用可信机器学习模型替代可信第三方,实现加密难题下的私有推理。
Trusted Machine Learning Models Unlock Private Inference for Problems Currently Infeasible with Cryptography
- 用可信赖的机器学习模型构建安全计算环境,控制信息流与状态。
- 在传统加密方法无法处理的复杂场景中实现私有推理。
- 适合需要高效率隐私保护的现实应用,如医疗数据分析。
我们常需与不可信方交互,但隐私保护往往限制了互动效果,因达成目标需共享敏感数据。传统方案依赖可信中介或密码协议(如多方计算、零知识证明),虽有进展,但在应用规模和复杂度上仍受限。本文提出,具备能力的机器学习模型可充当可信第三方,实现此前难以实现的安全计算。具体提出可信能力模型环境(TCME),通过输入输出约束、显式信息流控制和无状态机制,平衡隐私与计算效率,使经典密码学无法解决的应用实现私有推理。文中展示了多个适用场景,并证明部分经典密码问题已可通过TCME求解。最后分析当前局限并展望未来路径。
原文摘要 · Abstract (English)
We often interact with untrusted parties. Prioritization of privacy can limit the effectiveness of these interactions, as achieving certain goals necessitates sharing private data. Traditionally, addressing this challenge has involved either seeking trusted intermediaries or constructing cryptographic protocols that restrict how much data is revealed, such as multi-party computations or zero-knowledge proofs. While significant advances have been made in scaling cryptographic approaches, they remain limited in terms of the size and complexity of applications they can be used for. In this paper, we argue that capable machine learning models can fulfill the role of a trusted third party, thus enabling secure computations for applications that were previously infeasible. In particular, we describe Trusted Capable Model Environments (TCMEs) as an alternative approach for scaling secure computation, where capable machine learning model(s) interact under input/output constraints, with explicit information flow control and explicit statelessness. This approach aims to achieve a balance between privacy and computational efficiency, enabling private inference where classical cryptographic solutions are currently infeasible. We describe a number of use cases that are enabled by TCME, and show that even some simple classic cryptographic problems can already be solved with TCME. Finally, we outline current limitations and discuss the path forward in implementing them.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。