Deploying Convolutional Networks on Untrusted Platforms Using 2D Holographic Reduced Representations
Mohammad Mahmudul Alam, Edward Raff, Tim Oates, James Holt
Abstract
Due to the computational cost of running inference for a neural network, the need to deploy the inferential steps on a third party's compute environment or hardware is common. If the third party is not fully trusted, it is desirable to obfuscate the nature of the inputs and outputs, so that the third party can not easily determine what specific task is being performed. Provably secure protocols for leveraging an untrusted party exist but are too computational demanding to run in practice. We instead explore a different strategy of fast, heuristic security that we call Connectionist Symbolic Pseudo Secrets. By leveraging Holographic Reduced Representations (HRR), we create a neural network with a pseudo-encryption style defense that empirically shows robustness to attack, even under threat models that unrealistically favor the adversary.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- MIMONets: Multiple-Input-Multiple-Output Neural Networks Exploiting Computation in SuperpositionNicolas Menet, Michael Hersche, Geethan Karunaratne, Luca Benini et al.NeurIPS 2023 · 32 citations
- A Walsh Hadamard Derived Linear Vector Symbolic ArchitectureMohammad Mahmudul Alam, Alexander Oberle, Edward Raff, Stella Biderman et al.NeurIPS 2024 · 10 citations
Builds on6
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- Oblivious Neural Network Predictions via MiniONN TransformationsJian Liu, Mika Juuti, Yao Lu, N. AsokanCCS 2017 · 800 citations
- InstaHide: Instance-hiding Schemes for Private Distributed LearningYangsibo Huang, Zhao Song, Kai Li, Sanjeev AroraICML 2020 · 178 citations
- Is Private Learning Possible with Instance Encoding?Nicholas Carlini, Samuel Deng, Sanjam Garg, Somesh Jha et al.S&P 2021 · 45 citations
Related papers
- Meteor: Improved Secure 3-Party Neural Network Inference with Reducing Online Communication CostsYe Dong, Xiaojun Chen, Weizhan Jing, Kaiyun Li et al.WWW 2023 · 27 citations
- Hardware-Assisted Intellectual Property Protection of Deep Learning ModelsAbhishek Chakraborty, Ankit Mondal, Ankur SrivastavaDAC 2020 · 75 citations
- Deep Neural CryptographyDavid Gérault, Anna Hambitzer, Eyal Ronen, Adi ShamirEUROCRYPT 2026 · 1 citation
- Learning with Holographic Reduced RepresentationsAshwinkumar Ganesan, Hang Gao, Sunil Gandhi, Edward Raff et al.NeurIPS 2021 · 37 citations
- SOTER: Guarding Black-box Inference for General Neural Networks at the EdgeTianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang et al.USENIX ATC 2022 · 67 citations
