CC-Shield: A Unified Confidential Computing Framework for Securing AI Model Training and Inference
Автор: Gaurav Saxena
Журнал: International Journal of Mathematical Sciences and Computing @ijmsc
Статья в выпуске: 3 vol.12, 2026 года.
Бесплатный доступ
Artificial-intelligence workloads increasingly process proprietary and personally identifiable data, yet conventional security controls protect data only at rest and in transit, leaving computation itself exposed. This paper presents CC-Shield, a five-layer confidential-computing architecture that combines hardware trusted execution environments (Intel SGX, AMD SEV-SNP), differentially private federated aggregation, remote attestation, encrypted model lifecycle management, and LSTM-based anomaly detection into a single, formally analysed defence-in-depth stack. We derive a closed-form leakage bound that jointly composes TEE side-channel capacity and differential-privacy noise, prove three attack-resistance theorems covering membership inference, model inversion, and active-adversary integrity, and connect security overhead to system throughput via a queuing-theoretic performance model. On ResNet-50/ImageNet, BERT-base/SST-2, and a clinical MLP on MIMIC-III, CC-Shield with differential privacy (ε=1) reduces membership-inference attack success to 51.8% (statistically indistinguishable from the 50% random-chance baseline at a 95% confidence half-width of approximately 1.0 percentage point over 10,000 attack queries), versus 71.3% for an unprotected baseline, while introducing only 11.9%-13.9% inference latency overhead – more than three orders of magnitude lower than a homomorphic-encryption baseline. A seven-dimension qualitative comparison against five prior frameworks shows CC-Shield is the only approach satisfying data-in-use protection, computation integrity, training- and inference-time protection, quantum resistance, sub-15% latency overhead, and a formal security proof simultaneously.
Confidential Computing, Trusted Execution Environments, AI Model Security, Intel SGX, AMD SEV, Federated Learning, Model Inversion Attacks, Membership Inference, Differential Privacy, Homomorphic Encryption, TEE Attestation, Privacy-Preserving Machine Lea
Короткий адрес: https://sciup.org/15020529
IDR: 15020529 | DOI: 10.5815/ijmsc.2026.03.05