AIセキュリティポータル K Program
C2PI: An Efficient Crypto-Clear Two-Party Neural Network Private Inference
Share
Abstract
Recently, private inference (PI) has addressed the rising concern over data and model privacy in machine learning inference as a service. However, existing PI frameworks suffer from high computational and communication costs due to the expensive multi-party computation (MPC) protocols. Existing literature has developed lighter MPC protocols to yield more efficient PI schemes. We, in contrast, propose to lighten them by introducing an empirically-defined privacy evaluation. To that end, we reformulate the threat model of PI and use inference data privacy attacks (IDPAs) to evaluate data privacy. We then present an enhanced IDPA, named distillation-based inverse-network attack (DINA), for improved privacy evaluation. Finally, we leverage the findings from DINA and propose C2PI, a two-party PI framework presenting an efficient partitioning of the neural network model and requiring only the initial few layers to be performed with MPC protocols. Based on our experimental evaluations, relaxing the formal data privacy guarantees C2PI can speed up existing PI frameworks, including Delphi [1] and Cheetah [2], up to 2.89x and 3.88x under LAN and WAN settings, respectively, and save up to 2.75x communication costs.
Delphi: A cryptographic inference system for neural networks
Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, Raluca Ada Popa
Published: 2020
Analyzing the confidentiality of undistillable teachers in knowledge distillation
S. Kundu, Q. Sun, Y. Fu, M. Pedram, P. Beerel
Published: 2021
Oblivious neural network predictions via minionn transformations
J. Liu, M. Juuti, Y. Lu, N. Asokan
Published: 2017
Gazelle: A Low Latency Framework for Secure Neural Network Inference
Chiraag Juvekar, Vinod Vaikuntanathan, Anantha Chandrakasan
Published: 1.17.2018
Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy
Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, John Wensing
Published: 2016
XONN: xnor-based oblivious deep neural network inference
M. S. Riazi, M. Samragh, H. Chen, K. Laine, K. E. Lauter, F. Koushanfar
Published: 2019
Cryptflow2: Practical 2-party secure inference
D. Rathee, M. Rathee, N. Kumar, N. Chandran, D. Gupta, A. Rastogi, R. Sharma
Published: 2020
CryptGPU: Fast Privacy-Preserving Machine Learning on the GPU
Sijun Tan, Brian Knott, Yuan Tian, David J. Wu
Published: 4.22.2021
CrypTen: Secure Multi-Party Computation Meets Machine Learning
Brian Knott, Shobha Venkataraman, Awni Hannun, Shubho Sengupta, Mark Ibrahim, Laurens van der Maaten
Published: 9.2.2021
Muse: Secure inference resilient to malicious clients
R. Lehmkuhl, P. Mishra, A. Srinivasan, R. A. Popa
Published: 2021
Abnn2: secure two-party arbitrary-bitwidth quantized neural network predictions
L. Shen, Y. Dong, B. Fang, J. Shi, X. Wang, S. Pan, R. Shi
Published: 2022
Ressfl: A resistance transfer framework for defending model inversion attack in split federated learning
J. Li, A. S. Rakin, X. Chen, Z. He, D. Fan, C. Chakrabarti
Published: 2022
Model inversion attacks against collaborative inference
Z. He, T. Zhang, R. B. Lee
Published: 2019
Datamix: Efficient privacy-preserving edge-cloud inference
Z. Liu, Z. Wu, C. Gan, L. Zhu, S. Han
Published: 2020
Image quality assessment: from error visibility to structural similarity
Z. Wang, A. C. Bovik, H. R. Sheikh, E. P. Simoncelli
Published: 2004
Stealing neural network structure through remote fpga side-channel analysis
Y. Zhang, R. Yasaei, H. Chen, Z. Li, M. A. Al Faruque
Published: 2021
Circa: Stochastic relus for private deep learning
Z. Ghodsi, N. K. Jha, B. Reagen, S. Garg
Published: 2021
Selective network linearization for efficient private inference
Cho, M., Joshi, A., Reagen, B., Garg, S., Hegde, C.
Published: 2022
Making models shallow again: Jointly learning to reduce non-linearity and depth for latency-efficient private inference
S. Kundu, Y. Zhang, D. Chen, P. A. Beerel
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
Simc: Ml inference secure against malicious clients at semi-honest cost
N. Chandran, D. Gupta, S. L. B. Obbattu, A. Shah
Published: 2021
Very deep convolutional networks for large-scale image recognition
K. Simonyan, A. Zisserman
Published: 2015
Imagenet classification with deep convolutional neural networks
Alex Krizhevsky, Ilya Sutskever, Geoffrey E Hinton
Published: 2012
Attentionlite: Towards efficient self-attention models for vision
S. Kundu, S. Sundaresan
Published: 2021
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
Learning to linearize deep neural networks for secure and efficient private inference
S. Kundu, S. Lu, Y. Zhang, J. Liu, P. A. Beerel
Published: 2023
Share