{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T07:48:00Z","timestamp":1782892080075,"version":"3.54.5"},"reference-count":103,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:00:00Z","timestamp":1630454400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:00:00Z","timestamp":1630454400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1245847"],"award-info":[{"award-number":["1245847"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000002","name":"National Institutes of Health","doi-asserted-by":"publisher","award":["1R43AI136357-01A1"],"award-info":[{"award-number":["1R43AI136357-01A1"]}],"id":[{"id":"10.13039\/100000002","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the ever-growing data and the need for developing powerful machine learning models, data owners increasingly depend on various untrusted platforms (e.g., public clouds, edges, and machine learning service providers) for scalable processing or collaborative learning. Thus, sensitive data and models are in danger of unauthorized access, misuse, and privacy compromises. A relatively new body of research confidentially trains machine learning models on protected data to address these concerns. In this survey, we summarize notable studies in this emerging area of research. With a unified framework, we highlight the critical challenges and innovations in outsourcing machine learning confidentially. We focus on the cryptographic approaches for confidential machine learning (CML), primarily on model training, while also covering other directions such as perturbation-based approaches and CML in the hardware-assisted computing environment. The discussion will take a holistic way to consider a rich context of the related threat models, security assumptions, design principles, and associated trade-offs amongst data utility, cost, and confidentiality.<\/jats:p>","DOI":"10.1186\/s42400-021-00092-8","type":"journal-article","created":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:09:11Z","timestamp":1630454951000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Confidential machine learning on untrusted platforms: a survey"],"prefix":"10.1186","volume":"4","author":[{"given":"Sharma","family":"Sagar","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9996-156X","authenticated-orcid":false,"given":"Chen","family":"Keke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,9,1]]},"reference":[{"key":"92_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M, Chu A, Goodfellow I, McMahan HB, Mironov I, Talwar K, Zhang L (2016) Deep learning with differential privacy In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security CCS \u201916, 308\u2013318.. ACM, New York, NY, USA. http:\/\/doi.org\/10.1145\/2976749.2978318. http:\/\/doi.acm.org\/10.1145\/2976749.2978318.","DOI":"10.1145\/2976749.2978318"},{"key":"92_CR2","doi-asserted-by":"publisher","unstructured":"Acar, A, Aksu H, Uluagac AS, Conti M (2018) A survey on homomorphic encryption schemes: Theory and implementation. ACM Comput Surv 51(4). https:\/\/doi.org\/10.1145\/3214303.","DOI":"10.1145\/3214303"},{"key":"92_CR3","doi-asserted-by":"crossref","unstructured":"Aggarwal, CC, Yu PS (2008) Privacy-preserving data mining: models and algorithms. Springer Science & Business Media.","DOI":"10.1007\/978-0-387-70992-5"},{"key":"92_CR4","first-page":"439","volume-title":"Proceedings of ACM SIGMOD Conference","author":"R Agrawal","year":"2000","unstructured":"Agrawal, R, Srikant R (2000) Privacy-preserving data mining In: Proceedings of ACM SIGMOD Conference, 439\u2013450.. ACM, Dallas, Texas."},{"key":"92_CR5","doi-asserted-by":"crossref","unstructured":"Ahmad, A, Kim K, Sarfaraz MI, Lee B (2018) OBLIVIATE: A Data Oblivious Filesystem for Intel SGX In: NDSS, San Diego.","DOI":"10.14722\/ndss.2018.23284"},{"key":"92_CR6","doi-asserted-by":"publisher","unstructured":"Alam, AKMM, Sharma S, Chen KSgx-mr: Regulating dataflows for protecting access patterns of data-intensive sgx applications. Proc Priv Enhancing Technol 2021(1):5\u201320. https:\/\/doi.org\/10.2478\/popets-2021-0002. Accessed 01 Jan 2021.","DOI":"10.2478\/popets-2021-0002"},{"issue":"1","key":"92_CR7","doi-asserted-by":"publisher","first-page":"694","DOI":"10.1186\/s40064-015-1481-x","volume":"4","author":"YAAS Aldeen","year":"2015","unstructured":"Aldeen, YAAS, Salleh M, Razzaque MA (2015) A comprehensive review on privacy preserving data mining. SpringerPlus 4(1):694. https:\/\/doi.org\/10.1186\/s40064-015-1481-x.","journal-title":"SpringerPlus"},{"key":"92_CR8","first-page":"689","volume-title":"Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation OSDI\u201916","author":"S Arnautov","year":"2016","unstructured":"Arnautov, S, Trach B, Gregor F, Knauth T, Martin A, Priebe C, Lind J, Muthukumaran D, O\u2019Keeffe D, Stillwell ML, Goltzsche D, Eyers D, Kapitza R, Pietzuch P, Fetzer C (2016) Scone: Secure linux containers with intel sgx In: Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation OSDI\u201916, 689\u2013703.. USENIX Association, Berkeley, CA, USA."},{"key":"92_CR9","doi-asserted-by":"publisher","unstructured":"Asharov, G, Lindell Y, Schneider T, Zohner M (2013) More efficient oblivious transfer and extensions for faster secure computation In: 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS\u201913, Berlin, Germany, November 4-8, 2013, 535\u2013548. https:\/\/doi.org\/10.1145\/2508859.2516738.","DOI":"10.1145\/2508859.2516738"},{"key":"92_CR10","doi-asserted-by":"crossref","unstructured":"Boldyreva, A, Chenette N, Lee Y, O\u2019Neill A (2009) Order preserving symmetric encryption In: Proceedings of EUROCRYPT Conference.","DOI":"10.1007\/978-3-642-01001-9_13"},{"key":"92_CR11","first-page":"578","volume-title":"Annual Cryptology Conference","author":"A Boldyreva","year":"2011","unstructured":"Boldyreva, A, Chenette N, O\u2019Neill A (2011) Order-preserving encryption revisited: Improved security analysis and alternative solutions In: Annual Cryptology Conference, 578\u2013595.. Springer, Santa Barbara."},{"key":"92_CR12","doi-asserted-by":"crossref","unstructured":"Bost, R, Popa RA, Tu S, Goldwasser S (2015) Machine learning classification over encrypted data In: NDSS, vol 4324, 4325, San Diego.","DOI":"10.14722\/ndss.2015.23241"},{"issue":"3","key":"92_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2633600","volume":"6","author":"Z Brakerski","year":"2014","unstructured":"Brakerski, Z, Gentry C, Vaikuntanathan V (2014) (Leveled) fully homomorphic encryption without bootstrapping. ACM Trans Comput Theory (TOCT) 6(3):1\u201336.","journal-title":"ACM Trans Comput Theory (TOCT)"},{"key":"92_CR14","first-page":"991","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"JV Bulck","year":"2018","unstructured":"Bulck, JV, Minkin M, Weisse O, Genkin D, Kasikci B, Piessens F, Silberstein M, Wenisch TF, Yarom Y, Strackx R (2018) Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution In: 27th USENIX Security Symposium (USENIX Security 18), 991\u20131008.. USENIX Association, Baltimore, MD. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/bulck."},{"key":"92_CR15","doi-asserted-by":"publisher","first-page":"486","DOI":"10.1145\/1315245.1315306","volume-title":"Proceedings of the 14th ACM Conference on Computer and Communications Security CCS \u201907","author":"P Bunn","year":"2007","unstructured":"Bunn, P, Ostrovsky R (2007) Secure two-party k-means clustering In: Proceedings of the 14th ACM Conference on Computer and Communications Security CCS \u201907, 486\u2013497.. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/1315245.1315306."},{"key":"92_CR16","doi-asserted-by":"publisher","unstructured":"Canetti, R, Canetti R. (2001) Universally composable security: a new paradigm for cryptographic protocols In: Proceedings 42nd IEEE Symposium on Foundations of Computer Science, 136\u2013145. https:\/\/doi.org\/10.1109\/SFCS.2001.959888.","DOI":"10.1109\/SFCS.2001.959888"},{"key":"92_CR17","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/3345252.3345292","volume-title":"Proceedings of the 20th International Conference on Computer Systems and Technologies CompSysTech \u201919","author":"D Chakarov","year":"2019","unstructured":"Chakarov, D, Papazov Y (2019) Evaluation of the complexity of fully homomorphic encryption schemes in implementations of programs In: Proceedings of the 20th International Conference on Computer Systems and Technologies CompSysTech \u201919, 62\u201367.. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3345252.3345292."},{"key":"92_CR18","unstructured":"Chen, A (2010) Gcreep: Google engineer stalked teens, spied on chats. Gawker September."},{"issue":"2","key":"92_CR19","doi-asserted-by":"publisher","first-page":"584","DOI":"10.1109\/TCC.2015.2498921","volume":"6","author":"G Chen","year":"2018","unstructured":"Chen, G, Guo S (2018) RASP-Boost: Confidential Boosting-Model Learning with Perturbed Data in the Cloud. IEEE Trans Cloud Comput 6(2):584\u2013597.","journal-title":"IEEE Trans Cloud Comput"},{"issue":"3","key":"92_CR20","doi-asserted-by":"publisher","first-page":"657","DOI":"10.1007\/s10115-010-0362-4","volume":"29","author":"K Chen","year":"2011","unstructured":"Chen, K, Liu L (2011) Geometric data perturbation for privacy preserving outsourced data mining. Knowl Inf Syst 29(3):657\u2013695. https:\/\/doi.org\/10.1007\/s10115-010-0362-4.","journal-title":"Knowl Inf Syst"},{"key":"92_CR21","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1007\/978-3-319-70694-8_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"JH Cheon","year":"2017","unstructured":"Cheon, JH, Kim A, Kim M, Song Y (2017) Homomorphic encryption for arithmetic of approximate numbers. In: Takagi T Peyrin T (eds)Advances in Cryptology \u2013 ASIACRYPT 2017, 409\u2013437.. Springer, Cham."},{"issue":"1","key":"92_CR22","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00145-019-09319-x","volume":"33","author":"I Chillotti","year":"2020","unstructured":"Chillotti, I, Gama N, Georgieva M, Izabach\u00e8ne M (2020) TFHE: fast fully homomorphic encryption over the torus. J. Cryptology 33(1):34\u201391. https:\/\/doi.org\/10.1007\/s00145-019-09319-x.","journal-title":"J. Cryptology"},{"key":"92_CR23","first-page":"86","volume":"2016","author":"V Costan","year":"2016","unstructured":"Costan, V, Devadas S (2016) Intel sgx explained. IACR Cryptol ePrint Archive 2016:86.","journal-title":"IACR Cryptol ePrint Archive"},{"issue":"5","key":"92_CR24","doi-asserted-by":"publisher","first-page":"895","DOI":"10.3233\/JCS-2011-0426","volume":"19","author":"R Curtmola","year":"2011","unstructured":"Curtmola, R, Garay J, Kamara S, Ostrovsky R (2011) Searchable symmetric encryption: improved definitions and efficient constructions. J Comput Secur 19(5):895\u2013934.","journal-title":"J Comput Secur"},{"key":"92_CR25","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/978-3-642-32946-3_13","volume-title":"Financial Cryptography and Data Security","author":"M Dahl","year":"2012","unstructured":"Dahl, M, Ning C, Toft T (2012) On secure two-party integer division. In: Keromytis AD (ed)Financial Cryptography and Data Security, 164\u2013178.. Springer, Berlin, Heidelberg."},{"issue":"1","key":"92_CR26","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1145\/1327452.1327492","volume":"51","author":"J Dean","year":"2008","unstructured":"Dean, J, Ghemawat S (2008) MapReduce: simplified data processing on large clusters. Commun ACM 51(1):107\u2013113.","journal-title":"Commun ACM"},{"key":"92_CR27","doi-asserted-by":"crossref","unstructured":"Demmler, D, Schneider T, Zohner M (2015) ABY - A framework for efficient mixed-protocol secure two-party computation In: 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Diego, California, USA, February 8-11, 2015. https:\/\/www.ndss-symposium.org\/ndss2015\/aby---framework-efficient-mixed-protocol-secure-two-party-computation.","DOI":"10.14722\/ndss.2015.23113"},{"key":"92_CR28","doi-asserted-by":"publisher","first-page":"916","DOI":"10.1109\/PASSAT\/SocialCom.2011.19","volume-title":"2011 IEEE Third International Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third International Conference on Social Computing","author":"J Dreier","year":"2011","unstructured":"Dreier, J, Kerschbaum F (2011) Practical privacy-preserving multiparty linear programming based on problem transformation In: 2011 IEEE Third International Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third International Conference on Social Computing, 916\u2013924.. IEEE, Los Alamitos."},{"key":"92_CR29","doi-asserted-by":"crossref","unstructured":"Du, W, Zhan Z (2003) Using randomized response techniques for privacy-preserving data mining In: Proceedings of the ninth ACM SIGKDD international conference on Knowledge discovery and data mining, 505\u2013510, Washington, DC.","DOI":"10.1145\/956750.956810"},{"key":"92_CR30","doi-asserted-by":"publisher","first-page":"857","DOI":"10.1109\/TrustCom.2012.188","volume-title":"2012 IEEE 11th international conference on trust, security and privacy in computing and communications","author":"AJ Duncan","year":"2012","unstructured":"Duncan, AJ, Creese S, Goldsmith M (2012) Insider attacks in cloud computing In: 2012 IEEE 11th international conference on trust, security and privacy in computing and communications, 857\u2013862.. IEEE, Liverpool."},{"key":"92_CR31","doi-asserted-by":"publisher","first-page":"1054","DOI":"10.1145\/2660267.2660348","volume-title":"Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security CCS \u201914","author":"U Erlingsson","year":"2014","unstructured":"Erlingsson, U, Pihur V, Korolova A (2014) Rappor: Randomized aggregatable privacy-preserving ordinal response In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security CCS \u201914, 1054\u20131067.. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/2660267.2660348."},{"issue":"2-3","key":"92_CR32","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1561\/3300000019","volume":"2","author":"D Evans","year":"2018","unstructured":"Evans, D, Kolesnikov V, Rosulek M (2018) A Pragmatic Introduction to Secure Multi-Party Computation. Found Trends Priv Secur 2(2-3):70\u2013246. https:\/\/doi.org\/10.1561\/3300000019.","journal-title":"Found Trends Priv Secur"},{"key":"92_CR33","doi-asserted-by":"crossref","unstructured":"Fredrikson, M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 1322\u20131333, Denver.","DOI":"10.1145\/2810103.2813677"},{"key":"92_CR34","first-page":"17","volume-title":"23rd USENIX Security Symposium USENIX Security","author":"M Fredrikson","year":"2014","unstructured":"Fredrikson, M, Lantz E, Jha S, Lin S, Page D, Ristenpart T (2014) Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing In: 23rd USENIX Security Symposium USENIX Security, 17\u201332.. USENIX Association, San Diego, CA."},{"key":"92_CR35","first-page":"169","volume-title":"Annual ACM Symposium on Theory of Computing","author":"C Gentry","year":"2009","unstructured":"Gentry, C (2009) Fully homomorphic encryption using ideal lattices In: Annual ACM Symposium on Theory of Computing, 169\u2013178.. ACM, New York, NY, USA."},{"key":"92_CR36","first-page":"201","volume-title":"International Conference on Machine Learning","author":"R Gilad-Bachrach","year":"2016","unstructured":"Gilad-Bachrach, R, Dowlin N, Laine K, Lauter K, Naehrig M, Wernsing J (2016) Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy In: International Conference on Machine Learning, 201\u2013210.. PMLR, New York City."},{"key":"92_CR37","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1145\/28395.28420","volume-title":"Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing STOC \u201987","author":"O Goldreich","year":"1987","unstructured":"Goldreich, O, Micali S, Wigderson A (1987) How to play any mental game In: Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing STOC \u201987, 218\u2013229.. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/28395.28420."},{"key":"92_CR38","doi-asserted-by":"publisher","first-page":"431","DOI":"10.1145\/233551.233553","volume":"43","author":"O Goldreich","year":"1996","unstructured":"Goldreich, O, Ostrovsky R (1996) Software protection and simulation on oblivious ram. J ACM 43:431\u2013473.","journal-title":"J ACM"},{"key":"92_CR39","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/11889663_5","volume-title":"International Conference on Financial Cryptography and Data Security","author":"P Golle","year":"2006","unstructured":"Golle, P (2006) A private stable matching algorithm In: International Conference on Financial Cryptography and Data Security, 65\u201380.. Springer, Anguilla."},{"key":"92_CR40","doi-asserted-by":"publisher","unstructured":"Golle, P, Staddon J, Waters B (2004) Secure Conjunctive Keyword Search over Encrypted Data. In: Jakobsson M, Yung M, Zhou J (eds)Applied Cryptography and Network Security, Second International Conference, ACNS 2004, Yellow Mountain, China, June 8-11, 2004, Proceedings, vol 3089, 31\u201345.. Springer. https:\/\/doi.org\/10.1007\/978-3-540-24852-1_3.","DOI":"10.1007\/978-3-540-24852-1_3"},{"key":"92_CR41","first-page":"1","volume-title":"International Conference on Information Security and Cryptology","author":"T Graepel","year":"2012","unstructured":"Graepel, T, Lauter K, Naehrig M (2012) ML confidential: Machine learning on encrypted data In: International Conference on Information Security and Cryptology, 1\u201321.. Springer, Seoul."},{"key":"92_CR42","first-page":"3","volume":"37","author":"S Grigorescu","year":"2019","unstructured":"Grigorescu, S, Trasnea B, Cocias T, Macesanu G (2019) A survey of deep learning techniques for autonomous driving. J Field Robot 37:3.","journal-title":"J Field Robot"},{"key":"92_CR43","doi-asserted-by":"publisher","unstructured":"Garay, JA, Gennaro R (2014) Algorithms in HElib In: Advances in Cryptology - CRYPTO 2014 - 34th Annual Cryptology Conference, Santa Barbara, CA, USA, August 17-21, 2014, Proceedings, Part I. Lecture Notes in Computer Science, vol 8616, 554\u2013571.. Springer. https:\/\/doi.org\/10.1007\/978-3-662-44371-2_31.","DOI":"10.1007\/978-3-662-44371-2_31"},{"issue":"12-15","key":"92_CR44","first-page":"8","volume":"6","author":"S Halevi","year":"2013","unstructured":"Halevi, S, Shoup V (2013) Design and implementation of a homomorphic-encryption library. IBM Res (Manuscr) 6(12-15):8\u201336.","journal-title":"IBM Res (Manuscr)"},{"key":"92_CR45","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-21606-5","volume-title":"The Elements of Statistical Learning","author":"T Hastie","year":"2001","unstructured":"Hastie, T, Tibshirani R, Friedman J (2001) The Elements of Statistical Learning. Springer, New York City, New York."},{"key":"92_CR46","doi-asserted-by":"publisher","first-page":"451","DOI":"10.1145\/1866307.1866358","volume-title":"Proceedings of the 17th ACM Conference on Computer and Communications Security CCS \u201910","author":"W Henecka","year":"2010","unstructured":"Henecka, W, K \u00f6gl S, Sadeghi A-R, Schneider T, Wehrenberg I (2010) Tasty: Tool for automating secure two-party computations In: Proceedings of the 17th ACM Conference on Computer and Communications Security CCS \u201910, 451\u2013462.. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/1866307.1866358."},{"key":"92_CR47","unstructured":"Hesamifard, E, Takabi H, Ghasemi M (2017) Cryptodl: Deep neural networks over encrypted data. CoRR abs\/1711.05189. http:\/\/arxiv.org\/abs\/1711.05189."},{"key":"92_CR48","doi-asserted-by":"publisher","first-page":"603","DOI":"10.1145\/3133956.3134012","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security CCS \u201917","author":"B Hitaj","year":"2017","unstructured":"Hitaj, B, Ateniese G, Perez-Cruz F (2017) Deep models under the gan: Information leakage from collaborative deep learning In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security CCS \u201917, 603\u2013618.. ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/3133956.3134012."},{"key":"92_CR49","first-page":"331","volume-title":"USENIX Security Symposium, vol 201","author":"Y Huang","year":"2011","unstructured":"Huang, Y, Evans D, Katz J, Malka L (2011) Faster secure two-party computation using garbled circuits In: USENIX Security Symposium, vol 201, 331\u2013335.. USENIX, San Francisco."},{"key":"92_CR50","unstructured":"Ji, Z, Lipton ZC, Elkan C (2014) Differential Privacy and Machine Learning: a Survey and Review. CoRR abs\/1412.7584. http:\/\/arxiv.org\/abs\/1412.7584."},{"key":"92_CR51","doi-asserted-by":"publisher","first-page":"1209","DOI":"10.1145\/3243734.3243837","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security CCS \u201918","author":"X Jiang","year":"2018","unstructured":"Jiang, X, Kim M, Lauter K, Song Y (2018) Secure outsourced matrix computation and application to neural networks In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security CCS \u201918, 1209\u20131222.. ACM, New York. https:\/\/doi.org\/10.1145\/3243734.3243837."},{"key":"92_CR52","doi-asserted-by":"crossref","unstructured":"Kerschbaum, F (2015) Frequency-hiding order-preserving encryption In: Proceedings of ACM Conference on Computer and Communication Security.","DOI":"10.1145\/2810103.2813629"},{"key":"92_CR53","first-page":"1","volume-title":"2019 IEEE Symposium on Security and Privacy (SP)","author":"P Kocher","year":"2019","unstructured":"Kocher, P, Horn J, Fogh A, Genkin D, Gruss D, Haas W, Hamburg M, Lipp M, Mangard S, Prescher T, et al. (2019) Spectre attacks: Exploiting speculative execution In: 2019 IEEE Symposium on Security and Privacy (SP), 1\u201319.. IEEE, San Francisco."},{"key":"92_CR54","doi-asserted-by":"crossref","unstructured":"Kolesnikov, V, Schneider T (2008) Improved garbled circuit: Free XOR gates and applications In: International Colloquium on Automata, Languages, and Programming, 486\u2013498, Springer, Reykjavik.","DOI":"10.1007\/978-3-540-70583-3_40"},{"key":"92_CR55","doi-asserted-by":"publisher","unstructured":"Lazzeretti, R, Barni M (2011) Division between encrypted integers by means of garbled circuits In: 2011 IEEE International Workshop on Information Forensics and Security, 1\u20136. https:\/\/doi.org\/10.1109\/WIFS.2011.6123132.","DOI":"10.1109\/WIFS.2011.6123132"},{"key":"92_CR56","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun, Y, Bengio Y, Hinton G (2015) Deep learning. Nature 521:436\u2013444.","journal-title":"Nature"},{"key":"92_CR57","unstructured":"Lee, D, Kuvaiskii D, Vahldiek-Oberwagner A, Vij M (2020) Privacy-preserving machine learning in untrusted clouds made simple. CoRR abs\/2009.04390. http:\/\/arxiv.org\/abs\/2009.043902009.04390."},{"key":"92_CR58","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1007\/978-3-319-57048-8_6","volume-title":"Tutorials on the Foundations of Cryptography (2017)","author":"Y Lindell","year":"2017","unstructured":"Lindell, Y (2017) How to Simulate It \u2013 A Tutorial on the Simulation Proof Technique. In: Lindell Y (ed)Tutorials on the Foundations of Cryptography (2017), 277\u2013346.. Springer, Cham."},{"key":"92_CR59","unstructured":"Lindell, Y (2020) Secure Multiparty Computation (MPC). Cryptology ePrint Archive, Report 2020\/300. https:\/\/eprint.iacr.org\/2020\/300."},{"key":"92_CR60","unstructured":"Lipp, M, Schwarz M, Gruss D, Prescher T, Haas W, Fogh A, Horn J, Mangard S, Kocher P, Genkin D, et al. (2018) Meltdown: Reading kernel memory from user space In: 27th {USENIX} Security Symposium ({USENIX} Security 18), 973\u2013990, Baltimore."},{"issue":"1","key":"92_CR61","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1109\/TKDE.2006.14","volume":"18","author":"K Liu","year":"2006","unstructured":"Liu, K, Kargupta H, Ryan J (2006) Random projection-based multiplicative data perturbation for privacy preserving distributed data mining. IEEE Trans Knowl Data Eng (TKDE) 18(1):92\u2013106.","journal-title":"IEEE Trans Knowl Data Eng (TKDE)"},{"key":"92_CR62","doi-asserted-by":"publisher","first-page":"12103","DOI":"10.1109\/ACCESS.2018.2805680","volume":"6","author":"Q Liu","year":"2018","unstructured":"Liu, Q, Li P, Zhao W, Cai W, Yu S, Leung VCM (2018) A survey on security threats and defensive techniques of machine learning: A data driven view. IEEE Access 6:12103\u201312117. https:\/\/doi.org\/10.1109\/ACCESS.2018.2805680.","journal-title":"IEEE Access"},{"key":"92_CR63","doi-asserted-by":"publisher","unstructured":"Liu, C, Wang XS, Nayak K, Huang Y, Shi E (2015) Oblivm: A programming framework for secure computation In: 2015 IEEE Symposium on Security and Privacy, 359\u2013376. https:\/\/doi.org\/10.1109\/SP.2015.29.","DOI":"10.1109\/SP.2015.29"},{"key":"92_CR64","first-page":"1163","volume":"2016","author":"W Lu","year":"2016","unstructured":"Lu, W, Kawasaki S, Sakuma J (2016) Using Fully Homomorphic Encryption for Statistical Analysis of Categorical, Ordinal and Numerical Data. IACR Cryptol ePrint Arch 2016:1163.","journal-title":"IACR Cryptol ePrint Arch"},{"issue":"9","key":"92_CR65","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1016\/S1353-4858(15)30080-5","volume":"2015","author":"S Mansfield-Devine","year":"2015","unstructured":"Mansfield-Devine, S (2015) The Ashley Madison affair. Netw Secur 2015(9):8\u201316.","journal-title":"Netw Secur"},{"key":"92_CR66","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1007\/978-3-642-30487-3_11","volume-title":"Discrimination and Privacy in the Information Society","author":"S Matwin","year":"2013","unstructured":"Matwin, S (2013) Privacy-Preserving Data Mining Techniques: Survey and Challenges. In: Custers B, Calders T, Schermer B, Zarsky T (eds)Discrimination and Privacy in the Information Society, 209\u2013221.. Springer, Berlin."},{"key":"92_CR67","doi-asserted-by":"publisher","unstructured":"Mohassel, P, Rindal P (2018) ABY 3: A Mixed Protocol Framework for Machine Learning. In: Lie D, Mannan M, Backes M, Wang X (eds)Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018, Toronto, ON, Canada, October 15-19, 2018, 35\u201352.. ACM. https:\/\/doi.org\/10.1145\/3243734.3243760.","DOI":"10.1145\/3243734.3243760"},{"key":"92_CR68","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1109\/SP.2017.12","volume-title":"2017 IEEE Symposium on Security and Privacy (SP)","author":"P Mohassel","year":"2017","unstructured":"Mohassel, P, Zhang Y (2017) Secureml: A system for scalable privacy-preserving machine learning In: 2017 IEEE Symposium on Security and Privacy (SP), 19\u201338.. IEEE, San Jose."},{"key":"92_CR69","first-page":"113","volume-title":"Proceedings of Cloud Computing Security Workshop","author":"M Naehrig","year":"2011","unstructured":"Naehrig, M, Lauter K, Vaikuntanathan V (2011) Can homomorphic encryption be practical? In: Proceedings of Cloud Computing Security Workshop, 113\u2013124.. ACM, New York, NY, USA."},{"key":"92_CR70","doi-asserted-by":"crossref","unstructured":"Nikolaenko, V, Ioannidis S, Weinsberg U, Joye M, Taft N, Boneh D (2013) Privacy-preserving matrix factorization In: ACM SIGSAC Conference on Computer and Communications Security, 801\u2013812.","DOI":"10.1145\/2508859.2516751"},{"key":"92_CR71","doi-asserted-by":"crossref","unstructured":"Nikolaenko, V, Weinsberg U, Ioannidis S, Joye M, Boneh D, Taft N (2013) Privacy-preserving ridge regression on hundreds of millions of records In: IEEE Symposium on Security and Privacy, 334\u2013348.","DOI":"10.1109\/SP.2013.30"},{"key":"92_CR72","unstructured":"Ohrimenko, O, Schuster F, Fournet C, Mehta A, Nowozin S, Vaswani K, Costa M (2016) Oblivious multi-party machine learning on trusted processors. In: Holz T Savage S (eds)25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10-12, 2016, 619\u2013636.. USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/ohrimenko."},{"key":"92_CR73","first-page":"223","volume-title":"International conference on the theory and applications of cryptographic techniques","author":"P Paillier","year":"1999","unstructured":"Paillier, P (1999) Public-key cryptosystems based on composite degree residuosity classes In: International conference on the theory and applications of cryptographic techniques, 223\u2013238.. Springer, Berlin."},{"key":"92_CR74","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1109\/EuroSP.2018.00035","volume-title":"2018 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"N Papernot","year":"2018","unstructured":"Papernot, N, McDaniel P, Sinha A, Wellman MP (2018) Sok: Security and privacy in machine learning In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P), 399\u2013414.. IEEE, London."},{"key":"92_CR75","volume-title":"27th Annual Network and Distributed System Security Symposium, NDSS 2020, San Diego, California, USA, February 23-26, 2020","author":"A Patra","year":"2020","unstructured":"Patra, A, Suresh A (2020) BLAZE: Blazing Fast Privacy-Preserving Machine Learning In: 27th Annual Network and Distributed System Security Symposium, NDSS 2020, San Diego, California, USA, February 23-26, 2020.. The Internet Society, San Diego. https:\/\/www.ndss-symposium.org\/ndss-paper\/blaze-blazing-fast-privacy-preservingmachine-learning\/."},{"issue":"5","key":"92_CR76","doi-asserted-by":"publisher","first-page":"1333","DOI":"10.1109\/TIFS.2017.2787987","volume":"13","author":"LT Phong","year":"2018","unstructured":"Phong, LT, Aono Y, Hayashi T, Wang L, Moriai S (2018) Privacy-preserving deep learning via additively homomorphic encryption. IEEE Trans Inf Forensics Secur 13(5):1333\u20131345. https:\/\/doi.org\/10.1109\/TIFS.2017.2787987.","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"92_CR77","doi-asserted-by":"publisher","unstructured":"Rane, S, Sun W (2010) Privacy preserving string comparisons based on levenshtein distance In: 2010 IEEE International Workshop on Information Forensics and Security, 1\u20136. https:\/\/doi.org\/10.1109\/WIFS.2010.5711449.","DOI":"10.1109\/WIFS.2010.5711449"},{"key":"92_CR78","doi-asserted-by":"publisher","first-page":"707","DOI":"10.1145\/3196494.3196522","volume-title":"Proceedings of the 2018 on Asia Conference on Computer and Communications Security ASIACCS \u201918","author":"MS Riazi","year":"2018","unstructured":"Riazi, MS, Weinert C, Tkachenko O, Songhori EM, Schneider T, Koushanfar F (2018) Chameleon: A hybrid secure computation framework for machine learning applications In: Proceedings of the 2018 on Asia Conference on Computer and Communications Security ASIACCS \u201918, 707\u2013721.. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3196494.3196522."},{"key":"92_CR79","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1145\/1653662.1653687","volume-title":"Proceedings of the 16th ACM conference on Computer and Communications Security","author":"T Ristenpart","year":"2009","unstructured":"Ristenpart, T, Tromer E, Shacham H, Savage S (2009) Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds In: Proceedings of the 16th ACM conference on Computer and Communications Security, 199\u2013212.. ACM, New York."},{"issue":"3","key":"92_CR80","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3242899","volume":"11","author":"BD Rouhani","year":"2018","unstructured":"Rouhani, BD, Hussain SU, Lauter K, Koushanfar F (2018) Redcrypt: Real-time privacypreserving deep learning inference in clouds using fpgas. ACM Trans Reconfigurable Technol Syst (TRETS) 11(3):1\u201321.","journal-title":"ACM Trans Reconfigurable Technol Syst (TRETS)"},{"key":"92_CR81","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196023","volume-title":"Proceedings of the 55th Annual Design Automation Conference DAC \u201918","author":"BD Rouhani","year":"2018","unstructured":"Rouhani, BD, Riazi MS, Koushanfar F (2018) Deepsecure: Scalable provably-secure deep learning In: Proceedings of the 55th Annual Design Automation Conference DAC \u201918.. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3195970.3196023."},{"key":"92_CR82","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/978-3-642-31600-5_12","volume-title":"Advances in Computing and Information Technology","author":"A Sachan","year":"2013","unstructured":"Sachan, A, Roy D, Arun PV (2013) An analysis of privacy preservation techniques in data mining. In: Meghanathan N, Nagamalai D, Chaki N (eds)Advances in Computing and Information Technology, 119\u2013128.. Springer, Berlin, Heidelberg."},{"issue":"5","key":"92_CR83","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1109\/MSP.2013.2259911","volume":"30","author":"AD Sarwate","year":"2013","unstructured":"Sarwate, AD, Chaudhuri K (2013) Signal processing and machine learning with differential privacy: Algorithms and challenges for continuous data. IEEE Signal Proc Mag 30(5):86\u201394. https:\/\/doi.org\/10.1109\/MSP.2013.2259911.","journal-title":"IEEE Signal Proc Mag"},{"key":"92_CR84","doi-asserted-by":"crossref","unstructured":"Sasy, S, Gorbunov S, Fletcher CW (2018) ZeroTrace: Oblivious Memory Primitives from Intel SGX In: NDSS, San Diego.","DOI":"10.14722\/ndss.2018.23239"},{"key":"92_CR85","first-page":"1401","volume-title":"Proceedings of the 16th International Joint Conference on Artificial Intelligence - Volume 2 IJCAI\u201999","author":"RE Schapire","year":"1999","unstructured":"Schapire, RE (1999) A brief introduction to boosting In: Proceedings of the 16th International Joint Conference on Artificial Intelligence - Volume 2 IJCAI\u201999, 1401\u20131406.. Morgan Kaufmann Publishers Inc., San Francisco, CA, USA."},{"key":"92_CR86","first-page":"2","volume":"51","author":"Z Shan","year":"2018","unstructured":"Shan, Z, Ren K, Blanton M, Wang C (2018) Practical secure computation outsourcing: A survey. ACM Comput Surv 51:2.","journal-title":"ACM Comput Surv"},{"key":"92_CR87","doi-asserted-by":"crossref","unstructured":"Sharma, S, Chen K (2018) Image disguising for privacy-preserving deep learning In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2291\u20132293, New York.","DOI":"10.1145\/3243734.3278511"},{"key":"92_CR88","first-page":"41","volume-title":"European Symposium on Research in Computer Security","author":"S Sharma","year":"2019","unstructured":"Sharma, S, Chen K (2019) Confidential boosting with random linear classifiers for outsourced user-generated data In: European Symposium on Research in Computer Security, 41\u201365.. Springer, Cham."},{"issue":"2","key":"92_CR89","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1109\/MIC.2018.112102519","volume":"22","author":"S Sharma","year":"2018","unstructured":"Sharma, S, Chen K, Sheth A (2018) Toward practical privacy-preserving analytics for iot and cloud-based healthcare systems. IEEE Internet Comput 22(2):42\u201351. https:\/\/doi.org\/10.1109\/MIC.2018.112102519.","journal-title":"IEEE Internet Comput"},{"issue":"5","key":"92_CR90","doi-asserted-by":"publisher","first-page":"981","DOI":"10.1109\/TKDE.2018.2847662","volume":"31","author":"S Sharma","year":"2019","unstructured":"Sharma, S, Powers J, Chen K (2019) Privategraph: Privacy-preserving spectral analysis of encrypted graphs in the cloud. IEEE Trans Knowl Data Eng 31(5):981\u2013995. https:\/\/doi.org\/10.1109\/TKDE.2018.2847662.","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"92_CR91","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1145\/2897845.2897885","volume-title":"Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security ASIACCS16","author":"S Shinde","year":"2016","unstructured":"Shinde, S, Chua ZL, Narayanan V, Saxena P (2016) Preventing page faults from telling your secrets In: Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security ASIACCS16, 317\u2013328.. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/2897845.2897885."},{"key":"92_CR92","doi-asserted-by":"crossref","unstructured":"Shinde, S, Tien DL, Tople S, Saxena P (2017) Panoply: Low-TCB Linux Applications With SGX Enclaves In: NDSS, San Diego.","DOI":"10.14722\/ndss.2017.23500"},{"key":"92_CR93","doi-asserted-by":"crossref","unstructured":"Shokri, R, Shmatikov V (2015) Privacy-preserving deep learning In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, 1310\u20131321, New York City.","DOI":"10.1145\/2810103.2813687"},{"key":"92_CR94","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1109\/SP.2017.41","volume-title":"2017 IEEE Symposium on Security and Privacy (SP)","author":"R Shokri","year":"2017","unstructured":"Shokri, R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models In: 2017 IEEE Symposium on Security and Privacy (SP), 3\u201318.. IEEE, San Jose."},{"key":"92_CR95","unstructured":"Song, C, Shmatikov V (2019) Overlearning reveals sensitive attributes. arXiv preprint arXiv:1905.11742."},{"key":"92_CR96","first-page":"601","volume-title":"Proceedings of the 25th USENIX Conference on Security Symposium SEC\u201916","author":"F Tram\u00e8r","year":"2016","unstructured":"Tram\u00e8r, F, Zhang F, Juels A, Reiter MK, Ristenpart T (2016) Stealing machine learning models via prediction apis In: Proceedings of the 25th USENIX Conference on Security Symposium SEC\u201916, 601\u2013618.. USENIX Association, USA."},{"key":"92_CR97","unstructured":"Tsai, C, Porter DE, Vij M (2017) Graphene-sgx: A practical library OS for unmodified applications on SGX. In: Silva DD Ford B (eds)2017 USENIX Annual Technical Conference, USENIX ATC 2017, Santa Clara, CA, USA, July 12-14, 2017, 645\u2013658."},{"issue":"2","key":"92_CR98","first-page":"14","volume":"32","author":"L Unger","year":"2015","unstructured":"Unger, L (2015) Breaches to customer account data. Comput Internet Lawyer 32(2):14\u201320.","journal-title":"Comput Internet Lawyer"},{"issue":"2","key":"92_CR99","doi-asserted-by":"publisher","first-page":"166","DOI":"10.1504\/IJACT.2014.062738","volume":"3","author":"T Veugen","year":"2014","unstructured":"Veugen, T (2014) Encrypted integer division and secure comparison. Int J Appl Crypt 3(2):166.","journal-title":"Int J Appl Crypt"},{"issue":"1","key":"92_CR100","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10115-007-0114-2","volume":"14","author":"X Wu","year":"2007","unstructured":"Wu, X, Kumar V, Ross Quinlan J, Ghosh J, Yang Q, Motoda H, McLachlan GJ, Ng A, Liu B, Yu PS, Zhou Z-H, Steinbach M, Hand DJ, Steinberg D (2007) Top 10 algorithms in data mining. Knowl Inf Syst 14(1):1\u201337.","journal-title":"Knowl Inf Syst"},{"issue":"2","key":"92_CR101","first-page":"322","volume":"26","author":"H Xu","year":"2012","unstructured":"Xu, H, Guo S, Chen K (2012) Building confidential and efficient query services in the cloud with RASP data perturbation. IEEE Trans Knowl Data Eng 26(2):322\u2013335.","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"92_CR102","doi-asserted-by":"crossref","unstructured":"Yao, AC (1986) How to generate and exhange secrets In: IEEE Symposium on Foundations of Computer Science, 162\u2013167.","DOI":"10.1109\/SFCS.1986.25"},{"key":"92_CR103","volume-title":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","author":"S Zahur","year":"2015","unstructured":"Zahur, S, Rosulek M, Evans D (2015) Two Halves Make a Whole In: Annual International Conference on the Theory and Applications of Cryptographic Techniques.. Springer, Berlin."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00092-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00092-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00092-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,7]],"date-time":"2024-09-07T14:20:53Z","timestamp":1725718853000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00092-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,1]]},"references-count":103,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,12]]}},"alternative-id":["92"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00092-8","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,1]]},"assertion":[{"value":"14 January 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 April 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Not applicable.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"30"}}