POSEIDON: Privacy-Preserving Federated Neural Network Learning
Sinem Sav, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, David Froelicher, Jean-Philippe Bossuat, Joao Sa Sousa, Jean-Pierre Hubaux
Abstract
In this paper, we address the problem of privacy-preserving training and evaluation of neural networks in an -party, federated learning setting. We propose a novel system, POSEIDON, the first of its kind in the regime of privacy-preserving neural network training, employing multiparty lattice-based cryptography and preserving the confidentiality of the training data, the model, and the evaluation data, under a passive-adversary model and collusions between up to parties. To efficiently execute the secure backpropagation algorithm for training neural networks, we provide a generic packing approach that enables Single Instruction, Multiple Data (SIMD) operations on encrypted data. We also introduce arbitrary linear transformations within the cryptographic bootstrapping operation, optimizing the costly cryptographic computations over the parties, and we define a constrained optimization problem for choosing the cryptographic parameters. Our experimental results show that POSEIDON achieves accuracy similar to centralized or decentralized non-private approaches and that its computation and communication overhead scales linearly with the number of parties. POSEIDON trains a 3-layer neural network on the MNIST dataset with 784 features and 60K samples distributed among 10 parties in less than 2 hours.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60e784b6-4587-4b32-99d2-aac26dbc27c8Cited by top-tier papers22
- Eluding Secure Aggregation in Federated Learning via Model InconsistencyDario Pasquini, Danilo Francati, Giuseppe AtenieseCCS 2022 · 92 citations
- Cerebro: A Platform for Multi-Party Cryptographic Collaborative LearningWenting Zheng, Ryan Deng, Weikeng Chen, Raluca Ada Popa et al.USENIX Security 2021 · 85 citations
- Orca: FSS-based Secure Training and Inference with GPUsNeha Jawalkar, Kanav Gupta, Arkaprava Basu, Nishanth Chandran et al.S&P 2024 · 58 citations
- Secure Shapley Value for Cross-Silo Federated LearningShuyuan Zheng, Yang Cao, Masatoshi YoshikawaVLDB 2023 · 41 citations
- Sphinx: Enabling Privacy-Preserving Online Learning over the CloudHan Tian, Chaoliang Zeng, Zhenghang Ren, Di Chai et al.S&P 2022 · 37 citations
Builds on20
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
Related papers
- TransNet: Training Privacy-Preserving Neural Network over Transformed LayerQijian He, Wei Yang, Bingren Chen, Yangyang Geng et al.VLDB 2020
- Pencil: Private and Extensible Collaborative Learning without the Non-Colluding AssumptionXuanqi Liu, Zhuotao Liu, Qi Li, Ke Xu et al.NDSS 2024
- Secure Quantized Training for Deep LearningMarcel Keller, Ke SunICML 2022 · 84 citations
- CryptGPU: Fast Privacy-Preserving Machine Learning on the GPUSijun Tan, Brian Knott, Yuan Tian, David J. WuS&P 2021 · 241 citations
- ReBoot: Encrypted Training of Deep Neural Networks with CKKS BootstrappingAlberto Pirillo, Luca ColomboAAAI 2026
