Glyph: Fast and Accurately Training Deep Neural Networks on Encrypted Data
Qian Lou, Bo Feng, Geoffrey Charles Fox, Lei Jiang
Abstract
Because of the lack of expertise, to gain benefits from their data, average users have to upload their private data to cloud servers they may not trust. Due to legal or privacy constraints, most users are willing to contribute only their encrypted data, and lack interests or resources to join deep neural network (DNN) training in cloud. To train a DNN on encrypted data in a completely non-interactive way, a recent work proposes a fully homomorphic encryption (FHE)-based technique implementing all activations by Brakerski-Gentry-Vaikuntanathan (BGV)-based lookup tables. However, such inefficient lookup-table-based activations significantly prolong private training latency of DNNs. In this paper, we propose, Glyph, a FHE-based technique to fast and accurately train DNNs on encrypted data by switching between TFHE (Fast Fully Homomorphic Encryption over the Torus) and BGV cryptosystems. Glyph uses logicoperation-friendly TFHE to implement nonlinear activations, while adopts vectorialarithmetic-friendly BGV to perform multiply-accumulations (MACs). Glyph further applies transfer learning on DNN training to improve test accuracy and reduce the number of MACs between ciphertext and ciphertext in convolutional layers. Our experimental results show Glyph obtains state-of-the-art accuracy, and reduces training latency by 69% ∼ 99% over prior FHE-based privacy-preserving techniques on encrypted datasets. Recent works [2, 3, 4] propose cryptographic schemes to enable privacy-preserving training of DNNs. Private federated learning [4] (FL) is created to decentralize DNN training and enable users to train with their own data locally. QUOTIENT [3] takes advantage of multi-party computation (MPC) to interactively train DNNs on both servers and clients. Both FL and MPC require users to stay online and heavily involve in DNN training. However, in some cases, average users may not have strong interest, powerful hardware, or fast network connections for interactive DNN training [5]. To enable DNN training on encrypted data in a completely non-interactive way, a recent study presents the first fully homomorphic encryption (FHE)-based stochastic gradient descent technique [2], FHESGD. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da82d340-92c9-40b7-b436-6bddf1a1609dCited by top-tier papers14
- SiRnn: A Math Library for Secure RNN InferenceDeevashwer Rathee, Mayank Rathee, Rahul Kranti Kiran Goli, Divya Gupta et al.S&P 2021 · 154 citations
- Secure Quantized Training for Deep LearningMarcel Keller, Ke SunICML 2022 · 84 citations
- HEPrune: Fast Private Training of Deep Neural Networks With Encrypted Data PruningYancheng Zhang, Mengxin Zheng, Yuzhang Shang, Xun Chen et al.NeurIPS 2024 · 23 citations
- On the Gini-impurity Preservation For Privacy Random ForestsXinran Xie, Man-Jie Yuan, Xuetong Bai, Wei Gao et al.NeurIPS 2023 · 17 citations
- Coeus: A System for Oblivious Document Ranking and RetrievalIshtiyaque Ahmad, Laboni Sarker, Divyakant Agrawal, Amr El Abbadi et al.SOSP 2021 · 10 citations
Builds on1
Related papers
- FxHENN: FPGA-based acceleration framework for homomorphic encrypted CNN inferenceYilan Zhu, Xinyao Wang, Lei Ju, Shanqing GuoHPCA 2023 · 39 citations
- SpENCNN: Orchestrating Encoding and Sparsity for Fast Homomorphically Encrypted Neural Network InferenceRan Ran, Xinwei Luo, Wei Wang, Tao Liu et al.ICML 2023 · 17 citations
- PAPER: Privacy-Preserving Convolutional Neural Networks using Low-Degree Polynomial Approximations and Structural Optimizations on Leveled FHEEduardo Chielle, Manaar Alam, Jinting Liu, Jovan Kascelan et al.CCS 2026
- ReBoot: Encrypted Training of Deep Neural Networks with CKKS BootstrappingAlberto Pirillo, Luca ColomboAAAI 2026
- HETAL: Efficient Privacy-preserving Transfer Learning with Homomorphic EncryptionSeewoo Lee, Garam Lee, Jung Woo Kim, Junbum Shin et al.ICML 2023 · 52 citations
