HEKWS: Privacy-Preserving Convolutional Neural Network-based Keyword Spotting with a Ciphertext Packing Technique

HEKWS: Privacy-Preserving Convolutional Neural Network-based Keyword Spotting with a Ciphertext Packing Technique
复制标题

DOI:
10.1109/mmsp55362.2022.9949982
复制
发表时间:
2022-09
期刊:
2022 IEEE 24th International Workshop on Multimedia Signal Processing (MMSP)
影响因子:
--
通讯作者:
Daniel L. Elworth;Sunwoong Kim
Daniel L. Elworth;Sunwoong Kim
中科院分区:
其他
文献类型:
--
作者:
Daniel L. Elworth;Sunwoong Kim

文献摘要

相似文献

关键字识别是智能设备中的一项关键技术。然而,这些设备中的隐私问题不断被提出。为了解决这个问题,本文将同态加密(HE)应用于先前的基于小足迹卷积神经网络(CNN)的KWS算法。这允许无信任系统,其中命令字可以由远程云服务器安全地识别,而不会暴露客户端数据。为了减轻客户端边缘设备的负担,提出了一种新的打包技术,该技术将输入关键字的密文数量减少到一个。我们基于HE的KWS显示,对于具有12个标签的Google语音命令数据集,预测准确率为72%。这几乎与具有相同CNN层并以相同方式近似整流线性单元的非基于HE的实现的精度相同。在工作站上,处理一个关键字平均需要19秒,未来可以通过并行化、HE参数优化和/或使用自定义硬件加速器来改进。
Keyword spotting (KWS) is a key technology in smart devices. However, privacy issues in these devices have been constantly raised. To solve this problem, this paper applies homomorphic encryption (HE) to a previous small-footprint convolutional neural network (CNN)-based KWS algorithm. This allows for a trustless system in which a command word can be securely identified by a remote cloud server without exposing client data. To alleviate the burden on an edge device of a client, a novel packing technique is proposed that reduces the number of ciphertexts for an input keyword to one. Our HE-based KWS shows a prediction accuracy of 72% for Google's Speech Commands Dataset with 12 labels. This is almost identical to the accuracy of the non-HE-based implementation that has the same CNN layers and approximates a rectified linear unit in the same manner. On a workstation, it takes 19 seconds to process one keyword on average, which can be improved in the future through parallelization, HE parameter optimization, and/or the use of custom hardware accelerators.