{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T23:12:23Z","timestamp":1768518743896,"version":"3.49.0"},"reference-count":25,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,14]]},"DOI":"10.1109\/icpads67057.2025.11322962","type":"proceedings-article","created":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T20:36:54Z","timestamp":1768423014000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["Analysis of Bit-Flip Attacks on Encrypted Neural Networks"],"prefix":"10.1109","author":[{"given":"Zihao","family":"Yang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, CAS,State Key Laboratory of Cyberspace Security Defense,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yilan","family":"Zhu","sequence":"additional","affiliation":[{"name":"Ant Group,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Hou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS,State Key Laboratory of Cyberspace Security Defense,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Meng","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS,State Key Laboratory of Cyberspace Security Defense,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shengyu","family":"Fan","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS,State Key Laboratory of Cyberspace Security Defense,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingzhe","family":"Zhang","sequence":"additional","affiliation":[{"name":"Ant Group,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3560827.3563379"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22792-9_29"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-53368-6_16"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00432"},{"key":"ref6","article-title":"Somewhat practical fully homomorphic encryption","volume-title":"Cryptology ePrint Archive","author":"Fan","year":"2012"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_49"},{"key":"ref9","volume-title":"HElib","author":"Halevi","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44371-2_31"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref12","volume-title":"Microsoft SEAL","author":"Laine","year":"2017"},{"issue":"11","key":"ref13","article-title":"A survey of homomorphic encryption research progress","volume":"32","author":"Li","year":"2015","journal-title":"Application Research of Computers"},{"key":"ref14","first-page":"6347","article-title":"NeuroPots: Realtime proactive defense against bit-flip attacks in neural networks","volume-title":"USENIX Security Symposium","author":"Liu","year":"2023"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3439726"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3032227"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12040853"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref20","first-page":"169","article-title":"On data banks and privacy homomorphisms","author":"Rivest","year":"1978","journal-title":"Foundations of Secure Computation"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1142\/S0129065724500254"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1402008"},{"key":"ref23","volume":"arXiv:2405.13891","author":"Vel\u010dick\u00fd","year":"2024","journal-title":"DeepNCode: Encodingbased protection against bit-flip attacks on neural networks"},{"key":"ref24","article-title":"Privacy-preserving neural networks based on homomorphic encryption: A survey","author":"Wang","year":"2022","journal-title":"Journal of Cyber Security"},{"key":"ref25","volume":"arXiv:2305.08034","author":"Zhou","year":"2023","journal-title":"DNN-Defender: An in-dram deep neural network defense mechanism for adversarial weight attack"}],"event":{"name":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","location":"Hefei, China","start":{"date-parts":[[2025,12,14]]},"end":{"date-parts":[[2025,12,18]]}},"container-title":["2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11322805\/11322871\/11322962.pdf?arnumber=11322962","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T07:41:57Z","timestamp":1768462917000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11322962\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,14]]},"references-count":25,"URL":"https:\/\/doi.org\/10.1109\/icpads67057.2025.11322962","relation":{},"subject":[],"published":{"date-parts":[[2025,12,14]]}}}