FSAT: A Faster Secure Convolutional Neural Network Inference Framework With Adversarial Training in Resource-Constrained Scenarios
Dong Li, Anupam Chattopadhyay, Qingguo Lü, Jiahui Wu, Tao Xiang, Xiaofeng Liao · IEEE Transactions on Information Forensics and Security · 2026
Existing CNN inference frameworks based on FHE often suffer from reduced efficiency and accuracy due to the polynomial approximation of activation functions, and they lack effective mechanisms to prevent sensitive information leakage during the final classification stage. To address these limitations, we propose FSAT, a fast and secure inference framework enhanced with adversarial training. Specifically, FSAT employs a private CNN model architecture, where linear layers are computed through an optimized homomorphic ciphertext convolution operation, while non-linear layer operations are efficiently realized using a secure searchable index and an encrypted look-up table, which replace polynomial activation approximations and significantly improve inference accuracy and latency performance. To further mitigate information leakage, we introduce a dual-constraint adversarial training scheme that makes it substantially more difficult for an adversary to infer sensitive attributes of the input data. Experimental results demonstrate that FSAT achieves high inference accuracy and efficiency while substantially reducing the risk of sensitive data leakage.