Page 350 - 《软件学报》2026年第6期
P. 350
白浩 等: 基于秘密分享的高效隐私保护卷积神经网络预测 2669
表 6 修改模型架构后重新训练时间以及额外存储开销
开销类别 MNIST (LeNet) CIFAR-10 (ResNet18) CIFAR-100 (ResNet50)
时间开销 (min) 5.23 28.93 41.63
存储开销 (MB) 2.39 17.62 22.36
6 总 结
在本研究工作中, 提出了一种新的隐私保护预测框架, 确保了客户端的隐私数据. 为了提高效率, 设计了一种
基于秘密共享的矩阵分解计算协议以及参数化二次多项式近似计算 ReLU 方法. 实验结果表明, 所提框架比现有
方案快 2–15 倍, 同时保持了预测准确率. 然而, 我们仅关注在卷积神经网络的隐私预测. 在未来, 将扩展该框架到
Transformer 等不同模型架构上, 计划探索模块化设计以增强方法的泛化能力, 以及进一步在更多不同类型的数据
集上验证和优化该方法. 此外, 当前的研究集中在两个关键领域: 优化神经网络结构和设计更高效的协议. 探索这
些领域可以进一步提高隐私保护预测的安全性和效率.
References
[1] Deng JK, Guo J, Xue NN, Zafeiriou S. ArcFace: Additive angular margin loss for deep face recognition. In: Proc. of the 2019 IEEE/CVF
Conf. on Computer Vision and Pattern Recognition. Long Beach: IEEE, 2019. 4685–4694. [doi: 10.1109/CVPR.2019.00482]
[2] Schroff F, Kalenichenko D, Philbin J. FaceNet: A unified embedding for face recognition and clustering. In: Proc. of the 2015 IEEE Conf.
on Computer Vision and Pattern Recognition. Boston: IEEE, 2015. 815–823. [doi: 10.1109/CVPR.2015.7298682]
[3] Richens JG, Lee CM, Johri S. Improving the accuracy of medical diagnosis with causal machine learning. Nature Communications, 2020,
11(1): 3923. [doi: 10.1038/s41467-020-17419-7]
[4] Topol EJ. High-performance medicine: The convergence of human and artificial intelligence. Nature Medicine, 2019, 25(1): 44–56. [doi:
10.1038/s41591-018-0300-7]
[5] Shokri R, Shmatikov V. Privacy-preserving deep learning. In: Proc. of the 22nd ACM SIGSAC Conf. on Computer and Communications
Security. Denver: ACM, 2015. 1310–1321. [doi: 10.1145/2810103.2813687]
[6] Bonawitz K, Ivanov V, Kreuter B, Marcedone A, McMahan HB, Patel S, Ramage D, Segal A, Seth K. Practical secure aggregation for
privacy-preserving machine learning. In: Proc. of the 2017 ACM SIGSAC Conf. on Computer and Communications Security. Dallas:
ACM, 2017. 1175–1191. [doi: 10.1145/3133956.3133982]
[7] Official Journal of the European Union. General data protection regulation. 2021. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?
uri=CELEX:32016R0679
[8] Song L, Ma CG, Duan GH. Machine learning security and privacy: A survey. Chinese Journal of Network and Information Security,
2018, 4(8): 1–11 (in Chinese with English abstract). [doi: 10.11959/j.issn.2096-109x.2018067]
[9] Mishra P, Lehmkuhl R, Srinivasan A, Zheng WT, Popa RA. Delphi: A cryptographic inference service for neural networks. In: Proc. of
the 29th USENIX Conf. on Security Symp. ACM, 2020. 141.
3
[10] Mohassel P, Rindal P. ABY : A mixed protocol framework for machine learning. In: Proc. of the 2018 ACM SIGSAC Conf. on Computer
and Communications Security. Toronto: ACM, 2018. 35–52. [doi: 10.1145/3243734.3243760]
[11] Dowlin N, Gilad-Bachrach R, Laine K, Lauter K, Naehrig M, Wernsing J. CryptoNets: Applying neural networks to encrypted data with
high throughput and accuracy. In: Proc. of the 33rd Int’l Conf. on Machine Learning. New York: ACM, 2016. 201–210.
[12] Juvekar C, Vaikuntanathan V, Chandrakasan A. Gazelle: A low latency framework for secure neural network inference. In: Proc. of the
27th USENIX Conf. on Security Symp. Baltimore: ACM, 2018. 1651–1668.
[13] Zhang Q, Xin CS, Wu HY. GALA: Greedy computation for linear algebra in privacy-preserved neural networks. In: Proc. of the 28th
Annual Network and Distributed System Security Symp. The Internet Society, 2021.
[14] Huang ZC, Lu WJ, Hong C, Ding JS. Cheetah: Lean and fast secure two-party deep neural network inference. In: Proc. of the 31st
USENIX Security Symp. Boston: USENIX Association, 2022. 809–826.
[15] Ball M, Carmer B, Malkin T, Rosulek M, Schimanski N. Garbled neural networks are practical. 2019. https://eprint.iacr.org/2019/338.pdf
[16] Liu J, Juuti M, Lu Y, Asokan N. Oblivious neural network predictions via miniONN transformations. In: Proc. of the 2017 ACM

