{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T20:01:53Z","timestamp":1768593713836,"version":"3.49.0"},"reference-count":48,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372173"],"award-info":[{"award-number":["62372173"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372149"],"award-info":[{"award-number":["62372149"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U23A20303"],"award-info":[{"award-number":["U23A20303"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572168"],"award-info":[{"award-number":["62572168"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"Anhui Provincial Natural Science Foundation","doi-asserted-by":"publisher","award":["2508085MF151"],"award-info":[{"award-number":["2508085MF151"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Laboratory of Knowledge Engineering with Big Data","award":["BigKEOpen2025-04"],"award-info":[{"award-number":["BigKEOpen2025-04"]}]},{"name":"Open Foundation of State key Laboratory of Networking and Switching Technology","award":["SKLNST-2025-1-12"],"award-info":[{"award-number":["SKLNST-2025-1-12"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3616623","type":"journal-article","created":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T17:38:15Z","timestamp":1759340295000},"page":"10541-10555","source":"Crossref","is-referenced-by-count":1,"title":["VSecNN: Verifiable and Privacy-Preserving Neural Network Inference in Cloud Service"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0404-5738","authenticated-orcid":false,"given":"Wenti","family":"Yang","sequence":"first","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1444-6690","authenticated-orcid":false,"given":"Xuan","family":"Li","sequence":"additional","affiliation":[{"name":"School of Control and Computer Engineering, North China Electric Power University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3553-0813","authenticated-orcid":false,"given":"Meng","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6313-4407","authenticated-orcid":false,"given":"Zijian","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0901-8621","authenticated-orcid":false,"given":"Zhitao","family":"Guan","sequence":"additional","affiliation":[{"name":"School of Control and Computer Engineering, North China Electric Power University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3277-3887","authenticated-orcid":false,"given":"Liehuang","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2023.3332933"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2018.2851256"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref4","first-page":"809","article-title":"Cheetah: Lean and fast secure two-party deep neural network inference","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security)","author":"Huang"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00063"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3348760"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650088"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670334"},{"key":"ref9","first-page":"501","article-title":"Mystique: Efficient conversions for zero-knowledge proofs with applications to machine learning","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Weng"},{"key":"ref10","article-title":"A survey of zero-knowledge proof based verifiable machine learning","author":"Peng","year":"2025","journal-title":"arXiv:2502.18535"},{"key":"ref11","article-title":"Zero-knowledge proof-based verifiable decentralized machine learning in communication network: A comprehensive survey","author":"Xing","year":"2023","journal-title":"arXiv:2310.14848"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0011"},{"key":"ref14","first-page":"2183","article-title":"Fantastic four: Honest-majority four-party secure computation with malicious security","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Dalskov"},{"key":"ref15","first-page":"2227","article-title":"MD-ML: Super fast privacy-preserving machine learning for malicious security with a dishonest majority","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Yuan"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23199"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427232"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3110808"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3035591"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2024.107560"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102420"},{"key":"ref22","first-page":"4675","article-title":"SafetyNets: Verifiable execution of deep neural networks on an untrusted cloud","volume-title":"Proc. 31st Conf. Neural Inf. Process. Syst. (NIPS)","volume":"30","author":"Ghodsi"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"ref24","article-title":"An efficient and extensible zero-knowledge proof framework for neural networks","author":"Lu","year":"2024","journal-title":"Cryptol. ePrint Arch."},{"key":"ref25","article-title":"ZEN: An optimizing compiler for verifiable, zero-knowledge neural network inferences","author":"Feng","year":"2021","journal-title":"Cryptol. ePrint Arch."},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2024.3350233"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3371643"},{"key":"ref28","first-page":"35","article-title":"ABY3: A mixed protocol framework for machine learning","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Security","author":"Mohassel"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW54576.2021.00048"},{"key":"ref30","first-page":"4291","article-title":"Experimenting with collaborative zk-SNARKs: Zero-knowledge proofs for distributed secrets","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security)","author":"Ozdemir"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49896-5_11"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96878-0_17"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3263631"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref35","first-page":"2505","article-title":"DELPHI: A cryptographic inference service for neural networks","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur.)","author":"Srinivasan"},{"key":"ref36","first-page":"2201","article-title":"Muse: Secure inference resilient to malicious clients","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Lehmkuhl"},{"key":"ref37","first-page":"1361","article-title":"SIMC: ML inference secure against malicious clients at semi-honest cost","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Secur.)","author":"Chandran"},{"key":"ref38","article-title":"CipherGPT: Secure two-party GPT inference","author":"Hou","year":"2023","journal-title":"Cryptol. ePrint Arch."},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3262932"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC63791.2024.00063"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3521396"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_38"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23113"},{"key":"ref44","article-title":"PUMA: Secure inference of LLaMA-7B in five minutes","author":"Dong","year":"2023","journal-title":"arXiv:2307.12533"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-17373-8_11"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3204287"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3192367"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11187352.pdf?arnumber=11187352","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:52:43Z","timestamp":1760032363000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11187352\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":48,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3616623","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}