{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T08:00:15Z","timestamp":1776931215013,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["No.2023YFF0905200"],"award-info":[{"award-number":["No.2023YFF0905200"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,18]]},"DOI":"10.1145\/3725843.3756103","type":"proceedings-article","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T17:19:56Z","timestamp":1760721596000},"page":"326-339","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Athena: Accelerating Quantized Convolutional Neural Networks under Fully Homomorphic Encryption"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0551-5703","authenticated-orcid":false,"given":"Yinghao","family":"Yang","sequence":"first","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-0361-7894","authenticated-orcid":false,"given":"Xicheng","family":"Xu","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6685-5576","authenticated-orcid":false,"given":"Liang","family":"Chang","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China, Chengdu, China and Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6233-3538","authenticated-orcid":false,"given":"Hang","family":"Lu","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China and Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0874-814X","authenticated-orcid":false,"given":"Xiaowei","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China and Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA59077.2024.00060"},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"crossref","unstructured":"Ahmad Al\u00a0Badawi Chao Jin Jie Lin Chan\u00a0Fook Mun Sim\u00a0Jun Jie Benjamin Hong\u00a0Meng Tan Xiao Nan Khin Mi\u00a0Mi Aung and Vijay\u00a0Ramaseshan Chandrasekhar. 2020. Towards the alexnet moment for homomorphic encryption: Hcnn the first homomorphic cnn on encrypted data with gpus. IEEE Transactions on Emerging Topics in Computing 9 3 (2020) 1330\u20131343.","DOI":"10.1109\/TETC.2020.3014636"},{"key":"e_1_3_3_1_4_2","unstructured":"Amazon. [n. d.]. SageMaker with FHE. https:\/\/aws.amazon.com\/cn\/blogs\/machine-learning\/enable-fully-homomorphic-encryption-with-amazon-sagemaker-endpoints-for-secure-real-time-inferencing.."},{"key":"e_1_3_3_1_5_2","unstructured":"Ayoub Benaissa Bilal Retiat Bogdan Cebere and Alaa\u00a0Eddine Belfedhal. 2021. TenSEAL: A Library for Encrypted Tensor Operations Using Homomorphic Encryption. arxiv:https:\/\/arXiv.org\/abs\/2104.03152\u00a0[cs.CR]"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-03101-5_16"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134061"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78381-9_14"},{"key":"e_1_3_3_1_9_2","unstructured":"Jungwook Choi Zhuo Wang Swagath Venkataramani Pierce I-Jen Chuang Vijayalakshmi Srinivasan and Kailash Gopalakrishnan. 2018. Pact: Parameterized clipping activation for quantized neural networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1805.06085 (2018)."},{"key":"e_1_3_3_1_10_2","unstructured":"Edward Chou Josh Beal Daniel Levy Serena Yeung Albert Haque and Li Fei-Fei. 2018. Faster cryptonets: Leveraging sparsity for real-world encrypted inference. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1811.09953 (2018)."},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSE.2017.7945071"},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Daniel Demmler Peter Rindal Mike Rosulek and Ni Trieu. 2018. PIR-PSI: scaling private contact discovery. Cryptology ePrint Archive (2018).","DOI":"10.1515\/popets-2018-0037"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Craig Gentry Shai Halevi Chris Peikert and Nigel\u00a0P Smart. 2013. Field switching in BGV-style homomorphic encryption. Journal of Computer Security 21 5 (2013) 663\u2013684.","DOI":"10.3233\/JCS-130480"},{"key":"e_1_3_3_1_14_2","first-page":"201","volume-title":"International conference on machine learning","author":"Gilad-Bachrach Ran","year":"2016","unstructured":"Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In International conference on machine learning. PMLR, 201\u2013210."},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33019466"},{"key":"e_1_3_3_1_16_2","unstructured":"Ehsan Hesamifard Hassan Takabi and Mehdi Ghasemi. 2017. Cryptodl: Deep neural networks over encrypted data. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1711.05189 (2017)."},{"key":"e_1_3_3_1_17_2","first-page":"809","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Huang Zhicong","year":"2022","unstructured":"Zhicong Huang, Wen-jie Lu, Cheng Hong, and Jiansheng Ding. 2022. Cheetah: Lean and fast secure { Two-Party} deep neural network inference. In 31st USENIX Security Symposium (USENIX Security 22). 809\u2013826."},{"key":"e_1_3_3_1_18_2","unstructured":"Itay Hubara Yury Nahshan Yair Hanani Ron Banner and Daniel Soudry. 2020. Improving post training neural quantization: Layer-wise calibration and integer programming. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2006.10518 (2020)."},{"key":"e_1_3_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData50022.2020.9378372"},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00010"},{"key":"e_1_3_3_1_22_2","unstructured":"Jae\u00a0Hyung Ju Jaiyoung Park Jongmin Kim Donghwan Kim and Jung\u00a0Ho Ahn. 2023. Neujeans: Private neural network inference with joint optimization of convolution and bootstrapping. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2312.04356 (2023)."},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589053"},{"key":"e_1_3_3_1_24_2","unstructured":"Jongmin Kim Gwangho Lee Sangpyo Kim Gina Sohn John Kim Minsoo Rhu and Jung\u00a0Ho Ahn. 2022. ARK: Fully Homomorphic Encryption Accelerator with Runtime Data Generation and Inter-Operation Key Reuse. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2205.00922 (2022)."},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527415"},{"key":"e_1_3_3_1_26_2","unstructured":"Alex Krizhevsky Geoffrey Hinton et\u00a0al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"crossref","unstructured":"Yann LeCun L\u00e9on Bottou Yoshua Bengio and Patrick Haffner. 1998. Gradient-based learning applied to document recognition. Proc. IEEE 86 11 (1998) 2278\u20132324.","DOI":"10.1109\/5.726791"},{"key":"e_1_3_3_1_28_2","first-page":"12403","volume-title":"International Conference on Machine Learning","author":"Lee Eunsang","year":"2022","unstructured":"Eunsang Lee, Joon-Woo Lee, Junghyun Lee, Young-Sik Kim, Yongjune Kim, Jong-Seon No, and Woosuk Choi. 2022. Low-complexity deep convolutional neural networks on fully homomorphic encryption using multiplexed parallel convolutions. In International Conference on Machine Learning. PMLR, 12403\u201312422."},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"crossref","unstructured":"Joon-Woo Lee HyungChul Kang Yongwoo Lee Woosuk Choi Jieun Eom Maxim Deryabin Eunsang Lee Junghyun Lee Donghoon Yoo Young-Sik Kim et\u00a0al. 2022. Privacy-preserving machine learning with fully homomorphic encryption for deep neural network. IEEE Access 10 (2022) 30039\u201330054.","DOI":"10.1109\/ACCESS.2022.3159694"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-8736-8_4"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00043"},{"key":"e_1_3_3_1_32_2","unstructured":"NVIDIA. [n. d.]. 8-bit inference with TensorRT.https:\/\/www.cse.iitd.ac.in\/\u00a0rijurekha\/course\/tensorrt.pdf."},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3123939.3124545"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01225-0_36"},{"key":"e_1_3_3_1_35_2","doi-asserted-by":"crossref","unstructured":"Michael\u00a0S Paterson and Larry\u00a0J Stockmeyer. 1973. On the number of nonscalar multiplications necessary to evaluate polynomials. SIAM J. Comput. 2 1 (1973) 60\u201366.","DOI":"10.1137\/0202007"},{"key":"e_1_3_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA51647.2021.00013"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1109\/HPCA.2019.00052","volume-title":"2019 IEEE International symposium on high performance computer architecture (HPCA)","author":"Roy Sujoy\u00a0Sinha","year":"2019","unstructured":"Sujoy\u00a0Sinha Roy, Furkan Turan, Kimmo Jarvinen, Frederik Vercauteren, and Ingrid Verbauwhede. 2019. FPGA-based high-performance parallel architecture for homomorphic computing on encrypted data. In 2019 IEEE International symposium on high performance computer architecture (HPCA). IEEE, 387\u2013398."},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480070"},{"key":"e_1_3_3_1_39_2","first-page":"173","volume-title":"ISCA","author":"Samardzic Nikola","year":"2022","unstructured":"Nikola Samardzic, Axel Feldmann, Aleksandar Krastev, Nathan Manohar, Nicholas Genise, Srinivas Devadas, Karim Eldefrawy, Chris Peikert, and Daniel Sanchez. 2022. CraterLake: a hardware accelerator for efficient unbounded computation on encrypted data.. In ISCA. 173\u2013187."},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2014.94"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/BIBM.2018.8621291"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA56546.2023.10070984"},{"key":"e_1_3_3_1_43_2","unstructured":"Zhaomin Yang Xiang Xie Huajie Shen Shiying Chen and Jun Zhou. 2021. TOTA: fully homomorphic encryption with smaller parameters and stronger security. Cryptology ePrint Archive (2021)."},{"key":"e_1_3_3_1_44_2","first-page":"11875","volume-title":"International Conference on Machine Learning","author":"Yao Zhewei","year":"2021","unstructured":"Zhewei Yao, Zhen Dong, Zhangcheng Zheng, Amir Gholami, Jiali Yu, Eric Tan, Leyuan Wang, Qijing Huang, Yida Wang, Michael Mahoney, et\u00a0al. 2021. Hawq-v3: Dyadic neural network quantization. In International Conference on Machine Learning. PMLR, 11875\u201311886."}],"event":{"name":"MICRO 2025: 58th IEEE\/ACM International Symposium on Microarchitecture","location":"Seoul Korea","acronym":"MICRO 2025","sponsor":["SIGMICRO ACM Special Interest Group on Microarchitectural Research and Processing"]},"container-title":["Proceedings of the 58th IEEE\/ACM International Symposium on Microarchitecture"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3725843.3756103","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T21:43:11Z","timestamp":1769463791000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3725843.3756103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"references-count":43,"alternative-id":["10.1145\/3725843.3756103","10.1145\/3725843"],"URL":"https:\/\/doi.org\/10.1145\/3725843.3756103","relation":{},"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"2025-10-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}