{"id":"https://openalex.org/W4416549339","doi":"https://doi.org/10.1145/3719027.3765107","title":"The Phantom Menace in Crypto-Based PET-Hardened Deep Learning Models: Invisible Configuration-Induced Attacks","display_name":"The Phantom Menace in Crypto-Based PET-Hardened Deep Learning Models: Invisible Configuration-Induced Attacks","publication_year":2025,"publication_date":"2025-11-19","ids":{"openalex":"https://openalex.org/W4416549339","doi":"https://doi.org/10.1145/3719027.3765107"},"language":"en","primary_location":{"id":"doi:10.1145/3719027.3765107","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3719027.3765107","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3719027.3765107","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3719027.3765107","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5112200468","display_name":"Yiteng Peng","orcid":"https://orcid.org/0009-0006-2066-7939"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":true,"raw_author_name":"Yiteng Peng","raw_affiliation_strings":["The Hong Kong University of Science and Technology, Hong Kong, China"],"raw_orcid":"https://orcid.org/0009-0006-2066-7939","affiliations":[{"raw_affiliation_string":"The Hong Kong University of Science and Technology, Hong Kong, China","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070622803","display_name":"Dongwei Xiao","orcid":"https://orcid.org/0000-0002-4680-5715"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Dongwei Xiao","raw_affiliation_strings":["The Hong Kong University of Science and Technology, Hong Kong, China"],"raw_orcid":"https://orcid.org/0000-0002-4680-5715","affiliations":[{"raw_affiliation_string":"The Hong Kong University of Science and Technology, Hong Kong, China","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068911323","display_name":"Zhibo Liu","orcid":"https://orcid.org/0000-0002-7872-1129"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zhibo Liu","raw_affiliation_strings":["The Hong Kong University of Science and Technology, Hong Kong, China"],"raw_orcid":"https://orcid.org/0000-0002-7872-1129","affiliations":[{"raw_affiliation_string":"The Hong Kong University of Science and Technology, Hong Kong, China","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072001009","display_name":"Zhenlan Ji","orcid":"https://orcid.org/0000-0003-3167-0480"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zhenlan Ji","raw_affiliation_strings":["The Hong Kong University of Science and Technology, Hong Kong, China"],"raw_orcid":"https://orcid.org/0000-0003-3167-0480","affiliations":[{"raw_affiliation_string":"The Hong Kong University of Science and Technology, Hong Kong, China","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063510532","display_name":"Daoyuan Wu","orcid":"https://orcid.org/0000-0002-3752-0718"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Daoyuan Wu","raw_affiliation_strings":["Lingnan University, Hong Kong, China"],"raw_orcid":"https://orcid.org/0000-0002-3752-0718","affiliations":[{"raw_affiliation_string":"Lingnan University, Hong Kong, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100328264","display_name":"Shuai Wang","orcid":"https://orcid.org/0000-0002-0866-0308"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Shuai Wang","raw_affiliation_strings":["The Hong Kong University of Science and Technology, Hong Kong, China"],"raw_orcid":"https://orcid.org/0000-0002-0866-0308","affiliations":[{"raw_affiliation_string":"The Hong Kong University of Science and Technology, Hong Kong, China","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5042903073","display_name":"Juergen Rahmel","orcid":"https://orcid.org/0009-0007-5080-8736"},"institutions":[{"id":"https://openalex.org/I24190266","display_name":"HSBC Holdings","ror":"https://ror.org/02ygdtt22","country_code":"GB","type":"other","lineage":["https://openalex.org/I24190266"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Juergen Rahmel","raw_affiliation_strings":["HSBC, Hong Kong, China"],"raw_orcid":"https://orcid.org/0009-0007-5080-8736","affiliations":[{"raw_affiliation_string":"HSBC, Hong Kong, China","institution_ids":["https://openalex.org/I24190266"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5112200468"],"corresponding_institution_ids":["https://openalex.org/I200769079"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.18437156,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"4379","last_page":"4393"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.42570000886917114,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.42570000886917114,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.10409999638795853,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.09480000287294388,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.7027999758720398},{"id":"https://openalex.org/keywords/homomorphic-encryption","display_name":"Homomorphic encryption","score":0.6912999749183655},{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.5454000234603882},{"id":"https://openalex.org/keywords/plaintext","display_name":"Plaintext","score":0.5120999813079834},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.461899995803833},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.45159998536109924},{"id":"https://openalex.org/keywords/imaging-phantom","display_name":"Imaging phantom","score":0.4187000095844269},{"id":"https://openalex.org/keywords/computation","display_name":"Computation","score":0.3521000146865845}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7621999979019165},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.7027999758720398},{"id":"https://openalex.org/C158338273","wikidata":"https://www.wikidata.org/wiki/Q2154943","display_name":"Homomorphic encryption","level":3,"score":0.6912999749183655},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5507000088691711},{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.5454000234603882},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5439000129699707},{"id":"https://openalex.org/C92717368","wikidata":"https://www.wikidata.org/wiki/Q1162538","display_name":"Plaintext","level":3,"score":0.5120999813079834},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.461899995803833},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.45159998536109924},{"id":"https://openalex.org/C104293457","wikidata":"https://www.wikidata.org/wiki/Q28324852","display_name":"Imaging phantom","level":2,"score":0.4187000095844269},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.39649999141693115},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.3521000146865845},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.3375000059604645},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.3352999985218048},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.3253999948501587},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.32330000400543213},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3018999993801117},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.29260000586509705},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.2906999886035919},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2732999920845032},{"id":"https://openalex.org/C153701036","wikidata":"https://www.wikidata.org/wiki/Q659974","display_name":"Trustworthiness","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.2621999979019165},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.26109999418258667},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.2572000026702881},{"id":"https://openalex.org/C2778701210","wikidata":"https://www.wikidata.org/wiki/Q28130034","display_name":"Constructive","level":3,"score":0.2551000118255615},{"id":"https://openalex.org/C18396474","wikidata":"https://www.wikidata.org/wiki/Q2465888","display_name":"Secure multi-party computation","level":3,"score":0.25099998712539673},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2508000135421753}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3719027.3765107","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3719027.3765107","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3719027.3765107","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-167324","is_oa":false,"landing_page_url":"http://repository.hkust.edu.hk/ir/Record/1783.1-167324","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference paper"}],"best_oa_location":{"id":"doi:10.1145/3719027.3765107","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3719027.3765107","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3719027.3765107","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320307117","display_name":"HSBC Bank USA","ror":"https://ror.org/00t2kp174"},{"id":"https://openalex.org/F4320323537","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4416549339.pdf","grobid_xml":"https://content.openalex.org/works/W4416549339.grobid-xml"},"referenced_works_count":11,"referenced_works":["https://openalex.org/W2130486630","https://openalex.org/W2942255051","https://openalex.org/W2987932087","https://openalex.org/W3026923845","https://openalex.org/W3028852288","https://openalex.org/W4225377307","https://openalex.org/W4315706064","https://openalex.org/W4380082463","https://openalex.org/W4388856889","https://openalex.org/W4391725262","https://openalex.org/W4405182564"],"related_works":[],"abstract_inverted_index":{"The":[0,45,92],"increasing":[1],"use":[2],"of":[3,47],"deep":[4],"learning":[5],"(DL)":[6],"models":[7,106],"has":[8,26],"given":[9],"rise":[10],"to":[11,53,72,100,117,126],"significant":[12],"privacy":[13,128],"concerns":[14],"regarding":[15],"training":[16],"and":[17,41,65,76,109],"inference":[18],"data.":[19],"To":[20],"address":[21],"these":[22,83],"concerns,":[23],"the":[24,104],"community":[25],"increasingly":[27],"adopted":[28],"crypto-based":[29],"privacy-enhancing":[30],"technologies":[31],"(CPET)":[32],"like":[33,62],"homomorphic":[34],"encryption":[35],"(HE),":[36],"secure":[37],"multi-party":[38],"computation":[39],"(MPC),":[40],"zero-knowledge":[42],"proofs":[43],"(ZKP).":[44],"integration":[46],"CPET":[48],"with":[49],"DL,":[50],"often":[51],"referred":[52],"as":[54],"CPET-DL,":[55],"is":[56],"commonly":[57],"facilitated":[58],"by":[59,96],"specialized":[60],"frameworks":[61,68],"CrypTen,":[63],"TenSEAL,":[64],"EZKL.":[66],"These":[67],"offer":[69],"configurable":[70],"parameters":[71],"balance":[73],"model":[74],"accuracy":[75],"computational":[77],"efficiency":[78],"during":[79],"privacy-preserving":[80],"operations.":[81],"However,":[82],"configurations,":[84],"while":[85],"seemingly":[86],"harmless,":[87],"can":[88,129],"introduce":[89],"subtle":[90],"vulnerabilities.":[91],"stealthy":[93],"attacks":[94],"induced":[95],"misconfigurations":[97],"are":[98,114],"hard":[99],"detect":[101],"because":[102],"1)":[103],"plaintext":[105],"remain":[107],"vulnerability-free,":[108],"2)":[110],"existing":[111],"auditing":[112],"tools":[113,124],"hardly":[115],"applicable":[116],"CPET-hardened":[118],"models.":[119],"This":[120],"creates":[121],"a":[122],"paradox:":[123],"intended":[125],"protect":[127],"be":[130],"undermined":[131],"through":[132],"configuration":[133],"manipulation.":[134]},"counts_by_year":[],"updated_date":"2026-03-12T06:13:28.667946","created_date":"2025-11-23T00:00:00"}
