GForce: GPU-Friendly Oblivious and Rapid Neural Network Inference
Lucien K. L. Ng, Sherman S. M. Chow
摘要
Neural-network classification is getting more pervasive. It captures data of the subjects to be classified, e.g., appearance for facial recognition, which is personal and often sensitive. Oblivious inference protects the data privacy of both the query and the model. However, it is not as fast and as accurate as its plaintext counterpart. A recent cryptographic solution Delphi (Usenix Security 2020) strives for low latency by using GPU on linear layers and replacing some non-linear units in the model at a price of accuracy. It can handle a query on CIFAR-100 with ∼68% accuracy in 14s or ∼66% accuracy in 2.6s. We propose GForce, tackling the latency issue from the root causes instead of approximating non-linear computations. With the SWALP training approach (ICML 2019), we propose stochastic rounding and truncation (SRT) layers, which fuse quantization with dequantization between non-linear and linear layers and free us from floating-point operations for efficiency. They also ensure high accuracy while working over the severely-finite cryptographic field. We further propose a suite of GPU-friendly secure online/offline protocols for common operations, including comparison and wrap-around handling, which benefit non-linear layers, including our SRT. With our two innovations, GForce supports VGG-16, attaining ∼73% accuracy over CIFAR-100 for the first time, in 0.4s. Compared with the prior best non-approximated solution (Usenix Security 2018), GForce speeds up non-linear layers in VGG by >34×. Our techniques shed light on a new direction that utilizes GPU throughout the model to minimize latency. * Supported by General Research Fund (CUHK 14210319) of UGC, HK. model to the clients for evaluation is often impossible, not to say its financial and privacy implications. Oblivious inference resolves this dilemma. The server with a deep neural network DNN(•) can return the classification result DNN(x) to any client while remains oblivious about x without leaking its model DNN(•). From the perspective of computation nature, a neural network can be divided into linear layers and non-linear layers. Cryptographic solutions often handle linear layers and non-linear layers separately, such as using additive homomorphic encryption (AHE) and garbled circuits (GC), respectively, but these tools impose high overheads. A recurrent research problem is how to perform secure computations of non-linear functions efficiently.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Orca: FSS-based Secure Training and Inference with GPUsNeha Jawalkar, Kanav Gupta, Arkaprava Basu, Nishanth Chandran 等S&P 2024 · 被引用 58 次
- Honeycomb: Secure and Efficient GPU Executions via Static ValidationHaohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao 等OSDI 2023 · 被引用 39 次
- StrongBox: A GPU TEE on Arm EndpointsYunjie Deng, Chenxu Wang, Shunchang Yu, Shiqing Liu 等CCS 2022 · 被引用 37 次
- Sanitizing Sentence Embeddings (and Labels) for Local Differential PrivacyMinxin Du, Xiang Yue, Sherman S. M. Chow, Huan SunWWW 2023 · 被引用 26 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
它引用的顶会 Paper6
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 被引用 1,075 次
- Oblivious Neural Network Predictions via MiniONN TransformationsJian Liu, Mika Juuti, Yao Lu, N. AsokanCCS 2017 · 被引用 800 次
- XONN: XNOR-based Oblivious Deep Neural Network InferenceM. Sadegh Riazi, Mohammad Samragh, Hao Chen, Kim Laine 等USENIX Security 2019 · 被引用 314 次
- Let's Stride Blindfolded in a Forest: Sublinear Multi-Client Decision Trees EvaluationJack P. K. Ma, Raymond K. H. Tai, Yongjun Zhao, Sherman S. M. ChowNDSS 2021
- FALCON: A Fourier Transform Based Approach for Fast and Secure Convolutional Neural Network PredictionsShaohua Li, Kaiping Xue, Bin Zhu, Chenkai Ding 等CVPR 2020
相关 Paper
- Delphi: A Cryptographic Inference Service for Neural NetworksPratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng 等USENIX Security 2020
- Glyph: Fast and Accurately Training Deep Neural Networks on Encrypted DataQian Lou, Bo Feng, Geoffrey Charles Fox, Lei JiangNeurIPS 2020 · 被引用 106 次
- COINN: Crypto/ML Codesign for Oblivious Inference via Neural NetworksSiam Umar Hussain, Mojan Javaheripi, Mohammad Samragh, Farinaz KoushanfarCCS 2021 · 被引用 25 次
- CoPriv: Network/Protocol Co-Optimization for Communication-Efficient Private InferenceWenxuan Zeng, Meng Li, Haichuan Yang, Wen-jie Lu 等NeurIPS 2023 · 被引用 19 次
- DeepReDuce: ReLU Reduction for Fast Private InferenceNandan Kumar Jha, Zahra Ghodsi, Siddharth Garg, Brandon ReagenICML 2021 · 被引用 108 次
