PIPO: Privacy-Preserving Convolutional Neural Network Inference with Plaintext Operations

Tian Zhou, Lixin Gao · 2024

Neural network models have become essential building blocks for cloud-based services. However, these services require users to upload their data to the cloud and thereby potentially reveal private data about users. Privacy-preserving neural network inference has been proposed to protect users' data as well as the server's neural network models. These methods rely heavily on cryptographic operations which are compute-intensive. In this paper, we propose PIPO, a privacy-preserving framework for convolution neural network (CNN) inference. The key idea of PIPO is to accelerate the operations in neural networks by avoiding expensive cryptographic operations as much as possible. In particular, the client preprocesses the inference by performing linear operations, such as convolution, on a secret share of the input through homomorphic encryption. The user only needs to provide the rest of the secret shares of the input to the server to perform convolution on plaintext during the online inference. As a result, PIPO protects users' data while performing the inference with plaintext operations. To prevent model parameters from being revealed to the client directly, the server performs two reversible operations before sending intermediate results to the client: randomly scaling each entry with different scale factors and shuffling them. We evaluate PIPO on well-known CNN architectures and datasets and show that PIPO reduces the inference latency and communication volume by up to 78x and 26x respectively compared with Delphi [1]. The source code is available at GitHub.

Read the paper · More papers on PaperTik