Disparate Impact on Group Accuracy of Linearization for Private Inference
Saswat Das, Marco Romanelli, Ferdinando Fioretto
Abstract
Ensuring privacy-preserving inference on cryptographically secure data is a well-known computational challenge. To alleviate the bottleneck of costly cryptographic computations in non-linear activations, recent methods have suggested linearizing a targeted portion of these activations in neural networks. This technique results in significantly reduced runtimes with often negligible impacts on accuracy. In this paper, we demonstrate that such computational benefits may lead to increased fairness costs. Specifically, we find that reducing the number of ReLU activations disproportionately decreases the accuracy for minority groups compared to majority groups. To explain these observations, we provide a mathematical interpretation under restricted assumptions about the nature of the decision boundary, while also showing the prevalence of this problem across widely used datasets and architectures. Finally, we show how a simple procedure altering the fine-tuning step for linearized models can serve as an effective mitigation strategy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 51852b3c-910b-467a-8142-f53e0780a4caCited by top-tier papers2
- On The Fairness Impacts of Hardware Selection in Machine LearningSree Harsha Nelaturu, Nishaanth Kanna Ravichandran, Cuong Tran, Sara Hooker et al.ICML 2024 · 5 citations
- Disparate Privacy Vulnerability: Targeted Attribute Inference Attacks and DefensesEhsanul Kabir, Lucas Craig, Shagufta MehnazUSENIX Security 2025
Builds on7
- Fairness without Demographics through Adversarially Reweighted LearningPreethi Lahoti, Alex Beutel, Jilin Chen, Kang Lee et al.NeurIPS 2020 · 406 citations
- DeepReDuce: ReLU Reduction for Fast Private InferenceNandan Kumar Jha, Zahra Ghodsi, Siddharth Garg, Brandon ReagenICML 2021 · 108 citations
- CryptoNAS: Private Inference on a ReLU BudgetZahra Ghodsi, Akshaj Kumar Veldanda, Brandon Reagen, Siddharth GargNeurIPS 2020 · 103 citations
- SAFENet: A Secure, Accurate and Fast Neural Network InferenceQian Lou, Yilin Shen, Hongxia Jin, Lei JiangICLR 2021 · 65 citations
- Differentially Private Empirical Risk Minimization under the Fairness LensCuong Tran, My H. Dinh, Ferdinando FiorettoNeurIPS 2021 · 61 citations
Related papers
- Selective Network Linearization for Efficient Private InferenceMinsu Cho, Ameya Joshi, Brandon Reagen, Siddharth Garg et al.ICML 2022 · 55 citations
- Circa: Stochastic ReLUs for Private Deep LearningZahra Ghodsi, Nandan Kumar Jha, Brandon Reagen, Siddharth GargNeurIPS 2021 · 41 citations
- ReLUPruner: Rethinking ReLU Importance with Taylor Expansion for Efficient Private InferenceZhenpeng Li, Jinshuo Liu, Xinyan Wang, Lina Wang et al.AAAI 2026
- Deep Neural CryptographyDavid Gérault, Anna Hambitzer, Eyal Ronen, Adi ShamirEUROCRYPT 2026 · 1 citation
- Learning to Linearize Deep Neural Networks for Secure and Efficient Private InferenceSouvik Kundu, Shunlin Lu, Yuke Zhang, Jacqueline Tiffany Liu et al.ICLR 2023 · 3 citations
