{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:03:10Z","timestamp":1784390590115,"version":"3.55.0"},"reference-count":135,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,5,1]],"date-time":"2024-05-01T00:00:00Z","timestamp":1714521600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Shandong Provincial Key Research and Development","award":["2021CXGC010107"],"award-info":[{"award-number":["2021CXGC010107"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202339"],"award-info":[{"award-number":["62202339"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172307"],"award-info":[{"award-number":["62172307"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21A20466"],"award-info":[{"award-number":["U21A20466"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"New 20 Project of Higher Education of Jinan","award":["202228017"],"award-info":[{"award-number":["202228017"]}]},{"name":"Science and Technology Program of Hubei Provience","award":["2020AEA013"],"award-info":[{"award-number":["2020AEA013"]}]},{"name":"Science and Technology Program of Hubei Provience","award":["2021BAA025"],"award-info":[{"award-number":["2021BAA025"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2042023KF0203"],"award-info":[{"award-number":["2042023KF0203"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002383","name":"King Saud University","doi-asserted-by":"publisher","award":["RSP2023R12"],"award-info":[{"award-number":["RSP2023R12"]}],"id":[{"id":"10.13039\/501100002383","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Cloud Technology Endowed"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Knowl. Data Eng."],"published-print":{"date-parts":[[2024,5]]},"DOI":"10.1109\/tkde.2023.3321803","type":"journal-article","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T17:59:51Z","timestamp":1696355991000},"page":"1919-1934","source":"Crossref","is-referenced-by-count":22,"title":["Cryptographic Primitives in Privacy-Preserving Machine Learning: A Survey"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7220-5246","authenticated-orcid":false,"given":"Hong","family":"Qin","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2446-7436","authenticated-orcid":false,"given":"Debiao","family":"He","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6927-7855","authenticated-orcid":false,"given":"Qi","family":"Feng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6636-0533","authenticated-orcid":false,"given":"Muhammad Khurram","family":"Khan","sequence":"additional","affiliation":[{"name":"Center of Excellence in Information Assurance (CoEIA), King Saud University, Riyadh, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1819-9332","authenticated-orcid":false,"given":"Min","family":"Luo","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[{"name":"Department of Information Systems and Cyber Security, Department of Electrical and Computer Engineering, University of Texas at San Antonio, San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/S0950-7051(01)00143-5"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2016.2551720"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2017.09.017"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpb.2017.01.004"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_25"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-210165"},{"key":"ref7","article-title":"Differential privacy and machine learning: A survey and review","author":"Ji","year":"2014"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62223-7_36"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3436755"},{"key":"ref11","article-title":"Privacy-preserving machine learning: Methods, challenges and directions","author":"Xu","year":"2021"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417274"},{"key":"ref13","article-title":"Extending oblivious transfers efficiently-how to get robustness almost for free","volume-title":"Proc. IACR Cryptology ePrint Arch.","author":"Nielsen"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.38"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3411501.3419418"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/100216.100287"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70583-3_40"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10366-7_15"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46803-6_8"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3335741.3335755"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46766-1_34"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref25","first-page":"2165","article-title":"Ajith suresh, and hossein yalame. Aby2.0: Improved mixed-protocol secure two-party computation","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Patra"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3338466.3358922"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24202"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0036"},{"key":"ref30","first-page":"2651","article-title":"SWIFT: Super-fast and robust privacy-preserving machine learning","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Koti"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DAC.2018.8465894"},{"key":"ref33","first-page":"1501","article-title":"XONN: XNOR-based oblivious deep neural network inference","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Riazi"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0011"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-12612-4_24"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00078"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00086"},{"key":"ref41","first-page":"20473","article-title":"RNNPool: Efficient non-linear pooling for ram constrained inference","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Saha"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833697"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-20465-4_11"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_38"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40203-6_1"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978357"},{"key":"ref47","first-page":"769","article-title":"$\\mathrm{PLX.SPD}\\mathbb {Z}_{2^{k}}$ PLX. SPDZ2k: Efficient MPC mod $2^{k}$2k for dishonest majority","volume-title":"Proc. 38th Annu. Int. Cryptol. Conf.","author":"Cramer","year":"2018"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78372-7_6"},{"key":"ref49","first-page":"254","article-title":"Overdrive2k: Efficient secure MPC over from somewhat homomorphic encryption","volume-title":"Proc. Cryptographer Track RSA Conf.","author":"Orsini"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-21568-2_26"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23113"},{"key":"ref52","first-page":"35","article-title":"ABY3: A mixed protocol framework for machine learning","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Mohassel"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3138611"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3141391"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00045"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2021.3068195"},{"key":"ref57","first-page":"494","article-title":"Privacy-preserving decision trees evaluation via linear functions","volume-title":"Proc. 22nd Eur. Symp. Res. Comput. Secur.","author":"Raymond"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417278"},{"key":"ref59","article-title":"UCI machine learning repository","author":"Bache","year":"2013"},{"key":"ref60","article-title":"vCNN: Verifiable convolutional neural network based on zk-SNARKS","author":"Lee","year":"2020"},{"key":"ref61","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref62","article-title":"ZEN: An optimizing compiler for verifiable, zero-knowledge neural network inferences","author":"Feng","year":"2021"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49896-5_11"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"ref66","article-title":"On -protocolslecture notes,\u201d University of Aarhus, Department for Computer Science","author":"Damg\u00e5rd","year":"2002"},{"key":"ref67","first-page":"501","article-title":"Mystique: Efficient conversions for zero-knowledge proofs with applications to machine learning","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Weng"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93387-0_13"},{"key":"ref69","first-page":"2","article-title":"The million song dataset","volume-title":"Proc. 12nd Int. Soc. Music Inf. Retrieval","volume":"2","author":"Bertin-Mahieux","year":"2011"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.02.006"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref72","article-title":"Additively homomorphical encryption based deep neural network for asymmetrically collaborative machine learning","author":"Zhang","year":"2020"},{"key":"ref73","article-title":"Machine learning classification over encrypted data","author":"Bost","year":"2014"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS.2009.5386475"},{"key":"ref75","article-title":"Privately evaluating decision trees and random forests","author":"Wu","year":"2015"},{"key":"ref76","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"Proc. 33rd Int. Conf. Mach. Learn.","author":"Gilad-Bachrach"},{"key":"ref77","article-title":"Privacy-preserving classification on deep neural network","volume":"2017","author":"Chabanne","year":"2017","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref78","article-title":"CryptoDL: Deep neural networks over encrypted data","author":"Hesamifard","year":"2017"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96878-0_17"},{"key":"ref80","article-title":"SHE: A fast and accurate deep neural network for encrypted data","author":"Lou","year":"2019"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3035591"},{"key":"ref82","first-page":"1651","article-title":"GAZELLE: A low latency framework for secure neural network inference","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Juvekar"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0030"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24119"},{"key":"ref85","article-title":"Multiparty homomorphic encryption: From theory to practice","volume":"2020","author":"Mouchet","year":"2020","journal-title":"IACR Cryptol. ePrint Arch."},{"issue":"11","key":"ref86","first-page":"169","article-title":"On data banks and privacy homomorphisms","volume":"4","author":"Rivest","year":"1978","journal-title":"Found. Secure Comput."},{"key":"ref87","article-title":"Somewhat practical fully homomorphic encryption","author":"Fan","year":"2012"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090262"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46800-5_24"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-019-09319-x"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1515\/jmc-2019-0026"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00043"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00121"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_1"},{"key":"ref97","article-title":"Reading in the dark: Classifying encrypted digits with functional encryption","author":"Dufour-Sans","year":"2018"},{"key":"ref98","article-title":"Partially encrypted machine learning using functional encryption","author":"Ryffel","year":"2019"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-36938-5_21"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30576-7_18"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1007\/11426639_27"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19571-6_16"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10001327"},{"key":"ref104","article-title":"FastSecAgg: Scalable secure aggregation for privacy-preserving federated learning","author":"Kadhe","year":"2020"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00098"},{"key":"ref107","first-page":"911","article-title":"Fuzzy labeled private set intersection with applications to private real-time biometric search","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Uzun"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2007.66"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00019"},{"key":"ref112","article-title":"Concentrated differential privacy","author":"Dwork","year":"2016"},{"key":"ref113","article-title":"Generative models for effective ML on private, decentralized datasets","author":"Augenstein","year":"2019"},{"key":"ref114","article-title":"What are machine learning models hiding?","author":"Shmatikov"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-349-14424-2"},{"key":"ref116","first-page":"1","article-title":"Multiparty differential privacy via aggregation of locally trained classifiers","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"23","author":"Pathak"},{"key":"ref117","first-page":"1","article-title":"Distributed learning without distress: Privacy-preserving empirical risk minimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Jayaraman"},{"key":"ref118","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"Papernot","year":"2016"},{"key":"ref119","first-page":"1","article-title":"PATE-GAN: Generating synthetic data with differential privacy guarantees","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Jordon"},{"key":"ref120","article-title":"Scalable differentially private generative student model via pate","author":"Long","year":"2019"},{"key":"ref121","first-page":"12673","article-title":"GS-WGAN: A gradient-sanitized approach for learning differentially private generators","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"ref123","first-page":"619","article-title":"Oblivious multi-party machine learning on trusted processors","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Ohrimenko"},{"key":"ref124","article-title":"Efficient deep learning on multi-source private data","author":"Hynes","year":"2018"},{"key":"ref125","article-title":"Chiron: Privacy-preserving machine learning as a service","author":"Hunt","year":"2018"},{"key":"ref126","article-title":"SLALOM: Fast, verifiable and private execution of neural networks in trusted hardware","author":"Tramer","year":"2018"},{"key":"ref127","article-title":"Probabilistic machines can use less running time","volume-title":"Proc. IFIP Congr.","author":"Freivalds"},{"key":"ref128","article-title":"Securing input data of deep learning inference systems via partitioned enclave execution","author":"Gu","year":"2018"},{"key":"ref129","article-title":"Privacy-preserving inference in machine learning services using trusted execution environments","author":"Narra","year":"2019"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1994.365700"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28166-7_4"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-12280-9_10"},{"key":"ref133","article-title":"Universally composable oblivious transfer protocol based on the RLWE assumption","author":"Branco","year":"2018"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-34805-0_22"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48329-2_2"}],"container-title":["IEEE Transactions on Knowledge and Data Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/69\/10490287\/10269692.pdf?arnumber=10269692","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T18:32:13Z","timestamp":1725647533000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10269692\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5]]},"references-count":135,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tkde.2023.3321803","relation":{},"ISSN":["1041-4347","1558-2191","2326-3865"],"issn-type":[{"value":"1041-4347","type":"print"},{"value":"1558-2191","type":"electronic"},{"value":"2326-3865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,5]]}}}