Poster: Cryptographic Inferences for Video Deep Neural Networks

Poster: Cryptographic Inferences for Video Deep Neural Networks
复制标题

海报:视频深度神经网络的密码推理

DOI:
10.1145/3548606.3563543
复制
发表时间:
2022
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS
影响因子:
--
通讯作者:
Hong, Yuan
Hong, Yuan
中科院分区:
--
文献类型:
--
作者:
Liu, Bingyu;Wang, Rujia;Ba, Zhongjie;Zhou, Shanglin;Ding, Caiwen;Hong, Yuan

文献摘要

参考文献

相似文献

深度神经网络(DNN)服务已经广泛部署在许多不同的领域。例如,客户端可以将其私有输入数据(例如,图像、文本和视频)传输到云端,使用预先训练的DNN模型进行准确的推理。然而,由于潜在的数据或模型共享,这些应用程序中会出现严重的隐私问题。已经提出了利用加密技术的安全推断来解决这些问题,并且系统可以在每个客户端和云之间执行安全的双方推断。然而,大多数现有的密码系统仅关注DNN用于提取用于图像推断的2D特征,其在从视频中提取时空(3D)特征以进行准确推断的延迟和可扩展性上具有主要限制。为了解决这些关键的缺陷,我们设计并实现了第一个加密推理系统Crypto 3D,它可以在严格的隐私保证下私下推断3D功能上的视频。我们评估了Crypto 3D,并使用最先进的系统对UCF-101和HMDB-51数据集中的C3 D和I3 D模型进行了私下推断。我们的研究结果表明,Crypto 3D显着优于现有系统(大幅扩展到具有3D功能的推理):执行时间:与CryptoDL(3D)相比为186.89倍,与HEANN(3D)相比为63.75倍,与MP-SPDZ(3D)相比为61.52倍,与E2 DM(3D)相比为45倍,与Intel SGX(3D)相比为3.74倍,与Gazelle(3D)相比为3倍;准确性:82.3%,低于70%。
Deep neural network (DNN) services have been widely deployed in many different domains. For instance, a client may send its private input data (e.g., images, texts and videos) to the cloud for accurate inferences with pre-trained DNN models. However, significant privacy concerns would emerge in such applications due to the potential data or model sharing. Secure inferences with cryptographic techniques have been proposed to address such issues, and the system can perform secure two-party inferences between each client and cloud. However, most of existing cryptographic systems only focus on DNNs for extracting 2D features for image inferences, which have major limitations on latency and scalability for extracting spatio-temporal (3D) features from videos for accurate inferences. To address such critical deficiencies, we design and implement the first cryptographic inference system, Crypto3D, which privately infers videos on 3D features with rigorous privacy guarantees. We evaluate Crypto3D and benchmark with the state-of-the-art systems on privately inferring videos in the UCF-101 and HMDB-51 datasets with C3D and I3D models. Our results demonstrate that Crypto3D significantly outperforms existing systems (substantially extended to inferences with 3D features): execution time: 186.89x vs. CryptoDL (3D), 63.75x vs. HEANN (3D), 61.52x vs. MP-SPDZ (3D), 45x vs. E2DM (3D), 3.74x vs. Intel SGX (3D), and 3x vs. Gazelle (3D); accuracy: 82.3% vs. below 70% for all of them.
DOI: 10.1145/3411501.3419418
发表时间: 2020-11
期刊: Proceedings of the 2020 Workshop on Privacy-Preserving Machine Learning in Practice
影响因子: --
作者:
Pratyush Mishra;Ryan T. Lehmkuhl;Akshayaram Srinivasan;Wenting Zheng;Raluca A. Popa
通讯作者: Pratyush Mishra;Ryan T. Lehmkuhl;Akshayaram Srinivasan;Wenting Zheng;Raluca A. Popa