arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2503.05850cs.CRcs.CVcs.LG

使用部分同态加密的加密向量相似度计算:应用与性能分析

Encrypted Vector Similarity Computations Using Partially Homomorphic Encryption: Applications and Performance Analysis

  • Vorboss Limited(沃博斯有限公司)
  • Ibn Haldun University(伊本·赫勒敦大学)

机构由 AI 辅助整理,请以论文原文为准。

Sefik Serengil, Alper Ozpinar

更新

AI总结:

本文提出利用部分同态加密结合向量预归一化实现加密余弦相似度搜索,在LFW人脸识别等任务上验证其相比全同态加密更快、更省资源,适合隐私保护场景。

AI中文摘要:

本文探讨了使用部分同态加密(PHE)进行加密向量相似度搜索,重点关注人脸识别以及更广泛的应用,如反向图像搜索、推荐引擎和大语言模型(LLMs)。虽然全同态加密(FHE)已经存在,但我们证明了加密余弦相似度可以使用PHE来计算,从而提供了一种更实用的替代方案。由于PHE不直接支持余弦相似度,我们提出了一种预先对向量进行归一化的方法,使点积计算能够作为代理。我们还应用了最小-最大归一化来处理负维度值。在Labeled Faces in the Wild(LFW)数据集上的实验采用双塔架构,使用DeepFace的FaceNet128d、FaceNet512d和VGG-Face(4096d)模型。预先加密的嵌入存储在一个塔中,而边缘设备捕获图像、计算嵌入,并通过加法同态加密执行加密-明文点积运算。我们使用LightPHE实现了这一方案,评估了Paillier、Damgard-Jurik和Okamoto-Uchiyama方案,由于性能或解密复杂性问题排除了其他方案。在80位和112位安全级别(NIST安全至2030年)下的测试将PHE与FHE(通过TenSEAL)进行了比较,分析了加密、解密、运算时间、余弦相似度损失、密钥/密文大小。结果表明,PHE计算强度更低、速度更快,并且产生的密文/密钥更小,使其非常适合内存受限的环境和现实世界中的隐私保护加密相似度搜索。

英文摘要:

This paper explores the use of partially homomorphic encryption (PHE) for encrypted vector similarity search, with a focus on facial recognition and broader applications like reverse image search, recommendation engines, and large language models (LLMs). While fully homomorphic encryption (FHE) exists, we demonstrate that encrypted cosine similarity can be computed using PHE, offering a more practical alternative. Since PHE does not directly support cosine similarity, we propose a method that normalizes vectors in advance, enabling dot product calculations as a proxy. We also apply min-max normalization to handle negative dimension values. Experiments on the Labeled Faces in the Wild (LFW) dataset use DeepFace's FaceNet128d, FaceNet512d, and VGG-Face (4096d) models in a two-tower setup. Pre-encrypted embeddings are stored in one tower, while an edge device captures images, computes embeddings, and performs encrypted-plaintext dot products via additively homomorphic encryption. We implement this with LightPHE, evaluating Paillier, Damgard-Jurik, and Okamoto-Uchiyama schemes, excluding others due to performance or decryption complexity. Tests at 80-bit and 112-bit security (NIST-secure until 2030) compare PHE against FHE (via TenSEAL), analyzing encryption, decryption, operation time, cosine similarity loss, key/ciphertext sizes. Results show PHE is less computationally intensive, faster, and produces smaller ciphertexts/keys, making it well-suited for memory-constrained environments and real-world privacy-preserving encrypted similarity search.

↑