{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T02:09:24Z","timestamp":1785377364335,"version":"3.55.0"},"reference-count":56,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"1","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>We propose F<jats:sc>alcon<\/jats:sc>, an end-to-end 3-party protocol for efficient private training and inference of large machine learning models. F<jats:sc>alcon<\/jats:sc> presents four main advantages \u2013 (i) It is highly <jats:italic>expressive<\/jats:italic> with support for high capacity networks such as VGG16 (ii) it supports batch normalization which is important for training complex networks such as AlexNet (iii) F<jats:sc>alcon<\/jats:sc> guarantees <jats:italic>security with abort<\/jats:italic> against malicious adversaries, assuming an honest majority (iv) Lastly, F<jats:sc>alcon<\/jats:sc> presents new theoretical insights for protocol design that make it <jats:italic>highly efficient<\/jats:italic> and allow it to outperform existing secure deep learning solutions. Compared to prior art for private inference, we are about 8\u00d7 faster than SecureNN (PETS\u201919) on average and comparable to ABY<jats:sup>3<\/jats:sup> (CCS\u201918). We are about 16 \u2212 200\u00d7 more communication efficient than either of these. For private training, we are about 6\u00d7 faster than SecureNN, 4.4\u00d7 faster than ABY<jats:sup>3<\/jats:sup> and about 2\u221260\u00d7 more communication efficient. Our experiments in the WAN setting show that over large networks and datasets, <jats:italic>compute operations<\/jats:italic> dominate the overall latency of MPC, as opposed to the communication.<\/jats:p>","DOI":"10.2478\/popets-2021-0011","type":"journal-article","created":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T11:47:06Z","timestamp":1608637626000},"page":"188-208","source":"Crossref","is-referenced-by-count":180,"title":["Falcon: Honest-Majority Maliciously Secure Framework for Private Deep Learning"],"prefix":"10.56553","volume":"2021","author":[{"given":"Sameer","family":"Wagh","sequence":"first","affiliation":[{"name":"Princeton University & UC Berkeley"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shruti","family":"Tople","sequence":"additional","affiliation":[{"name":"Microsoft Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabrice","family":"Benhamouda","sequence":"additional","affiliation":[{"name":"Algorand Foundation"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eyal","family":"Kushilevitz","sequence":"additional","affiliation":[{"name":"Technion"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Prateek","family":"Mittal","sequence":"additional","affiliation":[{"name":"Princeton University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tal","family":"Rabin","sequence":"additional","affiliation":[{"name":"Algorand Foundation"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"2022042423324230106_j_popets-2021-0011_ref_001_w2aab3b7c22b1b6b1ab1ab1Aa","doi-asserted-by":"crossref","unstructured":"[1] E. Bursztein, E. Clarke, M. DeLaune, D. M. Elifff, N. Hsu, L. Olson, J. Shehan, M. Thakur, K. Thomas, and T. Bright, \u201cRethinking the detection of child sexual abuse imagery on the internet,\u201d in The World Wide Web Conference. ACM, 2019, pp. 2601\u20132607.10.1145\/3308558.3313482","DOI":"10.1145\/3308558.3313482"},{"key":"2022042423324230106_j_popets-2021-0011_ref_002_w2aab3b7c22b1b6b1ab1ab2Aa","unstructured":"[2] \u201cChild Abusers Run Rampant as Tech Companies Look the Other Way,\u201d https:\/\/www.nytimes.com\/interactive\/2019\/11\/09\/us\/internet-child-sex-abuse.html, 2019."},{"key":"2022042423324230106_j_popets-2021-0011_ref_003_w2aab3b7c22b1b6b1ab1ab3Aa","doi-asserted-by":"crossref","unstructured":"[3] H. Cho, D. J. Wu, and B. Berger, \u201cSecure genome-wide association analysis using multiparty computation,\u201d in Nature biotechnology, vol. 36, no. 6, 2018, p. 547.10.1038\/nbt.4108599044029734293","DOI":"10.1038\/nbt.4108"},{"key":"2022042423324230106_j_popets-2021-0011_ref_004_w2aab3b7c22b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"[4] P. Mohassel and Y. Zhang, \u201cSecureML: A system for scalable privacy-preserving machine learning,\u201d in IEEE Symposium on Security and Privacy (S&P), 2017.10.1109\/SP.2017.12","DOI":"10.1109\/SP.2017.12"},{"key":"2022042423324230106_j_popets-2021-0011_ref_005_w2aab3b7c22b1b6b1ab1ab5Aa","doi-asserted-by":"crossref","unstructured":"[5] M. S. Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schneider, and F. Koushanfar, \u201cChameleon: A hybrid secure computation framework for machine learning applications,\u201d in ACM Symposium on Information, Computer and Communications Security (ASIACCS), 2018.10.1145\/3196494.3196522","DOI":"10.1145\/3196494.3196522"},{"key":"2022042423324230106_j_popets-2021-0011_ref_006_w2aab3b7c22b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] J. Liu, M. Juuti, Y. Lu, and N. Asokan, \u201cOblivious neural network predictions via MiniONN transformations,\u201d in ACM Conference on Computer and Communications Security (CCS), 2017.10.1145\/3133956.3134056","DOI":"10.1145\/3133956.3134056"},{"key":"2022042423324230106_j_popets-2021-0011_ref_007_w2aab3b7c22b1b6b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"[7] N. Chandran, D. Gupta, A. Rastogi, R. Sharma, and S. Tripathi, \u201cEzPC: programmable, efficient, and scalable secure two-party computation for machine learning,\u201d in IEEE European Symposium on Security and Privacy (S&P), 2019.10.1109\/EuroSP.2019.00043","DOI":"10.1109\/EuroSP.2019.00043"},{"key":"2022042423324230106_j_popets-2021-0011_ref_008_w2aab3b7c22b1b6b1ab1ab8Aa","unstructured":"[8] C. Juvekar, V. Vaikuntanathan, and A. Chandrakasan, \u201cGazelle: A low latency framework for secure neural network inference,\u201d in USENIX Security Symposium, 2018."},{"key":"2022042423324230106_j_popets-2021-0011_ref_009_w2aab3b7c22b1b6b1ab1ab9Aa","unstructured":"[9] M. S. Riazi, M. Samragh, H. Chen, K. Laine, K. Lauter, and F. Koushanfar, \u201cXONN: XNOR-based oblivious deep neural network inference,\u201d in USENIX Security Symposium, 2019."},{"key":"2022042423324230106_j_popets-2021-0011_ref_010_w2aab3b7c22b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] P. Mishra, R. Lehmkuhl, A. Srinivasan, W. Zheng, and R. A. Popa, \u201cDelphi: A cryptographic inference service for neural networks,\u201d in USENIX Security Symposium, 2020.10.1145\/3411501.3419418","DOI":"10.1145\/3411501.3419418"},{"key":"2022042423324230106_j_popets-2021-0011_ref_011_w2aab3b7c22b1b6b1ab1ac11Aa","unstructured":"[11] P. Mohassel and P. Rindal, \u201cABY3: A mixed protocol framework for machine learning,\u201d in ACM Conference on Computer and Communications Security (CCS), 2018."},{"key":"2022042423324230106_j_popets-2021-0011_ref_012_w2aab3b7c22b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] S. Wagh, D. Gupta, and N. Chandran, \u201cSecureNN: 3-Party secure computation for neural network training,\u201d in Privacy Enhancing Technologies Symposium (PETS), 2019.10.2478\/popets-2019-0035","DOI":"10.2478\/popets-2019-0035"},{"key":"2022042423324230106_j_popets-2021-0011_ref_013_w2aab3b7c22b1b6b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"[13] N. Kumar, M. Rathee, N. Chandran, D. Gupta, A. Rastogi, and R. Sharma, \u201cCryptflow: Secure tensorflow inference,\u201d in IEEE Symposium on Security and Privacy (S&P), 2020.10.1109\/SP40000.2020.00092","DOI":"10.1109\/SP40000.2020.00092"},{"key":"2022042423324230106_j_popets-2021-0011_ref_014_w2aab3b7c22b1b6b1ab1ac14Aa","unstructured":"[14] A. Dalskov, D. Escudero, and M. Keller, \u201cSecure evaluation of quantized neural networks,\u201d https:\/\/eprint.iacr.org\/2019\/131, 2019."},{"key":"2022042423324230106_j_popets-2021-0011_ref_015_w2aab3b7c22b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] H. Chaudhari, A. Choudhury, A. Patra, and A. Suresh, \u201cAstra: High throughput 3pc over rings with application to secure prediction,\u201d in ACM SIGSAC Conference on Cloud Computing Security Workshop, 2019.10.1145\/3338466.3358922","DOI":"10.1145\/3338466.3358922"},{"key":"2022042423324230106_j_popets-2021-0011_ref_016_w2aab3b7c22b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] A. Patra and A. Suresh, \u201cBlaze: Blazing fast privacy-preserving machine learning,\u201d in Symposium on Network and Distributed System Security (NDSS), 2020.10.14722\/ndss.2020.24202","DOI":"10.14722\/ndss.2020.24202"},{"key":"2022042423324230106_j_popets-2021-0011_ref_017_w2aab3b7c22b1b6b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"[17] M. Byali, H. Chaudhari, A. Patra, and A. Suresh, \u201cFLASH: Fast and robust framework for privacy-preserving machine learning,\u201d in Privacy Enhancing Technologies Symposium (PETS), 2020.10.2478\/popets-2020-0036","DOI":"10.2478\/popets-2020-0036"},{"key":"2022042423324230106_j_popets-2021-0011_ref_018_w2aab3b7c22b1b6b1ab1ac18Aa","unstructured":"[18] R. Rachuri and A. Suresh, \u201cTrident: Efficient 4pc framework for privacy preserving machine learning,\u201d in Symposium on Network and Distributed System Security (NDSS), 2019."},{"key":"2022042423324230106_j_popets-2021-0011_ref_019_w2aab3b7c22b1b6b1ab1ac19Aa","doi-asserted-by":"crossref","unstructured":"[19] A. C. Yao, \u201cProtocols for secure computations,\u201d in IEEE Symposium on Foundations of Computer Science (FOCS), 1982.10.1109\/SFCS.1982.38","DOI":"10.1109\/SFCS.1982.38"},{"key":"2022042423324230106_j_popets-2021-0011_ref_020_w2aab3b7c22b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] A. Shamir, \u201cHow to share a secret,\u201d Communications of the ACM, vol. 22, no. 11, pp. 612\u2013613, 1979.10.1145\/359168.359176","DOI":"10.1145\/359168.359176"},{"key":"2022042423324230106_j_popets-2021-0011_ref_021_w2aab3b7c22b1b6b1ab1ac21Aa","doi-asserted-by":"crossref","unstructured":"[21] J. Furukawa, Y. Lindell, A. Nof, and O. Weinstein, \u201cHigh-throughput secure three-party computation for malicious adversaries and an honest majority,\u201d in Advances in Cryptology\u2014EUROCRYPT, 2017.10.1007\/978-3-319-56614-6_8","DOI":"10.1007\/978-3-319-56614-6_8"},{"key":"2022042423324230106_j_popets-2021-0011_ref_022_w2aab3b7c22b1b6b1ab1ac22Aa","unstructured":"[22] H. Chabanne, A. de Wargny, J. Milgram, C. Morel, and E. Prouff, \u201cPrivacy-preserving classification on deep neural network.\u201d IACR Cryptol. ePrint Arch., vol. 2017, p. 35, 2017."},{"key":"2022042423324230106_j_popets-2021-0011_ref_023_w2aab3b7c22b1b6b1ab1ac23Aa","doi-asserted-by":"crossref","unstructured":"[23] A. Ibarrondo and M. \u00d6nen, \u201cFhe-compatible batch normalization for privacy preserving deep learning,\u201d in Data Privacy Management, Cryptocurrencies and Blockchain Technology. Springer, 2018, pp. 389\u2013404.10.1007\/978-3-030-00305-0_27","DOI":"10.1007\/978-3-030-00305-0_27"},{"key":"2022042423324230106_j_popets-2021-0011_ref_024_w2aab3b7c22b1b6b1ab1ac24Aa","unstructured":"[24] E. Chou, J. Beal, D. Levy, S. Yeung, A. Haque, and L. Fei-Fei, \u201cFaster cryptonets: Leveraging sparsity for real-world encrypted inference,\u201d arXiv preprint arXiv:1811.09953, 2018."},{"key":"2022042423324230106_j_popets-2021-0011_ref_025_w2aab3b7c22b1b6b1ab1ac25Aa","unstructured":"[25] K. Simonyan and A. Zisserman, \u201cVery deep convolutional networks for large-scale image recognition,\u201d https:\/\/arxiv.org\/abs\/1409.1556, 2014."},{"key":"2022042423324230106_j_popets-2021-0011_ref_026_w2aab3b7c22b1b6b1ab1ac26Aa","unstructured":"[26] A. Krizhevsky, I. Sutskever, and G. E. Hinton, \u201cImagenet classification with deep convolutional neural networks,\u201d 2012."},{"key":"2022042423324230106_j_popets-2021-0011_ref_027_w2aab3b7c22b1b6b1ab1ac27Aa","unstructured":"[27] \u201cMNIST database,\u201d http:\/\/yann.lecun.com\/exdb\/mnist\/, accessed: 2017-09-24."},{"key":"2022042423324230106_j_popets-2021-0011_ref_028_w2aab3b7c22b1b6b1ab1ac28Aa","unstructured":"[28] A. Krizhevsky, V. Nair, and G. Hinton, \u201cThe CIFAR-10 dataset,\u201d 2014."},{"key":"2022042423324230106_j_popets-2021-0011_ref_029_w2aab3b7c22b1b6b1ab1ac29Aa","unstructured":"[29] J. Wu, Q. Zhang, and G. Xu, \u201cTiny ImageNet Challenge,\u201d http:\/\/cs231n.stanford.edu\/reports\/2017\/pdfs\/930.pdf."},{"key":"2022042423324230106_j_popets-2021-0011_ref_030_w2aab3b7c22b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] T. Araki, J. Furukawa, Y. Lindell, A. Nof, and K. Ohara, \u201cHigh-throughput semi-honest secure three-party computation with an honest majority,\u201d in ACM Conference on Computer and Communications Security (CCS), 2016.10.1145\/2976749.2978331","DOI":"10.1145\/2976749.2978331"},{"key":"2022042423324230106_j_popets-2021-0011_ref_031_w2aab3b7c22b1b6b1ab1ac31Aa","doi-asserted-by":"crossref","unstructured":"[31] D. Bogdanov, S. Laur, and J. Willemson, \u201cSharemind: A framework for fast privacy-preserving computations,\u201d in European Symposium on Research in Computer Security (ESORICS), 2008, pp. 192\u2013206.10.1007\/978-3-540-88313-5_13","DOI":"10.1007\/978-3-540-88313-5_13"},{"key":"2022042423324230106_j_popets-2021-0011_ref_032_w2aab3b7c22b1b6b1ab1ac32Aa","unstructured":"[32] \u201cAnnouncing securenn in tf-encrypted,\u201d https:\/\/mc.ai\/announcing-securenn-in-tf-encrypted\/, 2018."},{"key":"2022042423324230106_j_popets-2021-0011_ref_033_w2aab3b7c22b1b6b1ab1ac33Aa","unstructured":"[33] PySyft, \u201cImplement securenn within pysyft #1990,\u201d https:\/\/github.com\/OpenMined\/PySyft\/issues\/1990, 2019."},{"key":"2022042423324230106_j_popets-2021-0011_ref_034_w2aab3b7c22b1b6b1ab1ac34Aa","unstructured":"[34] \u201cMicrosoft photodna cloud service,\u201d 2018. [Online]. Available: https:\/\/www.microsoft.com\/en-us\/photodna"},{"key":"2022042423324230106_j_popets-2021-0011_ref_035_w2aab3b7c22b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"[35] R. Shokri, M. Stronati, C. Song, and V. Shmatikov, \u201cMembership inference attacks against machine learning models,\u201d in IEEE Symposium on Security and Privacy (S&P), 2017.10.1109\/SP.2017.41","DOI":"10.1109\/SP.2017.41"},{"key":"2022042423324230106_j_popets-2021-0011_ref_036_w2aab3b7c22b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"[36] M. Fredrikson, S. Jha, and T. Ristenpart, \u201cModel inversion attacks that exploit confidence information and basic countermeasures,\u201d in ACM Conference on Computer and Communications Security (CCS). ACM, 2015.10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"key":"2022042423324230106_j_popets-2021-0011_ref_037_w2aab3b7c22b1b6b1ab1ac37Aa","unstructured":"[37] F. Tram\u00e8r, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, \u201cStealing machine learning models via prediction APIs,\u201d in USENIX Security Symposium, 2016."},{"key":"2022042423324230106_j_popets-2021-0011_ref_038_w2aab3b7c22b1b6b1ab1ac38Aa","doi-asserted-by":"crossref","unstructured":"[38] E. Kushilevitz, Y. Lindell, and T. Rabin, \u201cInformation-theoretically secure protocols and security under composition,\u201d SIAM Journal on Computing, vol. 39, no. 5, pp. 2090\u20132112, 2010.","DOI":"10.1137\/090755886"},{"key":"2022042423324230106_j_popets-2021-0011_ref_039_w2aab3b7c22b1b6b1ab1ac39Aa","unstructured":"[39] S. Ioffe and C. Szegedy, \u201cBatch normalization: Accelerating deep network training by reducing internal covariate shift,\u201d in International Conference on Machine Learning, 2015, pp. 448\u2013456."},{"key":"2022042423324230106_j_popets-2021-0011_ref_040_w2aab3b7c22b1b6b1ab1ac40Aa","doi-asserted-by":"crossref","unstructured":"[40] O. Catrina and A. Saxena, \u201cSecure computation with fixed-point numbers,\u201d in International Conference on Financial Cryptography and Data Security, 2010, pp. 35\u201350.10.1007\/978-3-642-14577-3_6","DOI":"10.1007\/978-3-642-14577-3_6"},{"key":"2022042423324230106_j_popets-2021-0011_ref_041_w2aab3b7c22b1b6b1ab1ac41Aa","unstructured":"[41] M. Aliasgari, M. Blanton, Y. Zhang, and A. Steele, \u201cSecure computation on floating point numbers,\u201d in Symposium on Network and Distributed System Security (NDSS), 2013."},{"key":"2022042423324230106_j_popets-2021-0011_ref_042_w2aab3b7c22b1b6b1ab1ac42Aa","doi-asserted-by":"crossref","unstructured":"[42] O. Goldreich, S. Micali, and A. Wigderson, \u201cHow to play any mental game or a completeness theorem for protocols with honest majority,\u201d in ACM Symposium on Theory of Computing (STOC), 1987.10.1145\/28395.28420","DOI":"10.1145\/28395.28420"},{"key":"2022042423324230106_j_popets-2021-0011_ref_043_w2aab3b7c22b1b6b1ab1ac43Aa","doi-asserted-by":"crossref","unstructured":"[43] R. Canetti, \u201cSecurity and composition of multiparty cryptographic protocols,\u201d in Journal of CRYPTOLOGY, vol. 13, no. 1, 2000, pp. 143\u2013202.10.1007\/s001459910006","DOI":"10.1007\/s001459910006"},{"key":"2022042423324230106_j_popets-2021-0011_ref_044_w2aab3b7c22b1b6b1ab1ac44Aa","unstructured":"[44] \u2014\u2014, \u201cUniversally composable security: A new paradigm for cryptographic protocols,\u201d in IEEE Symposium on Foundations of Computer Science (FOCS), 2001, pp. 136\u2013."},{"key":"2022042423324230106_j_popets-2021-0011_ref_045_w2aab3b7c22b1b6b1ab1ac45Aa","doi-asserted-by":"crossref","unstructured":"[45] B. D. Rouhani, M. S. Riazi, and F. Koushanfar, \u201cDeepSecure: Scalable provably-secure deep learning,\u201d in Annual Design Automation Conference, 2018.10.1145\/3195970.3196023","DOI":"10.1145\/3195970.3196023"},{"key":"2022042423324230106_j_popets-2021-0011_ref_046_w2aab3b7c22b1b6b1ab1ac46Aa","unstructured":"[46] C. Peikert, V. Vaikuntanathan, and B. Waters, \u201cA framework for efficient and composable oblivious transfer.\u201d in Advances in Cryptology\u2014CRYPTO, 2008."},{"key":"2022042423324230106_j_popets-2021-0011_ref_047_w2aab3b7c22b1b6b1ab1ac47Aa","doi-asserted-by":"crossref","unstructured":"[47] W. Zheng, R. A. Popa, J. E. Gonzalez, and I. Stoica, \u201cHelen: Maliciously secure coopetitive learning for linear models,\u201d in IEEE Symposium on Security and Privacy (S&P), 2019.10.1109\/SP.2019.00045","DOI":"10.1109\/SP.2019.00045"},{"key":"2022042423324230106_j_popets-2021-0011_ref_048_w2aab3b7c22b1b6b1ab1ac48Aa","unstructured":"[48] R. Gilad-Bachrach, N. Dowlin, K. Laine, K. E. Lauter, M. Naehrig, and J. Wernsing, \u201cCryptoNets: Applying neural networks to encrypted data with high throughput and accuracy,\u201d in International Conference on Machine Learning, 2016."},{"key":"2022042423324230106_j_popets-2021-0011_ref_049_w2aab3b7c22b1b6b1ab1ac49Aa","doi-asserted-by":"crossref","unstructured":"[49] E. Hesamifard, H. Takabi, and M. Ghasemi, \u201cCryptoDL: Deep Neural Networks over Encrypted Data,\u201d in Privacy Enhancing Technologies Symposium (PETS), 2018.10.1145\/3292006.3300044","DOI":"10.1145\/3292006.3300044"},{"key":"2022042423324230106_j_popets-2021-0011_ref_050_w2aab3b7c22b1b6b1ab1ac50Aa","doi-asserted-by":"crossref","unstructured":"[50] D. Demmler, T. Schneider, and M. Zohner, \u201cABY \u2013 A framework for efficient mixed-protocol secure two-party computation.\u201d in Symposium on Network and Distributed System Security (NDSS), 2015.10.14722\/ndss.2015.23113","DOI":"10.14722\/ndss.2015.23113"},{"key":"2022042423324230106_j_popets-2021-0011_ref_051_w2aab3b7c22b1b6b1ab1ac51Aa","unstructured":"[51] F. Chollet et al., \u201cKeras,\u201d https:\/\/github.com\/fchollet\/keras, 2015."},{"key":"2022042423324230106_j_popets-2021-0011_ref_052_w2aab3b7c22b1b6b1ab1ac52Aa","doi-asserted-by":"crossref","unstructured":"[52] E. Makri, D. Rotaru, N. P. Smart, and F. Vercauteren, \u201cEPIC: efficient private image classification (or: learning from the masters),\u201d in Cryptographers\u2019 Track at the RSA Conference. Springer, 2019, pp. 473\u2013492.10.1007\/978-3-030-12612-4_24","DOI":"10.1007\/978-3-030-12612-4_24"},{"key":"2022042423324230106_j_popets-2021-0011_ref_053_w2aab3b7c22b1b6b1ab1ac53Aa","doi-asserted-by":"crossref","unstructured":"[53] N. Agrawal, A. Shahin Shamsabadi, M. J. Kusner, and A. Gasc\u00f3n, \u201cQuotient: Two-party secure neural network training and prediction,\u201d in ACM Conference on Computer and Communications Security (CCS). ACM, 2019, pp. 1231\u20131247.10.1145\/3319535.3339819","DOI":"10.1145\/3319535.3339819"},{"key":"2022042423324230106_j_popets-2021-0011_ref_054_w2aab3b7c22b1b6b1ab1ac54Aa","doi-asserted-by":"crossref","unstructured":"[54] B. Jacob, S. Kligys, B. Chen, M. Zhu, M. Tang, A. Howard, H. Adam, and D. Kalenichenko, \u201cQuantization and training of neural networks for efficient integer-arithmetic-only inference,\u201d in IEEE Conference on Computer Vision and Pattern Recognition, 2018.10.1109\/CVPR.2018.00286","DOI":"10.1109\/CVPR.2018.00286"},{"key":"2022042423324230106_j_popets-2021-0011_ref_055_w2aab3b7c22b1b6b1ab1ac55Aa","doi-asserted-by":"crossref","unstructured":"[55] Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, \u201cGradient-based learning applied to document recognition,\u201d Proceedings of the IEEE, vol. 86, no. 11, pp. 2278\u20132324, 1998.","DOI":"10.1109\/5.726791"},{"key":"2022042423324230106_j_popets-2021-0011_ref_056_w2aab3b7c22b1b6b1ab1ac56Aa","doi-asserted-by":"crossref","unstructured":"[56] Y. LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, and L. D. Jackel, \u201cBackpropagation applied to handwritten zip code recognition,\u201d Neural Computation, vol. 1, no. 4, pp. 541\u2013551, 1989.10.1162\/neco.1989.1.4.541","DOI":"10.1162\/neco.1989.1.4.541"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/content.sciendo.com\/view\/journals\/popets\/2021\/1\/article-p188.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0011","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:20Z","timestamp":1658334680000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0011.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":56,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2020,11,9]]},"published-print":{"date-parts":[[2021,1,1]]}},"alternative-id":["10.2478\/popets-2021-0011"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0011","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11,9]]}}}