AI 中文总结
针对深度学习隐私保护需求,提出PrivDNN框架,通过共享加密模型将计算卸载到用户端,利用部分DNN加密提高效率,采用核心神经元选择和加密方案确保模型准确与隐私,实验证明其能大幅减少推理时间和内存需求。
AI 中文摘要
在过去十年中,深度学习模型、平台和应用呈指数级增长。现有DL应用和机器学习即服务(MLaaS)框架假设模型完全可信,因此出现了对隐私保护DNN评估的需求。在安全多方计算场景中,模型和数据都被视为专有。传统的隐私保护深度学习解决方案要求用户向模型所有者发送加密样本,所有者必须用同态加密处理密文域计算。本文提出了一种新的解决方案PrivDNN,它通过与用户共享加密的深度学习模型将计算卸载到用户端,使用部分DNN加密显著提高DNN评估效率,通过核心神经元选择和加密方案确保模型准确性和隐私。实验结果表明,PrivDNN在保持模型性能和隐私的同时,将隐私保护DNN推理时间和内存需求减少了97%。代码可在指定网址获取。
英文摘要
In the past decade, we have witnessed an exponential growth of deep learning models, platforms, and applications. While existing DL applications and Machine Learning as a service (MLaaS) frameworks assume fully trusted models, the need for privacy-preserving DNN evaluation arises. In a secure multi-party computation scenario, both the model and the data are considered proprietary, i.e., the model owner does not want to reveal the highly valuable DL model to the user, while the user does not wish to disclose their private data samples either. Conventional privacy-preserving deep learning solutions ask the users to send encrypted samples to the model owners, who must handle the heavy lifting of ciphertext-domain computation with homomorphic encryption. In this paper, we present a novel solution, namely, PrivDNN, which (1) offloads the computation to the user side by sharing an encrypted deep learning model with them, (2) significantly improves the efficiency of DNN evaluation using partial DNN encryption, (3) ensures model accuracy and model privacy using a core neuron selection and encryption scheme. Experimental results show that PrivDNN reduces privacy-preserving DNN inference time and memory requirement by up to 97% while maintaining model performance and privacy. Codes can be found at https://github.com/LiangqinRen/PrivDNN
CommentsPublished in Proceedings on Privacy Enhancing Technologies (PoPETs 2024)
Journal refProceedings on Privacy Enhancing Technologies, 2024(3), 477-494