arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

私有语义计算的可信模型环境

Trusted Model Environment for Private Semantic Computations

Vasisht Duddu, Xi He

arXiv 2609.30032首次发表:更新:

发表机构

Vector Institute; University of Waterloo(Vector 研究所; 滑铁卢大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对私有语义计算缺乏高效原语的问题,提出可信模型环境(TME),在TEE内执行生成模型并控制输出泄漏,兼具有效性、机密性、可验证性等,经三个应用验证满足要求。

AI 中文摘要

私有语义计算原语使各方能够在需要理解语义、上下文和关系的结构化及非结构化数据上进行私有计算。标准密码学原语(如多方计算)不能直接支持此类计算。生成模型非常适合此类任务,但通常以明文处理数据,而密码学私有推理仍然效率低下且难以扩展。因此,我们需要一种新的私有语义计算原语。我们引入了可信模型环境(TME),这是首个在可信执行环境(TEE)内执行生成模型并控制输出泄漏的原语。TME的设计目标是:(i)有效性(正确执行语义任务);(ii)机密性(保护计算和敏感输入);(iii)效用保持(在其他任务上保持效用);(iv)可验证性(提供防篡改的计算证据);(v)高效性(与基线模型计算相比开销低);(vi)可扩展性(支持多方参与)。有效性源于生成模型,而TEE提供机密计算。对于敏感输入的机密性,我们结合对抗训练以抵抗逐字泄漏,并使用信息流控制模块抑制语义泄漏。对于可验证性,我们引入了新颖的证明,使各方能够验证TME对其数据和查询的操作,并采用优化(如批处理)以提高效率和可扩展性。我们设计并评估了TME在三个应用中的概念验证,表明它满足所有要求。

英文摘要

A private semantic computation primitive enables parties to privately compute over structured and unstructured data that requires understanding its semantics, context, and relationships. Standard cryptographic primitives (e.g., multiparty computation) do not readily support such computation. Generative models are well suited for such tasks but typically process data in plaintext, while cryptographic private inference remains inefficient and difficult to scale. Thus, we need a new primitive for private semantic computation. We introduce trusted model environments (TME), the first such primitive that executes generative models inside trusted execution environments (TEEs) while controlling output leakage. TME is designed to be (i) effective (correctly performs the semantic task); (ii) confidential (protects computation and sensitive inputs); (iii) utility-preserving (retains utility on other tasks); (iv) verifiable (provides tamper-resistant evidence of the computations); (v) efficient (incurs low overhead compared to baseline model computations); and (vi) scalable (supports multiple participating parties). Effectiveness follows from the generative models, while TEEs provide confidential computation. For confidentiality of sensitive inputs, we combine adversarial training to resist verbatim leakage with an information flow control module to suppress semantic leakage. For verifiability, we introduce novel attestations that let parties verify TME operations on their data and queries, along with optimizations (e.g., batching) for efficiency and scalability. We design and evaluate the proof-of-concept for TME across three applications, showing that it meets all the requirements.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑