Privacy preserving layer partitioning for Deep Neural Network models

被引:0
|
作者
Rajasekar, Kishore [1 ]
Loh, Randolph [1 ]
Fok, Kar Wai [1 ]
Thing, Vrizlynn L. L. [1 ]
机构
[1] ST Engn, Singapore, Singapore
关键词
enclave; model partition; private inference; Trusted execution environment; intel sgx; CNN;
D O I
10.1109/CAI59869.2024.00202
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
MLaaS (Machine Learning as a Service) has become popular in the cloud computing domain, allowing users to leverage cloud resources for running private inference of ML models on their data. However, ensuring user input privacy and secure inference execution is essential. One of the approaches to protect data privacy and integrity is to use Trusted Execution Environments (TEEs) by enabling execution of programs in secure hardware enclave. Using TEEs can introduce significant performance overhead due to the additional layers of encryption, decryption, security and integrity checks. This can lead to slower inference times compared to running on unprotected hardware. In our work, we enhance the runtime performance of ML models by introducing layer partitioning technique and offloading computations to GPU. The technique comprises two distinct partitions: one executed within the TEE, and the other carried out using a GPU accelerator. Layer partitioning exposes intermediate feature maps in the clear which can lead to reconstruction attacks to recover the input. We conduct experiments to demonstrate the effectiveness of our approach in protecting against input reconstruction attacks developed using trained conditional Generative Adversarial Network(c-GAN). The evaluation is performed on widely used models such as VGG-16, ResNet-50, and EfficientNetB0, using two datasets: ImageNet for Image classification and TON IoT dataset for cybersecurity attack detection.
引用
收藏
页码:1129 / 1135
页数:7
相关论文
共 50 条
  • [21] Privacy Partition: A Privacy-preserving Framework for Deep Neural Networks in Edge Networks
    Chi, Jianfeng
    Owusu, Emmanuel
    Yin, Xuwang
    Yu, Tong
    Chan, William
    Liu, Yiming
    Liu, Haodong
    Chen, Jiasen
    Sim, Swee
    Iyengar, Vibha
    Tague, Patrick
    Tian, Yuan
    2018 THIRD IEEE/ACM SYMPOSIUM ON EDGE COMPUTING (SEC), 2018, : 378 - 380
  • [22] POSEIDON: Privacy-Preserving Federated Neural Network Learning
    Sav, Sinem
    Pyrgelis, Apostolos
    Troncoso-Pastoriza, Juan Ramon
    Froelicher, David
    Bossuat, Jean-Philippe
    Sousa, Joao Sa
    Hubaux, Jean-Pierre
    28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [23] Personalized and privacy-preserving federated graph neural network
    Liu, Yanjun
    Li, Hongwei
    Hao, Meng
    FRONTIERS IN PHYSICS, 2024, 12
  • [24] A privacy preserving probabilistic neural network for horizontally partitioned databases
    Secretan, Jimmy
    Georgiopoulos, Michael
    Castro, Jose
    2007 IEEE INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, VOLS 1-6, 2007, : 1554 - +
  • [25] A Scheme of Privacy-Preserving Convolutional Neural Network Prediction
    Ren Y.-L.
    Yu L.-Z.
    He G.
    Zhang X.-P.
    Guo Z.
    Jisuanji Xuebao/Chinese Journal of Computers, 2023, 46 (08): : 1606 - 1619
  • [26] Decentralized Graph Neural Network for Privacy-Preserving Recommendation
    Zheng, Xiaolin
    Wang, Zhongyu
    Chen, Chaochao
    Qian, Jiashu
    Yang, Yao
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 3494 - 3504
  • [27] Heterogeneous Graph Neural Network for Privacy-Preserving Recommendation
    Wei, Yuecen
    Fu, Xingcheng
    Sun, Qingyun
    Peng, Hao
    Wu, Jia
    Wang, Jinyan
    Li, Xianxian
    2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2022, : 528 - 537
  • [28] A deeper look at Ariadne: a privacy-preserving network layer protocol
    Fressancourt, Antoine
    Iannone, Luigi
    Kerichard, Mael
    ANNALS OF TELECOMMUNICATIONS, 2024, 79 (11-12) : 745 - 762
  • [29] Network Layer Privacy Protection Using Format-Preserving Encryption
    Micovic, Marko
    Radenkovic, Uros
    Vuletic, Pavle
    ELECTRONICS, 2023, 12 (23)
  • [30] Privacy-Preserving Deep Learning NLP Models for Cancer Registries
    Alawad, Mohammed
    Yoon, Hong-Jun
    Gao, Shang
    Mumphrey, Brent
    Wu, Xiao-Cheng
    Durbin, Eric B.
    Jeong, Jong Cheol
    Hands, Isaac
    Rust, David
    Coyle, Linda
    Penberthy, Lynne
    Tourassi, Georgia
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2021, 9 (03) : 1219 - 1230