{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,10]],"date-time":"2025-04-10T05:15:21Z","timestamp":1744262121554,"version":"3.40.3"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031804076"},{"type":"electronic","value":"9783031804083"}],"license":[{"start":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T00:00:00Z","timestamp":1733702400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T00:00:00Z","timestamp":1733702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-80408-3_4","type":"book-chapter","created":{"date-parts":[[2024,12,12]],"date-time":"2024-12-12T10:29:38Z","timestamp":1733999378000},"page":"40-68","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Transferability of\u00a0Evasion Attacks Against FHE Encrypted Inference"],"prefix":"10.1007","author":[{"given":"Reeshav","family":"Chowdhury","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aman","family":"Kumar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vaibhav Dashrath","family":"Mohite","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ayantika","family":"Chatterjee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"4_CR1","doi-asserted-by":"crossref","unstructured":"Bost, R., Popa, R.A., Tu, S., Goldwasser, S.: Machine learning classification over encrypted data. Cryptology ePrint Archive (2014)","DOI":"10.14722\/ndss.2015.23241"},{"key":"4_CR2","doi-asserted-by":"crossref","unstructured":"Viand, A., Knabenhans, C., Hithnawi, A.: Verifiable fully homomorphic encryption. arXiv preprint arXiv:2301.07041 (2023)","DOI":"10.1145\/3689945.3694806"},{"key":"4_CR3","doi-asserted-by":"crossref","unstructured":"Biggio, B., et al.: Evasion Attacks against Machine Learning at Test Time, pp. 387\u2013402. Springer, Heidelberg (2013)","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"4_CR4","doi-asserted-by":"publisher","unstructured":"Costa, J.C., Roxo, T., Proen\u00e7a, H., In\u00e1cio, P.R.M.: How deep learning sees the world: a survey on adversarial attacks and defenses. IEEE Access 12, 61113\u201361136 (2024). https:\/\/doi.org\/10.1109\/access.2024.3395118. ISSN 2169-3536","DOI":"10.1109\/access.2024.3395118"},{"issue":"3","key":"4_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2633600","volume":"6","author":"Z Brakerski","year":"2014","unstructured":"Brakerski, Z., Gentry, C., Vaikuntanathan, V.: (leveled) fully homomorphic encryption without bootstrapping. ACM Trans. Comput. Theory (TOCT) 6(3), 1\u201336 (2014)","journal-title":"ACM Trans. Comput. Theory (TOCT)"},{"key":"4_CR6","unstructured":"Fan, J., Vercauteren, F.: Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive (2012)"},{"key":"4_CR7","doi-asserted-by":"crossref","unstructured":"Chillotti, I., Joye, M., Paillier, P.: Programmable bootstrapping enables efficient homomorphic inference of deep neural networks. In: Cyber Security Cryptography and Machine Learning: 5th International Symposium, CSCML 2021, Be\u2019er Sheva, 8\u20139 July 2021, Proceedings 5, pp. 1\u201319. Springer (2021)","DOI":"10.1007\/978-3-030-78086-9_1"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Cheon, J.H., Kim, A., Kim, M., Song, Y.: Homomorphic encryption for arithmetic of approximate numbers. In: Advances in Cryptology\u2013ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, 3\u20137 December 2017, Proceedings, Part I 23, pp. 409\u2013437. Springer (2017)","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"4_CR9","unstructured":"Benaissa, A., Retiat, B., Cebere, B., Belfedhal, A.E.: Tenseal: a library for encrypted tensor operations using homomorphic encryption. arXiv preprint arXiv:2104.03152 (2021)"},{"key":"4_CR10","unstructured":"Zama. Concrete ML: a privacy-preserving machine learning library using fully homomorphic encryption for data scientists (2024). https:\/\/github.com\/zama-ai\/concrete-ml"},{"issue":"6","key":"4_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1568318.1568324","volume":"56","author":"O Regev","year":"2009","unstructured":"Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. J. ACM 56(6), 1\u201340 (2009)","journal-title":"J. ACM"},{"key":"4_CR12","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples (2015)"},{"key":"4_CR13","doi-asserted-by":"crossref","unstructured":"Combey, T., Loison, A., Faucher, M., Hajri, H.: Probabilistic Jacobian-based saliency maps attacks (2020)","DOI":"10.3390\/make2040030"},{"key":"4_CR14","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Frossard, P.: Deepfool: A Simple and Accurate Method to Fool Deep Neural Networks, pp. 2574\u20132582 (2016). https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"4_CR15","doi-asserted-by":"publisher","unstructured":"Carlini, N., Wagner, D.: Towards Evaluating the Robustness of Neural Networks, pp. 39\u201357 (2017). https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"4_CR16","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks (2019)"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., Frossard, P.: Universal Adversarial Perturbations (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"4_CR18","unstructured":"Chaturvedi, B., Chakraborty, A., Chatterjee, A., Mukhopadhyay, D.: A practical full key recovery attack on TFHE and FHEW by inducing decryption errors. Cryptology ePrint Archive (2022)"},{"key":"4_CR19","unstructured":"Guo, Q., Nabokov, D., Suvanto, E., Johansson, T.: Key recovery attacks on approximate homomorphic encryption with non-worst-case noise flooding countermeasures. In: Usenix Security (2024)"},{"issue":"23","key":"4_CR20","doi-asserted-by":"publisher","first-page":"7806","DOI":"10.3390\/s21237806","volume":"21","author":"J Shin","year":"2021","unstructured":"Shin, J., Choi, S.-H., Choi, Y.-H.: Is homomorphic encryption-based deep learning secure enough? Sensors 21(23), 7806 (2021)","journal-title":"Sensors"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1765\u20131773 (2017)","DOI":"10.1109\/CVPR.2017.17"},{"issue":"11","key":"4_CR22","doi-asserted-by":"publisher","first-page":"268","DOI":"10.3390\/a13110268","volume":"13","author":"H Hirano","year":"2020","unstructured":"Hirano, H., Takemoto, K.: Simple iterative method for generating targeted universal adversarial perturbations. Algorithms 13(11), 268 (2020)","journal-title":"Algorithms"},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Marcolla, C., Sucasas, V., Manzano, M., Bassoli, R., Fitzek, F.H.P., Aaraj, N.: Survey on fully homomorphic encryption, theory, and applications. Proceedings of the IEEE 110(10), 1572\u20131609 (2022)","DOI":"10.1109\/JPROC.2022.3205665"},{"key":"4_CR24","unstructured":"Trusted AI. Adversarial robustness toolbox. (2024). https:\/\/github.com\/Trusted-AI\/adversarial-robustness-toolbox"},{"key":"4_CR25","unstructured":"Nicolae, M.-I., et\u00a0al.: Adversarial robustness toolbox v1. 0.0. arXiv preprint arXiv:1807.01069 (2018)"},{"key":"4_CR26","unstructured":"Zama. Concrete: TFHE compiler that converts python programs into FHE equivalent (2024). https:\/\/github.com\/zama-ai\/concrete"},{"key":"4_CR27","unstructured":"Zama AI. Composition - concrete documentation (2024). https:\/\/docs.zama.ai\/concrete\/v\/2.5\/tutorials\/composition"},{"key":"4_CR28","unstructured":"Zama. Concrete: Python frontend - circuit compilation (2024). https:\/\/github.com\/zama-ai\/concrete\/blob\/main\/frontends\/concrete-python\/concrete\/fhe\/compilation\/circuit.py"},{"key":"4_CR29","unstructured":"Zama AI. Concrete optimizer repository (2024). https:\/\/github.com\/zama-ai\/concrete\/tree\/main\/compilers\/concrete-optimizer"},{"key":"4_CR30","unstructured":"Zama. Composition - concrete documentation (2024). https:\/\/docs.zama.ai\/concrete\/compilation\/composition"},{"key":"4_CR31","unstructured":"Zama AI. Quantization in concrete ml (2023). https:\/\/docs.zama.ai\/concrete-ml\/explanations\/quantization. Accessed 10 Oct 2024"},{"key":"4_CR32","unstructured":"Zama AI. Quantizers in concrete ml (2023). https:\/\/github.com\/zama-ai\/concrete-ml\/blob\/main\/src\/concrete\/ml\/quantization\/quantizers.py#L692. Accessed 20 Oct 2024"},{"key":"4_CR33","unstructured":"Skklearn. Sklearn\u2019s digits dataset (2024). https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.datasets.load_digits.html"},{"key":"4_CR34","doi-asserted-by":"crossref","unstructured":"Din, S.U., Akhtar, N., Younis, S., Shafait, F., Mansoor, A., Shafique, M.: Steganographic universal adversarial perturbations. Pattern Recogn. Lett. 135, 146\u2013152 (2020)","DOI":"10.1016\/j.patrec.2020.04.025"},{"key":"4_CR35","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"4_CR36","doi-asserted-by":"crossref","unstructured":"Chillotti, I., Joye, M., Paillier, P.: Programmable bootstrapping enables efficient homomorphic inference of deep neural networks. In: Cyber Security Cryptography and Machine Learning: 5th International Symposium, CSCML 2021, Be\u2019er Sheva, 8\u20139 July 2021, Proceedings 5, pp. 1\u201319. Springer (2021)","DOI":"10.1007\/978-3-030-78086-9_1"},{"key":"4_CR37","doi-asserted-by":"crossref","unstructured":"Bergerat, L., et al.: Parameter optimization and larger precision for (t) FHE. J. Cryptol. 36(3), 28 (2023)","DOI":"10.1007\/s00145-023-09463-5"},{"key":"4_CR38","unstructured":"Zama. Parameter optimization and larger precision for TFH (2024). https:\/\/www.zama.ai\/post\/parameter-optimization-and-larger-precision-for-tfhe"},{"key":"4_CR39","unstructured":"Zama. TFHE-parametrization (2024). https:\/\/docs.zama.ai\/concrete\/v\/2.5\/explanations\/compilation"},{"key":"4_CR40","unstructured":"Zama AI. Fhe-look-up-table (2024). https:\/\/docs.zama.ai\/concrete\/v\/2.5\/explanations\/compilation\/dialects\/fhelinalgdialect#fhelinalg.apply_lookup_table-mlir-concretelang-fhelinalg-applylookuptableeintop"},{"key":"4_CR41","unstructured":"Zama AI. FHE-look-up-table (2024). https:\/\/www.zama.ai\/post\/zama-concrete-fully-homomorphic-encryption-compiler"},{"key":"4_CR42","unstructured":"Zama AI. Concrete: FHE linalg dialect (2024). https:\/\/docs.zama.ai\/concrete\/2.5\/explanations\/compilation\/dialects\/fhelinalgdialect"},{"key":"4_CR43","doi-asserted-by":"crossref","unstructured":"Stoian, A., Frery, J., Bredehoft, R., Montero, L., Kherfallah, C., Chevallier-Mames, B.: Deep neural networks for encrypted inference with TFHE. In: International Symposium on Cyber Security, Cryptology, and Machine Learning, pp. 493\u2013500. Springer (2023)","DOI":"10.1007\/978-3-031-34671-2_34"}],"container-title":["Lecture Notes in Computer Science","Security, Privacy, and Applied Cryptography Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-80408-3_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,6]],"date-time":"2025-03-06T07:54:51Z","timestamp":1741247691000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-80408-3_4"}},"subtitle":["Official Work-in-Progress Paper"],"short-title":[],"issued":{"date-parts":[[2024,12,9]]},"ISBN":["9783031804076","9783031804083"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-80408-3_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024,12,9]]},"assertion":[{"value":"9 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SPACE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security, Privacy, and Applied Cryptography Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kottayam","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 December 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 December 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"space2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/space2024.cse.iitk.ac.in\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}