LAORAM: A Look Ahead ORAM Architecture for Training Large Embedding Tables
Rachit Rajat, Yongqin Wang, Murali Annavaram
摘要
Data confidentiality/privacy is becoming a significant concern, especially in the cloud computing era. Memory access patterns have been demonstrated to leak critical information such as security keys and a program's spatial and temporal information. This information leak poses an even more significant privacy challenge in machine learning models with embedding tables. Embedding tables are routinely used to learn categorical features from training data. Even knowing the locations of the embedding table entries accessed, not the data within the embedding table, will compromise categorical input data to the model. Embedding entries are privacy sensitive since they disclose valuable properties about the user. Oblivious RAM (ORAM), and its enhanced variants such as PathORAM have emerged as viable solutions to hide leakage from memory access streams. PathORAM fetches an entire path of memory blocks even if a single block is needed. Once the block is fetched a new path is randomly assigned thereby leading to substantial bandwidth and performance overheads.
In this work, we present LAORAM, an ORAM framework explicitly designed to protect user privacy during embedding table training. LAORAM exploits the unique property of training, namely the training samples that are going to be used in the future are known beforehand. LAORAM preprocesses the training samples (securely without revealing the entry values) to identify the memory blocks which are accessed together in the near future. The system tries to assign these blocks to as few paths as possible within the PathORAM infrastructure.
LAORAM does this operation by combining multiple blocks accessed together as superblocks. Thus, future accesses to a collection of blocks can be satisfied from a few paths, effectively reducing the number of reads and writes required by the framework. To further increase performance, LAORAM uses a fat-tree structure for PathORAM, i.e. a tree with variable bucket size, effectively reducing the number of background evictions required, which improves the stash usage. We have evaluated LAORAM using both a recommendation model (DLRM) and a NLP model (XLM-R) embedding table configurations. LAORAM performs 5 times faster than PathORAM on a recommendation dataset (Kaggle) and 5.4x faster on a NLP dataset (XNLI), while guaranteeing the same security guarantees as the original PathORAM.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted HardwareHanieh Hashemi, Yongqin Wang, Murali AnnavaramMICRO 2021 · 被引用 51 次
- GPU-based Private Information Retrieval for On-Device Machine Learning InferenceMaximilian Lam, Jeff Johnson, Wenjie Xiong, Kiwan Maeng 等ASPLOS 2024 · 被引用 11 次
- MPC-Pipe: an Efficient Pipeline Scheme for Semi-honest MPC Machine LearningYongqin Wang, Rachit Rajat, Murali AnnavaramASPLOS 2024 · 被引用 5 次
- LazyDP: Co-Designing Algorithm-Software for Scalable Training of Differentially Private Recommendation ModelsJuntaek Lim, Youngeun Kwon, Ranggi Hwang, Kiwan Maeng 等ASPLOS 2024 · 被引用 3 次
- Practical Federated Recommendation Model Learning Using ORAM with Controlled PrivacyJinyu Liu, Wenjie Xiong, G. Edward Suh, Kiwan MaengASPLOS 2025 · 被引用 2 次
它引用的顶会 Paper9
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 被引用 2,107 次
- VideoBERT: A Joint Model for Video and Language Representation LearningChen Sun, Austin Myers, Carl Vondrick, Kevin Murphy 等ICCV 2019 · 被引用 1,396 次
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 被引用 1,075 次
- ABY3: A Mixed Protocol Framework for Machine LearningPayman Mohassel, Peter RindalCCS 2018 · 被引用 898 次
相关 Paper
- Efficient Memory Side-Channel Protection for Embedding Generation in Machine LearningMuhammad Umar, Akhilesh Parag Marathe, Monami Dutta Gupta, Shubham Jogprakash Ghosh 等HPCA 2025 · 被引用 2 次
- PageORAM: An Efficient DRAM Page Aware ORAM StrategyRachit Rajat, Yongqin Wang, Murali AnnavaramMICRO 2022 · 被引用 5 次
- Towards Practical Oblivious JoinZhao Chang, Dong Xie, Sheng Wang, Feifei LiSIGMOD 2022 · 被引用 20 次
- Bulkor: Enabling Bulk Loading for Path ORAMXiang Li, Yunqian Luo, Mingyu GaoS&P 2024 · 被引用 8 次
- IR-ORAM: Path Access Type Based Memory Intensity Reduction for Path-ORAMMehrnoosh Raoufi, Youtao Zhang, Jun YangHPCA 2022 · 被引用 9 次
