{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T17:53:07Z","timestamp":1782150787599,"version":"3.54.5"},"reference-count":41,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012472","name":"Education and Scientific Research Project of Shanghai","doi-asserted-by":"publisher","award":["C160076"],"award-info":[{"award-number":["C160076"]}],"id":[{"id":"10.13039\/501100012472","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772128"],"award-info":[{"award-number":["61772128"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007219","name":"Natural Science Foundation of Shanghai Municipality","doi-asserted-by":"publisher","award":["19ZR1402000"],"award-info":[{"award-number":["19ZR1402000"]}],"id":[{"id":"10.13039\/100007219","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neurocomputing"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.neucom.2026.134269","type":"journal-article","created":{"date-parts":[[2026,6,14]],"date-time":"2026-06-14T17:20:20Z","timestamp":1781457620000},"page":"134269","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Integrity verification of cloud-based neural network model training"],"prefix":"10.1016","volume":"698","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4103-1968","authenticated-orcid":false,"given":"Guangwei","family":"Xu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shifei","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunxuan","family":"Feng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xin","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyang","family":"Feng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanglan","family":"Gan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neucom.2026.134269_bib0005","author":"Simonyan"},{"key":"10.1016\/j.neucom.2026.134269_bib0010","series-title":"Proceedings of International Conference on Electrical Energy Systems (ICEES)","first-page":"543","article-title":"A machine learning based implementation of product and service recommendation models","author":"Mana","year":"2021"},{"key":"10.1016\/j.neucom.2026.134269_bib0015","series-title":"Proceedings of Conference on Neural Information Processing Systems (NeurIPS)","first-page":"1877","article-title":"Language models are few-shot learners","author":"Brown","year":"2020"},{"issue":"1","key":"10.1016\/j.neucom.2026.134269_bib0020","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000006","article-title":"Learning deep architectures for AI","volume":"2","author":"Bengio","year":"2009","journal-title":"Found. trends\u00ae Mach. Learn."},{"key":"10.1016\/j.neucom.2026.134269_bib0025","author":"Chang"},{"key":"10.1016\/j.neucom.2026.134269_bib0030","doi-asserted-by":"crossref","first-page":"3476","DOI":"10.1109\/TIFS.2023.3283104","article-title":"Achieving privacy-preserving and verifiable support vector machine training in the cloud","volume":"18","author":"Hu","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.134269_bib0035","doi-asserted-by":"crossref","first-page":"1736","DOI":"10.1109\/TIFS.2020.3043139","article-title":"Verifl: communication-efficient and fast verifiable aggregation for federated learning","volume":"16","author":"Guo","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.134269_bib0040","doi-asserted-by":"crossref","first-page":"911","DOI":"10.1109\/TIFS.2019.2929409","article-title":"VerifyNet: secure and verifiable federated learning","volume":"15","author":"Xu","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"10","key":"10.1016\/j.neucom.2026.134269_bib0045","first-page":"4675","article-title":"Safetynets: verifiable execution of deep neural networks on an untrusted cloud","volume":"30","author":"Ghodsi","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.neucom.2026.134269_bib0050","first-page":"584","article-title":"vCNN: verifiable convolutional neural network","volume":"2020","author":"Lee","year":"2020","journal-title":"IACR Cryptol. ePrint Arch"},{"issue":"3","key":"10.1016\/j.neucom.2026.134269_bib0055","doi-asserted-by":"crossref","first-page":"1703","DOI":"10.1109\/TDSC.2020.3035591","article-title":"Toward verifiable and privacy preserving machine learning prediction","volume":"19","author":"Niu","year":"2020","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"10","key":"10.1016\/j.neucom.2026.134269_bib0060","doi-asserted-by":"crossref","first-page":"2524","DOI":"10.1109\/TPDS.2021.3068195","article-title":"Veriml: enabling integrity assurances and fair payments for machine learning as a service","volume":"32","author":"Zhao","year":"2021","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"10.1016\/j.neucom.2026.134269_bib0065","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"4316","article-title":"Zero-knowledge proofs of training for deep neural networks","author":"Abbaszadeh","year":"2024"},{"key":"10.1016\/j.neucom.2026.134269_bib0070","author":"Ge"},{"key":"10.1016\/j.neucom.2026.134269_bib0075","author":"Tramer"},{"key":"10.1016\/j.neucom.2026.134269_bib0080","series-title":"Proceedings of 2020-IEEE Conference on Computer Communications","first-page":"1877","article-title":"Enabling execution assurance of federated learning at untrusted participants","author":"Zhang","year":"2020"},{"key":"10.1016\/j.neucom.2026.134269_bib0085","series-title":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","first-page":"1246","article-title":"A generative framework for low-cost result validation of machine learning-as-a-Service inference","author":"Kumar","year":"2024"},{"issue":"3","key":"10.1016\/j.neucom.2026.134269_bib0090","doi-asserted-by":"crossref","first-page":"1032","DOI":"10.1109\/TDSC.2023.3266427","article-title":"VeriTrain: validating MLaaS training efforts via anomaly detection","volume":"21","author":"Zhang","year":"2024","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10.1016\/j.neucom.2026.134269_bib0095","series-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","first-page":"35","article-title":"ABY3: a mixed protocol framework for machine learning","author":"Mohassel","year":"2018"},{"key":"10.1016\/j.neucom.2026.134269_bib0100","doi-asserted-by":"crossref","first-page":"26","DOI":"10.2478\/popets-2019-0035","article-title":"SecureNN: 3-party secure computation for neural network training","volume":"2019","author":"Wagh","year":"2019","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"10.1016\/j.neucom.2026.134269_bib0105","series-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1231","article-title":"QUOTIENT: two-party secure neural network training and prediction","author":"Agrawal","year":"2019"},{"key":"10.1016\/j.neucom.2026.134269_bib0110","series-title":"Proceedings of USENIX Security Symposium","first-page":"1651","article-title":"GAZELLE: a low latency framework for secure neural network inference","author":"Juvekar","year":"2018"},{"key":"10.1016\/j.neucom.2026.134269_bib0115","series-title":"Proceedings of International Conference on Machine Learning","first-page":"201","article-title":"Cryptonets: applying neural networks to encrypted data with high throughput and accuracy","author":"Gilad-Bachrach","year":"2016"},{"key":"10.1016\/j.neucom.2026.134269_bib0120","doi-asserted-by":"crossref","first-page":"3637","DOI":"10.1109\/TIFS.2022.3211707","article-title":"SOCI: a toolkit for secure outsourced computation on integers","volume":"17","author":"Zhao","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.134269_bib0125","series-title":"Proceedings of International Cryptology Conference (CRYPTO)","first-page":"483","article-title":"Fast homomorphic evaluation of deep discretized neural networks","author":"Bourse","year":"2018"},{"key":"10.1016\/j.neucom.2026.134269_bib0130","series-title":"Proceedings of International Conference on Machine Learning","first-page":"812","article-title":"Low latency privacy preserving inference","author":"Brutzkus","year":"2019"},{"key":"10.1016\/j.neucom.2026.134269_bib0135","author":"Chou"},{"key":"10.1016\/j.neucom.2026.134269_bib0140","series-title":"Proceedings of Annual Computer Security Applications Conference (ACSAC 2016)","first-page":"1","article-title":"Cryptodl: towards deep learning over encrypted data","author":"Hesamifard","year":"2016"},{"key":"10.1016\/j.neucom.2026.134269_bib0145","series-title":"Proceedings of International Conference on Machine Learning","first-page":"4490","article-title":"TAPAS: tricks to accelerate (encrypted) prediction as a service","author":"Sanyal","year":"2018"},{"key":"10.1016\/j.neucom.2026.134269_bib0150","series-title":"Privacy in Statistical Databases (PSD)","first-page":"315","article-title":"A protocol for privacy preserving neural network learning on horizontally partitioned data","author":"Schlitter","year":"2008"},{"issue":"10","key":"10.1016\/j.neucom.2026.134269_bib0155","doi-asserted-by":"crossref","first-page":"1554","DOI":"10.1109\/TNN.2009.2026902","article-title":"Privacy-preserving backpropagation neural network learning","volume":"20","author":"Chen","year":"2009","journal-title":"IEEE Trans. Neural Netw."},{"issue":"1","key":"10.1016\/j.neucom.2026.134269_bib0160","doi-asserted-by":"crossref","first-page":"143","DOI":"10.1007\/s00521-010-0346-z","article-title":"Privacy preserving back-propagation neural network learning over arbitrarily partitioned data","volume":"20","author":"Bansal","year":"2011","journal-title":"Neural Comput. Appl."},{"key":"10.1016\/j.neucom.2026.134269_bib0165","series-title":"Proceedings of IEEE Symposium on Security and Privacy (SP)","first-page":"19","article-title":"Secureml: a system for scalable privacy-preserving machine learning","author":"Mohassel","year":"2017"},{"issue":"11","key":"10.1016\/j.neucom.2026.134269_bib0170","doi-asserted-by":"crossref","first-page":"2513","DOI":"10.1109\/TIFS.2016.2585121","article-title":"Privacy-preserving outsourced calculation on floating point numbers","volume":"11","author":"Liu","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.134269_bib0175","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.ins.2020.02.037","article-title":"A training-integrity privacy-preserving federated learning scheme with trusted execution environment","volume":"522","author":"Chen","year":"2020","journal-title":"Inf. Sci."},{"key":"10.1016\/j.neucom.2026.134269_bib0180","series-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","first-page":"270","article-title":"Towncrier: an authenticated data feed for smart contracts","author":"Zhang","year":"2016"},{"issue":"2","key":"10.1016\/j.neucom.2026.134269_bib0185","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1007\/s00145-007-9005-7","article-title":"Short signatures without random oracles and the SDH assumption in bilinear groups","volume":"21","author":"Boneh","year":"2008","journal-title":"J. Cryptol."},{"key":"10.1016\/j.neucom.2026.134269_bib0190","series-title":"Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","first-page":"1150","article-title":"Gcc: graph contrastive coding for graph neural network pre-training","author":"Qiu","year":"2020"},{"key":"10.1016\/j.neucom.2026.134269_bib0195","author":"Kipf"},{"issue":"5","key":"10.1016\/j.neucom.2026.134269_bib0200","doi-asserted-by":"crossref","first-page":"4245","DOI":"10.1109\/TDSC.2022.3208706","article-title":"Achieving efficient and privacy-preserving neural network training and prediction in cloud environments","volume":"20","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"6","key":"10.1016\/j.neucom.2026.134269_bib0205","first-page":"2969","article-title":"NPMML: a framework for non-interactive privacy-preserving multi-party machine learning","volume":"18","author":"Li","year":"2021","journal-title":"IEEE Trans. Dependable Secure Comput."}],"container-title":["Neurocomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S092523122601667X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S092523122601667X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T17:39:31Z","timestamp":1782149971000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S092523122601667X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":41,"alternative-id":["S092523122601667X"],"URL":"https:\/\/doi.org\/10.1016\/j.neucom.2026.134269","relation":{},"ISSN":["0925-2312"],"issn-type":[{"value":"0925-2312","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Integrity verification of cloud-based neural network model training","name":"articletitle","label":"Article Title"},{"value":"Neurocomputing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neucom.2026.134269","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"134269"}}