LAORAM: A Look Ahead ORAM Architecture for Training Large Embedding Tables
Rachit Rajat, Yongqin Wang, Murali Annavaram
Abstract
Data confidentiality/privacy is becoming a significant concern, especially in the cloud computing era. Memory access patterns have been demonstrated to leak critical information such as security keys and a program's spatial and temporal information. This information leak poses an even more significant privacy challenge in machine learning models with embedding tables. Embedding tables are routinely used to learn categorical features from training data. Even knowing the locations of the embedding table entries accessed, not the data within the embedding table, will compromise categorical input data to the model. Embedding entries are privacy sensitive since they disclose valuable properties about the user. Oblivious RAM (ORAM), and its enhanced variants such as PathORAM have emerged as viable solutions to hide leakage from memory access streams. PathORAM fetches an entire path of memory blocks even if a single block is needed. Once the block is fetched a new path is randomly assigned thereby leading to substantial bandwidth and performance overheads.
In this work, we present LAORAM, an ORAM framework explicitly designed to protect user privacy during embedding table training. LAORAM exploits the unique property of training, namely the training samples that are going to be used in the future are known beforehand. LAORAM preprocesses the training samples (securely without revealing the entry values) to identify the memory blocks which are accessed together in the near future. The system tries to assign these blocks to as few paths as possible within the PathORAM infrastructure.
LAORAM does this operation by combining multiple blocks accessed together as superblocks. Thus, future accesses to a collection of blocks can be satisfied from a few paths, effectively reducing the number of reads and writes required by the framework. To further increase performance, LAORAM uses a fat-tree structure for PathORAM, i.e. a tree with variable bucket size, effectively reducing the number of background evictions required, which improves the stash usage. We have evaluated LAORAM using both a recommendation model (DLRM) and a NLP model (XLM-R) embedding table configurations. LAORAM performs 5 times faster than PathORAM on a recommendation dataset (Kaggle) and 5.4x faster on a NLP dataset (XNLI), while guaranteeing the same security guarantees as the original PathORAM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da51a626-eb64-4cb4-9870-084f50803fc8Cited by top-tier papers9
- DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted HardwareHanieh Hashemi, Yongqin Wang, Murali AnnavaramMICRO 2021 · 51 citations
- GPU-based Private Information Retrieval for On-Device Machine Learning InferenceMaximilian Lam, Jeff Johnson, Wenjie Xiong, Kiwan Maeng et al.ASPLOS 2024 · 11 citations
- MPC-Pipe: an Efficient Pipeline Scheme for Semi-honest MPC Machine LearningYongqin Wang, Rachit Rajat, Murali AnnavaramASPLOS 2024 · 5 citations
- LazyDP: Co-Designing Algorithm-Software for Scalable Training of Differentially Private Recommendation ModelsJuntaek Lim, Youngeun Kwon, Ranggi Hwang, Kiwan Maeng et al.ASPLOS 2024 · 3 citations
- Practical Federated Recommendation Model Learning Using ORAM with Controlled PrivacyJinyu Liu, Wenjie Xiong, G. Edward Suh, Kiwan MaengASPLOS 2025 · 2 citations
Builds on9
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- VideoBERT: A Joint Model for Video and Language Representation LearningChen Sun, Austin Myers, Carl Vondrick, Kevin Murphy et al.ICCV 2019 · 1,396 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- ABY3: A Mixed Protocol Framework for Machine LearningPayman Mohassel, Peter RindalCCS 2018 · 898 citations
Related papers
- Efficient Memory Side-Channel Protection for Embedding Generation in Machine LearningMuhammad Umar, Akhilesh Parag Marathe, Monami Dutta Gupta, Shubham Jogprakash Ghosh et al.HPCA 2025 · 2 citations
- PageORAM: An Efficient DRAM Page Aware ORAM StrategyRachit Rajat, Yongqin Wang, Murali AnnavaramMICRO 2022 · 5 citations
- Towards Practical Oblivious JoinZhao Chang, Dong Xie, Sheng Wang, Feifei LiSIGMOD 2022 · 20 citations
- Bulkor: Enabling Bulk Loading for Path ORAMXiang Li, Yunqian Luo, Mingyu GaoS&P 2024 · 8 citations
- IR-ORAM: Path Access Type Based Memory Intensity Reduction for Path-ORAMMehrnoosh Raoufi, Youtao Zhang, Jun YangHPCA 2022 · 9 citations
