{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T22:46:12Z","timestamp":1776725172000,"version":"3.51.2"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002167"],"award-info":[{"award-number":["62002167"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072239"],"award-info":[{"award-number":["62072239"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972448"],"award-info":[{"award-number":["61972448"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Natural Science Foundation of Jiangsu Province","doi-asserted-by":"publisher","award":["BK20200461"],"award-info":[{"award-number":["BK20200461"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Natural Science Foundation of Jiangsu Province","doi-asserted-by":"publisher","award":["BK20211192"],"award-info":[{"award-number":["BK20211192"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2021A1515110027"],"award-info":[{"award-number":["2021A1515110027"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."],"published-print":{"date-parts":[[2023,4]]},"DOI":"10.1109\/tcad.2022.3197499","type":"journal-article","created":{"date-parts":[[2022,8,9]],"date-time":"2022-08-09T20:37:03Z","timestamp":1660077423000},"page":"1185-1198","source":"Crossref","is-referenced-by-count":10,"title":["RBNN: Memory-Efficient Reconfigurable Deep Binary Neural Network With IP Protection for Internet of Things"],"prefix":"10.1109","volume":"42","author":[{"given":"Huming","family":"Qiu","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hua","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3604-5369","authenticated-orcid":false,"given":"Zhi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Sydney, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5783-2172","authenticated-orcid":false,"given":"Yansong","family":"Gao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7852-6051","authenticated-orcid":false,"given":"Yifeng","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1632-5737","authenticated-orcid":false,"given":"Anmin","family":"Fu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8629-4622","authenticated-orcid":false,"given":"Pan","family":"Zhou","sequence":"additional","affiliation":[{"name":"Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0945-2674","authenticated-orcid":false,"given":"Derek","family":"Abbott","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3242-8197","authenticated-orcid":false,"given":"Said F.","family":"Al-Sarawi","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.11.041"},{"key":"ref2","first-page":"9181","article-title":"Analyzing the confidentiality of undistillable teachers in knowledge distillation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Kundu"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref4","article-title":"SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and <0.5 MB model size","author":"Iandola","year":"2016","journal-title":"arXiv:1602.07360"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00165"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00716"},{"key":"ref8","article-title":"TensorFlow lite micro: Embedded machine learning on TinyML systems","author":"David","year":"2020","journal-title":"arXiv:2010.08678"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-6666-3_1"},{"key":"ref10","first-page":"4107","article-title":"Binarized neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"29","author":"Hubara"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_32"},{"key":"ref12","first-page":"62","article-title":"XNOR-Net++: Improved binary neural networks","volume-title":"Proc. Brit. Mach. Vis. Conf. (BMVC)","author":"Bulat"},{"key":"ref13","article-title":"Training binary neural networks with real-to-binary convolutions","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Martinez"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2017.2682138"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2018.2857019"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107281"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3431920.3439296"},{"key":"ref18","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Adi"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/tcad.2020.3018403"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218651"},{"key":"ref22","article-title":"An overview of multi-task learning in deep neural networks","author":"Ruder","year":"2017","journal-title":"arXiv:1706.05098"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref24","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and Huffman coding","volume-title":"Proc. NIPS Deep Learn. Symp.","author":"Han"},{"key":"ref25","first-page":"344","article-title":"DNR: A tunable robust pruning framework through dynamic network rewiring of DNNs","volume-title":"Proc. 26th Asia South Pac. Design Autom. Conf.","author":"Kundu"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref27","article-title":"Model compression via distillation and quantization","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Polino"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.23919\/DATE54114.2022.9774740"},{"key":"ref29","article-title":"Deepobfuscation: Securing the structure of convolutional neural networks via knowledge distillation","author":"Xu","year":"2018","journal-title":"arXiv:1806.10313"},{"key":"ref30","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv:2007.10760"},{"key":"ref31","first-page":"1505","article-title":"Blind Backdoors in deep learning models","volume-title":"Proc. USENIX Secur. Symp.","author":"Bagdasaryan"},{"key":"ref32","article-title":"Trojannet: Exposing the danger of trojan horse attack on neural networks","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Guo"},{"key":"ref33","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417231"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0072"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"issue":"1","key":"ref37","article-title":"Neural networks for machine learning","volume":"264","author":"Hinton","year":"2012","journal-title":"Coursera, Video Lectures"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref39","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"key":"ref40","volume-title":"Reading Digits in Natural Images With Unsupervised Feature Learning","author":"Netzer","year":"2011"},{"key":"ref41","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref43","volume-title":"Speech Commands: A Dataset for Limited-Vocabulary Speech Recognition","author":"Warden","year":"2018"},{"key":"ref44","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58568-6_9"},{"key":"ref46","article-title":"Learning class unique features in fine-grained visual classification","author":"Zheng","year":"2020","journal-title":"arXiv:2011.10951"},{"key":"ref47","article-title":"L2 regularization for learning kernels","author":"Cortes","year":"2012","journal-title":"arXiv:1205.2653"},{"key":"ref48","article-title":"Sgdr: Stochastic gradient descent with warm restarts","author":"Loshchilov","year":"2016","journal-title":"arXiv:1608.03983"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00020"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_19"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.21105\/joss.01746"},{"key":"ref52","first-page":"4055","article-title":"Image transformer","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Parmar"},{"key":"ref53","first-page":"7354","article-title":"Self-attention generative adversarial networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1038\/s41928-020-0372-5"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2019.2935465"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2886624"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3057446"},{"key":"ref58","article-title":"Anatomy of catastrophic forgetting: Hidden representations and task semantics","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Ramasesh"},{"key":"ref59","article-title":"NoisFre: Noise-tolerant memory fingerprints from commodity devices for security functions","author":"Gao","year":"2021","journal-title":"arXiv:2109.02942"}],"container-title":["IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/43\/10077488\/09852785.pdf?arnumber=9852785","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T12:12:44Z","timestamp":1706789564000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9852785\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4]]},"references-count":59,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tcad.2022.3197499","relation":{},"ISSN":["0278-0070","1937-4151"],"issn-type":[{"value":"0278-0070","type":"print"},{"value":"1937-4151","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4]]}}}