In privacy-preserving neural network, the high communication costs of securely computing non-linear functions is the primary performance bottleneck. For commonly used non-linear functions, such as ReLU, existing methods adopt an offline-online computation paradigm and utilizes distributed comparison function (DCF) to reduce communication costs. Specifically, these methods prepare DCF keys in the offline phase and perform secure non-linear function computation using these keys in the online phase. However, the practicality of these methods is limited due to the substantial size of DCF keys and the heavy reliance on a trusted third party during the offline phase. In this work, we introduce FssNN, a communication-efficient secure two-party neural network framework, which features a key-reduced DCF scheme without a trusted third party to enable practical secure training and inference. Firstly, by analyzing the correlations between DCF keys to eliminate redundant parameters, we propose a key-reduced DCF scheme with a compact additive construction, decreasing the size of DCF keys by about \(17.9\%\) and offline communication costs by approximately \(28.0\%\) . Secondly, leveraging an MPC-friendly pseudorandom number generator, we propose a secure two-party distributed key generation protocol for our key-reduced DCF, eliminating the need for a trusted third party. Finally, we utilize the key-reduced DCF and additive secret sharing to compute non-linear and linear functions, and design secure computation protocols with constant online communication rounds for neural network operations, reducing online communication costs by 28.9%–43.4%. We provide formal security proofs and evaluate the performance of FssNN on various models and datasets. Experimental results show that compared to the state-of-the-art framework AriaNN, our framework reduces the total communication costs of secure training and inference by approximately \(25.4\%\) and \(26.4\%\) respectively.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Communication-Efficient Secure Neural Network via Key-Reduced Distributed Comparison Function

  • Peng Yang,
  • Zoe Lin Jiang,
  • Shiqi Gao,
  • Hongxiao Wang,
  • Jun Zhou,
  • Yangyiye Jin,
  • Siu-Ming Yiu,
  • Junbin Fang

摘要

In privacy-preserving neural network, the high communication costs of securely computing non-linear functions is the primary performance bottleneck. For commonly used non-linear functions, such as ReLU, existing methods adopt an offline-online computation paradigm and utilizes distributed comparison function (DCF) to reduce communication costs. Specifically, these methods prepare DCF keys in the offline phase and perform secure non-linear function computation using these keys in the online phase. However, the practicality of these methods is limited due to the substantial size of DCF keys and the heavy reliance on a trusted third party during the offline phase. In this work, we introduce FssNN, a communication-efficient secure two-party neural network framework, which features a key-reduced DCF scheme without a trusted third party to enable practical secure training and inference. Firstly, by analyzing the correlations between DCF keys to eliminate redundant parameters, we propose a key-reduced DCF scheme with a compact additive construction, decreasing the size of DCF keys by about \(17.9\%\) and offline communication costs by approximately \(28.0\%\) . Secondly, leveraging an MPC-friendly pseudorandom number generator, we propose a secure two-party distributed key generation protocol for our key-reduced DCF, eliminating the need for a trusted third party. Finally, we utilize the key-reduced DCF and additive secret sharing to compute non-linear and linear functions, and design secure computation protocols with constant online communication rounds for neural network operations, reducing online communication costs by 28.9%–43.4%. We provide formal security proofs and evaluate the performance of FssNN on various models and datasets. Experimental results show that compared to the state-of-the-art framework AriaNN, our framework reduces the total communication costs of secure training and inference by approximately \(25.4\%\) and \(26.4\%\) respectively.