让加密数据库支持安全机器学习查询,兼顾隐私与可用性。
MLQENABLER: Enabling Secure Machine Learning Queries over Encrypted Database in Cloud Computing

- 用索引辅助技术实现加密数据上的机器学习
- 实验显示性能损失小,安全级别可接受
- 适合云上敏感数据的机器学习场景
在云计算中,公共云服务提供商(CSPs)可提供云存储为主的服务,并利用客户端存储的数据提供基于机器学习(ML)的附加服务。这一商业模式拓展了云服务边界,带来新的增长机会。然而,该模式也引发安全担忧,因公共商业云不可完全信任,可能将客户敏感数据出售给政府或其他公司。为解决此问题,一种即时方案是要求客户端在数据外送前进行加密。但若数据库被正式加密,则其内容仅为伪随机数,无法支持机器学习操作。本文提出 MLQENABLER(ML 查询启用器)方案,实现云存储中加密数据库上的安全机器学习查询。该方案采用索引辅助方法,同时实现安全性与机器学习能力。初步实验表明,MLQENABLER 在保持可接受安全水平的同时,仅造成轻微的机器学习性能下降。
原文摘要 · Abstract (English)
In cloud computing, the public cloud service providers (CSPs) can provide cloud storage as the primary service while providing additional machine learning (ML)-based services by using the clients' data in storage. This business model extends the border of cloud computing services and brings in new business growth possibilities. Although it is promising, the model also brings in security concerns since the public commercial cloud cannot be fully trusted. For example, the public commercial clouds may sell clients' sensitive data to the government or other companies. To address the security concerns, an immediate solution is to require clients to encrypt their datasets before outsourcing to the cloud. However, if a database is formally encrypted, then the database contains only pseudorandom numbers, making it impossible to enable ML over it. In this project, we propose MLQENABLER (ML Queries Enabler) scheme to enable secure ML queries over encrypted database in cloud storage. MLQENABLER employs an index-aid approach to achieve security and ML capability simultaneously. Our initial experiments show that MLQENABLER achieves an acceptable security level while incurring only a slight ML performance degradation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。