{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T10:37:00Z","timestamp":1781606220281,"version":"3.54.5"},"reference-count":170,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2023,11,27]],"date-time":"2023-11-27T00:00:00Z","timestamp":1701043200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2024,5,31]]},"abstract":"<jats:p>Neural networks\u00a0(NNs) have become one of the most important tools for artificial intelligence. Well-designed and trained\u00a0NNs can perform inference\u00a0(e.g., make decisions or predictions) on unseen inputs with high accuracy. Using\u00a0NNs often involves sensitive data: Depending on the specific use case, the input to the\u00a0NN and\/or the internals of the\u00a0NN \u00a0(e.g., the weights and biases) may be sensitive. Thus, there is a need for techniques for performing\u00a0NN inference securely, ensuring that sensitive data remain secret.<\/jats:p>\n          <jats:p>In the past few years, several approaches have been proposed for\u00a0secure neural network inference. These approaches achieve better and better results in terms of efficiency, security, accuracy, and applicability, thus making big progress toward practical\u00a0secure neural network inference. The proposed approaches make use of many different techniques, such as\u00a0homomorphic encryption and\u00a0secure multi-party computation. The aim of this article is to give an overview of the main approaches proposed so far, their different properties, and the techniques used. In addition, remaining challenges toward large-scale deployments are identified.<\/jats:p>","DOI":"10.1145\/3628446","type":"journal-article","created":{"date-parts":[[2023,10,18]],"date-time":"2023-10-18T21:39:11Z","timestamp":1697665151000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["Towards Practical Secure Neural Network Inference: The Journey So Far and the Road Ahead"],"prefix":"10.1145","volume":"56","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5741-2709","authenticated-orcid":false,"given":"Zolt\u00e1n \u00c1d\u00e1m","family":"Mann","sequence":"first","affiliation":[{"name":"University of Amsterdam, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4906-6871","authenticated-orcid":false,"given":"Christian","family":"Weinert","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-5817-4279","authenticated-orcid":false,"given":"Daphnee","family":"Chabal","sequence":"additional","affiliation":[{"name":"University of Amsterdam, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1010-8157","authenticated-orcid":false,"given":"Joppe W.","family":"Bos","sequence":"additional","affiliation":[{"name":"NXP Semiconductors, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,27]]},"reference":[{"issue":"4","key":"e_1_3_2_2_2","first-page":"79:1\u201379:35","article-title":"A survey on homomorphic encryption schemes: Theory and implementation","volume":"51","author":"Acar Abbas","year":"2018","unstructured":"Abbas Acar, Hidayet Aksu, A. Selcuk Uluagac, and Mauro Conti. 2018. A survey on homomorphic encryption schemes: Theory and implementation. ACM Comput. Surv. 51, 4 (2018), 79:1\u201379:35.","journal-title":"ACM Comput. Surv."},{"key":"e_1_3_2_3_2","first-page":"1","volume-title":"ic-ETITE","author":"Ajit Arohan","year":"2020","unstructured":"Arohan Ajit, Koustav Acharya, and Abhishek Samanta. 2020. A review of convolutional neural networks. In ic-ETITE. IEEE, 1\u20135."},{"key":"e_1_3_2_4_2","first-page":"99","volume-title":"STOC","author":"Ajtai Mikl\u00f3s","year":"1996","unstructured":"Mikl\u00f3s Ajtai. 1996. Generating hard instances of lattice problems (extended abstract). In STOC. ACM, 99\u2013108."},{"key":"e_1_3_2_5_2","volume-title":"Status Report on the Third Round of the NIST Post-quantum Cryptography Standardization Process","author":"Alagic Gorjan","year":"2022","unstructured":"Gorjan Alagic, Daniel Apon, David Cooper, Quynh Dang, Thinh Dang, John Kelsey, Jacob Lichtinger, Carl Miller, Dustin Moody, Rene Peralta, et\u00a0al. 2022. Status Report on the Third Round of the NIST Post-quantum Cryptography Standardization Process. Technical Report NISTIR 8413. National Institute of Standards and Technology."},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-016-9236-6"},{"key":"e_1_3_2_7_2","article-title":"OpenFHE: Open-Source Fully Homomorphic Encryption Library","author":"Badawi Ahmad Al","year":"2022","unstructured":"Ahmad Al Badawi, Jack Bates, Fl\u00e1vio Bergamaschi, et\u00a0al. 2022. OpenFHE: Open-Source Fully Homomorphic Encryption Library. Cryptology ePrint Archive, Paper 2022\/915. (2022).","journal-title":"Cryptology ePrint Archive, Paper 2022\/915"},{"key":"e_1_3_2_8_2","first-page":"245","volume-title":"CSCML\u201920","author":"Bakshi Maya","year":"2020","unstructured":"Maya Bakshi and Mark Last. 2020. CryptoRNN - Privacy-preserving recurrent neural networks using homomorphic encryption. In CSCML\u201920. Springer, 245\u2013253."},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1145\/1161366.1161393","volume-title":"MM&Sec","author":"Barni Mauro","year":"2006","unstructured":"Mauro Barni, Claudio Orlandi, and Alessandro Piva. 2006. A privacy-preserving protocol for neural-network-based computation. In MM&Sec. ACM, 146\u2013151."},{"key":"e_1_3_2_10_2","first-page":"420","volume-title":"CRYPTO","author":"Beaver Donald","year":"1991","unstructured":"Donald Beaver. 1991. Efficient multiparty protocols using circuit randomization. In CRYPTO. Springer, 420\u2013432."},{"key":"e_1_3_2_11_2","first-page":"97","volume-title":"CRYPTO","author":"Beaver Donald","year":"1995","unstructured":"Donald Beaver. 1995. Precomputing oblivious transfer. In CRYPTO. Springer, 97\u2013109."},{"key":"e_1_3_2_12_2","first-page":"478","volume-title":"SP","author":"Bellare Mihir","year":"2013","unstructured":"Mihir Bellare, Viet Tung Hoang, Sriram Keelveedhi, and Phillip Rogaway. 2013. Efficient garbling from a fixed-key blockcipher. In SP. IEEE Computer Society, 478\u2013492."},{"key":"e_1_3_2_13_2","first-page":"547","volume-title":"CRYPTO","author":"Bellare Mihir","year":"1989","unstructured":"Mihir Bellare and Silvio Micali. 1989. Non-interactive oblivious transfer and applications. In CRYPTO. Springer, 547\u2013557."},{"key":"e_1_3_2_14_2","first-page":"1746","volume-title":"ECAI (Frontiers in Artificial Intelligence and Applications)","author":"Bian Song","year":"2020","unstructured":"Song Bian, Weiwen Jiang, Qing Lu, Yiyu Shi, and Takashi Sato. 2020. NASS: Optimizing secure inference via neural architecture search. In ECAI (Frontiers in Artificial Intelligence and Applications), Vol. 325. IOS Press, 1746\u20131753."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2877890"},{"key":"e_1_3_2_16_2","first-page":"14:1\u201314:10","volume-title":"ARES","author":"Boemer Fabian","year":"2020","unstructured":"Fabian Boemer, Rosario Cammarota, Daniel Demmler, Thomas Schneider, and Hossein Yalame. 2020. MP2ML: A mixed-protocol machine learning framework for private inference. In ARES. ACM, 14:1\u201314:10."},{"key":"e_1_3_2_17_2","first-page":"45","volume-title":"WAHC@CCS","author":"Boemer Fabian","year":"2019","unstructured":"Fabian Boemer, Anamaria Costache, Rosario Cammarota, and Casimir Wierzynski. 2019. nGraph-HE2: A High-throughput framework for neural network inference on encrypted data. In WAHC@CCS. ACM, 45\u201356."},{"key":"e_1_3_2_18_2","first-page":"3","volume-title":"CF","author":"Boemer Fabian","year":"2019","unstructured":"Fabian Boemer, Yixing Lao, Rosario Cammarota, and Casimir Wierzynski. 2019. nGraph-HE: A graph compiler for deep learning on homomorphically encrypted data. In CF. ACM, 3\u201313."},{"key":"e_1_3_2_19_2","first-page":"579","volume-title":"CHES","author":"Bonte Charlotte","year":"2017","unstructured":"Charlotte Bonte, Carl Bootland, Joppe W. Bos, Wouter Castryck, Ilia Iliashenko, and Frederik Vercauteren. 2017. Faster homomorphic function evaluation using non-integral base encoding. In CHES. Springer, 579\u2013600."},{"key":"e_1_3_2_20_2","first-page":"184","volume-title":"AFRICACRYPT","author":"Bos Joppe W.","year":"2017","unstructured":"Joppe W. Bos, Wouter Castryck, Ilia Iliashenko, and Frederik Vercauteren. 2017. Privacy-friendly forecasting for the smart grid using homomorphic encryption and the group method of data handling. In AFRICACRYPT. 184\u2013201."},{"key":"e_1_3_2_21_2","first-page":"45","volume-title":"IMACC","author":"Bos Joppe W.","year":"2013","unstructured":"Joppe W. Bos, Kristin E. Lauter, Jake Loftus, and Michael Naehrig. 2013. Improved security for a ring-based fully homomorphic encryption scheme. In IMACC. Springer, 45\u201364."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.11.041"},{"key":"e_1_3_2_23_2","first-page":"483","volume-title":"CRYPTO","author":"Bourse Florian","year":"2018","unstructured":"Florian Bourse, Michele Minelli, Matthias Minihold, and Pascal Paillier. 2018. Fast homomorphic evaluation of deep discretized neural networks. In CRYPTO. Springer, 483\u2013512."},{"key":"e_1_3_2_24_2","first-page":"291","volume-title":"CCS","author":"Boyle Elette","year":"2019","unstructured":"Elette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai, Lisa Kohl, Peter Rindal, and Peter Scholl. 2019. Efficient two-round OT extension and silent non-interactive secure computation. In CCS. ACM, 291\u2013308."},{"key":"e_1_3_2_25_2","first-page":"387","volume-title":"CRYPTO","author":"Boyle Elette","year":"2020","unstructured":"Elette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai, Lisa Kohl, and Peter Scholl. 2020. Efficient pseudorandom correlation generators from ring-LPN. In CRYPTO. 387\u2013416."},{"key":"e_1_3_2_26_2","first-page":"457","volume-title":"CRYPTO","author":"Boyle Elette","year":"2021","unstructured":"Elette Boyle, Niv Gilboa, Yuval Ishai, and Ariel Nof. 2021. Sublinear GMW-style compiler for MPC with preprocessing. In CRYPTO. Springer, 457\u2013485."},{"key":"e_1_3_2_27_2","first-page":"868","volume-title":"CRYPTO","author":"Brakerski Zvika","year":"2012","unstructured":"Zvika Brakerski. 2012. Fully homomorphic encryption without modulus switching from classical GapSVP. In CRYPTO. Springer, 868\u2013886."},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"309","DOI":"10.1145\/2090236.2090262","volume-title":"ITCS","author":"Brakerski Zvika","year":"2012","unstructured":"Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. 2012. (Leveled) fully homomorphic encryption without bootstrapping. In ITCS. ACM, 309\u2013325."},{"key":"e_1_3_2_29_2","first-page":"1","volume-title":"ITCS","author":"Brakerski Zvika","year":"2014","unstructured":"Zvika Brakerski and Vinod Vaikuntanathan. 2014. Lattice-based FHE as secure as PKE. In ITCS. ACM, 1\u201312."},{"key":"e_1_3_2_30_2","first-page":"812","volume-title":"ICML (Proceedings of Machine Learning Research)","volume":"97","author":"Brutzkus Alon","year":"2019","unstructured":"Alon Brutzkus, Ran Gilad-Bachrach, and Oren Elisha. 2019. Low latency privacy preserving inference. In ICML (Proceedings of Machine Learning Research), Vol. 97. PMLR, 812\u2013821."},{"key":"e_1_3_2_31_2","first-page":"847","volume-title":"CCS","author":"B\u00fcscher Niklas","year":"2018","unstructured":"Niklas B\u00fcscher, Daniel Demmler, Stefan Katzenbeisser, David Kretzmer, and Thomas Schneider. 2018. HyCC: Compilation of hybrid protocols for practical secure computation. In CCS. ACM, 847\u2013861."},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0036"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.5194\/os-9-1-2013"},{"key":"e_1_3_2_34_2","first-page":"136","volume-title":"FOCS","author":"Canetti Ran","year":"2001","unstructured":"Ran Canetti. 2001. Universally composable security: A new paradigm for cryptographic protocols. In FOCS. IEEE Computer Society, 136\u2013145."},{"key":"e_1_3_2_35_2","first-page":"311","volume-title":"ECIR","author":"Caragea Cornelia","year":"2014","unstructured":"Cornelia Caragea, Jian Wu, Alina Maria Ciobanu, Kyle Williams, Juan Pablo Fern\u00e1ndez Ram\u00edrez, Hung-Hsuan Chen, Zhaohui Wu, and C. Lee Giles. 2014. CiteSeer x : A scholarly big dataset. In ECIR. Springer, 311\u2013322."},{"key":"e_1_3_2_36_2","first-page":"357","volume-title":"PKC","author":"Catalano Dario","year":"2020","unstructured":"Dario Catalano, Mario Di Raimondo, Dario Fiore, and Irene Giacomelli. 2020. Mon \\(\\mathbb {Z}_{2^k}\\) a: Fast maliciously secure two party computation on \\(\\mathbb {Z}_{2^k}\\) . In PKC. 357\u2013386."},{"key":"e_1_3_2_37_2","article-title":"On achieving privacy-preserving state-of-the-art edge intelligence","author":"Chabal Daphnee","year":"2023","unstructured":"Daphnee Chabal, Dolly Sapra, and Zolt\u00e1n \u00c1d\u00e1m Mann. 2023. On achieving privacy-preserving state-of-the-art edge intelligence. PPAI.","journal-title":"PPAI"},{"key":"e_1_3_2_38_2","first-page":"1361","volume-title":"USENIX Security Symposium","author":"Chandran Nishanth","year":"2022","unstructured":"Nishanth Chandran, Divya Gupta, Sai Lakshmi Bhavana Obbattu, and Akash Shah. 2022. SIMC: ML inference secure against malicious clients at semi-honest cost. In USENIX Security Symposium. USENIX Association, 1361\u20131378."},{"key":"e_1_3_2_39_2","first-page":"496","volume-title":"EuroS&P","author":"Chandran Nishanth","year":"2019","unstructured":"Nishanth Chandran, Divya Gupta, Aseem Rastogi, Rahul Sharma, and Shardul Tripathi. 2019. EzPC: Programmable and efficient secure two-party computation for machine learning. In EuroS&P. IEEE, 496\u2013511."},{"key":"e_1_3_2_40_2","first-page":"81","volume-title":"CCSW@CCS","author":"Chaudhari Harsh","year":"2019","unstructured":"Harsh Chaudhari, Ashish Choudhury, Arpita Patra, and Ajith Suresh. 2019. ASTRA: High throughput 3pc over rings with application to secure prediction. In CCSW@CCS. ACM, 81\u201392."},{"key":"e_1_3_2_41_2","volume-title":"NDSS","author":"Chaudhari Harsh","year":"2020","unstructured":"Harsh Chaudhari, Rahul Rachuri, and Ajith Suresh. 2020. Trident: Efficient 4PC framework for privacy preserving machine learning. In NDSS. The Internet Society."},{"key":"e_1_3_2_42_2","unstructured":"Yuanfeng Chen Gaofeng Huang Junjie Shi Xiang Xie and Yilin Yan. 2020. Rosetta: A Privacy-Preserving Framework Based on TensorFlow. Retrieved from https:\/\/github.com\/LatticeX-Foundation\/Rosetta."},{"key":"e_1_3_2_43_2","first-page":"409","volume-title":"ASIACRYPT","author":"Cheon Jung Hee","year":"2017","unstructured":"Jung Hee Cheon, Andrey Kim, Miran Kim, and Yong Soo Song. 2017. Homomorphic encryption for arithmetic of approximate numbers. In ASIACRYPT. Springer, 409\u2013437."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-019-09319-x"},{"key":"e_1_3_2_45_2","article-title":"Faster CryptoNets: Leveraging sparsity for real-world encrypted inference","volume":"1811","author":"Chou Edward","year":"2018","unstructured":"Edward Chou, Josh Beal, Daniel Levy, Serena Yeung, Albert Haque, and Li Fei-Fei. 2018. Faster CryptoNets: Leveraging sparsity for real-world encrypted inference. CoRR abs\/1811.09953 (2018).","journal-title":"CoRR"},{"key":"e_1_3_2_46_2","first-page":"40","volume-title":"LATINCRYPT","author":"Chou Tung","year":"2015","unstructured":"Tung Chou and Claudio Orlandi. 2015. The simplest protocol for oblivious transfer. In LATINCRYPT. 40\u201358."},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-12164-7"},{"key":"e_1_3_2_48_2","first-page":"502","volume-title":"CRYPTO","author":"Couteau Geoffroy","year":"2021","unstructured":"Geoffroy Couteau, Peter Rindal, and Srinivasan Raghuraman. 2021. Silver: Silent VOLE and oblivious transfer from hardness of decoding structured LDPC codes. In CRYPTO. Springer, 502\u2013534."},{"key":"e_1_3_2_49_2","first-page":"769","volume-title":"CRYPTO","author":"Cramer Ronald","year":"2018","unstructured":"Ronald Cramer, Ivan Damg\u00e5rd, Daniel Escudero, Peter Scholl, and Chaoping Xing. 2018. SPD \\(\\mathbb {Z}\\) \\({}_{\\mbox{2${}^{\\mbox{k}}$}}\\) : Efficient MPC mod 2 \\({}^{\\mbox{k}}\\) for Dishonest Majority. In CRYPTO. Springer, 769\u2013798."},{"key":"e_1_3_2_50_2","first-page":"1","volume-title":"WAHC@CCS","author":"Crawford Jack L. H.","year":"2018","unstructured":"Jack L. H. Crawford, Craig Gentry, Shai Halevi, Daniel Platt, and Victor Shoup. 2018. Doing real work with FHE: The case of logistic regression. In WAHC@CCS. ACM, 1\u201312."},{"key":"e_1_3_2_51_2","first-page":"318","volume-title":"ICISC","author":"Damg\u00e5rd Ivan","year":"2008","unstructured":"Ivan Damg\u00e5rd, Jesper Buus Nielsen, and Claudio Orlandi. 2008. Essentially optimal universally composable oblivious transfer. In ICISC. Springer, 318\u2013335."},{"key":"e_1_3_2_52_2","first-page":"142","volume-title":"PLDI","author":"Dathathri Roshan","year":"2019","unstructured":"Roshan Dathathri, Olli Saarikivi, Hao Chen, Kim Laine, Kristin E. Lauter, Saeed Maleki, Madanlal Musuvathi, and Todd Mytkowicz. 2019. CHET: An optimizing compiler for fully-homomorphic neural-network inferencing. In PLDI. ACM, 142\u2013156."},{"key":"e_1_3_2_53_2","first-page":"1504","volume-title":"CCS","author":"Demmler Daniel","year":"2015","unstructured":"Daniel Demmler, Ghada Dessouky, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider, and Shaza Zeitouni. 2015. Automated synthesis of optimized circuits for secure computation. In CCS. ACM, 1504\u20131517."},{"key":"e_1_3_2_54_2","volume-title":"NDSS","author":"Demmler Daniel","year":"2015","unstructured":"Daniel Demmler, Thomas Schneider, and Michael Zohner. 2015. ABY - A framework for efficient mixed-protocol secure two-party computation. In NDSS. The Internet Society."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"e_1_3_2_56_2","first-page":"617","volume-title":"EUROCRYPT","author":"Ducas L\u00e9o","year":"2015","unstructured":"L\u00e9o Ducas and Daniele Micciancio. 2015. FHEW: Bootstrapping homomorphic encryption in less than a second. In EUROCRYPT. Springer, 617\u2013640."},{"key":"e_1_3_2_57_2","unstructured":"ENCRYPTO Group. 2021. ENCRYPTO Utils. Retrieved from https:\/\/github.com\/encryptogroup\/ENCRYPTO_utils\/."},{"key":"e_1_3_2_58_2","article-title":"Somewhat Practical Fully Homomorphic Encryption","author":"Fan Junfeng","year":"2012","unstructured":"Junfeng Fan and Frederik Vercauteren. 2012. Somewhat Practical Fully Homomorphic Encryption. IACR Cryptol. ePrint Arch., Paper 2012\/144. (2012).","journal-title":"IACR Cryptol. ePrint Arch., Paper 2012\/144"},{"key":"e_1_3_2_59_2","unstructured":"Galois Inc.2019. fancy-garbling. https:\/\/github.com\/GaloisInc\/fancy-garbling."},{"key":"e_1_3_2_60_2","first-page":"169","volume-title":"STOC","author":"Gentry Craig","year":"2009","unstructured":"Craig Gentry. 2009. Fully homomorphic encryption using ideal lattices. In STOC. ACM, 169\u2013178."},{"key":"e_1_3_2_61_2","first-page":"201","volume-title":"ICML (JMLR Workshop and Conference Proceedings)","volume":"48","author":"Gilad-Bachrach Ran","year":"2016","unstructured":"Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin E. Lauter, Michael Naehrig, and John Wernsing. 2016. CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy. In ICML (JMLR Workshop and Conference Proceedings), Vol. 48. JMLR.org, 201\u2013210."},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511721656"},{"key":"e_1_3_2_63_2","first-page":"218","volume-title":"STOC","author":"Goldreich Oded","year":"1987","unstructured":"Oded Goldreich, Silvio Micali, and Avi Wigderson. 1987. How to play any mental game or A completeness theorem for protocols with honest majority. In STOC. ACM, 218\u2013229."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-021-01453-z"},{"key":"e_1_3_2_65_2","first-page":"15718","article-title":"Iron: Private inference on transformers","volume":"35","author":"Hao Meng","year":"2022","unstructured":"Meng Hao, Hongwei Li, Hanxiao Chen, Pengzhi Xing, Guowen Xu, and Tianwei Zhang. 2022. Iron: Private inference on transformers. Adv. Neural Inf. Process. Syst. 35 (2022), 15718\u201315731.","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_66_2","first-page":"1220","volume-title":"SP","author":"Hastings Marcella","year":"2019","unstructured":"Marcella Hastings, Brett Hemenway, Daniel Noble, and Steve Zdancewic. 2019. SoK: General purpose compilers for secure multi-party computation. In SP. IEEE, 1220\u20131237."},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.5555\/1941859"},{"key":"e_1_3_2_68_2","first-page":"1026","volume-title":"ICCV","author":"He Kaiming","year":"2015","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2015. Delving deep into rectifiers: Surpassing human-level performance on ImageNet classification. In ICCV. IEEE Computer Society, 1026\u20131034."},{"key":"e_1_3_2_69_2","first-page":"763","volume-title":"CRYPTO","author":"Heath David","year":"2020","unstructured":"David Heath and Vladimir Kolesnikov. 2020. Stacked garbling\u2014Garbled circuit proportional to longest execution path. In CRYPTO. Springer, 763\u2013792."},{"key":"e_1_3_2_70_2","first-page":"574","volume-title":"CCS","author":"Heath David","year":"2021","unstructured":"David Heath and Vladimir Kolesnikov. 2021. One hot garbling. In CCS. ACM, 574\u2013593."},{"key":"e_1_3_2_71_2","first-page":"3","volume-title":"EUROCRYPT","author":"Heath David","year":"2022","unstructured":"David Heath, Vladimir Kolesnikov, and Rafail Ostrovsky. 2022. EpiGRAM: Practical garbled RAM. In EUROCRYPT. Springer, 3\u201333."},{"key":"e_1_3_2_72_2","first-page":"99","volume-title":"ACNS","author":"Heldmann Tim","year":"2021","unstructured":"Tim Heldmann, Thomas Schneider, Oleksandr Tkachenko, Christian Weinert, and Hossein Yalame. 2021. LLVM-based circuit compilation for practical secure computation. In ACNS. Springer, 99\u2013121."},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.05.002"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3126315"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.3233\/JIFS-179652"},{"issue":"3","key":"e_1_3_2_76_2","first-page":"1441","article-title":"A lightweight privacy-preserving CNN feature extraction framework for mobile sensing","volume":"18","author":"Huang Kai","year":"2021","unstructured":"Kai Huang, Ximeng Liu, Shaojing Fu, Deke Guo, and Ming Xu. 2021. A lightweight privacy-preserving CNN feature extraction framework for mobile sensing. IEEE Trans. Depend. Secur. Comput. 18, 3 (2021), 1441\u20131455.","journal-title":"IEEE Trans. Depend. Secur. Comput."},{"key":"e_1_3_2_77_2","first-page":"809","volume-title":"USENIX Security Symposium","author":"Huang Zhicong","year":"2022","unstructured":"Zhicong Huang, Wen-jie Lu, Cheng Hong, and Jiansheng Ding. 2022. Cheetah: Lean and fast secure two-party deep neural network inference. In USENIX Security Symposium. USENIX Association, 809\u2013826."},{"key":"e_1_3_2_78_2","first-page":"3266","volume-title":"CCS","author":"Hussain Siam Umar","year":"2021","unstructured":"Siam Umar Hussain, Mojan Javaheripi, Mohammad Samragh, and Farinaz Koushanfar. 2021. COINN: Crypto\/ML codesign for oblivious inference via neural networks. In CCS. ACM, 3266\u20133281."},{"key":"e_1_3_2_79_2","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1145\/3437880.3460394","volume-title":"IH&MMSec","author":"Ibarrondo Alberto","year":"2021","unstructured":"Alberto Ibarrondo, Herv\u00e9 Chabanne, and Melek \u00d6nen. 2021. Banners: Binarized neural networks with replicated secret sharing. In IH&MMSec. ACM, 63\u201374."},{"key":"e_1_3_2_80_2","first-page":"44","volume-title":"STOC","author":"Impagliazzo Russell","year":"1989","unstructured":"Russell Impagliazzo and Steven Rudich. 1989. Limits on the provable consequences of one-way permutations. In STOC. ACM, 44\u201361."},{"key":"e_1_3_2_81_2","first-page":"145","volume-title":"CRYPTO","author":"Ishai Yuval","year":"2003","unstructured":"Yuval Ishai, Joe Kilian, Kobbi Nissim, and Erez Petrank. 2003. Extending oblivious transfers efficiently. In CRYPTO. Springer, 145\u2013161."},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1016\/0005-1098(70)90092-0"},{"key":"e_1_3_2_83_2","first-page":"528","volume-title":"ICC","author":"Jie Yixin","year":"2022","unstructured":"Yixin Jie, Yixuan Ren, Qingtao Wang, Yankai Xie, Chi Zhang, Lingbo Wei, and Jianqing Liu. 2022. Multi-party secure computation with intel sgx for graph neural networks. In ICC. IEEE, 528\u2013533."},{"key":"e_1_3_2_84_2","first-page":"1651","volume-title":"USENIX Security Symposium","author":"Juvekar Chiraag","year":"2018","unstructured":"Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha P. Chandrakasan. 2018. GAZELLE: A low latency framework for secure neural network inference. In USENIX Security Symposium. USENIX Association, 1651\u20131669."},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.5555\/2700550"},{"key":"e_1_3_2_86_2","first-page":"1575","volume-title":"CCS","author":"Keller Marcel","year":"2020","unstructured":"Marcel Keller. 2020. MP-SPDZ: A versatile framework for multi-party computation. In CCS. ACM, 1575\u20131590."},{"key":"e_1_3_2_87_2","first-page":"724","volume-title":"CRYPTO","author":"Keller Marcel","year":"2015","unstructured":"Marcel Keller, Emmanuela Orsini, and Peter Scholl. 2015. Actively secure OT extension with optimal overhead. In CRYPTO. Springer, 724\u2013741."},{"key":"e_1_3_2_88_2","first-page":"830","volume-title":"CCS","author":"Keller Marcel","year":"2016","unstructured":"Marcel Keller, Emmanuela Orsini, and Peter Scholl. 2016. MASCOT: Faster malicious arithmetic secure computation with oblivious transfer. In CCS. ACM, 830\u2013842."},{"key":"e_1_3_2_89_2","first-page":"158","volume-title":"EUROCRYPT","author":"Keller Marcel","year":"2018","unstructured":"Marcel Keller, Valerio Pastro, and Dragos Rotaru. 2018. Overdrive: Making SPDZ great again. In EUROCRYPT. Springer, 158\u2013189."},{"key":"e_1_3_2_90_2","first-page":"4961","volume-title":"NeurIPS","author":"Knott Brian","year":"2021","unstructured":"Brian Knott, Shobha Venkataraman, Awni Y. Hannun, Shubho Sengupta, Mark Ibrahim, and Laurens van der Maaten. 2021. CrypTen: Secure multi-party computation meets machine learning. In NeurIPS. 4961\u20134973."},{"key":"e_1_3_2_91_2","first-page":"54","volume-title":"CRYPTO","author":"Kolesnikov Vladimir","year":"2013","unstructured":"Vladimir Kolesnikov and Ranjit Kumaresan. 2013. Improved OT extension for transferring short secrets. In CRYPTO. Springer, 54\u201370."},{"key":"e_1_3_2_92_2","first-page":"440","volume-title":"CRYPTO","author":"Kolesnikov Vladimir","year":"2014","unstructured":"Vladimir Kolesnikov, Payman Mohassel, and Mike Rosulek. 2014. FleXOR: Flexible garbling for XOR gates that beats free-XOR. In CRYPTO. Springer, 440\u2013457."},{"key":"e_1_3_2_93_2","first-page":"486","volume-title":"ICALP","author":"Kolesnikov Vladimir","year":"2008","unstructured":"Vladimir Kolesnikov and Thomas Schneider. 2008. Improved garbled circuit: Free XOR gates and applications. In ICALP. Springer, 486\u2013498."},{"key":"e_1_3_2_94_2","first-page":"2651","volume-title":"USENIX Security Symposium","author":"Koti Nishat","year":"2021","unstructured":"Nishat Koti, Mahak Pancholi, Arpita Patra, and Ajith Suresh. 2021. SWIFT: Super-fast and robust privacy-preserving machine learning. In USENIX Security Symposium. USENIX Association, 2651\u20132668."},{"key":"e_1_3_2_95_2","volume-title":"NDSS","author":"Koti Nishat","year":"2022","unstructured":"Nishat Koti, Arpita Patra, Rahul Rachuri, and Ajith Suresh. 2022. Tetrad: Actively secure 4PC for secure training and inference. In NDSS. The Internet Society."},{"key":"e_1_3_2_96_2","first-page":"285","volume-title":"USENIX Security Symposium","author":"Kreuter Benjamin","year":"2012","unstructured":"Benjamin Kreuter, Abhi Shelat, and Chih-Hao Shen. 2012. Billion-gate secure computation with malicious adversaries. In USENIX Security Symposium. USENIX Association, 285\u2013300."},{"key":"e_1_3_2_97_2","volume-title":"Learning Multiple Layers of Features from Tiny Images","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. Master\u2019s thesis. University of Toronto."},{"key":"e_1_3_2_98_2","first-page":"336","volume-title":"SP","author":"Kumar Nishant","year":"2020","unstructured":"Nishant Kumar, Mayank Rathee, Nishanth Chandran, Divya Gupta, Aseem Rastogi, and Rahul Sharma. 2020. CrypTFlow: Secure TensorFlow inference. In SP. IEEE, 336\u2013353."},{"key":"e_1_3_2_99_2","first-page":"7","volume-title":"ICDCS Workshops","author":"Lachner Clemens","year":"2021","unstructured":"Clemens Lachner, Zolt\u00e1n \u00c1d\u00e1m Mann, and Schahram Dustdar. 2021. Towards understanding the adaptation space of AI-assisted data protection for video analytics at the edge. In ICDCS Workshops. IEEE, 7\u201312."},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3159694"},{"key":"e_1_3_2_103_2","first-page":"2201","volume-title":"USENIX Security Symposium","author":"Lehmkuhl Ryan","year":"2021","unstructured":"Ryan Lehmkuhl, Pratyush Mishra, Akshayaram Srinivasan, and Raluca Ada Popa. 2021. Muse: Secure inference resilient to malicious clients. In USENIX Security Symposium. USENIX Association, 2201\u20132218."},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57048-8_6"},{"key":"e_1_3_2_105_2","first-page":"619","volume-title":"CCS","author":"Liu Jian","year":"2017","unstructured":"Jian Liu, Mika Juuti, Yao Lu, and N. Asokan. 2017. Oblivious neural network predictions via MiniONN transformations. In CCS. ACM, 619\u2013631."},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"e_1_3_2_107_2","first-page":"10035","volume-title":"NeurIPS","author":"Lou Qian","year":"2019","unstructured":"Qian Lou and Lei Jiang. 2019. SHE: A fast and accurate deep neural network for encrypted data. In NeurIPS. 10035\u201310043."},{"key":"e_1_3_2_108_2","first-page":"7102","volume-title":"ICML (Proceedings of Machine Learning Research)","volume":"139","author":"Lou Qian","year":"2021","unstructured":"Qian Lou and Lei Jiang. 2021. HEMET: A homomorphic-encryption-friendly privacy-preserving mobile neural network architecture. In ICML (Proceedings of Machine Learning Research), Vol. 139. PMLR, 7102\u20137110."},{"key":"e_1_3_2_109_2","first-page":"1","volume-title":"EUROCRYPT","author":"Lyubashevsky Vadim","year":"2010","unstructured":"Vadim Lyubashevsky, Chris Peikert, and Oded Regev. 2010. On ideal lattices and learning with errors over rings. In EUROCRYPT. Springer, 1\u201323."},{"issue":"6","key":"e_1_3_2_110_2","first-page":"1247","article-title":"GPGPU: Hardware\/Software co-design for the masses","volume":"30","author":"Mann Zolt\u00e1n \u00c1d\u00e1m","year":"2011","unstructured":"Zolt\u00e1n \u00c1d\u00e1m Mann. 2011. GPGPU: Hardware\/Software co-design for the masses. Comput. Inf. 30, 6 (2011), 1247\u20131257.","journal-title":"Comput. Inf."},{"key":"e_1_3_2_111_2","first-page":"296","volume-title":"Computer Security\u2013ESORICS 2021 International Workshops","author":"Mann Zolt\u00e1n \u00c1d\u00e1m","year":"2021","unstructured":"Zolt\u00e1n \u00c1d\u00e1m Mann. 2021. Security- and privacy-aware IOT application placement and user assignment. In Computer Security\u2013ESORICS 2021 International Workshops. Springer, 296\u2013316."},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/3124441"},{"key":"e_1_3_2_113_2","unstructured":"Microsoft Research. ([n.d.]). Microsoft SEAL. https:\/\/github.com\/Microsoft\/SEAL."},{"key":"e_1_3_2_114_2","first-page":"2505","volume-title":"USENIX Security Symposium","author":"Mishra Pratyush","year":"2020","unstructured":"Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca Ada Popa. 2020. Delphi: A cryptographic inference service for neural networks. In USENIX Security Symposium. USENIX Association, 2505\u20132522."},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1963\/1\/012173"},{"key":"e_1_3_2_116_2","first-page":"35","volume-title":"CCS","author":"Mohassel Payman","year":"2018","unstructured":"Payman Mohassel and Peter Rindal. 2018. ABY \\({}^{\\mbox{3}}\\) : A mixed protocol framework for machine learning. In CCS. ACM, 35\u201352."},{"key":"e_1_3_2_117_2","first-page":"19","volume-title":"SP","author":"Mohassel Payman","year":"2017","unstructured":"Payman Mohassel and Yupeng Zhang. 2017. SecureML: A system for scalable privacy-preserving machine learning. In SP. IEEE Computer Society, 19\u201338."},{"key":"e_1_3_2_118_2","first-page":"448","volume-title":"SODA","author":"Naor Moni","year":"2001","unstructured":"Moni Naor and Benny Pinkas. 2001. Efficient oblivious transfer protocols. In SODA. ACM\/SIAM, 448\u2013457."},{"key":"e_1_3_2_119_2","first-page":"129","volume-title":"EC","author":"Naor Moni","year":"1999","unstructured":"Moni Naor, Benny Pinkas, and Reuban Sumner. 1999. Privacy preserving auctions and mechanism design. In EC. ACM, 129\u2013139."},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1145\/3434237"},{"key":"e_1_3_2_121_2","article-title":"Oblivious neural network computing via homomorphic encryption","volume":"2007","author":"Orlandi Claudio","year":"2007","unstructured":"Claudio Orlandi, Alessandro Piva, and Mauro Barni. 2007. Oblivious neural network computing via homomorphic encryption. EURASIP J. Inf. Secur. 2007 (2007).","journal-title":"EURASIP J. Inf. Secur."},{"key":"e_1_3_2_122_2","first-page":"254","volume-title":"CT-RSA","author":"Orsini Emmanuela","year":"2020","unstructured":"Emmanuela Orsini, Nigel P. Smart, and Frederik Vercauteren. 2020. Overdrive2k: Efficient secure MPC over \\(\\mathbb {Z}_{2^k}\\) from somewhat homomorphic encryption. In CT-RSA. Springer, 254\u2013283."},{"issue":"5","key":"e_1_3_2_123_2","first-page":"4505","article-title":"A hybrid deep learning architecture for privacy-preserving mobile analytics","volume":"7","author":"Osia Seyed Ali","year":"2020","unstructured":"Seyed Ali Osia, Ali Shahin Shamsabadi, Sina Sajadmanesh, Ali Taheri, Kleomenis Katevas, Hamid R. Rabiee, Nicholas D. Lane, and Hamed Haddadi. 2020. A hybrid deep learning architecture for privacy-preserving mobile analytics. IEEE IoT J. 7, 5 (2020), 4505\u20134518.","journal-title":"IEEE IoT J."},{"key":"e_1_3_2_124_2","first-page":"223","volume-title":"EUROCRYPT","author":"Paillier Pascal","year":"1999","unstructured":"Pascal Paillier. 1999. Public-key cryptosystems based on composite degree residuosity classes. In EUROCRYPT. Springer, 223\u2013238."},{"key":"e_1_3_2_125_2","first-page":"399","volume-title":"EuroS&P","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Patrick D. McDaniel, Arunesh Sinha, and Michael P. Wellman. 2018. SoK: Security and privacy in machine learning. In EuroS&P. IEEE, 399\u2013414."},{"key":"e_1_3_2_126_2","first-page":"2165","volume-title":"USENIX Security Symposium","author":"Patra Arpita","year":"2021","unstructured":"Arpita Patra, Thomas Schneider, Ajith Suresh, and Hossein Yalame. 2021. ABY2.0: Improved mixed-protocol secure two-party computation. In USENIX Security Symposium. USENIX Association, 2165\u20132182."},{"key":"e_1_3_2_127_2","volume-title":"NDSS","author":"Patra Arpita","year":"2020","unstructured":"Arpita Patra and Ajith Suresh. 2020. BLAZE: Blazing fast privacy-preserving machine learning. In NDSS. The Internet Society."},{"key":"e_1_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1561\/0400000074"},{"key":"e_1_3_2_129_2","first-page":"461","volume-title":"STOC","author":"Peikert Chris","year":"2017","unstructured":"Chris Peikert, Oded Regev, and Noah Stephens-Davidowitz. 2017. Pseudorandomness of ring-LWE for any ring and modulus. In STOC. ACM, 461\u2013473."},{"key":"e_1_3_2_130_2","first-page":"554","volume-title":"CRYPTO","author":"Peikert Chris","year":"2008","unstructured":"Chris Peikert, Vinod Vaikuntanathan, and Brent Waters. 2008. A framework for efficient and composable oblivious transfer. In CRYPTO. Springer, 554\u2013571."},{"key":"e_1_3_2_131_2","unstructured":"Lance Roy Peter Rindal. libOTe: An efficient portable and easy to use Oblivious Transfer Library. Retrieved from https:\/\/github.com\/osu-crypto\/libOTe."},{"key":"e_1_3_2_132_2","first-page":"250","volume-title":"ASIACRYPT","author":"Pinkas Benny","year":"2009","unstructured":"Benny Pinkas, Thomas Schneider, Nigel P. Smart, and Stephen C. Williams. 2009. Secure two-party computation is practical. In ASIACRYPT. Springer, 250\u2013267."},{"key":"e_1_3_2_133_2","first-page":"2129","volume-title":"USENIX Security Symposium","author":"Poddar Rishabh","year":"2021","unstructured":"Rishabh Poddar, Sukrit Kalra, Avishay Yanai, Ryan Deng, Raluca Ada Popa, and Joseph M. Hellerstein. 2021. Senate: A maliciously-secure MPC platform for collaborative analytics. In USENIX Security Symposium. USENIX Association, 2129\u20132146."},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1971-0301966-0"},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.1145\/3234150"},{"key":"e_1_3_2_136_2","first-page":"44","volume-title":"Middleware","author":"Quoc Do Le","year":"2020","unstructured":"Do Le Quoc, Franz Gregor, Sergei Arnautov, Roland Kunkel, Pramod Bhatotia, and Christof Fetzer. 2020. SecureTF: A secure TensorFlow framework. In Middleware. ACM, 44\u201359."},{"key":"e_1_3_2_137_2","unstructured":"Michael O. Rabin. 1981. How to exchange secrets with oblivious transfer. Technical Report TR-81 Aiken Computation Lab Harvard University (1981)."},{"key":"e_1_3_2_138_2","first-page":"1003","volume-title":"SP","author":"Rathee Deevashwer","year":"2021","unstructured":"Deevashwer Rathee, Mayank Rathee, Rahul Kranti Kiran Goli, Divya Gupta, Rahul Sharma, Nishanth Chandran, and Aseem Rastogi. 2021. SiRnn: A math library for secure RNN inference. In SP. IEEE, 1003\u20131020."},{"key":"e_1_3_2_139_2","first-page":"325","volume-title":"CCS","author":"Rathee Deevashwer","year":"2020","unstructured":"Deevashwer Rathee, Mayank Rathee, Nishant Kumar, Nishanth Chandran, Divya Gupta, Aseem Rastogi, and Rahul Sharma. 2020. CrypTFlow2: Practical 2-party secure inference. In CCS. ACM, 325\u2013342."},{"key":"e_1_3_2_140_2","first-page":"347","volume-title":"CANS","author":"Rathee Deevashwer","year":"2019","unstructured":"Deevashwer Rathee, Thomas Schneider, and K. K. Shukla. 2019. Improved multiplication triple generation over rings via RLWE-based AHE. In CANS. Springer, 347\u2013359."},{"key":"e_1_3_2_141_2","first-page":"26","volume-title":"HPCA","author":"Reagen Brandon","year":"2021","unstructured":"Brandon Reagen, Wooseok Choi, Yeongil Ko, Vincent T. Lee, Hsien-Hsin S. Lee, Gu-Yeon Wei, and David Brooks. 2021. Cheetah: Optimizing and accelerating homomorphic encryption for private inference. In HPCA. IEEE, 26\u201339."},{"key":"e_1_3_2_142_2","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1145\/1060590.1060603","volume-title":"STOC","author":"Regev Oded","year":"2005","unstructured":"Oded Regev. 2005. On lattices, learning with errors, random linear codes, and cryptography. In STOC. ACM, 84\u201393."},{"key":"e_1_3_2_143_2","first-page":"1","volume-title":"PST","author":"Ren Yixuan","year":"2021","unstructured":"Yixuan Ren, Yixin Jie, Qingtao Wang, Bingbing Zhang, Chi Zhang, and Lingbo Wei. 2021. A hybrid secure computation framework for graph neural networks. In PST. IEEE, 1\u20136."},{"key":"e_1_3_2_144_2","first-page":"1501","volume-title":"USENIX Security Symposium","author":"Riazi M. Sadegh","year":"2019","unstructured":"M. Sadegh Riazi, Mohammad Samragh, Hao Chen, Kim Laine, Kristin E. Lauter, and Farinaz Koushanfar. 2019. XONN: XNOR-based oblivious deep neural network inference. In USENIX Security Symposium. 1501\u20131518."},{"key":"e_1_3_2_145_2","doi-asserted-by":"crossref","first-page":"707","DOI":"10.1145\/3196494.3196522","volume-title":"AsiaCCS","author":"Riazi M. Sadegh","year":"2018","unstructured":"M. Sadegh Riazi, Christian Weinert, Oleksandr Tkachenko, Ebrahim M. Songhori, Thomas Schneider, and Farinaz Koushanfar. 2018. Chameleon: A hybrid secure computation framework for machine learning applications. In AsiaCCS. ACM, 707\u2013721."},{"key":"e_1_3_2_146_2","first-page":"896","volume-title":"ICMLA","author":"Ribeiro Mauro","year":"2015","unstructured":"Mauro Ribeiro, Katarina Grolinger, and Miriam A. M. Capretz. 2015. MLaaS: Machine learning as a service. In ICMLA. IEEE, 896\u2013902."},{"issue":"11","key":"e_1_3_2_147_2","first-page":"169","article-title":"On data banks and privacy homomorphisms","volume":"4","author":"Rivest Ronald L.","year":"1978","unstructured":"Ronald L. Rivest, Len Adleman, and Michael L. Dertouzos. 1978. On data banks and privacy homomorphisms. Found. Secure Comput. 4, 11 (1978), 169\u2013180.","journal-title":"Found. Secure Comput."},{"key":"e_1_3_2_148_2","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"e_1_3_2_149_2","first-page":"94","volume-title":"CRYPTO","author":"Rosulek Mike","year":"2021","unstructured":"Mike Rosulek and Lawrence Roy. 2021. Three halves make a whole? beating the half-gates lower bound for garbled circuits. In CRYPTO. Springer, 94\u2013124."},{"key":"e_1_3_2_150_2","first-page":"2:1\u20132:6","volume-title":"DAC","author":"Rouhani Bita Darvish","year":"2018","unstructured":"Bita Darvish Rouhani, M. Sadegh Riazi, and Farinaz Koushanfar. 2018. DeepSecure: Scalable provably-secure deep learning. In DAC. ACM, 2:1\u20132:6."},{"key":"e_1_3_2_151_2","unstructured":"Lawrence Roy. 2022. oftSpokenOT: Communication-computation tradeoffs in OT extension. In Springer."},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0015"},{"key":"e_1_3_2_153_2","first-page":"93","volume-title":"AISec@CCS","author":"Schl\u00f6gl Alexander","year":"2020","unstructured":"Alexander Schl\u00f6gl and Rainer B\u00f6hme. 2020. eNNclave: Offline inference with model confidentiality. In AISec@CCS. ACM, 93\u2013104."},{"key":"e_1_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0260681"},{"key":"e_1_3_2_155_2","first-page":"411","volume-title":"SP","author":"Songhori Ebrahim M.","year":"2015","unstructured":"Ebrahim M. Songhori, Siam U. Hussain, Ahmad-Reza Sadeghi, Thomas Schneider, and Farinaz Koushanfar. 2015. TinyGarble: Highly compressed and scalable sequential garbled circuits. In SP. IEEE Computer Society, 411\u2013428."},{"key":"e_1_3_2_156_2","first-page":"1021","volume-title":"SP","author":"Tan Sijun","year":"2021","unstructured":"Sijun Tan, Brian Knott, Yuan Tian, and David J. Wu. 2021. CryptGPU: Fast privacy-preserving machine learning on the GPU. In SP. IEEE, 1021\u20131038."},{"key":"e_1_3_2_157_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68176-0_7"},{"key":"e_1_3_2_158_2","volume-title":"ICLR","author":"Tram\u00e8r Florian","year":"2019","unstructured":"Florian Tram\u00e8r and Dan Boneh. 2019. Slalom: Fast, verifiable and private execution of neural networks in trusted hardware. In ICLR. OpenReview.net."},{"key":"e_1_3_2_159_2","doi-asserted-by":"publisher","DOI":"10.1162\/COLI_a_00076"},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"e_1_3_2_161_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0011"},{"key":"e_1_3_2_162_2","unstructured":"Xiao Wang Alex J. Malozemoff and Jonathan Katz. EMP-toolkit: Efficient MultiParty computation toolkit. Retrieved from https:\/\/github.com\/emp-toolkit."},{"key":"e_1_3_2_163_2","first-page":"187","volume-title":"ISPASS","author":"Wang Yongqin","year":"2022","unstructured":"Yongqin Wang, G. Edward Suh, Wenjie Xiong, Benjamin Lefaudeux, Brian Knott, Murali Annavaram, and Hsien-Hsin S. Lee. 2022. Characterization of MPC-based private inference for transformer-based models. In ISPASS. IEEE, 187\u2013197."},{"key":"e_1_3_2_164_2","volume-title":"USENIX Security Symposium","author":"Watson Jean-Luc","year":"2022","unstructured":"Jean-Luc Watson, Sameer Wagh, and Raluca Ada Popa. 2022. Piranha: A GPU platform for secure computation. In USENIX Security Symposium. USENIX Association."},{"key":"e_1_3_2_165_2","first-page":"1607","volume-title":"CCS","author":"Yang Kang","year":"2020","unstructured":"Kang Yang, Chenkai Weng, Xiao Lan, Jiang Zhang, and Xiao Wang. 2020. Ferret: Fast extension for correlated OT with small communication. In CCS. ACM, 1607\u20131626."},{"key":"e_1_3_2_166_2","first-page":"160","volume-title":"FOCS","author":"Yao Andrew Chi-Chih","year":"1982","unstructured":"Andrew Chi-Chih Yao. 1982. Protocols for secure computations (extended abstract). In FOCS. 160\u2013164."},{"key":"e_1_3_2_167_2","first-page":"162","volume-title":"FOCS","author":"Yao Andrew Chi-Chih","year":"1986","unstructured":"Andrew Chi-Chih Yao. 1986. How to generate and exchange secrets (extended abstract). In FOCS. 162\u2013167."},{"key":"e_1_3_2_168_2","first-page":"220","volume-title":"EUROCRYPT","author":"Zahur Samee","year":"2015","unstructured":"Samee Zahur, Mike Rosulek, and David Evans. 2015. Two halves make a whole - reducing data transfer in garbled circuits using half gates. In EUROCRYPT. Springer, 220\u2013250."},{"issue":"13","key":"e_1_3_2_169_2","first-page":"10412","article-title":"Privacy-preserving deep learning based on multiparty secure computation: A survey","volume":"8","author":"Zhang Qiao","year":"2021","unstructured":"Qiao Zhang, Chunsheng Xin, and Hongyi Wu. 2021. Privacy-preserving deep learning based on multiparty secure computation: A survey. IEEE IoT J. 8, 13 (2021), 10412\u201310429.","journal-title":"IEEE IoT J."},{"key":"e_1_3_2_170_2","first-page":"2723","volume-title":"USENIX Security Symposium","author":"Zheng Wenting","year":"2021","unstructured":"Wenting Zheng, Ryan Deng, Weikeng Chen, Raluca Ada Popa, Aurojit Panda, and Ion Stoica. 2021. Cerebro: A platform for multi-party cryptographic collaborative learning. In USENIX Security Symposium. USENIX Association, 2723\u20132740."},{"key":"e_1_3_2_171_2","first-page":"275","volume-title":"ESORICS","author":"Zhu Wenxing","year":"2022","unstructured":"Wenxing Zhu, Mengqi Wei, Xiangxue Li, and Qiang Li. 2022. SecureBiNN: 3-party secure computation for binarized neural network inference. In ESORICS. Springer, 275\u2013294."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3628446","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3628446","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:52Z","timestamp":1750178212000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3628446"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,27]]},"references-count":170,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,5,31]]}},"alternative-id":["10.1145\/3628446"],"URL":"https:\/\/doi.org\/10.1145\/3628446","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,27]]},"assertion":[{"value":"2022-10-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-09-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-11-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}