USENIX Security2021Top-tier venue
Muse: Secure Inference Resilient to Malicious Clients
Ryan Lehmkuhl, Pratyush Mishra, Akshayaram Srinivasan, Raluca Ada Popa
Abstract
The increasing adoption of machine learning inference in applications has led to a corresponding increase in concerns surrounding the privacy guarantees offered by existing mechanisms for inference. Such concerns have motivated the construction of efficient secure inference protocols that allow parties to perform inference without revealing their sensitive information. Recently, there has been a proliferation of such proposals, rapidly improving efficiency. However, most of these protocols assume that the client is semi-honest, that is, the client does not deviate from the protocol; yet in practice, clients are many, have varying incentives, and can behave arbitrarily. To demonstrate that a malicious client can completely break the security of semi-honest protocols, we first develop a new model-extraction attack against many state-of-the-art secure inference protocols. Our attack enables a malicious client to learn model weights with 22×-312× fewer queries than the best black-box model-extraction attack [CJM20] and scales to much deeper networks. Motivated by the severity of our attack, we design and implement MUSE, an efficient two-party secure inference protocol resilient to malicious clients. MUSE introduces a novel cryptographic protocol for conditional disclosure of secrets to switch between authenticated additive secret shares and garbled circuit labels, and an improved Beaver's triple generation procedure which is 8×-12.5× faster than existing techniques. These protocols allow MUSE to push a majority of its cryptographic overhead into a preprocessing phase: compared to the equivalent semi-honest protocol (which is close to state-ofthe-art), MUSE's online phase is only 1.7×-2.2× slower and uses 1.4× more communication. Overall, MUSE is 13.4×-21× faster and uses 2×-3.6× less communication than existing secure inference protocols which defend against malicious clients. vulnerable to malicious clients requires network 4 modification 3 Table 1 : Related work on secure convolutional neural network (CNN) inference. See Section 7 for more details. This table compares specialized secure inference protocols, not generic frameworks for MPC. We compare against generic frameworks in Section 6. HE = Homomorphic Encryption, GC = Garbled Circuits, SS = Secret Sharing. Network modifications are optional 1 See Section 2.1 2 See Remark 2.1 3 Requires that two of the three parties act honestly 4 Polynomial activations or binarized/discretized weights-may reduce network accuracy
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 72add3c3-dca6-452d-99b9-13cf5d8b1849Cited by top-tier papers18
- Iron: Private Inference on TransformersMeng Hao, Hongwei Li, Hanxiao Chen, Pengzhi Xing et al.NeurIPS 2022 · 209 citations
- BOLT: Privacy-Preserving, Accurate and Efficient Inference for TransformersQi Pang, Jinhao Zhu, Helen Möllering, Wenting Zheng et al.S&P 2024 · 149 citations
- Cerebro: A Platform for Multi-Party Cryptographic Collaborative LearningWenting Zheng, Ryan Deng, Weikeng Chen, Raluca Ada Popa et al.USENIX Security 2021 · 85 citations
- Orca: FSS-based Secure Training and Inference with GPUsNeha Jawalkar, Kanav Gupta, Arkaprava Basu, Nishanth Chandran et al.S&P 2024 · 58 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
Builds on17
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- ABY3: A Mixed Protocol Framework for Machine LearningPayman Mohassel, Peter RindalCCS 2018 · 898 citations
- Oblivious Neural Network Predictions via MiniONN TransformationsJian Liu, Mika Juuti, Yao Lu, N. AsokanCCS 2017 · 800 citations
- HAWQ: Hessian AWare Quantization of Neural Networks With Mixed-PrecisionZhen Dong, Zhewei Yao, Amir Gholami, Michael W. Mahoney et al.ICCV 2019 · 645 citations
Related papers
- SIMC: ML Inference Secure Against Malicious Clients at Semi-Honest CostNishanth Chandran, Divya Gupta, Sai Lakshmi Bhavana Obbattu, Akash ShahUSENIX Security 2022
- CRISP: An Efficient Cryptographic Framework for ML Inference Against Malicious ClientsXiaoyu Fang, Shihui Zheng, Lize GuNDSS 2026
- Fusion: Efficient and Secure Inference Resilient to Malicious ServersCaiqin Dong, Jian Weng, Jia-Nan Liu, Yue Zhang et al.NDSS 2023
- Meteor: Improved Secure 3-Party Neural Network Inference with Reducing Online Communication CostsYe Dong, Xiaojun Chen, Weizhan Jing, Kaiyun Li et al.WWW 2023 · 27 citations
- Characterizing and Optimizing End-to-End Systems for Private InferenceKarthik Garimella, Zahra Ghodsi, Nandan Kumar Jha, Siddharth Garg et al.ASPLOS 2023 · 15 citations
