{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T03:31:02Z","timestamp":1783049462412,"version":"3.54.6"},"reference-count":119,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Indonesia Endowment Fund for Education, Lembaga Pengelola Dana Pendidikan (LPDP) and Institute for Information and communications Technology Planning and Evaluation (IITP), grant"},{"DOI":"10.13039\/501100014188","name":"Korea government, Ministry of Science and ICT (MSIT)","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100014188","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.3023084","type":"journal-article","created":{"date-parts":[[2020,9,10]],"date-time":"2020-09-10T20:41:46Z","timestamp":1599770506000},"page":"167425-167447","source":"Crossref","is-referenced-by-count":133,"title":["Privacy-Preserving Deep Learning on Machine Learning as a Service\u2014a Comprehensive Survey"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2668-559X","authenticated-orcid":false,"given":"Harry Chandra","family":"Tanuwidjaja","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6166-8173","authenticated-orcid":false,"given":"Rakyong","family":"Choi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Seunggeun","family":"Baek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8922-6203","authenticated-orcid":false,"given":"Kwangjo","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","first-page":"47","article-title":"Identity-based cryptosystems and signature schemes","author":"shamir","year":"1984","journal-title":"Proc Workshop Theory Appl Cryptograph Techn"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70936-7_29"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44371-2_31"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-019-09319-x"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53887-6_1"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1504\/IJACT.2017.089356"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19571-6_16"},{"key":"ref36","first-page":"457","article-title":"Fuzzy identity-based encryption","author":"sahai","year":"2005","journal-title":"Proc Annu Int Conf Theory Appl Cryptograph Techn"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46800-5_24"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2633600"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40041-4_5"},{"key":"ref29","first-page":"144","article-title":"Somewhat practical fully homomorphic encryption","author":"fan","year":"2012"},{"key":"ref20","first-page":"169","article-title":"On data banks and privacy homomorphisms","volume":"4","author":"rivest","year":"1978","journal-title":"Foundations of Secure Computation"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_2"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38348-9_20"},{"key":"ref101","article-title":"CrypTFlow: Secure TensorFlow inference","author":"kumar","year":"2019","journal-title":"arXiv 1909 07814"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22792-9_29"},{"key":"ref100","first-page":"8024","article-title":"PyTorch: An imperative style, high-performance deep learning library","author":"paszke","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1137\/120868669"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.11.021"},{"key":"ref51","article-title":"Chiron: Privacy-preserving machine learning as a service","author":"hunt","year":"2018","journal-title":"arXiv 1803 05961"},{"key":"ref59","article-title":"CryptoDL: Deep neural networks over encrypted data","author":"hesamifard","year":"2017","journal-title":"arXiv 1711 05189"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.02.013"},{"key":"ref57","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"arXiv 1502 03167"},{"key":"ref56","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46805-6_19"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3231594"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2017.38"},{"key":"ref52","author":"intel","year":"2014","journal-title":"Software Guard Extensions Programming Reference"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44647-8_13"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0024"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3140649.3140655"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2822693"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2706947"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2019.04.011"},{"key":"ref49","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","author":"dwork","year":"2006","journal-title":"Proc Theory Cryptogr Conf"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2820162"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2889996"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180418"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_28"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/28395.28420"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_27"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/11426639_7"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39200-9_16"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374407"},{"key":"ref73","article-title":"Bitwise neural networks","author":"kim","year":"2016","journal-title":"arXiv 1601 06071 [cs]"},{"key":"ref72","article-title":"TAPAS: Tricks to accelerate (encrypted) prediction as a service","author":"sanyal","year":"2018","journal-title":"arXiv 1806 03461"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196023"},{"key":"ref70","first-page":"35","article-title":"Privacy-preserving classification on deep neural network","author":"chabanne","year":"2017"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243837"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/DSC.2018.00067"},{"key":"ref74","first-page":"6869","article-title":"Quantized neural networks: Training neural networks with low precision weights and activations","volume":"18","author":"hubara","year":"2017","journal-title":"J Mach Learn Res"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96878-0_17"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00121"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/91.531779"},{"key":"ref60","first-page":"752","article-title":"Privacy-preserving all convolutional net based on homomorphic encryption","author":"liu","year":"2018","journal-title":"Proc Int Conf Netw -Based Inf Syst"},{"key":"ref62","first-page":"1","article-title":"ML confidential: Machine learning on encrypted data","author":"graepel","year":"2012","journal-title":"Proc Int Conf Inf Security Cryptol"},{"key":"ref61","first-page":"201","article-title":"Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy","author":"gilad-bachrach","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/s100440200011"},{"key":"ref64","first-page":"659","article-title":"Robust Fisher discriminant analysis","author":"kim","year":"2006","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref65","article-title":"Faster CryptoNets: Leveraging sparsity for real-world encrypted inference","author":"chou","year":"2018","journal-title":"arXiv 1811 09953"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref67","first-page":"601","article-title":"Stealing machine learning models via prediction apis","author":"tram\u00e8r","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SACI.2009.5136308"},{"key":"ref69","first-page":"1310","article-title":"Privacy-preserving deep learning","author":"shokri","year":"2015","journal-title":"Proc 53rd Annu Allerton Conf Commun Control Comput (Allerton)"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30619-9_4"},{"key":"ref109","article-title":"Can you really backdoor federated learning?","author":"sun","year":"2019","journal-title":"arXiv 1911 07963"},{"key":"ref95","first-page":"619","article-title":"Oblivious multi-party machine learning on trusted processors","author":"ohrimenko","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref108","article-title":"PrivacyFL: A simulator for privacy-preserving and secure federated learning","author":"mugunthan","year":"2020","journal-title":"arXiv 2002 08423"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1145\/2948618.2954331"},{"key":"ref107","article-title":"Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption","author":"hardy","year":"2017","journal-title":"arXiv 1711 10677"},{"key":"ref93","first-page":"991","article-title":"Foreshadow: Extracting the keys to the Intel SGX kingdom with transient out-of-order execution","author":"van bulck","year":"2018","journal-title":"Proc 7th USENIX Secur Symp (USENIX Secur )"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"ref92","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"tram\u00e8r","year":"2018","journal-title":"arXiv 1806 03287"},{"key":"ref105","first-page":"1832","article-title":"Collaborative learning for deep neural networks","author":"song","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref91","article-title":"Deep learning with Gaussian differential privacy","author":"bu","year":"2019","journal-title":"arXiv 1911 11607"},{"key":"ref104","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"brendan mcmahan","year":"2016","journal-title":"arXiv 1602 05629"},{"key":"ref90","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"papernot","year":"2016","journal-title":"arXiv 1610 05755"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2015.10"},{"key":"ref102","first-page":"1223","article-title":"Large scale distributed deep networks","author":"dean","year":"2012","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2016.2594205"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1145\/3302505.3310070"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref98","first-page":"762","article-title":"Private collaborative neural network learning","author":"chase","year":"2017","journal-title":"Tech Rep 2017\/762"},{"key":"ref99","article-title":"A generic framework for privacy preserving deep learning","author":"ryffel","year":"2018","journal-title":"arXiv 1811 04017"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-7998-1294-4.ch006"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2019.08.007"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3363347.3363357"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2935666"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.03.014"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.03.023"},{"key":"ref118","first-page":"1003","article-title":"Regression model fitting under differential privacy and model inversion attack","author":"wang","year":"2015","journal-title":"Proc 24th Int Joint Conf Artif Intell"},{"key":"ref16","article-title":"Protecting privacy when disclosing information: K-anonymity and its enforcement through generalization and suppression","author":"samarati","year":"1998"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.11.041"},{"key":"ref117","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","author":"fredrikson","year":"2014","journal-title":"Proc 23rd USENIX Secur Symp (USENIX Secur )"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1023\/A:1008940618127"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2007.367856"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909559"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/1247480.1247556"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref114","article-title":"ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"salem","year":"2018","journal-title":"arXiv 1806 01246"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78381-9_14"},{"key":"ref116","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model","volume":"11","author":"rahman","year":"2018","journal-title":"Trans Data Privacy"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.1978.268028"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref89","article-title":"CodedPrivateML: A fast and privacy-preserving framework for distributed machine learning","author":"so","year":"2019","journal-title":"arXiv 1902 00641"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243760"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"ref88","first-page":"1651","article-title":"GAZELLE: A low latency framework for secure neural network inference","author":"juvekar","year":"2018","journal-title":"Proc 7th USENIX Secur Symp (USENIX Secur )"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09194237.pdf?arnumber=9194237","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T19:55:50Z","timestamp":1639770950000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9194237\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":119,"URL":"https:\/\/doi.org\/10.1109\/access.2020.3023084","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}