Page 350 - 《软件学报》2026年第6期
P. 350

白浩 等: 基于秘密分享的高效隐私保护卷积神经网络预测                                                     2669



                                       表 6 修改模型架构后重新训练时间以及额外存储开销

                              开销类别          MNIST (LeNet)  CIFAR-10 (ResNet18)  CIFAR-100 (ResNet50)
                            时间开销 (min)          5.23             28.93              41.63
                            存储开销 (MB)           2.39             17.62              22.36

                  6   总 结

                    在本研究工作中, 提出了一种新的隐私保护预测框架, 确保了客户端的隐私数据. 为了提高效率, 设计了一种
                 基于秘密共享的矩阵分解计算协议以及参数化二次多项式近似计算                        ReLU  方法. 实验结果表明, 所提框架比现有
                 方案快   2–15  倍, 同时保持了预测准确率. 然而, 我们仅关注在卷积神经网络的隐私预测. 在未来, 将扩展该框架到
                 Transformer 等不同模型架构上, 计划探索模块化设计以增强方法的泛化能力, 以及进一步在更多不同类型的数据
                 集上验证和优化该方法. 此外, 当前的研究集中在两个关键领域: 优化神经网络结构和设计更高效的协议. 探索这
                 些领域可以进一步提高隐私保护预测的安全性和效率.


                 References
                  [1]   Deng JK, Guo J, Xue NN, Zafeiriou S. ArcFace: Additive angular margin loss for deep face recognition. In: Proc. of the 2019 IEEE/CVF
                     Conf. on Computer Vision and Pattern Recognition. Long Beach: IEEE, 2019. 4685–4694. [doi: 10.1109/CVPR.2019.00482]
                  [2]   Schroff F, Kalenichenko D, Philbin J. FaceNet: A unified embedding for face recognition and clustering. In: Proc. of the 2015 IEEE Conf.
                     on Computer Vision and Pattern Recognition. Boston: IEEE, 2015. 815–823. [doi: 10.1109/CVPR.2015.7298682]
                  [3]   Richens JG, Lee CM, Johri S. Improving the accuracy of medical diagnosis with causal machine learning. Nature Communications, 2020,
                     11(1): 3923. [doi: 10.1038/s41467-020-17419-7]
                  [4]   Topol EJ. High-performance medicine: The convergence of human and artificial intelligence. Nature Medicine, 2019, 25(1): 44–56. [doi:
                     10.1038/s41591-018-0300-7]
                  [5]   Shokri R, Shmatikov V. Privacy-preserving deep learning. In: Proc. of the 22nd ACM SIGSAC Conf. on Computer and Communications
                     Security. Denver: ACM, 2015. 1310–1321. [doi: 10.1145/2810103.2813687]
                  [6]   Bonawitz K, Ivanov V, Kreuter B, Marcedone A, McMahan HB, Patel S, Ramage D, Segal A, Seth K. Practical secure aggregation for
                     privacy-preserving machine learning. In: Proc. of the 2017 ACM SIGSAC Conf. on Computer and Communications Security. Dallas:
                     ACM, 2017. 1175–1191. [doi: 10.1145/3133956.3133982]
                  [7]   Official Journal of the European Union. General data protection regulation. 2021. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?
                     uri=CELEX:32016R0679
                  [8]   Song L, Ma CG, Duan GH. Machine learning security and privacy: A survey. Chinese Journal of Network and Information Security,
                     2018, 4(8): 1–11 (in Chinese with English abstract). [doi: 10.11959/j.issn.2096-109x.2018067]
                  [9]   Mishra P, Lehmkuhl R, Srinivasan A, Zheng WT, Popa RA. Delphi: A cryptographic inference service for neural networks. In: Proc. of
                     the 29th USENIX Conf. on Security Symp. ACM, 2020. 141.
                                      3
                 [10]   Mohassel P, Rindal P. ABY : A mixed protocol framework for machine learning. In: Proc. of the 2018 ACM SIGSAC Conf. on Computer
                     and Communications Security. Toronto: ACM, 2018. 35–52. [doi: 10.1145/3243734.3243760]
                 [11]   Dowlin N, Gilad-Bachrach R, Laine K, Lauter K, Naehrig M, Wernsing J. CryptoNets: Applying neural networks to encrypted data with
                     high throughput and accuracy. In: Proc. of the 33rd Int’l Conf. on Machine Learning. New York: ACM, 2016. 201–210.
                 [12]   Juvekar C, Vaikuntanathan V, Chandrakasan A. Gazelle: A low latency framework for secure neural network inference. In: Proc. of the
                     27th USENIX Conf. on Security Symp. Baltimore: ACM, 2018. 1651–1668.
                 [13]   Zhang Q, Xin CS, Wu HY. GALA: Greedy computation for linear algebra in privacy-preserved neural networks. In: Proc. of the 28th
                     Annual Network and Distributed System Security Symp. The Internet Society, 2021.
                 [14]   Huang ZC, Lu WJ, Hong C, Ding JS. Cheetah: Lean and fast secure two-party deep neural network inference. In: Proc. of the 31st
                     USENIX Security Symp. Boston: USENIX Association, 2022. 809–826.
                 [15]   Ball M, Carmer B, Malkin T, Rosulek M, Schimanski N. Garbled neural networks are practical. 2019. https://eprint.iacr.org/2019/338.pdf
                 [16]   Liu  J,  Juuti  M,  Lu  Y,  Asokan  N.  Oblivious  neural  network  predictions  via  miniONN  transformations.  In:  Proc.  of  the  2017  ACM
   345   346   347   348   349   350   351   352   353   354   355