Falcon: Fast Spectral Inference on Encrypted Data

Falcon: Fast Spectral Inference on Encrypted Data
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Qian Lou;Wen-jie Lu;Cheng Hong;Lei Jiang
Qian Lou;Wen-jie Lu;Cheng Hong;Lei Jiang
中科院分区:
其他
文献类型:
--
作者:
Qian Lou;Wen-jie Lu;Cheng Hong;Lei Jiang

文献摘要

被引文献

相似文献

基于同态加密(HE)的安全神经网络(nn)推理是新兴机器学习即服务(MLaaS)最有前途的安全解决方案之一。在基于he的MLaaS场景中,客户端对敏感数据进行加密后,将加密后的数据上传到服务器,服务器直接处理加密后的数据,不进行解密,并将加密后的结果返回给客户端。由于只有客户端拥有私钥,因此客户端的数据隐私得以保留。然而,现有的HE-enabled Neural Networks (HENNs)存在大量的计算开销。最先进的henn采用密文封装技术,通过将多个消息封装到一个密文中来减少同态乘法。然而,在这些henn中需要旋转来实现相同密文中的元素之和。我们观察到,henn必须在旋转上支付大量的计算开销,并且每次旋转比密文和明文之间的同态乘法要昂贵10倍。因此,大规模的旋转已经成为高效henn的主要障碍。在本文中,我们提出了一种称为Falcon的快速频域深度神经网络,用于对加密数据的快速推断。Falcon包括一个快速同态离散傅立叶变换(HDFT),它使用块循环矩阵来支持同态频谱操作。我们还提出了几种有效的方法来减少推理延迟,包括同态谱卷积和同态谱全连接操作,通过将批处理HE和块循环矩阵相结合。我们的实验结果表明,Falcon达到了最先进的推理精度,并将推理延迟减少了45%。45% ~ 85%。34%
Homomorphic Encryption (HE) based secure Neural Networks(NNs) inference is one of the most promising security solutions to emerging Machine Learning as a Service (MLaaS). In the HE-based MLaaS setting, a client encrypts the sensitive data, and uploads the encrypted data to the server that directly processes the encrypted data without decryption, and returns the encrypted result to the client. The client’S data privacy is preserved since only the client has the private key. Existing HE-enabled Neural Networks (HENNs), however, suffer from heavy computational overheads. The state-of-the-art HENNs adopt ciphertext packing techniques to reduce homomorphic multiplications by packing multiple messages into one single ciphertext. Nevertheless, rotations are required in these HENNs to implement the sum of the elements within the same ciphertext. We observed that HENNs have to pay significant computing overhead on rotations, and each of rotations is ∼ 10 × more expensive than homomorphic multiplications between ciphertext and plaintext. So the massive rotations have become a primary obstacle of efficient HENNs. In this paper, we propose a fast, frequency-domain deep neural network called Falcon, for fast inferences on encrypted data. Falcon includes a fast Homomor-phic Discrete Fourier Transform (HDFT) using block-circulant matrices to ho-momorphically support spectral operations. We also propose several efficient methods to reduce inference latency, including Homomorphic Spectral Convolu-tion and Homomorphic Spectral Fully Connected operations by combining the batched HE and block-circulant matrices. Our experimental results show Falcon achieves the state-of-the-art inference accuracy and reduces the inference latency by 45 . 45% ∼ 85 . 34% over