AutoPrivacy: Automated Layer-wise Parameter Selection for Secure Neural Network Inference

AutoPrivacy: Automated Layer-wise Parameter Selection for Secure Neural Network Inference
复制标题

DOI:
--
复制
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Qian Lou;B. Song;Lei Jiang
Qian Lou;B. Song;Lei Jiang
中科院分区:
其他
文献类型:
--
作者:
Qian Lou;B. Song;Lei Jiang

文献摘要

被引文献

相似文献

混合隐私保护神经网络(HPPNN)通过同态加密(HE)实现线性层,通过乱码电路(GC)实现非线性层,是新兴的机器学习即服务(MLaaS)最有前途的安全解决方案之一。不幸的是,HPPNN遭受长的推理延迟,例如,$\sim100$秒/图像,这使得MLaaS不能令人满意。由于HPPNN的基于HE的线性层的推理延迟成本为93\%$,因此选择一组HE参数以最小化线性层的计算开销至关重要。现有的HPPNN过于悲观地选择巨大的HE参数来维持大的噪声预算,因为它们对于整个网络使用相同的HE参数集合并且忽略网络的容错能力。在本文中,为了快速准确的安全神经网络推理,我们提出了一种自动分层参数选择器AutoPrivacy,它利用深度强化学习来自动确定HPPNN中每个线性层的HE参数集。基于学习的HE参数选择策略优于传统的基于规则的HE参数选择策略。与以前的HPPNN相比,AutoPrivacy优化的HPPNN将推理延迟减少了53\%\sim70\%$,而准确性损失可以忽略不计。
Hybrid Privacy-Preserving Neural Network (HPPNN) implementing linear layers by Homomorphic Encryption (HE) and nonlinear layers by Garbled Circuit (GC) is one of the most promising secure solutions to emerging Machine Learning as a Service (MLaaS). Unfortunately, a HPPNN suffers from long inference latency, e.g., $\sim100$ seconds per image, which makes MLaaS unsatisfactory. Because HE-based linear layers of a HPPNN cost $93\%$ inference latency, it is critical to select a set of HE parameters to minimize computational overhead of linear layers. Prior HPPNNs over-pessimistically select huge HE parameters to maintain large noise budgets, since they use the same set of HE parameters for an entire network and ignore the error tolerance capability of a network. In this paper, for fast and accurate secure neural network inference, we propose an automated layer-wise parameter selector, AutoPrivacy, that leverages deep reinforcement learning to automatically determine a set of HE parameters for each linear layer in a HPPNN. The learning-based HE parameter selection policy outperforms conventional rule-based HE parameter selection policy. Compared to prior HPPNNs, AutoPrivacy-optimized HPPNNs reduce inference latency by $53\%\sim70\%$ with negligible loss of accuracy.