TENNOR: Trustworthy Execution for Neural Networks through Obliviousness and Retrievals
Zifan Qu, Vasileios P. Kemerlis, Giuseppe Ateniese, Evgenios M. Kornaropoulos
Abstract
Training wide neural networks on sensitive data in untrusted cloud environments requires simultaneously achieving computational efficiency and rigorous privacy guarantees. Sparsification techniques, essential for scalable training of wide layers, expose inputdependent memory-access patterns (i.e., leakage) that are visible and can be exploited by a host OS/hypervisor, even when computation is protected by a Trusted Execution Environment.
We present TENNOR, a system that resolves this tension by codesigning the neural network training pipeline with doubly oblivious primitives, eliminating value-dependent neural network accesspattern leakage while also utilizing adaptive sparsification. TENNOR recasts sparse neuron activation as a locality-sensitive hashing (LSH) retrieval problem, reducing secure sparsification to doubly oblivious accesses over an LSH data structure. To eliminate the prohibitive storage cost of "multi-table" LSH, we introduce Multi-Probe Winner-Take-All (MP-WTA): the first multi-probe scheme for rank-based LSH, achieving a 50× reduction in (hash table) memory while preserving model accuracy. We evaluate TENNOR on extreme multi-label classification benchmarks, with output layers of up to hundreds of thousands of neurons under different batch sizes inside an Intel TDX Trusted Domain, achieving per-batch training speedups of 13×-470× over a Path ORAM baseline and reducing a 208-hour run to about 26 minutes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d931b6e3-fab8-42a3-9def-1a3fead1222bBuilds on41
- Reformer: The Efficient TransformerNikita Kitaev, Lukasz Kaiser, Anselm LevskayaICLR 2020 · 2,878 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- ABY3: A Mixed Protocol Framework for Machine LearningPayman Mohassel, Peter RindalCCS 2018 · 898 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
Related papers
- DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted HardwareHanieh Hashemi, Yongqin Wang, Murali AnnavaramMICRO 2021 · 51 citations
- TensorDash: Exploiting Sparsity to Accelerate Deep Neural Network TrainingMostafa Mahmoud, Isak Edo, Ali Hadi Zadeh, Omar Mohamed Awad et al.MICRO 2020 · 78 citations
- Bulkor: Enabling Bulk Loading for Path ORAMXiang Li, Yunqian Luo, Mingyu GaoS&P 2024 · 8 citations
- LAORAM: A Look Ahead ORAM Architecture for Training Large Embedding TablesRachit Rajat, Yongqin Wang, Murali AnnavaramISCA 2023 · 6 citations
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 14 citations
