Privacy preserving layer partitioning for Deep Neural Network models

被引:0
|
作者
Rajasekar, Kishore [1 ]
Loh, Randolph [1 ]
Fok, Kar Wai [1 ]
Thing, Vrizlynn L. L. [1 ]
机构
[1] ST Engn, Singapore, Singapore
关键词
enclave; model partition; private inference; Trusted execution environment; intel sgx; CNN;
D O I
10.1109/CAI59869.2024.00202
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
MLaaS (Machine Learning as a Service) has become popular in the cloud computing domain, allowing users to leverage cloud resources for running private inference of ML models on their data. However, ensuring user input privacy and secure inference execution is essential. One of the approaches to protect data privacy and integrity is to use Trusted Execution Environments (TEEs) by enabling execution of programs in secure hardware enclave. Using TEEs can introduce significant performance overhead due to the additional layers of encryption, decryption, security and integrity checks. This can lead to slower inference times compared to running on unprotected hardware. In our work, we enhance the runtime performance of ML models by introducing layer partitioning technique and offloading computations to GPU. The technique comprises two distinct partitions: one executed within the TEE, and the other carried out using a GPU accelerator. Layer partitioning exposes intermediate feature maps in the clear which can lead to reconstruction attacks to recover the input. We conduct experiments to demonstrate the effectiveness of our approach in protecting against input reconstruction attacks developed using trained conditional Generative Adversarial Network(c-GAN). The evaluation is performed on widely used models such as VGG-16, ResNet-50, and EfficientNetB0, using two datasets: ImageNet for Image classification and TON IoT dataset for cybersecurity attack detection.
引用
收藏
页码:1129 / 1135
页数:7
相关论文
共 50 条
  • [31] Locality Preserving Projection via Deep Neural Network
    Long, Tianhang
    Gao, Junbin
    Yang, Mingyan
    Hu, Yongli
    Yin, Baocai
    2019 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2019,
  • [32] Patch-based Privacy Preserving Neural Network for Vision Tasks
    Mabuchi, Mitsuhiro
    Ishikawa, Tetsuya
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 1550 - 1559
  • [33] A privacy-preserving algorithm for distributed training of neural network ensembles
    Yuan Zhang
    Sheng Zhong
    Neural Computing and Applications, 2013, 22 : 269 - 282
  • [34] Rule Extraction from Privacy Preserving Neural Network: Application to Banking
    Naveen, Nekuri
    Ravi, V.
    Rao, C. Raghavendra
    MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 920 - 928
  • [35] PpNNT: Multiparty Privacy-Preserving Neural Network Training System
    Feng Q.
    He D.
    Shen J.
    Luo M.
    Choo K.-K.R.
    IEEE Transactions on Artificial Intelligence, 2024, 5 (01): : 370 - 383
  • [36] Optimizing Privacy-Preserving Outsourced Convolutional Neural Network Predictions
    Li, Minghui
    Chow, Sherman S. M.
    Hu, Shengshan
    Yan, Yuejing
    Shen, Chao
    Wang, Qian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (03) : 1592 - 1604
  • [37] Efficient and Privacy-Preserving Neural Network Prediction Scheme with TEE
    Liu, Xingdong
    Zhu, Hui
    Wang, Fengwei
    Zheng, Yandong
    Liu, Zhe
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 2306 - 2311
  • [38] Privacy-Preserving Computing Scheme for Ciphertext Neural Network Training
    Yang, Shuya
    Li, Xiaodong
    Zhang, Jianyi
    PROCEEDINGS OF 2024 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, NETWORK SECURITY AND COMMUNICATION TECHNOLOGY, CNSCT 2024, 2024, : 148 - 152
  • [39] A federated graph neural network framework for privacy-preserving personalization
    Chuhan Wu
    Fangzhao Wu
    Lingjuan Lyu
    Tao Qi
    Yongfeng Huang
    Xing Xie
    Nature Communications, 13
  • [40] A federated graph neural network framework for privacy-preserving personalization
    Wu, Chuhan
    Wu, Fangzhao
    Lyu, Lingjuan
    Qi, Tao
    Huang, Yongfeng
    Xie, Xing
    NATURE COMMUNICATIONS, 2022, 13 (01)