SepMM: A General Matrix Multiplication Optimization Approach for Privacy-Preserving Machine Learning
Tsai Tung-Lin, Wu Pei-yuan · 2023
Privacy-preserving machine learning (PPML) has gained significant attention in recent years due to the increasing need to protect sensitive data while obtaining accurate predictions. This is attributed to secure encryption schemes such as homomorphic encryption and secure multi-party computation, which allow some parties to jointly compute the results without knowing others’ data. However, practical implementations of these methods require secure computation under encryption, which significantly increase communication and computation costs compared to plaintext computation. In view that matrix multiplication is a key operation in machine learning applications, and typically serves as a bottleneck under secure multi party computation framework due to the massive communications it requires between parties, we propose SepMM as a novel secure matrix multiplication optimization approach for 2-party computation. SepMM ensures that, assuming uniform distribution prior, the chances for the adverary to reveal any entry in the matrix decreases exponentially with the increase in bitlength. SepMM can be integrated with secure matrix multiplication methods that are bitwise equivalent to plaintext execution. Experimental results show that, by integrating SepMM with state-of-the-art PPML framework SIRNN, the communication cost and inference time are reduced by 4.67x - 13.29x and 3.64x - 9.44x, respectively, for widely adopted neural networks SqueezeNet, ResNet50, and DenseNet121.