conference-paper

Secure and Verifiable Inference in Deep Neural Networks

  • Annual Computer Security Applications Conference
Research footprint

At a glance

Citations
26
References
60
Comments
0
Paper overview

Abstract

Outsourced inference service has enormously promoted the popularity of deep learning, and helped users to customize a range of personalized applications. However, it also entails a variety of security and privacy issues brought by untrusted service providers. Particularly, a malicious adversary may violate user privacy during the inference process, or worse, return incorrect results to the client through compromising the integrity of the outsourced model. To address these problems, we propose SecureDL to protect the model’s integrity and user’s privacy in Deep Neural Networks (DNNs) inference process. In SecureDL, we first transform complicated non-linear activation functions of DNNs to low-degree polynomials. Then, we give a novel method to generate sensitive-samples, which can verify the integrity of a model’s parameters outsourced to the server with high accuracy. Finally, We exploit Leveled Homomorphic Encryption (LHE) to achieve the privacy-preserving inference. We shown that our sensitive-samples are indeed very sensitive to model changes, such that even a small change in parameters can be reflected in the model outputs. Based on the experiments conducted on real data and different types of attacks, we demonstrate the superior performance of SecureDL in terms of detection accuracy, inference accuracy, computation, and communication overheads.

Record transparency

Publication details

DOI
10.1145/3427228.3427232
OpenAlex
W3111925745
Document type
conference-paper
Language
EN
Source
Annual Computer Security Applications Conference
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.