公共衰减同态状态空间模型用于隐私序列推断
Public-Decay Homomorphic State Space Models for Private Sequence Inference
- School of Technology and Management (ESTG-IPVC) Polytechnic Institute of Viana do Castelo(技术与管理学院(ESTG-IPVC)葡萄牙维亚纳多卡斯托尔理工大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出公共衰减同态状态空间模型(HSSMs),通过加密-明文公共衰减更新状态,实现隐私序列推断,在保持加密状态的同时提升效率和准确性。
AI中文摘要:
完全同态加密(FHE)改变了序列模型设计,因为旋转、加密乘积、密文材料化、乘法深度和启动压力可能主导普通神经网络成本。本文提出了公共衰减同态状态空间模型(HSSMs),即具有递归/状态空间块的循环/状态空间块,其携带状态通过密文-明文公共衰减更新,而密文-密文乘法仍保持在本地写路径上。该设计在序列中保持加密状态不变。评估的工作流将客户端侧的标记化、冻结的fastText查找、投影、裁剪、加密、解密和阈值处理与服务器侧的加密评估分离,基于有限投影特征。在完整的烂番茄和SST-2验证分割上,加密HSSM路径精确匹配明文分类,并达到0.7505和0.7420的准确率。与HE友好的多项式注意力在相同fastText工作负载上相比,HSSM在运行约5倍快的同时匹配或超过全序列任务质量。配对的L40S操作级行显示1.34-1.62倍的延迟低于缓存的最终标记多项式注意力,30-258倍的延迟低于全序列多项式注意力,并且具有更低的逻辑加密状态足迹。一个T=16/32比较器,具有加密公共线性输入和Q/K/V投影,显示在深度8/环32768下,投影HSSM成功,而投影注意力在深度10/环65536下成功。一个匹配的T=8 OpenFHE/FIDESlib跟踪在两个后端上均在最终级别3和噪声尺度度2完成。这些结果使公共衰减成为加密序列推断的实用FHE协同设计杠杆,从有限投影特征中推断。
英文摘要:
Fully homomorphic encryption (FHE) changes sequence-model design because rotations, encrypted products, ciphertext materialization, multiplicative depth, and bootstrapping pressure can dominate ordinary neural-network costs. This paper presents public-decay homomorphic state space models (HSSMs), recurrent/state-space blocks whose carried state is updated through ciphertext-plaintext public decay while ciphertext-ciphertext multiplication remains on a local write path. The design keeps a fixed encrypted state across the sequence. The evaluated workflow separates client-side tokenization, frozen fastText lookup, projection, clipping, encryption, decryption, and thresholding from server-side encrypted evaluation over bounded projected features. On full Rotten Tomatoes and SST-2 validation splits, the encrypted HSSM path exactly matches plaintext classifications and reaches 0.7505 and 0.7420 accuracy. Against HE-friendly polynomial attention on the same fastText workloads, HSSM matches or exceeds full-sequence task quality while running about 5x faster. Paired L40S operation-level rows show 1.34-1.62x lower latency than cached final-token polynomial attention, 30-258x lower latency than full-sequence polynomial attention, and lower logical encrypted-state footprint. A T = 16/32 comparator with encrypted public-linear input and Q/K/V projections shows projected HSSM succeeding under depth 8/ring 32768, while projected attention succeeds under depth 10/ring 65536. A matched T = 8 OpenFHE/FIDESlib trace finishes at final level 3 and noise-scale degree 2 on both backends. These results make public-decay carry a practical FHE co-design lever for encrypted sequence inference from bounded projected features.