基于全同态加密的协作价值实用化隐私保证方法
Practical, Private Assurance of the Value of Collaboration via Fully Homomorphic Encryption
- Macquarie University(麦考瑞大学)
- Western Sydney University(西悉尼大学)
- James Cook University(詹姆斯库克大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对两方协作前需在不披露模型和数据集的前提下验证协作收益的问题,提出结合TFHE全同态加密与标签差分隐私的交互式神经网络协议,在诚实但好奇模型下可证安全,速度比纯FHE方案快多个数量级。
AI中文摘要:
两方希望基于各自的数据集开展协作,但在向对方披露数据集之前,双方都希望先获得协作能够产生实际收益的保证。我们从机器学习视角研究该问题:其中一方承诺通过引入另一方的数据来提升自身预测模型的性能,只有当更新后的模型展现出准确率提升时,双方才愿意进一步开展协作。在确认这一点之前,两方都不愿披露自身的模型和数据集。\n本研究基于环面全同态加密方案(TFHE)和标签差分隐私,构建了针对该问题的交互式协议,协议底层的机器学习模型为神经网络。标签差分隐私用于避免计算完全在加密域内进行——根据当前最先进的全同态加密(FHE)实现方案,完全加密域计算是神经网络训练的显著瓶颈。我们在假设参与方为诚实但好奇模式(其中一方可能不具备为自身初始数据集打标签的专业能力)的前提下,形式化证明了所提方案的安全性。实验结果表明,我们的方案可得到更新后模型准确率的输出,其耗时比采用纯FHE运算的协议快多个数量级。
英文摘要:
Two parties wish to collaborate on their datasets. However, before they reveal their datasets to each other, the parties want to have the guarantee that the collaboration would be fruitful. We look at this problem from the point of view of machine learning, where one party is promised an improvement on its prediction model by incorporating data from the other party. The parties would only wish to collaborate further if the updated model shows an improvement in accuracy. Before this is ascertained, the two parties would not want to disclose their models and datasets. In this work, we construct an interactive protocol for this problem based on the fully homomorphic encryption scheme over the Torus (TFHE) and label differential privacy, where the underlying machine learning model is a neural network. Label differential privacy is used to ensure that computations are not done entirely in the encrypted domain, which is a significant bottleneck for neural network training according to the current state-of-the-art FHE implementations. We formally prove the security of our scheme assuming honest-but-curious parties, but where one party may not have any expertise in labelling its initial dataset. Experiments show that we can obtain the output, i.e., the accuracy of the updated model, with time many orders of magnitude faster than a protocol using entirely FHE operations.