arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.12911cs.CR

仅打乱顺序是不够的:破解混合FHE推理中基于置换的模型机密性

Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference

发表机构全北国立大学 · 中央大学
查看机构详情
  • Jeonbuk National University(全北国立大学)
  • Chung-Ang University(中央大学)

机构由 AI 辅助整理,请以论文原文为准。

Jiseung Kim, Hyung Tae Lee

首次发表
浏览论文内容

中文总结 AI 辅助

该研究揭示混合FHE推理中基于置换的模型机密性保护存在根本缺陷,通过每层d+1次查询即可精确恢复模型,并验证了该攻击在多种模型上的有效性。

中文摘要 AI 辅助

混合全同态加密(FHE)推理通过让服务器同态地评估线性层,而客户端解密并应用非线性层,从而提高了私有推理的实用性。近期方案试图通过返回带噪声的、输出置换后的响应,并借助置换模型差分隐私(DP)来保护模型机密性。我们证明,在混合FHE系统所需的正确性机制下,这种保护是失败的。对于一个d输入的线性层,d+1次可允许的查询就足以精确恢复一个置换不变的层摘要,从而实现完美的模型区分。我们进一步表明,输入DP与模型机密性是正交的,并且置换放大所需的局部DP前提在正确性受限的噪声下无法成立。我们从TFHE转录中端到端地恢复了\safhire{}风格的ResNet-20的所有线性层,零错误,每层使用d+1次查询,总计5,712次直接查询。在相同的查询模型下,我们还确认了在预训练的ImageNet规模的CNN和ViT-B/16上实现了精确的逐层恢复。泄露的频谱使得指纹识别、谱系归属和改进的基于logit的提取成为可能,而抑制这些频谱则会破坏推理效用。

英文摘要

Hybrid fully homomorphic encryption~(FHE) inference improves the practicality of private inference by letting the server evaluate linear layers homomorphically while the client decrypts and applies nonlinearities. Recent schemes attempt to protect model confidentiality by returning noisy, output-permuted responses and appealing to shuffle-model differential privacy~(DP). We show that this protection fails in the correctness regime required by hybrid FHE systems. For a $d$-input linear layer, $d+1$ admissible queries suffice for exact recovery of a permutation-invariant layer summary, hence for perfect model distinguishability. We further show that input DP is orthogonal to model confidentiality and that the local-DP premise required for shuffle amplification cannot hold under correctness-bounded noise. We recover all linear layers of a \safhire{}-style ResNet-20 end-to-end from TFHE transcripts with zero error, using $d+1$ queries per layer for a total of $5{,}712$ direct queries. Under the same query model, we also confirm exact per-layer recovery on pretrained ImageNet-scale CNNs and ViT-B/16. The leaked spectra enable fingerprinting, lineage attribution, and improved logit-based extraction, while suppressing them destroys inference utility.

↑