A Verifiable Delivery Framework for Web Applications That Use Trusted Execution Environments
Bibliographic record
Abstract
Web applications have become increasingly popular, as they are convenient for many computing tasks and are accessible from any device with a web browser. Although existing web security mechanisms such as TLS, CSP and SRI protect against a variety of threats, web applications are still vulnerable to insider attacks in which a malicious hosting server delivers an altered version of the application. This threat is particularly critical for web applications that employ trusted execution environments (TEE), as a lack of verifiability of the application's code undermines the confidentiality guarantees provided by TEE. To ensure that sensitive data is sent to an authentic TEE, such web applications rely on browser extensions to perform critical operations such as attestation and communication, as they are isolated from the web application and thereby shielded from tampering. However, this is not a scalable approach as it is infeasible for users to install application-specific browser extensions for every TEE-enabled web application. In this work, we present a scalable method for trustworthy delivery and user-verifiable attestation for web applications that use TEEs to provide privacy guarantees for user input. To evaluate a proof-of-concept of our method, we implemented a web application that uses a TEE-based password authentication service called SafeKeeper. We then extended Meta's Code Verify browser extension to validate the integrity of our web application's code, which includes TEE-specific operations, thereby eliminating the need for a separate application-specific browser extension. This method ensures both the integrity of the delivered application and the confidentiality of user input, offering a unified and scalable solution for the trustworthy delivery of web applications that use TEEs.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.007 | 0.011 |
| Meta-epidemiology (narrow) | 0.001 | 0.002 |
| Meta-epidemiology (broad) | 0.001 | 0.002 |
| Bibliometrics | 0.002 | 0.001 |
| Science and technology studies | 0.002 | 0.003 |
| Scholarly communication | 0.004 | 0.007 |
| Open science | 0.005 | 0.005 |
| Research integrity | 0.003 | 0.006 |
| Insufficient payload (model declined to judge) | 0.007 | 0.004 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".