Formal Privacy Proof of Data Encoding: The Possibility and Impossibility of Learnable Encryption

Hanshen Xiao, G. Edward Suh, Srinivas Devadas · 2024

We initiate a formal study on the concept of learnable obfuscation and aim to answer the following question: is there a type of data encoding that maintains the "learnability" of encoded samples, thereby enabling direct model training on transformed data, while ensuring the privacy of both plaintext and the secret encoding function? This long-standing open problem has prompted many efforts to design such an encryption function, for example, NeuraCrypt and TransNet. Nonetheless, all existing constructions are heuristic without formal privacy guarantees, and many successful reconstruction attacks are known on these constructions assuming an adversary with substantial prior knowledge.

Read the paper · More papers on PaperTik