arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2508.11575cs.CR

激活我!:为基于全同态加密的隐私保护机器学习设计高效激活函数

Activate Me!: Designing Efficient Activation Functions for Privacy-Preserving Machine Learning with Fully Homomorphic Encryption

Nges Brian Njungle, Michel A. Kinsy

更新

AI总结:

本文针对全同态加密机器学习中非线性激活函数难以实现的问题,在 LeNet-5 和 ResNet-20 上设计并评估了平方函数和 ReLU 的多种实现方案,揭示了推理速度与准确率之间的关键权衡。

AI中文摘要:

机器学习在医疗和国防等敏感领域的日益普及带来了重大的隐私与安全挑战。这些领域要求强有力的数据保护,因为模型在训练和推理过程中都依赖大量敏感信息。全同态加密(FHE)提供了一种极具吸引力的解决方案,它允许直接在加密数据上进行计算,从而在整个机器学习工作流程中保持机密性。然而,FHE 本质上仅支持线性运算,这使得实现非线性激活函数变得困难,而激活函数是现代神经网络的关键组成部分。本工作专注于设计、实现和评估适用于基于 FHE 的机器学习的激活函数。我们使用 OpenFHE 库中的 CKKS 方案,在 LeNet-5 和 ResNet-20 架构上研究了两种常用函数:平方函数和修正线性单元(ReLU)。对于 ReLU,我们评估了两种方法:传统的低阶多项式近似,以及一种新颖的方案切换技术,该技术能够在 FHE 约束下安全地评估 ReLU。我们的研究结果表明,平方函数在 LeNet-5 等浅层网络中表现良好,达到 99.4% 的准确率,每张图像耗时 128 秒。相比之下,ResNet-20 等更深的模型从 ReLU 中获益更多。多项式近似方法达到 83.8% 的准确率,每张图像耗时 1,145 秒,而我们的方案切换方法将准确率提高到 89.8%,尽管推理时间更长,为 1,697 秒。这些结果凸显了基于 FHE 的机器学习中的一个关键权衡:更快的激活函数通常会降低准确率,而保持准确率的激活函数则需要更大的计算资源。

英文摘要:

The growing adoption of machine learning in sensitive areas such as healthcare and defense introduces significant privacy and security challenges. These domains demand robust data protection, as models depend on large volumes of sensitive information for both training and inference. Fully Homomorphic Encryption (FHE) presents a compelling solution by enabling computations directly on encrypted data, maintaining confidentiality across the entire machine learning workflow. However, FHE inherently supports only linear operations, making it difficult to implement non-linear activation functions, essential components of modern neural networks. This work focuses on designing, implementing, and evaluating activation functions tailored for FHE-based machine learning. We investigate two commonly used functions: the Square function and Rectified Linear Unit (ReLU), using LeNet-5 and ResNet-20 architectures with the CKKS scheme from the OpenFHE library. For ReLU, we assess two methods: a conventional low-degree polynomial approximation and a novel scheme-switching technique that securely evaluates ReLU under FHE constraints. Our findings show that the Square function performs well in shallow networks like LeNet-5, achieving 99.4% accuracy with 128 seconds per image. In contrast, deeper models like ResNet-20 benefit more from ReLU. The polynomial approximation yields 83.8% accuracy with 1,145 seconds per image, while our scheme-switching method improves accuracy to 89.8%, albeit with a longer inference time of 1,697 seconds. These results underscore a critical trade-off in FHE-based ML: faster activation functions often reduce accuracy, whereas those preserving accuracy demand greater computational resources.

↑