发表机构
The University of Texas at Austin; The University of Texas at Austin College of Pharmacy(德克萨斯大学奥斯汀分校; 德克萨斯大学奥斯汀分校药学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究评估了基因组基础模型在同态加密下的推理可行性,提出客户端辅助近似同态加密协议,在单个加速器上以6,683秒完成全模型推理,匹配明文标签,证明了加密推理的算术可行性。
AI 中文摘要
人类基因组序列能够识别个体,一旦泄露便无法更换,且它们是基因组基础模型设计用于解读的输入。我们评估计算提供方能否在不以明文形式接收查询衍生基因组值的情况下执行已发布的基因组基础模型,以及正确性、内存或成本是否会阻碍完整的加密推理。我们首先在三个基因组任务族上复现已发布的模型,并冻结一个经独立验证的数值参考。随后,我们实现了一种客户端辅助的近似同态加密协议:提供方在密文上执行线性代数运算,而持有密钥的数据所有者则在固定边界处执行精确的归一化、因果softmax和激活函数。一种非交互式配置完成了一个已发布权重块,但在配置为组合时超出了所测试的加速器内存范围。客户端辅助配置执行了所有已发布的Transformer块以及任务头,针对一个保留的基因组信号输入,在其完整提示长度下进行。该配置匹配冻结的最终标签,峰值加速器内存为9,839 MiB,并在单个加速器上耗时6,683秒完成。这些结果确立了完整分类器在算术上的可行性,而可重复性、网络传输和私有令牌索引查找仍未解决。其生物医学意义在于,在所声明的威胁模型下,一个服务的基因组模型可以处理编码序列,而不会向计算提供方暴露明文的查询衍生激活。
英文摘要
Human genomic sequences can identify individuals, cannot be replaced after disclosure, and are the inputs that genomic foundation models are designed to interpret. We assess whether a compute provider can execute a released genomic foundation model without receiving query-derived genomic values in plaintext and whether correctness, memory, or cost prevents complete encrypted inference. We first reproduce the released model on three genomic task families and freeze an independently validated numerical reference. We then implement a client-assisted approximate homomorphic encryption protocol: the provider evaluates linear algebra on ciphertexts, while the key-holding data owner evaluates exact normalization, causal softmax, and activation functions at fixed boundaries. A noninteractive configuration completes one released-weight block but exceeds the tested accelerator-memory envelope when configured for composition. The client-assisted configuration executes all released transformer blocks and the task head for one heldout genomic-signal input at its full prompt length. It matches the frozen final label, peaks at 9,839 mebibytes of accelerator memory, and completes in 6,683 seconds on one accelerator. These results establish arithmetic feasibility for a complete classifier, while repeatability, network transport, and private token-index lookup remain unresolved. The biomedical significance is that, under the stated threat model, a served genomic model can process an encoded sequence without exposing plaintext queryderived activations to the compute provider.
Comments13 pages, 8 figures