Skip to content
Open access

CC-Shield: A Unified Confidential ComputingFramework for Securing AI Model Training andInference

Aug 2026 · International Journal of Mathematical Sciences and Computing · Vol 12, pp. 81-94 · 0 citations

TL;DR

A seven-dimension qualitative comparison against fiveprior frameworks shows CC-Shield is the only approach satisfying data-in-use protection, computation integrity, training- and inference-time protection, quantum resistance, sub-15% latency overhead, and a formal security proofsimultaneously.

Abstract

Artificial-intelligence workloads increasingly process proprietary and personally identifiable data, yetconventional security controls protect data only at rest and in transit, leaving computation itself exposed. This paperpresents CC-Shield, a five-layer confidential-computing architecture that combines hardware trusted executionenvironments (Intel SGX, AMD SEV-SNP), differentially private federated aggregation, remote attestation, encryptedmodel lifecycle management, and LSTM-based anomaly detection into a single, formally analysed defence-in-depthstack. We derive a closed-form leakage bound that jointly composes TEE side-channel capacity and differential-privacynoise, prove three attack-resistance theorems covering membership inference, model inversion, and active-adversaryintegrity, and connect security overhead to system throughput via a queuing-theoretic performance model. On ResNet50/ImageNet, BERT-base/SST-2, and a clinical MLP on MIMIC-III, CC-Shield with differential privacy ( )reduces membership-inference attack success to 51.8% (statistically indistinguishable from the 50% random-chancebaseline at a 95% confidence half-width of approximately 1.0 percentage point over 10,000 attack queries), versus 71.3%for an unprotected baseline, while introducing only 11.9%-13.9% inference latency overhead – more than three ordersof magnitude lower than a homomorphic-encryption baseline. A seven-dimension qualitative comparison against fiveprior frameworks shows CC-Shield is the only approach satisfying data-in-use protection, computation integrity,training- and inference-time protection, quantum resistance, sub-15% latency overhead, and a formal security proofsimultaneously.

Read PDF

Similar papers

Preprint Aug 2026

SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring

This work introduces GASHE (Gradient-Aware Selective Homomorphic Encryption), a novel selective encryption strategy that dynamically identifies and encrypts only the gradient components exceeding a DP-calibrated sensitivity threshold, rather than encrypting all parameters uniformly as in static layer-based or full-parameter CKKS schemes.

Baran Can Gül, Hanuma Siddhartha Tunuguntla, Anjana Arvind Naik et al. · 0 citations
2025

LoRO: Real-Time on-Device Secure Inference for LLMs via TEE-Based Low Rank Obfuscation

While Large Language Models (LLMs) have gained remarkable success, they are consistently at risk of being stolen when deployed on untrusted edge devices. As a solution, TEE-based secure inference has been proposed to protect valuable model property. However, we identify a statistical vulnerability in existing protection methods, and furtherly compromise their security guarantees by proposed Model Stealing Attack with Prior. To eliminate this vulnerability, LoRO is presented in this paper, which leverages dense mask to completely obfuscate parameters. LoRO includes two innovations: (1) Low Rank Mask, which uses low-rank factors to generate dense masks efficiently. The computing complexity in TEE is hence reduced by an exponential amount to achieve inference speed up, while providing robust model confidentiality. (2) Factors Multiplexing, which reuses several cornerstone factors to generate masks for all layers. Compared to one-mask-per-layer, the secure memory requirement is reduced from GB-level to tens of MB, hence avoiding the hundred-fold latency introduced by secure memory paging. Experimental results indicate that LoRO achieve a 0 . 94 × Model Stealing (MS) accuracy, while SOTA methods presents 3 . 37 × at least. The averaged inference latency of LoRO is only 1 . 49 × , compared to the 112 × of TEE-shielded inference. Moreover, LoRO results no accuracy loss, and requires no re-training and structure modification. LoRO can solve the concerns regarding model thefts on edge devices in an efficient and secure manner, facilitating the wide edge application of LLMs.

Gaojian Xiong, Yu Sun, Jian-Hua Liu et al. · 5 citations
Open access Jul 2026

A Behaviour-Based Authentication and Encrypted Chunking Framework for Resilient Cloud Security

Cloud services lingers to transfigure information management and computation, it also presents momentous sanctuary apprehensions—predominantly in terms of identifying user credentials and secure information handling in decentralized networks. Outdated text-based access control mechanisms and even enhanced identity verification methods repeatedly fail to meet expectations in counter to advanced cyberattacks such as phishing schemes, identity compromise and session manipulations. To challenge these complications, this research presents an advanced, math-driven sanctuary prototype precisely premeditated for safe cloud computation. The projected model integrates three critical components: (1) data-level packet chunking, (2) AES-based encryption enhanced by a Dynamic Permutation Matrix (DPM), and (3) a new behaviour-driven authentication system called Behaviour-Linked One-Time Challenge (BLOC). This AI-powered validation technique powers behavioural biometrics such as typing undercurrents and mouse movement forms for safe and adaptive user proof. By uniting coarse data fortification and smart verification, the projected outline boosts privacy, veracity, and access control inside the cloud growth, offering greater flexibility against contemporary attack trajectories while upholding performance and scalability.

B. Sowmya, Meeravali Shaik · 0 citations
Conference Open access Jul 2026

MOSAIC-FL, a Micro-Service Based Privacy-Preserving Framework with Application to Genomics

The FL framework integrates an efficient gRPC communication layer and a Finite State Machine to ensure robust component synchronization and threat detection, while relying on a fault-tolerant secure aggregation protocol using a Threshold variant of the CKKS homomorphic cryptosystem.

P. Largillier, Karl Paygambar, Cédric Gouy-Pailler et al. · 0 citations
Open access Aug 2026

RAFALE: Runtime Attestation for Secure and Trustworthy Federated Learning on Edge Devices

Federated learning (FL) enables training on edge devices, but update-based defenses may overlook runtime tampering, control-flow manipulation, and microarchitectural attacks. RAFALE strengthens integrity through verifiable runtime evidence collected during local training. Control-Flow Integrity (CFI) evidence and Hardware Performance Counter (HPC) measurements obtained through the normal-world performance-monitoring interface are transferred to an OP-TEE Trusted Application, where they are bound to the training round and model update, digested, and signed for server verification. RAFALE was implemented on Raspberry Pi 3B+ clients and evaluated using convolutional neural networks on MNIST and CIFAR-10. Physical-device trials distinguished benign execution from loss-function omission and indirect-target redirection. At T=2 and K=2, HPC-based detection achieved 83.88% accuracy, 91.94% precision, 76.39% recall, an F1-score of 83.44%, and a 7.60% false positive rate. Combined CFI/HPC monitoring required 29.653s per Raspberry Pi training run. Authentication of one physical-device evidence and model record averaged 1.513ms, and each evidence record occupied 588bytes. A 64-client simulation showed that admitting redirected adversarial updates reduced balanced CIFAR-10 accuracy from 68.59% to 25.49% at 50% malicious participation. These results show that authenticated runtime evidence can distinguish the evaluated execution deviations without revealing local training data.

Pravin Srivastav, Anandpreet Kaur, Bibhas Ghoshal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.