发表机构
The University of Osaka; Central China Normal University(大阪大学; 华中师范大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对持续认证中行为特征外包计算导致的隐私泄露问题,提出TFHE兼容的瓶颈注意力网络FBAN,通过整数化两阶段训练和加密推理协议,在保护原始特征的同时实现轻量级高精度认证。
AI 中文摘要
持续认证(CA)通过在设备交互期间反复验证用户来增强会话安全性,然而它本质上依赖于高度敏感的行为痕迹(例如,细粒度的触摸动态),这些痕迹通常被外包给云/边缘服务以进行可扩展的推理。这引发了一个根本性的使用中隐私挑战:在计算过程中保护行为特征,而不仅仅是在传输或存储中。全同态加密(FHE)提供了一种原则性解决方案,但在FHE下部署现代CA模型仍然困难,因为非线性操作和注意力风格操作会导致高昂的密文成本。我们提出了FBAN,一种TFHE兼容的瓶颈注意力网络,以及一个端到端的加密CA框架。FBAN通过两阶段流水线(浮点预训练后跟量化感知训练)设计为仅整数执行,并被编译成TFHE电路以进行同态推理。我们进一步指定了一个客户端-服务器协议,具有会话绑定的盲化和解密-返回验证,使服务器能够在没有观察到原始行为特征的情况下对用户进行认证。我们针对诚实但好奇的服务器在TFHE IND-CPA安全下提供了密码学安全性分析,并形式化了在没有TFHE密钥的情况下对重放和冒充的抵抗能力。在两个公共触摸屏数据集上的实验表明,FBAN在加密推理下实现了强大的认证效用,同时保持了轻量级的模型足迹,TFHE参数实例化为≥128位安全性。
英文摘要
Continuous authentication (CA) strengthens session security by repeatedly verifying the user during device interaction, yet it inherently relies on highly sensitive behavioral traces (e.g., fine-grained touch dynamics) that are often outsourced to cloud/edge services for scalable inference. This raises a fundamental privacy-in-use challenge: protecting behavioral features during computation, not only in transit or at rest. Fully homomorphic encryption (FHE) offers a principled solution, but deploying modern CA models under FHE remains difficult due to non-linearities and attention-style operations that incur high ciphertext cost. We propose FBAN, a TFHE-compatible Bottleneck Attention Network and an end-to-end encrypted CA framework. FBAN is designed for integer-only execution via a two-stage pipeline (floating-point pretraining followed by quantization-aware training) and is compiled into TFHE circuits for homomorphic inference. We further specify a client-server protocol with session-bound blinding and decrypt-and-return verification, enabling the server to authenticate users without observing raw behavioral features. We provide a cryptographic security analysis against an honest-but-curious server under TFHE IND-CPA security, and formalize resistance to replay and impersonation without the TFHE secret key. Experiments on two public touchscreen datasets demonstrate that FBAN achieves strong authentication utility under encrypted inference while maintaining a lightweight model footprint, with TFHE parameters instantiated at $\geq 128$-bit security.
Comments20 pages. This paper has been accepted at the 28th International Conference on Information and Communications Security (ICICS 2026)