{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:27:40Z","timestamp":1766442460325,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":75,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765056","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:37:25Z","timestamp":1763854645000},"page":"1053-1067","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Zero-Knowledge AI Inference with High Precision"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9502-7500","authenticated-orcid":false,"given":"Arman","family":"Riasi","sequence":"first","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5453-4126","authenticated-orcid":false,"given":"Haodi","family":"Wang","sequence":"additional","affiliation":[{"name":"City University of Hong Kong, Kowloon Tong, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0423-7606","authenticated-orcid":false,"given":"Rouzbeh","family":"Behnia","sequence":"additional","affiliation":[{"name":"University of South Florida, Tampa, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5984-7981","authenticated-orcid":false,"given":"Viet","family":"Vo","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2229-3863","authenticated-orcid":false,"given":"Thang","family":"Hoang","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/IEEESTD.2019.8766229"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670316"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88238-9_21"},{"key":"e_1_3_2_2_4_1","volume-title":"International Workshop on Large-scale Annotation of Biomedical data and Expert Label Synthesis. Springer, 115--124","author":"Askari Hemmat Mohammad Hossein","year":"2019","unstructured":"Mohammad Hossein Askari Hemmat, Sina Honari, Lucas Rouhier, Christian S Perone, Julien Cohen-Adad, Yvon Savaria, and Jean-Pierre David. 2019. U-net fixed-point quantization for medical image segmentation. In International Workshop on Large-scale Annotation of Biomedical data and Expert Label Synthesis. Springer, 115--124."},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC63791.2024.00069"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.5819104"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00020"},{"key":"e_1_3_2_2_8_1","volume-title":"if-ZKP: Intel FPGA-Based Acceleration of Zero Knowledge Proofs. arXiv preprint arXiv:2412.12481","author":"Butt Shahzad Ahmad","year":"2024","unstructured":"Shahzad Ahmad Butt, Benjamin Reynolds, Veeraraghavan Ramamurthy, Xiao Xiao, Pohrong Chu, Setareh Sharifian, Sergey Gribok, and Bogdan Pasca. 2024. if-ZKP: Intel FPGA-Based Acceleration of Zero Knowledge Proofs. arXiv preprint arXiv:2412.12481 (2024)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339820"},{"key":"e_1_3_2_2_10_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Chandrasekaran Varun","year":"2020","unstructured":"Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020. Exploring connections between active learning and model extraction. In 29th USENIX Security Symposium (USENIX Security 20). 1309--1326."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-30617-4_17"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650088"},{"key":"e_1_3_2_2_13_1","volume-title":"Verifying computations with streaming interactive proofs. arXiv preprint arXiv:1109.6882","author":"Cormode Graham","year":"2011","unstructured":"Graham Cormode, Justin Thaler, and Ke Yi. 2011. Verifying computations with streaming interactive proofs. arXiv preprint arXiv:1109.6882 (2011)."},{"key":"e_1_3_2_2_14_1","volume-title":"Intel SGX explained. Cryptology ePrint Archive","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3695053.3731021"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3656019.3676898"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"e_1_3_2_2_18_1","volume-title":"Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies","volume":"1","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). 4171--4186."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1093\/oso\/9780198534419.001.0001"},{"key":"e_1_3_2_2_20_1","volume-title":"Zero-Knowledge Location Privacy via Accurate Floating-Point SNARKs. arXiv preprint arXiv:2404.14983","author":"Ernstberger Jens","year":"2024","unstructured":"Jens Ernstberger, Chengru Zhang, Luca Ciprian, Philipp Jovanovic, and Sebastian Steinhorst. 2024. Zero-Knowledge Location Privacy via Accurate Floating-Point SNARKs. arXiv preprint arXiv:2404.14983 (2024)."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560565"},{"key":"e_1_3_2_2_22_1","unstructured":"Xiaoyu Fan Kun Chen Guosai Wang Mingchun Zhuang Yi Li and Wei Xu. 2022. NFGen: Automatic Non-Linear Function Evaluation Code Generator for General-purpose MPC Platforms. https:\/\/github.com\/Fannxy\/NFGen."},{"key":"e_1_3_2_2_23_1","volume-title":"Zen: An optimizing compiler for verifiable, zero-knowledge neural network inferences. Cryptology ePrint Archive","author":"Feng Boyuan","year":"2021","unstructured":"Boyuan Feng, Lianke Qin, Zhenfei Zhang, Yufei Ding, and Shumo Chu. 2021. Zen: An optimizing compiler for verifiable, zero-knowledge neural network inferences. Cryptology ePrint Archive (2021)."},{"key":"e_1_3_2_2_24_1","volume-title":"Plonk: Permutations over lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive","author":"Gabizon Ariel","year":"2019","unstructured":"Ariel Gabizon, Zachary J Williamson, and Oana Ciobotaru. 2019. Plonk: Permutations over lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive (2019)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623202"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560653"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38348-9_37"},{"key":"e_1_3_2_2_28_1","volume-title":"Safetynets: Verifiable execution of deep neural networks on an untrusted cloud. Advances in Neural Information Processing Systems 30","author":"Ghodsi Zahra","year":"2017","unstructured":"Zahra Ghodsi, Tianyu Gu, and Siddharth Garg. 2017. Safetynets: Verifiable execution of deep neural networks on an untrusted cloud. Advances in Neural Information Processing Systems 30 (2017)."},{"key":"e_1_3_2_2_29_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Hao Meng","year":"2024","unstructured":"Meng Hao, Hanxiao Chen, Hongwei Li, Chenkai Weng, Yuan Zhang, Haomiao Yang, and Tianwei Zhang. 2024. Scalable zero-knowledge proofs for non-linear functions in machine learning. In 33rd USENIX Security Symposium (USENIX Security 24). 3819--3836."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1098\/rstl.1819.0023"},{"key":"e_1_3_2_2_32_1","volume-title":"Compact: Approximating complex activation functions for secure computation. arXiv preprint arXiv:2309.04664","author":"Islam Mazharul","year":"2023","unstructured":"Mazharul Islam, Sunpreet S Arora, Rahul Chatterjee, Peter Rindal, and Maliheh Shirvanian. 2023. Compact: Approximating complex activation functions for secure computation. arXiv preprint arXiv:2309.04664 (2023)."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-17373-8_11"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3348760"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00035"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"e_1_3_2_2_39_1","volume-title":"Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692","author":"Liu Yinhan","year":"2019","unstructured":"Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019)."},{"key":"e_1_3_2_2_40_1","volume-title":"An efficient and extensible zero-knowledge proof framework for neural networks. Cryptology ePrint Archive","author":"Lu Tao","year":"2024","unstructured":"Tao Lu, Haoyu Wang, Wenjie Qu, Zonghui Wang, Jinye He, Tianyang Tao, Wenzhi Chen, and Jiaheng Zhang. 2024. An efficient and extensible zero-knowledge proof framework for neural networks. Cryptology ePrint Archive (2024)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2023.i3.194-220"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575711"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1201\/9781420036114"},{"key":"e_1_3_2_2_44_1","unstructured":"John McKinstry Joshua Webb Ganesh Janakiraman and Benjamin Kelly. 2021. UTKFace Age Prediction -- Basic Model. https:\/\/www.kaggle.com\/code\/ johnmckinstry\/utkface-age-prediction-gtech-final-project. Accessed: 2025-04-14."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2856449"},{"key":"e_1_3_2_2_46_1","volume-title":"Informatics","volume":"11","author":"Pereira Ivo","year":"2024","unstructured":"Ivo Pereira, Ana Madureira, Nuno Bettencourt, Duarte Coelho, Miguel \u00c2ngelo Rebelo, Carolina Ara\u00fajo, and Daniel Alves de Oliveira. 2024. A Machine Learning as a Service (MLaaS) Approach to Improve Marketing Success. In Informatics, Vol. 11. MDPI, 19."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2025.i2.489-510"},{"key":"e_1_3_2_2_48_1","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei Ilya Sutskever et al. 2019. Language models are unsupervised multitask learners. OpenAI blog 1 8 (2019) 9."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358646"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC63791.2024.00063"},{"key":"e_1_3_2_2_51_1","volume-title":"Don't trigger me! a triggerless backdoor attack against deep neural networks. arXiv preprint arXiv:2010.03282","author":"Salem Ahmed","year":"2020","unstructured":"Ahmed Salem, Michael Backes, and Yang Zhang. 2020. Don't trigger me! a triggerless backdoor attack against deep neural networks. arXiv preprint arXiv:2010.03282 (2020)."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO61859.2024.00035"},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_2_55_1","volume-title":"Zkdl: Efficient zero-knowledge proofs of deep learning training","author":"Sun Haochen","year":"2024","unstructured":"Haochen Sun, Tonghe Bai, Jason Li, and Hongyang Zhang. 2024. Zkdl: Efficient zero-knowledge proofs of deep learning training. IEEE Transactions on Information Forensics and Security (2024)."},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670334"},{"volume-title":"25th USENIX security symposium (USENIX Security 16). 601--618.","author":"Tram\u00e8r Florian","key":"e_1_3_2_2_57_1","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction {APIs}. In 25th USENIX security symposium (USENIX Security 16). 601--618."},{"key":"e_1_3_2_2_58_1","volume-title":"21 Numerical Analysis. The Princeton Companion to Mathematics (illustrated edition ed.)","author":"Trefethen Lloyd N","year":"2008","unstructured":"Lloyd N Trefethen. 2008. IV. 21 Numerical Analysis. The Princeton Companion to Mathematics (illustrated edition ed.). Princeton University Press, USA (2008)."},{"key":"e_1_3_2_2_59_1","volume-title":"Well-read students learn better: On the importance of pre-training compact models. arXiv preprint arXiv:1908.08962","author":"Turc Iulia","year":"2019","unstructured":"Iulia Turc, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Well-read students learn better: On the importance of pre-training compact models. arXiv preprint arXiv:1908.08962 (2019)."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.3390\/cancers15061652"},{"key":"e_1_3_2_2_61_1","unstructured":"Yash Verma and Sunil Bharti. 2025. AI in the Crosshairs: Understanding and Detecting Attacks on AWS AI Services with Trend Vision One. https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/virtualization-andcloud\/ detecting-attacks-on-aws-ai-services-with-trend-vision-one Accessed 7 Jul. 2025."},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.48"},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC"},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0061"},{"key":"e_1_3_2_2_66_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Weng Chenkai","year":"2021","unstructured":"Chenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz, and Xiao Wang. 2021. Mystique: Efficient conversions for {Zero-Knowledge} proofs with applications to machine learning. In 30th USENIX Security Symposium (USENIX Security 21). 501--518."},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3262932"},{"key":"e_1_3_2_2_68_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Wu Howard","year":"2018","unstructured":"Howard Wu, Wenting Zheng, Alessandro Chiesa, Raluca Ada Popa, and Ion Stoica. 2018. {DIZK}: A distributed zero knowledge proof system. In 27th USENIX Security Symposium (USENIX Security 18). 675--692."},{"key":"e_1_3_2_2_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"e_1_3_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560646"},{"key":"e_1_3_2_2_71_1","volume-title":"Caulk: Lookup arguments in sublinear time. https:\/\/github.com\/caulk-crypto\/caulk.","author":"Zapico Arantxa","year":"2022","unstructured":"Arantxa Zapico, Vitalik Buterin, Dmitry Khovratovich, Mary Maller, Anca Nitulescu, and Mark Simkin. 2022. Caulk: Lookup arguments in sublinear time. https:\/\/github.com\/caulk-crypto\/caulk."},{"key":"e_1_3_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2021.3110101"},{"key":"e_1_3_2_2_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417278"},{"key":"e_1_3_2_2_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.463"},{"key":"e_1_3_2_2_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2021.3068195"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765056","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:25:55Z","timestamp":1766442355000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765056"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":75,"alternative-id":["10.1145\/3719027.3765056","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765056","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}