{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T16:20:25Z","timestamp":1781972425428,"version":"3.54.5"},"reference-count":54,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,10,28]],"date-time":"2023-10-28T00:00:00Z","timestamp":1698451200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,10,28]],"date-time":"2023-10-28T00:00:00Z","timestamp":1698451200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62004011,62002006,62202028,62172025,U21B2021,61932011,61932014,61972018,61972019,U2241213"],"award-info":[{"award-number":["62004011,62002006,62202028,62172025,U21B2021,61932011,61932014,61972018,61972019,U2241213"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000143","name":"CCF-Huawei Populus euphratica project","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000143","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,10,28]]},"DOI":"10.1109\/iccad57390.2023.10323851","type":"proceedings-article","created":{"date-parts":[[2023,11,30]],"date-time":"2023-11-30T18:58:45Z","timestamp":1701370725000},"page":"1-9","source":"Crossref","is-referenced-by-count":4,"title":["THE-V: Verifiable Privacy-Preserving Neural Network via Trusted Homomorphic Execution"],"prefix":"10.1109","author":[{"given":"Yuntao","family":"Wei","sequence":"first","affiliation":[{"name":"School of Integrated Circuit Science and Engineering, Beihang University,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xueyan","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Integrated Circuit Science and Engineering, Beihang University,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Song","family":"Bian","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Beihang University,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weisheng","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Integrated Circuit Science and Engineering, Beihang University,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yier","family":"Jin","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, University of Science and Technology of China,Hefei,China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-20901-7_2"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref3","first-page":"2505","article-title":"Delphi: A cryptographic inference service for neural networks","volume-title":"29th USENIX Security Symposium","author":"Srinivasan"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417274"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/DAC.2018.8465894"},{"key":"ref6","first-page":"201","article-title":"Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"International conference on machine learning","author":"Gilad-Bachrach"},{"key":"ref7","first-page":"8638","article-title":"Autoprivacy: Automated layer-wise parameter selection for secure neural network inference","volume":"33","author":"Lou","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00942"},{"key":"ref9","first-page":"2505","article-title":"Cheetah: Lean and fast secure two-party deep neural network inference","volume-title":"31st USENIX Security Symposium","author":"Huang"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14623-7_25"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-45388-6_5"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-75248-4_19"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-023-09481-3"},{"key":"ref14","article-title":"Intel SGX explained","author":"Costan","year":"2016","journal-title":"Cryptology ePrint Archive"},{"key":"ref15","article-title":"Verifiable fully homomorphic encryption","author":"Viand","year":"2023","journal-title":"arXiv preprint"},{"key":"ref16","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"Tramer","year":"2018","journal-title":"arXiv preprint"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277277"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00087"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2864220"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3397513"},{"key":"ref23","first-page":"3917","article-title":"{\u00c6PIC} leak: Architecturally leaking uninitialized data from the microarchitecture","volume-title":"31st USENIX Security Symposium","author":"Borrello"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2021.3084997"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2802870"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218660"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2023.3288509"},{"key":"ref28","first-page":"812","article-title":"Low latency privacy preserving inference","volume-title":"International Conference on Machine Learning","author":"Brutzkus"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3090959"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00043"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref32","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref33","article-title":"Somewhat practical fully homomorphic encryption","author":"Fan","year":"2012","journal-title":"Cryptology ePrint Archive"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46800-5_24"},{"key":"ref35","first-page":"719","article-title":"Flush+ reload: A high resolution, low noise, 13 cache side-channel attack","volume-title":"23rd USENIX Security Symposium","author":"Yarom"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134038"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00064"},{"key":"ref39","volume-title":"Apparatus and method for bus signal termination compensation during detected quiet cycle","author":"Kurts","year":"2005"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.28"},{"key":"ref41","article-title":"Safetynets: Verifiable execution of deep neural networks on an untrusted cloud","volume":"30","author":"Ghodsi","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-42045-0_16"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38348-9_21"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660366"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94289-6_7"},{"key":"ref48","article-title":"Verifiable encodings for secure homomorphic analytics","author":"Chatel","year":"2022","journal-title":"arXiv preprint"},{"key":"ref49","article-title":"Chex-mix: Combining homomorphic encryption with trusted execution environments for two-party oblivious inference in the cloud","author":"Natarajan","year":"2021","journal-title":"Cryptology ePrint Archive"},{"key":"ref50","article-title":"Microsoft SEAL (release 3.6)","year":"2020","journal-title":"microsoft Research"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref52","volume-title":"OpenCheetah","year":"2022"},{"key":"ref53","volume-title":"OpenPEGASUS","year":"2021"},{"key":"ref54","volume-title":"Gramine (release 1.3.1)","year":"2022"}],"event":{"name":"2023 IEEE\/ACM International Conference on Computer Aided Design (ICCAD)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,10,28]]},"end":{"date-parts":[[2023,11,2]]}},"container-title":["2023 IEEE\/ACM International Conference on Computer Aided Design (ICCAD)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10323590\/10323543\/10323851.pdf?arnumber=10323851","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,14]],"date-time":"2024-03-14T01:30:59Z","timestamp":1710379859000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10323851\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,28]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/iccad57390.2023.10323851","relation":{},"subject":[],"published":{"date-parts":[[2023,10,28]]}}}