can protect ML model IP, which design aspects must be considered, and the limitations of existing approaches, including alternative TEE technologies.","Trusted Execution Environments in Protecting Machine Learning Models  \nMaster of Science Thesis  \nUniversity of Turku Department of Computing Computer Science  \n2023  \nMaks Turtiainen  \nThe originality of this thesis has been checked in accordance with the University of Turku quality assurance system using the Turnitin OriginalityCheck service.  \nUNIVERSITY OF TURKU Department of Computing  \nMaks Turtiainen: Trusted Execution Environments in Protecting Machine Learning Models  \nMaster of Science Thesis, 51 p.  \nComputer Science June 2023  \nThe adaptation and application of machine learning (ML) has grown extensively in recent years, and has awakened concern about the safety of intellectual property (IP) related to the machine learning models. The training of machine learning models is a time-consuming and expensive task, that has increased the demand of better solutions to protect the intellectual property of the machine learning models. This thesis explores the promising potential of Trusted Execution Environments (TEE) like Intel’s Software Guard Extensions (Intel SGX), in protecting intellectual property related to machine learning models. The concern of ML model safety arises especially when the software solution needs to be distributed to clients or machine learning operations needs to be done in an untrusted environment. The main focus of this thesis is on Intel’s SGX, which is one of the most used TEE implementations. This thesis tries to answer to the questions on how TEEs can be used to protect IP of the ML models, what aspects need to be considered and what limitations mayarise.  \nKeywords: Trusted Execution Environment, TEE, Software Guard Extension, Intel SGX, Machine Learning, Gramine  \nContents  \n1 Introduction 1  \n2 The Problem 4  \n2.1 Problem When Distributing Software .................. 4  \n2.2 Problem When Using Cloud Environments ............... 5  \n2.3 Limitations of Existing Approaches ................... 5  \n3 Previous Research 7  \n4 Machine Learning 13  \n4.1 Introduction to Artificial Intelligence .................. 13  \n4.2 Types of Machine Learning ........................ 17  \n4.2.1 Supervised Machine learning ................... 17  \n4.2.2 Unsupervised Machine Learning ................. 18  \n4.2.3 Reinforcement Learning ..................... 19  \n4.2.4 Deep Learning ........................... 19  \n4.3 Machine Learning Algorithms ...................... 19  \n5 Trusted Execution Environments 22  \n5.1 Use Cases ................................. 23  \n5.1.1 Protecting Intellectual Property ................. 23  \n5.1.2 Protecting Sensitive Personal Information ........... 23  \n5.1.3 Financial Services ......................... 23  \n5.1.4 Biometric Authentication .................... 24  \n5.2 Intel Software Guard Extensions (Intel SGX) .............. 24  \n5.2.1 Remote Attestation ........................ 25  \n5.2.2 Using Intel SGX on Linux .................... 26  \n5.2.3 Limitations ............................ 27  \n5.2.4 Gramine LibOS .......................... 28  \n5.3 AMD Secure Encrypted Virtualization (SEV) ............. 30  \n5.4 ARM TrustZone .............................. 30  \n5.5 Cloud Provider’s Solutions ........................ 30  \n6 Solution 32  \n6.1 Implementation .............................. 32  \n6.1.1 Description of the Data ...................... 35  \n6.1.2 Overview of the Application Stack ............... 35  \n6.1.3 Setting Up ............................. 38  \n6.1.4 Usage ............................... 42  \n6.2 Performance and Limitations ....................... 43  \n6.2.1 Testing Setup ........................... 44  \n6.2.2 Performance ............................ 45  \n6.2.3 Limitations and Drawbacks ................... 47  \n7 Conclusion 49  \nReferences 52  \nList of Figures  \n3.1 System overview of SecureTF from Secure TF: A Secure TensorFlow Framework ................................ 8  \n3.2 Query and load sequence diagram of proposed method from Securely Exposing Machine Learning Mo","cbCaigs0l5k4LOzi","https://ap.wps.com/l/cbCaigs0l5k4LOzi","pdf",2555950,1,62,"English","en",105,"# Introduction\n# The Problem\n## Problem When Distributing Software\n## Problem When Using Cloud Environments\n## Limitations of Existing Approaches\n# Previous Research\n# Machine Learning\n## Introduction to Artificial Intelligence\n## Types of Machine Learning\n## Machine Learning Algorithms\n# Trusted Execution Environments\n## Use Cases\n## Intel Software Guard Extensions (Intel SGX)\n## AMD Secure Encrypted Virtualization (SEV)\n## ARM TrustZone\n## Cloud Provider’s Solutions\n# Solution\n## Implementation\n## Performance and Limitations\n# Conclusion","[{\"question\":\"Why do ML model intellectual property protections become more important as machine learning adoption grows?\",\"answer\":\"ML models become valuable assets, but distributing software to clients or running ML operations in untrusted environments increases exposure. This raises risks related to intellectual property tied to the models.\"},{\"question\":\"How does this thesis use Trusted Execution Environments to protect ML model IP?\",\"answer\":\"The thesis explores TEEs as secure, isolated execution settings for sensitive computations. It emphasizes how TEEs can help safeguard ML-related workloads under untrusted conditions.\"},{\"question\":\"What aspects and limitations are examined for Intel SGX-based protection?\",\"answer\":\"The thesis focuses on key SGX elements such as remote attestation, how SGX is used on Linux, and the resulting limitations. It also evaluates performance and drawbacks in the proposed solution.\"}]","Trusted Execution Environments in Protecting Machine Learning Models - Master of Science Thesis | PDF",1785672478,156,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"trusted-execution-environments-in-protecting-machine-learning-models-master-of-science-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/trusted-execution-environments-in-protecting-machine-learning-models-master-of-science-thesis/116913/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do ML model intellectual property protections become more important as machine learning adoption grows?","Question",{"text":75,"@type":76},"ML models become valuable assets, but distributing software to clients or running ML operations in untrusted environments increases exposure. This raises risks related to intellectual property tied to the models.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does this thesis use Trusted Execution Environments to protect ML model IP?",{"text":80,"@type":76},"The thesis explores TEEs as secure, isolated execution settings for sensitive computations. It emphasizes how TEEs can help safeguard ML-related workloads under untrusted conditions.",{"name":82,"@type":73,"acceptedAnswer":83},"What aspects and limitations are examined for Intel SGX-based protection?",{"text":84,"@type":76},"The thesis focuses on key SGX elements such as remote attestation, how SGX is used on Linux, and the resulting limitations. It also evaluates performance and drawbacks in the proposed solution.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]