{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T07:16:52Z","timestamp":1781248612597,"version":"3.54.1"},"reference-count":66,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3550834","type":"journal-article","created":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T17:39:41Z","timestamp":1741801181000},"page":"3534-3549","source":"Crossref","is-referenced-by-count":3,"title":["MD-SONIC: Maliciously-Secure Outsourcing Neural Network Inference With Reduced Online Communication"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-0672-4354","authenticated-orcid":false,"given":"Yansong","family":"Zhang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0362-847X","authenticated-orcid":false,"given":"Xiaojun","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2105-8047","authenticated-orcid":false,"given":"Ye","family":"Dong","sequence":"additional","affiliation":[{"name":"National University of Singapore, Tampines, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-0271-7507","authenticated-orcid":false,"given":"Qinghui","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9215-7632","authenticated-orcid":false,"given":"Rui","family":"Hou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0046-7001","authenticated-orcid":false,"given":"Qiang","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0369-9899","authenticated-orcid":false,"given":"Xudong","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, State Key Laboratory of Cyberspace Security Defense, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417274"},{"key":"ref3","first-page":"2201","article-title":"Muse: Secure inference resilient to malicious clients","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Lehmkuhl"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3288557"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.38"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref7","first-page":"2165","article-title":"ABY2.0: Improved mixed-protocol secure two-party computation","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Patra"},{"key":"ref8","first-page":"827","article-title":"Piranha: A GPU platform for secure computation","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Secur.)","author":"Watson"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583272"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265342"},{"key":"ref11","first-page":"1939","article-title":"Scalable multi-party computation protocols for machine learning in the honest-majority setting","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Liu"},{"key":"ref12","first-page":"35","article-title":"ABY3: A mixed protocol framework for machine learning","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Mohassel"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24202"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"ref15","first-page":"2183","article-title":"Fantastic four: Honest-majority four-party secure computation with malicious security","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Dalskov"},{"key":"ref16","first-page":"2651","article-title":"SWIFT: Super-fast and robust privacy-preserving machine learning","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Koti"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0011"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24058"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00078"},{"key":"ref20","first-page":"769","article-title":"SPDZ2k: Efficient MPC mod 2k for dishonest majority","volume-title":"Proc. Annu. Int. Cryptol. Conf.","author":"Cramer"},{"key":"ref21","first-page":"2227","article-title":"MD-ML: Super fast privacy-preserving machine learning for malicious security with a dishonest majority","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Yuan"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-21568-2_26"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15317-4_13"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_38"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40203-6_1"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2664168.2664170"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2370255"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-54970-4_10"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56880-1_29"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-35423-7_12"},{"key":"ref31","first-page":"495","article-title":"Dishonest majority multi-party computation for binary circuits","volume-title":"Proc. 34th Annu. Int. Cryptol. Conf.","author":"Larraia"},{"key":"ref32","first-page":"711","article-title":"A unified approach to MPC with preprocessing using OT","volume-title":"Proc. 21st Int. Conf. Theory Appl. Cryptol. Inf. Secur.","author":"Frederiksen"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-021-09403-1"},{"key":"ref34","first-page":"247","article-title":"Universally composable efficient multiparty computation from threshold homomorphic encryption","volume-title":"Proc. Annu. Int. Cryptol. Conf.","author":"Damg\u00e5rd"},{"key":"ref35","volume-title":"FRESCO\u2014A Framework for Efficient Secure Computation","author":"Alexandra","year":"2024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.2001.959888"},{"key":"ref37","first-page":"645","article-title":"Secure equality and greater-than tests with sublinear online complexity","volume-title":"Proc. 40th Int. Colloq. Automata Lang. Program. (ICALP)","author":"Lipmaa"},{"key":"ref38","volume-title":"Deliverable D9.2, EUFP7 Project Secure Supply Chain Management","year":"2009"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3141391"},{"key":"ref40","volume-title":"Mnist Handwritten Digit Database","author":"LeCun","year":"2010"},{"key":"ref41","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"issue":"7","key":"ref42","first-page":"3","article-title":"Tiny ImageNet visual recognition challenge","volume":"7","author":"Le","year":"2015"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref46","first-page":"84","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NIPS)","volume":"25","author":"Krizhevsky"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref48","volume-title":"Rings: Efficient Java\/Scala Library for Polynomial Rings","author":"Stanislav","year":"2024"},{"key":"ref49","volume-title":"The Bouncy Castle Crypto Package For Java","year":"2024"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417872"},{"key":"ref51","volume-title":"Fresco Outsourcing\u2014Tools to Work With FRESCO in the Outsourced MPC Setting","author":"Alexandra","year":"2024"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23113"},{"key":"ref53","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref54","first-page":"2147","article-title":"GForce: GPU-friendly oblivious and rapid neural network inference","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Ng"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00098"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0077"},{"key":"ref57","first-page":"497","article-title":"SoK: Cryptographic neural-network computation","volume-title":"Proc. IEEE Symp. Secur. Privacy (SP)","author":"Ng"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978357"},{"key":"ref59","first-page":"158","article-title":"Overdrive: Making SPDZ great again","volume-title":"Proc. Int. Conf. Theory Appl. Cryptograph. Techn. (EUROCRYPT)","author":"Keller"},{"key":"ref60","first-page":"383","article-title":"More efficient dishonest majority secure computation over Z2k via Galois rings","volume-title":"Proc. Annu. Int. Cryptol. Conf.","author":"Escudero"},{"key":"ref61","first-page":"395","article-title":"Amortized complexity of information-theoretically secure MPC revisited","volume-title":"Proc. 38th Annu. Int. Cryptol. Conf.","author":"Cascudo"},{"key":"ref62","first-page":"681","article-title":"A new approach to practical active-secure two-party computation","volume-title":"Proc. Cryptol. Conf. (CRYPTO)","author":"Nielsen"},{"key":"ref63","first-page":"169","article-title":"Semi-homomorphic encryption and multiparty computation","volume-title":"Proc. 30th Annu. Int. Conf. Theory Appl. Cryptograph. Techn.","author":"Bendlin"},{"key":"ref64","first-page":"21","article-title":"Authenticated garbling and efficient maliciously secure two-party computation","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Wang"},{"key":"ref65","first-page":"39","article-title":"Global-scale secure multiparty computation","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Wang"},{"key":"ref66","first-page":"1627","article-title":"More efficient MPC from improved triple generation and authenticated garbling","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Yang"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10924655.pdf?arnumber=10924655","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T20:56:34Z","timestamp":1743540994000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10924655\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3550834","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}