发表机构
Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences(中国科学院信息工程研究所; 中国科学院大学网络空间安全学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
Gecko通过安全卸载公共编码器实现快速私有推理,在图像和音频任务中推理耗时0.4-2.2秒、通信量≤10.8 MB,准确率与迁移学习基线相当,且能抵御模型提取攻击。
AI 中文摘要
私有推理可在神经网络推理过程中保护用户输入和服务器模型,但现有方案速度过慢,难以实际部署。这推动了近期将公共编码器(如预训练骨干网络)置于保护边界外,仅对小型私有预测器进行密码学评估的研究。该设计虽具效率优势,但并非天生安全:直接卸载公共编码器可能产生特征空间捷径,提取型敌手可能比原始模型的输入-输出行为更容易学习剩余私有预测器的特征-输出映射。我们提出Gecko,旨在在保留紧凑加密预测器的同时限制额外风险。我们利用贡献分层特征的冻结骨干网络、压缩这些特征的固定Fastfood投影,以及为预测做准备的私有特征门控。我们将理想独立性和信息保留条件形式化为设计指南,随后分别评估组件复用提取攻击。在图像和音频任务中,Gecko实现0.4-2.2秒的推理时间,通信量最多为10.8 MB,准确率与迁移学习基线相当。在评估的攻击下,复用卸载的公共编码器不会为模型提取敌手提供显著优势。源代码和演示可在该https URL获取。
英文摘要
Private inference protects both user inputs and server models during neural network inference, but existing solutions remain too slow for practical deployment. This motivates recent efforts to run a public encoder, such as a pretrained backbone, outside the protection boundary and evaluate only a small private predictor cryptographically. While appealing for efficiency, this design is not inherently secure: naively offloading a public encoder may create a feature-space shortcut: an extraction adversary may learn the remaining private predictor's feature-to-output mapping more easily than the original model's input-to-output behavior. We present Gecko, designed to limit this additional risk while retaining a compact encrypted predictor. We leverage a frozen backbone that contributes hierarchical features, fixed Fastfood projections that compress them, and private feature gating that prepares them for prediction. We formalize ideal independence and information-preservation conditions as design guidance, then separately evaluate component-reuse extraction attacks. Across image and audio tasks, Gecko achieves 0.4-2.2 second inference with at most 10.8 MB communication and accuracy comparable to transfer-learning baselines. Under the evaluated attacks, reusing the offloaded public encoder provides no significant advantage to model-extraction adversaries. Source code and a demo are available at https://github.com/CassiniHuy/gecko-infer.
Comments12 pages, 10 figures, and 5 tables