发表机构
Humboldt University of Berlin; Tallinn University of Technology(柏林洪堡大学; 塔林理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究在同态加密下神经网络结构化剪枝对模型可靠性的影响,提出多项式灵敏度感知剪枝方法PSAP,通过共同评分滤波器集中剪枝于容错区,实验表明其在提升模型可靠性同时兼具效率优势。
AI 中文摘要
结构化剪枝对于在同态加密(HE)下使神经网络推理可行至关重要,但其对模型可靠性的影响尚未得到探索。本文对剪枝后的CKKS加密神经网络进行了系统的可靠性表征,并引入了多项式灵敏度感知剪枝(PSAP),这是一种内在具有可靠性感知的结构化剪枝方法。PSAP通过权重大小、多项式激活灵敏度和旋转成本共同对滤波器进行评分,将剪枝集中在容错区域。在两个架构、两个数据集、两种数值表示和五个误码率下进行实验,PSAP剪枝模型将灾难性(准确率下降>10个百分点)层限制在最多两层,而幅度剪枝基线为5 - 14层,在int32位翻转注入下将最坏情况的脆弱性降低了29倍。直接CKKS加密故障注入表明在BER~10^{-5}附近有一个安全操作边界,支持将int32注入作为保守的可靠性代理。故障关键结构层仅占参数的1.1%,能够以最小的开销进行选择性强化。在获得这些可靠性提升的同时,PSAP在效率方面也具有竞争力:在ResNet - 32上,PSAP将Halevi - Shoup旋转减少了45.2%,自适应混合度分配方案将乘法深度从66级降低到56级,无需引导即可进行分层推理。
英文摘要
Structured pruning is essential for making neural network inference feasible under homomorphic encryption (HE), yet its impact on model reliability has remained unexplored. This paper presents a systematic reliability characterization of pruned CKKS-encrypted neural networks and introduces Polynomial-Sensitivity-Aware Pruning (PSAP), a structured pruning method that is inherently reliability-aware. PSAP scores filters jointly by weight magnitude, polynomial activation sensitivity, and rotation cost, which concentrates pruning in fault-tolerant regions. Across two architectures, two datasets, two numerical representations, and five bit-error rates (40 full-model and 108 per-layer experiments), PSAP-pruned models limit catastrophic (>10 pp accuracy drop) layers to at most two versus 5--14 for magnitude-pruned baselines, reducing worst-case vulnerability by up to 29 times under int32 bit-flip injection. Direct CKKS encrypted fault injection indicates a safe operating boundary near BER~ 10^{-5}, supporting int32 injection as a conservative reliability proxy. The fault-critical structural layers account for only 1.1% of parameters, enabling selective hardening at minimal overhead. These reliability gains are obtained alongside competitive efficiency: PSAP reduces Halevi--Shoup rotations by up to 45.2\% on ResNet-32, and an adaptive mixed-degree allocation scheme lowers multiplicative depth from 66 to 56 levels, enabling leveled inference without bootstrapping.