ReBoot: Encrypted Training of Deep Neural Networks with CKKS Bootstrapping
Alberto Pirillo, Luca Colombo
摘要
Growing concerns over data privacy underscore the need for deep learning methods capable of processing sensitive information without compromising confidentiality. Among privacy-enhancing technologies, Homomorphic Encryption (HE) stands out by providing post-quantum cryptographic security and end-to-end data protection, safeguarding data even during computation. While Deep Neural Networks (DNNs) have gained attention in HE settings, their use has largely been restricted to encrypted inference. Prior research on encrypted training has primarily focused on logistic regression or has relied on multi-party computation to enable model finetuning. This stems from the substantial computational overhead and algorithmic complexity involved in DNNs training under HE. In this paper, we present ReBoot, the first framework to enable fully encrypted and non-interactive training of DNNs. Built upon the CKKS scheme, ReBoot introduces a novel HE-compliant neural network architecture based on local error signals, specifically designed to minimize multiplicative depth and reduce noise accumulation. ReBoot employs a tailored packing strategy that leverages real-number arithmetic via SIMD operations, significantly lowering both computational and memory overhead. Furthermore, by integrating approximate bootstrapping, ReBoot learning algorithm supports effective training of arbitrarily deep multi-layer perceptrons, making it well-suited for machine learning as-a-service. ReBoot is evaluated on both image recognition and tabular benchmarks, achieving accuracy comparable to 32-bit floating-point plaintext training while enabling fully encrypted training. It improves test accuracy by up to +3.27% over encrypted logistic regression, and up to +6.83% over existing encrypted DNN frameworks, while reducing training latency by up to 8.83×. ReBoot is made available to the scientific community as a public repository.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Efficient Bootstrapping for Approximate Homomorphic Encryption with Non-sparse KeysJean-Philippe Bossuat, Christian Mouchet, Juan Ramón Troncoso-Pastoriza, Jean-Pierre HubauxEUROCRYPT 2021 · 被引用 179 次
- Glyph: Fast and Accurately Training Deep Neural Networks on Encrypted DataQian Lou, Bo Feng, Geoffrey Charles Fox, Lei JiangNeurIPS 2020 · 被引用 106 次
- Securing Approximate Homomorphic Encryption Using Differential PrivacyBaiyu Li, Daniele Micciancio, Mark Schultz, Jessica SorrellCRYPTO 2022 · 被引用 55 次
- HETAL: Efficient Privacy-preserving Transfer Learning with Homomorphic EncryptionSeewoo Lee, Garam Lee, Jung Woo Kim, Junbum Shin 等ICML 2023 · 被引用 52 次
- META-BTS: Bootstrapping Precision Beyond the LimitYoungjin Bae, Jung Hee Cheon, Wonhee Cho, Jaehyung Kim 等CCS 2022 · 被引用 36 次
相关 Paper
- PAPER: Privacy-Preserving Convolutional Neural Networks using Low-Degree Polynomial Approximations and Structural Optimizations on Leveled FHEEduardo Chielle, Manaar Alam, Jinting Liu, Jovan Kascelan 等CCS 2026
- RBOOT: Accelerating Homomorphic Neural Network Inference by Fusing ReLU within BootstrappingZhaomin Yang, Chao Niu, Benqiang Wei, Zhicong Huang 等USENIX Security 2026 · 被引用 1 次
- FxHENN: FPGA-based acceleration framework for homomorphic encrypted CNN inferenceYilan Zhu, Xinyao Wang, Lei Ju, Shanqing GuoHPCA 2023 · 被引用 39 次
- Hadal: Centralized Label DP without a Trusted PartyJames Choncholas, Stanislav Peceny, Amit Agarwal, Mariana Raykova 等S&P 2026
- MAD: Memory-Aware Design Techniques for Accelerating Fully Homomorphic EncryptionRashmi Agrawal, Leo de Castro, Chiraag Juvekar, Anantha P. Chandrakasan 等MICRO 2023 · 被引用 32 次
