跳到主要导航 跳到搜索 跳到主要内容

Privacy Leakage in Privacy-Preserving Neural Network Inference

  • Mengqi Wei
  • , Wenxing Zhu
  • , Liangkun Cui
  • , Xiangxue Li*
  • , Qiang Li
  • *此作品的通讯作者
  • East China Normal University
  • MatrixElements Technologies
  • Shanghai Jiao Tong University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The community has seen many attempts to secure machine learning algorithms from multi-party computation or other cryptographic primitives. An interesting 3-party framework (SCSDF hereafter) for privacy-preserving neural network inference was presented at ESORICS 2020. SCSDF defines several protocols for non-linear activation functions including ReLU, Sigmoid, etc. In particular, these protocols reckon on a protocol DReLU (derivative computation for ReLU function) they proposed as a building block. All protocols are claimed secure (against one single semi-honest corruption and against one malicious corruption). Unfortunately, the paper shows that there exists grievous privacy leakage of private inputs during SCSDF executions. This would completely destroy the framework security. We first give detailed cryptanalysis on SCSDF from the perspective of the real-ideal simulation paradigm and indicate that these claimed-secure protocols do not meet the underlying security model. We then go into particular steps in SCSDF and demonstrate that the signs of input data would be inevitably revealed to the (either semi-honest or malicious) third party responsible for assisting protocol executions. To show such leakage more explicitly, we perform plenteous experiment evaluations on the MNIST dataset, the CIFAR-10 dataset, and CFD (Chicago Face Database) for both ReLU and Sigmoid non-linear activation functions. All experiments succeed in disclosing original private data of the data owner in the inference process. Potential countermeasures are recommended and demonstrated as well.

源语言英语
主期刊名Computer Security – ESORICS 2022 - 27th European Symposium on Research in Computer Security, Proceedings
编辑Vijayalakshmi Atluri, Roberto Di Pietro, Christian D. Jensen, Weizhi Meng
出版商Springer Science and Business Media Deutschland GmbH
133-152
页数20
ISBN(印刷版)9783031171390
DOI
出版状态已出版 - 2022
活动27th European Symposium on Research in Computer Security, ESORICS 2022 - Hybrid, Copenhagen, 丹麦
期限: 26 9月 202230 9月 2022

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
13554 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议27th European Symposium on Research in Computer Security, ESORICS 2022
国家/地区丹麦
Hybrid, Copenhagen
时期26/09/2230/09/22

指纹

探究 'Privacy Leakage in Privacy-Preserving Neural Network Inference' 的科研主题。它们共同构成独一无二的指纹。

引用此