PrivDNN: A Secure Multi-Party Computation Framework for Deep Learning using Partial DNN Encryption
Liangqin Ren, Zeyan Liu, Fengjun Li, Kaitai Liang, Zhu Li, Bo Luo
cs.CR
Submitted: 2026-07-24
Comments: Published in Proceedings on Privacy Enhancing Technologies (PoPETs 2024)
Journal ref: Proceedings on Privacy Enhancing Technologies, 2024(3), 477-494
DOI: 10.56553/popets-2024-0089
Code: https://github.com/LiangqinRen/PrivDNN
License: http://creativecommons.org/licenses/by/4.0/
The gist: In the past decade, we have witnessed an exponential growth of deep learning models, platforms, and applications.
Terminology
Abstract
In the past decade, we have witnessed an exponential growth of deep learning models, platforms, and applications. While existing DL applications and Machine Learning as a service (MLaaS) frameworks assume fully trusted models, the need for privacy-preserving DNN evaluation arises. In a secure multi-party computation scenario, both the model and the data are considered proprietary, i.e., the model owner does not want to reveal the highly valuable DL model to the user, while the user does not wish to disclose their private data samples either. Conventional privacy-preserving deep learning solutions ask the users to send encrypted samples to the model owners, who must handle the heavy lifting of ciphertext-domain computation with homomorphic encryption. In this paper, we present a novel solution, namely, PrivDNN, which (1) offloads the computation to the user side by sharing an encrypted deep learning model with them, (2) significantly improves the efficiency of DNN evaluation using partial DNN encryption, (3) ensures model accuracy and model privacy using a core neuron selection and encryption scheme. Experimental results show that PrivDNN reduces privacy-preserving DNN inference time and memory requirement by up to 97% while maintaining model performance and privacy. Codes can be found at https://github.com/LiangqinRen/PrivDNN
Sources
- Soft Filter Pruning for Accelerating Deep Convolutional Neural Networks
- Structured Pruning for Deep Convolutional Neural Networks: A survey
- CryptoDL: Deep Neural Networks over Encrypted Data
- Security Analysis of Deep Neural Networks Operating in the Presence of Cache Side-Channel Attacks
- Efficient CNN Building Blocks for Encrypted Data
- Faster CryptoNets: Leveraging Sparsity for Real-World Encrypted Inference
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Pruning Filters for Efficient ConvNets
- Rethinking the Value of Network Pruning
- Searching for Activation Functions
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs