Privacy preserving layer partitioning for Deep Neural Network models

被引:0
|
作者
Rajasekar, Kishore [1 ]
Loh, Randolph [1 ]
Fok, Kar Wai [1 ]
Thing, Vrizlynn L. L. [1 ]
机构
[1] ST Engn, Singapore, Singapore
关键词
enclave; model partition; private inference; Trusted execution environment; intel sgx; CNN;
D O I
10.1109/CAI59869.2024.00202
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
MLaaS (Machine Learning as a Service) has become popular in the cloud computing domain, allowing users to leverage cloud resources for running private inference of ML models on their data. However, ensuring user input privacy and secure inference execution is essential. One of the approaches to protect data privacy and integrity is to use Trusted Execution Environments (TEEs) by enabling execution of programs in secure hardware enclave. Using TEEs can introduce significant performance overhead due to the additional layers of encryption, decryption, security and integrity checks. This can lead to slower inference times compared to running on unprotected hardware. In our work, we enhance the runtime performance of ML models by introducing layer partitioning technique and offloading computations to GPU. The technique comprises two distinct partitions: one executed within the TEE, and the other carried out using a GPU accelerator. Layer partitioning exposes intermediate feature maps in the clear which can lead to reconstruction attacks to recover the input. We conduct experiments to demonstrate the effectiveness of our approach in protecting against input reconstruction attacks developed using trained conditional Generative Adversarial Network(c-GAN). The evaluation is performed on widely used models such as VGG-16, ResNet-50, and EfficientNetB0, using two datasets: ImageNet for Image classification and TON IoT dataset for cybersecurity attack detection.
引用
收藏
页码:1129 / 1135
页数:7
相关论文
共 50 条
  • [1] Privacy-Preserving Text Classification on Deep Neural Network
    Li, Kunhong
    Huang, Ruwei
    Yang, Bo
    NEURAL PROCESSING LETTERS, 2025, 57 (02)
  • [2] MULTI-KERNEL, DEEP NEURAL NETWORK AND HYBRID MODELS FOR PRIVACY PRESERVING MACHINE LEARNING
    Al, Mert
    Chanyaswad, Thee
    Kung, Sun-Yuan
    2018 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2018, : 2891 - 2895
  • [3] Research on Federated Deep Neural Network Model for Data Privacy Preserving
    Zhang Z.-H.
    Fu Y.
    Gao T.-G.
    Zidonghua Xuebao/Acta Automatica Sinica, 2022, 48 (05): : 1273 - 1284
  • [4] A layer-wise Perturbation based Privacy Preserving Deep Neural Networks
    Adesuyi, Tosin A.
    Kim, Byeong Man
    2019 1ST INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE IN INFORMATION AND COMMUNICATION (ICAIIC 2019), 2019, : 389 - 394
  • [5] TransNet: Training Privacy-Preserving Neural Network over Transformed Layer
    He, Qijian
    Yang, Wei
    Chen, Bingren
    Geng, Yangyang
    Huang, Liusheng
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2020, 13 (11): : 1849 - 1862
  • [6] Privacy Leakage in Privacy-Preserving Neural Network Inference
    Wei, Mengqi
    Zhu, Wenxing
    Cui, Liangkun
    Li, Xiangxue
    Li, Qiang
    COMPUTER SECURITY - ESORICS 2022, PT I, 2022, 13554 : 133 - 152
  • [7] CORK: A privacy-preserving and lossless federated learning scheme for deep neural network
    Zhao, Jiaqi
    Zhu, Hui
    Wang, Fengwei
    Lu, Rongxing
    Li, Hui
    Tu, Jingwei
    Shen, Jie
    INFORMATION SCIENCES, 2022, 603 : 190 - 209
  • [8] Privacy-Preserving Machine Learning With Fully Homomorphic Encryption for Deep Neural Network
    Lee, Joon-Woo
    Kang, Hyungchul
    Lee, Yongwoo
    Choi, Woosuk
    Eom, Jieun
    Deryabin, Maxim
    Lee, Eunsang
    Lee, Junghyun
    Yoo, Donghoon
    Kim, Young-Sik
    No, Jong-Seon
    IEEE ACCESS, 2022, 10 : 30039 - 30054
  • [9] SieveNet: Decoupling activation function neural network for privacy-preserving deep learning
    Wang, Qizheng
    Ma, Wenping
    Liu, Ge
    INFORMATION SCIENCES, 2021, 573 : 262 - 278
  • [10] Low-Latency Privacy-Preserving Outsourcing of Deep Neural Network Inference
    Tian, Yifan
    Njilla, Laurent
    Yuan, Jiawei
    Yu, Shucheng
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (05) : 3300 - 3309