加密参数的高维计算,让私密推理更快更省带宽。
EP-HDC: Hyperdimensional Computing with Encrypted Parameters for High-Throughput Privacy-Preserving Inference
- 客户端用加密模型直接推理,减少传输和加解密开销。
- 批量推理吞吐提升36.52至1068倍,延迟降低6.45至733倍。
- 适合需要高隐私、高并发的智能终端场景。
虽然同态加密(HE)提供强隐私保护,但其高计算成本限制了在复杂任务中的应用。近期,将高维计算(HDC)应用于HE,在隐私保护机器学习(PPML)中展现出良好前景。然而,在真实场景如批量推理中,基于HDC的HE仍存在极高计算时间及加密与数据传输开销。为此,我们提出加密参数的高维计算(EP-HDC),一种新型的客户端侧同态加密推理方法,即在客户端使用加密模型进行推理。该方法有效降低加密与传输开销,并支持多客户端高可扩展性,同时保障用户数据与模型参数安全。我们还针对量化、架构和HE参数进行了设计空间探索。实验基于BFV方案与人脸/情绪数据集表明,相比以往方法,本方法在批量推理中实现吞吐量提升36.52~1068倍、延迟降低6.45~733倍,且准确率损失低于1%。
原文摘要 · Abstract (English)
While homomorphic encryption (HE) provides strong privacy protection, its high computational cost has restricted its application to simple tasks. Recently, hyperdimensional computing (HDC) applied to HE has shown promising performance for privacy-preserving machine learning (PPML). However, when applied to more realistic scenarios such as batch inference, the HDC-based HE has still very high compute time as well as high encryption and data transmission overheads. To address this problem, we propose HDC with encrypted parameters (EP-HDC), which is a novel PPML approach featuring client-side HE, i.e., inference is performed on a client using a homomorphically encrypted model. Our EP-HDC can effectively mitigate the encryption and data transmission overhead, as well as providing high scalability with many clients while providing strong protection for user data and model parameters. In addition to application examples for our client-side PPML, we also present design space exploration involving quantization, architecture, and HE-related parameters. Our experimental results using the BFV scheme and the Face/Emotion datasets demonstrate that our method can improve throughput and latency of batch inference by orders of magnitude over previous PPML methods (36.52~1068x and 6.45~733x, respectively) with less than 1% accuracy degradation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。