Sphinx: Enabling Privacy-Preserving Online Learning over the Cloud
Han Tian, Chaoliang Zeng, Zhenghang Ren, Di Chai, Junxue Zhang, Kai Chen, Qiang Yang
Abstract
With the growing complexity of deep learning applications, users have started to delegate their data and models to the cloud. Among these applications, online learning services, which involve both training and inference procedures, are widely deployed. To ensure privacy guarantee on the public cloud, researchers have proposed a plethora of privacy-preserving deep learning algorithms with different techniques, ranging from obfuscation mechanisms to cryptographic tools. However, none of them is applicable to online learning services. They either focus only on inference or training procedure while ignoring the other, or require non-colluding or trusted third parties. In this paper, we present Sphinx, an efficient and privacy-preserving online deep learning system without any trusted third parties. Sphinx strikes a balance between model performance, computational efficiency, and privacy preservation with systematical optimizations on both private inference and training protocols. At its core, Sphinx synthesizes homomorphic encryption and differential privacy reciprocally to maintain the model by keeping most of its parameters as plaintexts, enabling fast training and inference protocol designs. Meanwhile, by refining the homomorphic operation behaviors, Sphinx avoids most of the heavyweight homomorphic operations and minimizes the communication cost. As a result, Sphinx is able to reduce the training time significantly while achieving real-time inference without exposing user privacy. In our experiments, we find that compared to the pure homomorphic encryption solution, Sphinx is faster for training and 4 orders of magnitude faster for inference, providing real-time inference response (0.05 seconds for MNIST and 0.08 seconds for CIFAR-10). Our experiments also demonstrate that Sphinx achieves promising model accuracy under a tight privacy budget (96% accuracy under for MNIST) without a trusted data aggregator, and is more robust against practical reconstruction attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Practical Lossless Federated Singular Vector Decomposition over Billion-Scale DataDi Chai, Leye Wang, Junxue Zhang, Liu Yang et al.KDD 2022 · 31 citations
- FLASH: Towards a High-performance Hardware Acceleration Architecture for Cross-silo Federated LearningJunxue Zhang, Xiaodian Cheng, Wei Wang, Liu Yang et al.NSDI 2023 · 29 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Efficient Decentralized Federated Singular Vector DecompositionDi Chai, Junxue Zhang, Liu Yang, Yilun Jin et al.USENIX ATC 2024 · 9 citations
- Accelerating Privacy-Preserving Machine Learning With GeniBatchXinyang Huang, Junxue Zhang, Xiaodian Cheng, Hong Zhang et al.EuroSys 2024 · 8 citations
Builds on15
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- ABY3: A Mixed Protocol Framework for Machine LearningPayman Mohassel, Peter RindalCCS 2018 · 898 citations
Related papers
- FALCON: A Fourier Transform Based Approach for Fast and Secure Convolutional Neural Network PredictionsShaohua Li, Kaiping Xue, Bin Zhu, Chenkai Ding et al.CVPR 2020
- Private and Reliable Neural Network InferenceNikola Jovanovic, Marc Fischer, Samuel Steffen, Martin T. VechevCCS 2022 · 16 citations
- All Rivers Run to the Sea: Private Learning with Asymmetric FlowsYue Niu, Ramy E. Ali, Saurav Prakash, Salman AvestimehrCVPR 2024
- PAPER: Privacy-Preserving Convolutional Neural Networks using Low-Degree Polynomial Approximations and Structural Optimizations on Leveled FHEEduardo Chielle, Manaar Alam, Jinting Liu, Jovan Kascelan et al.CCS 2026
- Cheetah: Lean and Fast Secure Two-Party Deep Neural Network InferenceZhicong Huang, Wen-jie Lu, Cheng Hong, Jiansheng DingUSENIX Security 2022
