arXiv:2412.14392cs.CRcs.LG2024-12

Nemesis加速加密机器学习,让隐私保护计算更快更实用。

Nemesis: Noise-randomized Encryption with Modular Efficiency and Secure Integration in Machine Learning Systems

  • 用高级缓存和数学工具优化多槽全同态加密运算
  • 在MNIST等数据集上显著降低计算开销
  • 适合需要高安全性的大规模隐私计算场景

基于全同态加密(FHE)的机器学习系统能保障安全与隐私,但其计算效率低下限制了实际应用。本文提出Nemesis框架,在不牺牲准确性和安全性前提下加速FHE系统。该设计受Rache(SIGMOD'23)启发,引入更先进的缓存机制与数学工具,支持多槽FHE方案下的高效操作,并突破Rache对明文结构的限制,可处理通用明文形式。我们在标准密码学假设下严格证明了Nemesis的安全性,并在MNIST、FashionMNIST和CIFAR-10等常用数据集上进行了全面评估。结果表明,Nemesis显著降低了FHE系统计算开销,推动隐私保护技术在更大范围的应用。

原文摘要 · Abstract (English)

Machine learning (ML) systems that guarantee security and privacy often rely on Fully Homomorphic Encryption (FHE) as a cornerstone technique, enabling computations on encrypted data without exposing sensitive information. However, a critical limitation of FHE is its computational inefficiency, making it impractical for large-scale applications. In this work, we propose \textit{Nemesis}, a framework that accelerates FHE-based systems without compromising accuracy or security. The design of Nemesis is inspired by Rache (SIGMOD'23), which introduced a caching mechanism for encrypted integers and scalars. Nemesis extends this idea with more advanced caching techniques and mathematical tools, enabling efficient operations over multi-slot FHE schemes and overcoming Rache's limitations to support general plaintext structures. We formally prove the security of Nemesis under standard cryptographic assumptions and evaluate its performance extensively on widely used datasets, including MNIST, FashionMNIST, and CIFAR-10. Experimental results show that Nemesis significantly reduces the computational overhead of FHE-based ML systems, paving the way for broader adoption of privacy-preserving technologies.

全同态加密隐私计算机器学习安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。