{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:28:13Z","timestamp":1772040493438,"version":"3.50.1"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Graduate Research and Innovation Foundation of Chongqing","award":["CYB25038"],"award-info":[{"award-number":["CYB25038"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20A20176"],"award-info":[{"award-number":["U20A20176"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072062"],"award-info":[{"award-number":["62072062"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100005230","name":"Natural Science Foundation of Chongqing","doi-asserted-by":"publisher","award":["CSTB2023NSCQ-LZX0149"],"award-info":[{"award-number":["CSTB2023NSCQ-LZX0149"]}],"id":[{"id":"10.13039\/501100005230","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Sci. Eng."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tnse.2025.3598578","type":"journal-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T17:35:35Z","timestamp":1755106535000},"page":"1647-1661","source":"Crossref","is-referenced-by-count":2,"title":["SecDV: A Lightweight Secure Deep Neural Network Inference Service With Dynamic Verification"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-3221-2671","authenticated-orcid":false,"given":"Dong","family":"Li","sequence":"first","affiliation":[{"name":"Key Laboratory of Dependable Services Computing in Cyber Physical &amp; Society-Ministry of Education, College of Computer, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8818-6983","authenticated-orcid":false,"given":"Anupam","family":"Chattopadhyay","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-6377-322X","authenticated-orcid":false,"given":"Yang","family":"Zhou","sequence":"additional","affiliation":[{"name":"Tencent Technology Company, Ltd., Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2938-8506","authenticated-orcid":false,"given":"Bowen","family":"Xing","sequence":"additional","affiliation":[{"name":"Key Laboratory of Dependable Services Computing in Cyber Physical &amp; Society-Ministry of Education, College of Computer, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3602-0946","authenticated-orcid":false,"given":"Qingguo","family":"L\u00fc","sequence":"additional","affiliation":[{"name":"Key Laboratory of Dependable Services Computing in Cyber Physical &amp; Society-Ministry of Education, College of Computer, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0121-5575","authenticated-orcid":false,"given":"Jiahui","family":"Wu","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9439-4623","authenticated-orcid":false,"given":"Tao","family":"Xiang","sequence":"additional","affiliation":[{"name":"Key Laboratory of Dependable Services Computing in Cyber Physical &amp; Society-Ministry of Education, College of Computer, Chongqing University, Chongqing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3566-8161","authenticated-orcid":false,"given":"Xiaofeng","family":"Liao","sequence":"additional","affiliation":[{"name":"Key Laboratory of Dependable Services Computing in Cyber Physical &amp; Society-Ministry of Education, College of Computer, Chongqing University, Chongqing, China"}]}],"member":"263","reference":[{"issue":"1","key":"ref1","first-page":"68","article-title":"Big data analysis by infinite deep neural networks","volume":"53","author":"Zhang","year":"2016","journal-title":"J. Comput. Res. Develop."},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2024.3432917"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/s10278-024-01384-4"},{"key":"ref4","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Gilad-Bachrach","year":"2016"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-45239-0_4"},{"key":"ref6","first-page":"1","article-title":"Privacy-preserving classification on deep neural network","author":"Chabanne","year":"2017","journal-title":"Cryptol. ePrint Arch."},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3411501.3419418"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-008-9036-8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3138611"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3355223"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s102070100002"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2018-0024"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/547"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.12.015"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-70896-1_20"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314628"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3386023"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3474366.3486929"},{"key":"ref20","first-page":"2201","article-title":"Muse: Secure inference resilient to malicious clients","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Lehmkuhl","year":"2021"},{"key":"ref21","first-page":"812","article-title":"Low latency privacy preserving inference","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Brutzkus","year":"2019"},{"key":"ref22","first-page":"2364","article-title":"Falcon: Fast spectral inference on encrypted data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Lou","year":"2020"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00942"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00873"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96878-0_17"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-78086-9_1"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_14"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2023.3332760"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3251982"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2020.3040704"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3141391"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3287072"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2913362"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3029899"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2023.3307884"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2022.3177755"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2024.3434643"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2023.3349298"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103142"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3486611"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2021.3090173"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315318"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/1870779"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM52923.2024.10901319"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2020.3043755"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3262932"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC63791.2024.00063"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3348760"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-54773-7_15"},{"key":"ref51","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Chandrasekaran","year":"2020"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358646"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref54","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Jia","year":"2021"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485838"},{"key":"ref56","first-page":"15241","article-title":"How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mazeika","year":"2022"},{"key":"ref57","first-page":"1","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","volume-title":"Proc. Int. Conf. Representation Learn.","author":"Orekondy","year":"2020"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3474366.3486923"},{"key":"ref59","article-title":"Pure-python ECDSA signature\/verification and ECDH key agrrement","author":"Kario","year":"2021"},{"key":"ref60","article-title":"The MNIST database of handwritten digits","author":"LeCun","year":"1998"},{"key":"ref61","article-title":"CIFAR10 (Canadian Institute for Advanced Research)","author":"Alex","year":"2009"}],"container-title":["IEEE Transactions on Network Science and Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6488902\/11264281\/11123773.pdf?arnumber=11123773","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T18:43:49Z","timestamp":1764787429000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11123773\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tnse.2025.3598578","relation":{},"ISSN":["2327-4697","2334-329X"],"issn-type":[{"value":"2327-4697","type":"electronic"},{"value":"2334-329X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}