{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T18:00:36Z","timestamp":1773511236250,"version":"3.50.1"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["2018YFB0803400"],"award-info":[{"award-number":["2018YFB0803400"]}]},{"name":"Tsinghua University - AsiaInfo Technologies Inc."},{"name":"Joint Rsearch Center","award":["20203910074"],"award-info":[{"award-number":["20203910074"]}]},{"DOI":"10.13039\/501100005153","name":"China National Funds for Distinguished Young Scientists","doi-asserted-by":"publisher","award":["61625205"],"award-info":[{"award-number":["61625205"]}],"id":[{"id":"10.13039\/501100005153","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62132018"],"award-info":[{"award-number":["62132018"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61751211"],"award-info":[{"award-number":["61751211"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61572347"],"award-info":[{"award-number":["61572347"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61520106007"],"award-info":[{"award-number":["61520106007"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Research Program of Frontier Sciences, CAS","award":["QYZDY-SSW-JSC002"],"award-info":[{"award-number":["QYZDY-SSW-JSC002"]}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1526638"],"award-info":[{"award-number":["CNS-1526638"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022,11,1]]},"DOI":"10.1109\/tdsc.2021.3126315","type":"journal-article","created":{"date-parts":[[2021,11,9]],"date-time":"2021-11-09T20:39:46Z","timestamp":1636490386000},"page":"4270-4284","source":"Crossref","is-referenced-by-count":42,"title":["Model Protection: Real-Time Privacy-Preserving Inference Service for Model Privacy at the Edge"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3340-8585","authenticated-orcid":false,"given":"Jiahui","family":"Hou","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1879-0779","authenticated-orcid":false,"given":"Huiqi","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7352-8955","authenticated-orcid":false,"given":"Yunxin","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute for AI Industry Research (AIR), Tsinghua University, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3511-0288","authenticated-orcid":false,"given":"Yu","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Sciences, Temple University, Philadelphia, PA, USA"}]},{"given":"Peng-Jun","family":"Wan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Illinois Institute of Technology, Chicago, IL, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6070-6625","authenticated-orcid":false,"given":"Xiang-Yang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China, Hefei, Anhui, China"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Privacy-preserving inference in machine learning services using trusted execution environments","author":"narra","year":"2019"},{"key":"ref38","article-title":"TensorSCONE: A secure tensorflow framework using Intel SGX","author":"kunkel","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.17"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345447"},{"key":"ref30","article-title":"YerbaBuena: Securing deep learning inference data via enclave-based ternary model partitioning","author":"gu","year":"2018"},{"key":"ref37","first-page":"619","article-title":"Oblivious multi-party machine learning on trusted processors","author":"ohrimenko","year":"2016","journal-title":"Proc 25th USENIX Secur Symp"},{"key":"ref36","first-page":"2505","article-title":"Delphi: A cryptographic inference service for neural networks","author":"mishra","year":"2020","journal-title":"Proc Usenix Secur Symp"},{"key":"ref35","first-page":"1651","article-title":"GAZELLE: A low latency framework for secure neural network inference","author":"juvekar","year":"2018","journal-title":"Proc Usenix Secur Symp"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref28","article-title":"Keras Applications","year":"0"},{"key":"ref27","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref29","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"tramer","year":"2019","journal-title":"Proc 7th Int Conf Learn Representations"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2920283"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCE.2019.8661990"},{"key":"ref20","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and Huffman coding","author":"han","year":"2016","journal-title":"Proc 4th Int Conf Learn Representations"},{"key":"ref22","article-title":"Analysis and optimization of convolutional neural network architectures","author":"thoma","year":"2017"},{"key":"ref21","article-title":"Pruning filters for efficient ConvNets","author":"li","year":"2017","journal-title":"Proc 5th Int Conf Learn Representations"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1137\/1037125"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref26","article-title":"TensorFlow: Large-scale machine learning on heterogeneous distributed systems","author":"abadi","year":"2016"},{"key":"ref25","doi-asserted-by":"crossref","first-page":"354","DOI":"10.1007\/BF02165411","article-title":"Gaussian elimination is not optimal","volume":"13","author":"strassen","year":"1969","journal-title":"Numerische Mathematik"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3326285.3329042"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref54","first-page":"1345","article-title":"High accuracy and high fidelity extraction of neural networks","author":"jagielski","year":"2020","journal-title":"Proc 29th USENIX Secur Symp"},{"key":"ref53","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"papernot","year":"2017","journal-title":"Proc 5th Int Conf Learn Representations"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref10","article-title":"MLCapsule: Guarded offline deployment of machine learning as a service","author":"hanzlik","year":"2018"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116560"},{"key":"ref40","article-title":"Confidential deep learning: Executing proprietary models on untrusted devices","author":"vannostrand","year":"2019"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref14","first-page":"1","article-title":"Intel SGX explained","volume":"2016","author":"costan","year":"2016","journal-title":"IACR Cryptol ePrint Arch"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"ref16","article-title":"Privado: Practical and secure DNN inference with enclaves","author":"grover","year":"2018"},{"key":"ref17","article-title":"SGAxe: How SGX fails in practice","author":"van schaik","year":"2020"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2908843"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1056\/NEJMra1814259"},{"key":"ref6","article-title":"EfficientNet: Rethinking model scaling for convolutional neural networks","author":"tan","year":"2019"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref8","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","author":"bachrach","year":"2016","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref49","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tram\u00e8r","year":"2016","journal-title":"Proc Usenix Secur Symp"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23241"},{"key":"ref46","first-page":"557","article-title":"Inferring fine-grained control flow inside SGX enclaves with branch shadowing","author":"lee","year":"2017","journal-title":"Proc 26th USENIX Secur Symp"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00057"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3456631"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134038"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3411508.3421376"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00020"},{"key":"ref43","first-page":"991","article-title":"Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution","author":"van bulck","year":"2018","journal-title":"Proc Usenix Secur Symp"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/8858\/9945627\/9609559-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/9945627\/09609559.pdf?arnumber=9609559","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,12]],"date-time":"2022-12-12T19:25:19Z","timestamp":1670873119000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9609559\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,1]]},"references-count":54,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2021.3126315","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,1]]}}}