The Avg-Act Swap and Plaintext Overflow Detection in Fully Homomorphic Operations Over Deep Circuits
Ihyun Nam · 2024
Fully homomorphic encryption is a cryptographic scheme that enables any function to be computed on encrypted data. Although homomorphic evaluation on deep circuits has many real-life applications, fully homomorphic encryption is not commercialized due to its low speed and huge computational overhead. In the aim to make fully homomorphic operations faster and bridge the gap between security and practicality, we introduce the Avg-Act Swap. The Avg-Act Swap is a deployable tool in privacy-preserving machine learning; it places the average pool layerbefore the activation layer as opposed to the conventional practice of ordering them the other way around in neural networks over unencrypted data. We introduce two FHE-friendly convolutional neural networks and a modified version of Lenet-5 that utilize the Avg-Act Swap to demonstrate improvements in encrypted inference speed. Most notably, we improve the encrypted inference speed of Lenet-5 by 28.58% after modifying it with the Avg-Act Swap, with a 90% accuracy. Plaintext overflow is a plausible problem in deep circuit homomorphic evaluations. We introduce (to our knowledge) the first formalized protocol to detect plaintext overflows in fixed-point arithmetic fully homomorphic encryption schemes that maintains indistinguishability over chosen plaintext attacks. We show that a remote server can homomorphically compute the maximum relative error bound of the client's plaintext only using encrypted inputs from the client. After all operations are done, the client can compare the received relative error bound to the actual error bound in the decrypted plaintext to detect an overflow. Further research to make this work in progress more efficient is encouraged.