{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:31:19Z","timestamp":1784874679712,"version":"3.55.0"},"reference-count":192,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"13","license":[{"start":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T00:00:00Z","timestamp":1625097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T00:00:00Z","timestamp":1625097600000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T00:00:00Z","timestamp":1625097600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T00:00:00Z","timestamp":1625097600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1828593"],"award-info":[{"award-number":["CNS-1828593"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["OAC-1829771"],"award-info":[{"award-number":["OAC-1829771"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["EEC-1840458"],"award-info":[{"award-number":["EEC-1840458"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1950704"],"award-info":[{"award-number":["CNS-1950704"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-20-1-2065"],"award-info":[{"award-number":["N00014-20-1-2065"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Commonwealth Cyber Initiative, an Investment in the Advancement of Cyber Research and Development, Innovation and Workforce Development"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2021,7,1]]},"DOI":"10.1109\/jiot.2021.3058638","type":"journal-article","created":{"date-parts":[[2021,2,13]],"date-time":"2021-02-13T02:20:10Z","timestamp":1613182810000},"page":"10412-10429","source":"Crossref","is-referenced-by-count":48,"title":["Privacy-Preserving Deep Learning Based on Multiparty Secure Computation: A Survey"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7752-0528","authenticated-orcid":false,"given":"Qiao","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5575-2849","authenticated-orcid":false,"given":"Chunsheng","family":"Xin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongyi","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref170","year":"2020"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0168054"},{"key":"ref171","year":"2020"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM48280.2020.00037"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417274"},{"key":"ref176","author":"morshed","year":"2020","journal-title":"CPU and GPU accelerated fully homomorphic encryption"},{"key":"ref175","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378523"},{"key":"ref178","author":"han","year":"2015","journal-title":"Deep compression Compressing deep neural networks with pruning trained quantization and huffman coding"},{"key":"ref177","author":"reis","year":"2020","journal-title":"Computing-in-memory for performance and energy efficient homomorphic encryption"},{"key":"ref168","year":"2020"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref39","author":"mirshghallah","year":"2020","journal-title":"Privacy in deep learning A survey"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3158363"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"ref32","year":"2019","journal-title":"France Fines Google 57 Million for Breaking Europe&#x2019;s Strict New Privacy Rules"},{"key":"ref31","year":"2019","journal-title":"Data Breach News PDPC Fines IHiS SingHealth"},{"key":"ref30","year":"2018","journal-title":"Uber to Pay 148 Million Penalty to Settle 2016 Data Breach"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2018.2888775"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30619-9_4"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref181","author":"kozlov","year":"2020","journal-title":"Neural network compression framework for fast model inference"},{"key":"ref180","doi-asserted-by":"publisher","DOI":"10.1145\/3007787.3001163"},{"key":"ref185","doi-asserted-by":"publisher","DOI":"10.1006\/jcom.1998.0476"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.1145\/1077464.1077466"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1145\/2608628.2608664"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA47549.2020.00030"},{"key":"ref189","author":"dahl","year":"2018","journal-title":"Private machine learning in TensorFlow using secure computation"},{"key":"ref188","author":"ryffel","year":"2018","journal-title":"A generic framework for privacy preserving deep learning"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00092"},{"key":"ref186","author":"zhao","year":"2020","journal-title":"Efficient integer-arithmetic-only convolutional neural networks"},{"key":"ref28","article-title":"An introduction to the California consumer privacy act (CCPA)","author":"goldman","year":"2020","journal-title":"Santa Clara Univ Legal Studies Research Paper"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2013.07.010"},{"key":"ref179","first-page":"1135","article-title":"Learning both weights and connections for efficient neural network","author":"han","year":"2015","journal-title":"Advances in neural information processing systems"},{"key":"ref29","article-title":"Health insurance portability and accountability act of 1996","year":"1996","journal-title":"Public Law 104-191"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/257874.257896"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/s00779-016-0963-3"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1080\/15265161.2010.494215"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/IEMBS.2006.260060"},{"key":"ref101","year":"2020"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref100","year":"2020"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2018.2846736"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243837"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48910-X_16"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0024"},{"key":"ref153","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00045"},{"key":"ref156","author":"banerjee","year":"2020","journal-title":"SESAME Software defined enclaves to secure inference accelerators with multi-tenant execution"},{"key":"ref155","article-title":"Privacy-preserving classification on deep neural network","author":"chabanne","year":"2017"},{"key":"ref150","author":"froelicher","year":"2020","journal-title":"Scalable privacy-preserving distributed learning"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.12.015"},{"key":"ref151","author":"badawi","year":"2018","journal-title":"The alexnet moment for homomorphic encryption Hcnn the first homomorphic cnn on encrypted data with gpus"},{"key":"ref146","author":"zhang","year":"2019","journal-title":"CHEETAH An ultra-fast approximation-free and privacy-preserved neural network framework based on joint obscure linear and nonlinear computations"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00152"},{"key":"ref148","author":"lou","year":"2020","journal-title":"AutoPrivacy Automated layer-wise parameter selection for secure neural network inference"},{"key":"ref149","first-page":"9403","article-title":"ENSEI: Efficient secure inference via frequency-domain homomorphic convolution for privacy-preserving visual recognition","author":"bian","year":"2020","journal-title":"Proc IEEE Conf Comput Vis and Pattern Recog"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363207"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-012-9720-4"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref56","article-title":"Somewhat practical fully homomorphic encryption","author":"fan","year":"2012"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_50"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref53","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1007\/978-3-540-30576-7_18","article-title":"Evaluating 2-DNF formulas on ciphertexts","author":"boneh","year":"2005","journal-title":"Proc Theory Cryptogr Conf"},{"key":"ref52","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1109\/TIT.1985.1057074","article-title":"A public key cryptosystem and a signature scheme based on discrete logarithms","volume":"31","author":"elgamal","year":"1985","journal-title":"IEEE Trans Inf Theory"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.11.041"},{"key":"ref167","article-title":"Fast homomorphic evaluation of deep discretized neural networks","author":"bourse","year":"2017"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23241"},{"key":"ref165","first-page":"265","article-title":"TensorFlow: A system for large-scale machine learning","author":"abadi","year":"2016","journal-title":"Proc 12th USENIX Symp Oper Syst Design Implement"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref163","author":"ioffe","year":"2015","journal-title":"Batch Normalization Accelerating Deep Network Training by Reducing Internal Covariate Shift"},{"key":"ref162","author":"wang","year":"2016","journal-title":"EMP-toolkit Efficient multiparty computation toolkit"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516738"},{"key":"ref160","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1561\/3300000019","article-title":"A pragmatic introduction to secure multi-party computation","volume":"2","author":"evans","year":"2017","journal-title":"Foundations and Trends in Privacy and Security"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2875149"},{"key":"ref3","volume":"9","author":"adshead","year":"2014","journal-title":"Data set to grow 10-fold by 2020 as internet of things takes off"},{"key":"ref6","first-page":"73","article-title":"Survey on evolving deep learning neural network architectures","volume":"1","author":"bashar","year":"2019","journal-title":"J Artif Intell"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2853676"},{"key":"ref159","author":"hunt","year":"2018","journal-title":"Chiron Privacy-preserving machine learning as a service"},{"key":"ref8","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Advances in neural information processing systems"},{"key":"ref49","article-title":"Computing blindfolded on data homomorphically encrypted under multiple keys: An extended survey","author":"aloufi","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2830661"},{"key":"ref157","author":"hashemi","year":"2020","journal-title":"DarKnight A data privacy scheme for training and inference of deep neural networks"},{"key":"ref158","author":"tram\u00e8r","year":"2018","journal-title":"Slalom Fast verifiable and private execution of neural networks in trusted hardware"},{"key":"ref9","author":"simonyan","year":"2014","journal-title":"Very Deep Convolutional Networks for Large-scale Image Recognition"},{"key":"ref46","first-page":"396","article-title":"Handwritten digit recognition with a back-propagation network","author":"lecun","year":"1990","journal-title":"Advances in neural information processing systems"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2976475"},{"key":"ref48","author":"liu","year":"2020","journal-title":"MPC-enabled privacy-preserving neural network training against malicious attack"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"ref42","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"dwork","year":"2014","journal-title":"Found Trends Theor Comput Sci"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref44","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","author":"dwork","year":"2006","journal-title":"Proc Theory Cryptogr Conf"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.12"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988132"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref73","year":"2020"},{"key":"ref72","year":"2020"},{"key":"ref129","author":"koti","year":"2020","journal-title":"SWIFT Super-fast and robust privacy-preserving machine learning"},{"key":"ref71","year":"2020"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref70","year":"2020"},{"key":"ref76","first-page":"1651","article-title":"GAZELLE: A low latency framework for secure neural network inference","author":"juvekar","year":"2018","journal-title":"Proc 27th USENIX Security Symp"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.38"},{"key":"ref74","year":"2020"},{"key":"ref75","year":"2020"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2913362"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-011-9107-0"},{"key":"ref132","article-title":"Securenn: Efficient and private neural network training","author":"wagh","year":"2018"},{"key":"ref79","first-page":"2505","article-title":"Delphi: A cryptographic inference service for neural networks","author":"mishra","year":"2020","journal-title":"Proc 29th USENIX Security Symp"},{"key":"ref136","author":"aggarwal","year":"2020","journal-title":"SOTERIA In search of efficient neural networks for private inference"},{"key":"ref135","article-title":"Leia: A lightweight cryptographic neural network inference system at the edge","author":"liu","year":"2020"},{"key":"ref138","first-page":"1501","article-title":"XONN XNOR-based oblivious deep neural network inference","author":"riazi","year":"2019","journal-title":"Proc 28th USENIX Security Symp"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196023"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3394658"},{"key":"ref139","article-title":"Practical MPC+FHE with applications in secure multi-partyneural network evaluation","author":"zhu","year":"2020"},{"key":"ref62","year":"2020"},{"key":"ref61","year":"2020"},{"key":"ref63","year":"2020"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/2633600"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/671"},{"key":"ref65","year":"2020"},{"key":"ref141","author":"reagen","year":"2020","journal-title":"Cheetah Optimizing and accelerating homomorphic encryption for private inference"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40041-4_5"},{"key":"ref142","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","author":"gilad-bachrach","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref67","year":"2020"},{"key":"ref143","author":"chou","year":"2018","journal-title":"Faster CryptoNets Leveraging sparsity for real-world encrypted inference"},{"key":"ref68","year":"2020"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/547"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2875244"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-20465-4_4"},{"key":"ref145","first-page":"8705","article-title":"FALCON: A fourier transform based approach for fast and secure convolutional neural network predictions","author":"li","year":"2020","journal-title":"Proc IEEE Conf Comput Vis and Pattern Recog"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2720635"},{"key":"ref109","year":"2020"},{"key":"ref95","year":"2020"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1145\/3338469.3358944"},{"key":"ref108","year":"2020"},{"key":"ref94","year":"2020"},{"key":"ref191","doi-asserted-by":"publisher","DOI":"10.1145\/3310273.3323047"},{"key":"ref107","year":"2020"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00028"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1145\/3411501.3419425"},{"key":"ref106","year":"2020"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.15"},{"key":"ref105","first-page":"35","article-title":"ABY3: A mixed protocol framework for machine learning","author":"mohassel","year":"2018","journal-title":"Proc ACM SIGSAC Conf Comput Commun Security"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978331"},{"key":"ref104","year":"2020"},{"key":"ref90","first-page":"420","article-title":"Efficient multiparty protocols using circuit randomization","author":"beaver","year":"1991","journal-title":"Proc Annu Int Cryptol Conf"},{"key":"ref103","year":"2020"},{"key":"ref102","year":"2020"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1145\/2948618.2954331"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"ref110","doi-asserted-by":"crossref","DOI":"10.1145\/3372297.3417872","article-title":"MP-SPDZ: A versatile framework for multi-party computation","author":"keller","year":"2020"},{"key":"ref98","year":"2020"},{"key":"ref99","year":"2020"},{"key":"ref96","year":"2020"},{"key":"ref97","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2011.2134090"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6639344"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2670780"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2944377"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2018.00178"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1145\/3065913.3065915"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2844341"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.39"},{"key":"ref117","first-page":"11","article-title":"Software grand exposure: SGX cache attacks are practical","author":"brasser","year":"2017","journal-title":"Proc 11th USENIX Workshop Offensive Technol"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2838574"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/100216.100287"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339819"},{"key":"ref119","first-page":"1213","article-title":"The guard&#x2019;s dilemma: Efficient code-reuse attacks against Intel SGX","author":"biondo","year":"2018","journal-title":"Proc 27th USENIX Security Symp"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46803-6_8"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-22846-4_11"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70972-7_27"},{"key":"ref116","year":"2020"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70583-3_40"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.28"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref89","author":"goldreich","year":"2009","journal-title":"Foundations of Cryptography Volume 2 Basic Applications"},{"key":"ref121","author":"wagh","year":"2020","journal-title":"Falcon Honest-majority maliciously secure framework for private deep learning"},{"key":"ref122","author":"zhu","year":"2020","journal-title":"Hermes attack Steal DNN models with lossless inference accuracy"},{"key":"ref123","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tram\u00e8r","year":"2016","journal-title":"Proc 25th Usenix Security Symp"},{"key":"ref85","article-title":"Yao&#x2019;s garbled circuits: Recent directions and implementations","author":"snyder","year":"2014","journal-title":"Literature Review"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/28395.28420"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_9"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/6488907\/9462546\/9352960-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/9462546\/09352960.pdf?arnumber=9352960","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,17]],"date-time":"2022-12-17T04:14:32Z","timestamp":1671250472000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9352960\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,1]]},"references-count":192,"journal-issue":{"issue":"13"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2021.3058638","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,1]]}}}