Privacy-Preserving Training and Inference of CNNs: A Medical Performance Case Study

Thomas Prantl, Louis Schneider, Simon Engel, L.-C. Horn, Vanessa Borst, Christian Krupitzer, Samuel Kounev, Rafael I. Bonilla · 2025

Artificial intelligence is on the rise, with new models and new applications emerging almost every day. However, this often happens at the expense of data privacy. Highly sensitive data is commonly required for applications used in critical areas such as healthcare and finance. One approach to bridging the gap between AI and data privacy is multi-party computation. It enables privacy-preserving machine learning by allowing multiple parties to compute a joint function while keeping their own portion of the dataset private. In this paper, we implement a simple convolutional neural network (CNN) for binary medical X-ray image classification and compare the performance differences between the secure variant with MPC and the classical insecure approach. The results show that the overall classification performance is similar. However, the privacy gained through MPC comes at the cost of three to four orders of magnitude longer runtimes. In addition, careful consideration must be given to choosing the right cryptographic parameters to keep computation within an acceptable time window. Since inference only takes approximately four minutes, using MPC is reasonable considering the large gain in privacy, especially in these sensitive environments.

Read the paper · More papers on PaperTik