Privacy-Preserving Computing Scheme for Ciphertext Neural Network Training
Shuya Yang, Xiaodong Li, Jianyi Zhang · 2024
With the rapid development of artificial intelligence, privacy protection of AI is critical for prediction and training on sensitive data. A novel scheme is presented for privacy-preserving neural network training based on homomorphic encryption. As neural network is trained in ciphertext, the nonlinear activation function has to be polynomial approximated for computation with arithmetic operations. A new method is proposed to the nonlinear activation function approximation using a generalized Lagrange interpolation formula for derivatives. By selecting proper interpolation points, the general forms of the mainstream activation functions are derived. The proposed scheme is evaluated using a sensitive medical dataset, demonstrating its practicality in speed and computational complexity. Experimental results show that this scheme effectively addresses the polynomial approximation problem of the activation function in ciphertext neural network training. It maintains the computability of ciphertext data while ensuring data privacy, improves the accuracy of ciphertext training, and reduces the mean square error. Meanwhile, the feasibility of training deeper ciphertext deep neural networks is verified. This scheme provides practical support for mainstream learning models, such as logistic regression and multi-layer neural networks.