🤖 AI Summary
This work addresses the limitations of existing secure multi-party computation (MPC)-based neural network inference protocols in wide-area networks, which suffer from restricted participant scalability, high communication overhead, and substantial latency. Focusing on the honest-majority setting, we propose an efficient inference framework built upon packed Shamir secret sharing (PSS). The framework introduces a communication-efficient vector-matrix multiplication protocol, an optimized packing strategy for convolutional filters, and seamless integration of nonlinear operations into the PSS paradigm, enabling end-to-end parallelization. Experimental results demonstrate that, in wide-area network environments, our approach reduces total communication by 6.83× and accelerates runtime by 1.75× compared to the state-of-the-art protocol by Liu et al., significantly enhancing both efficiency and scalability for secure deep neural network inference.
📝 Abstract
Most existing secure neural network inference protocols based on secure multi-party computation (MPC) typically support at most four participants, demonstrating severely limited scalability. Liu et al. (USENIX Security'24) presented the first relatively practical approach by utilizing Shamir secret sharing with Mersenne prime fields. However, when processing deeper neural networks such as VGG16, their protocols incur substantial communication overhead, resulting in particularly significant latency in wide-area network (WAN) environments. In this paper, we propose a high-throughput and scalable MPC protocol for neural network inference against semi-honest adversaries in the honest-majority setting. The core of our approach lies in leveraging packed Shamir secret sharing (PSS) to enable parallel computation and reduce communication complexity. The main contributions are three-fold: i) We present a communication-efficient protocol for vector-matrix multiplication, based on our newly defined notion of vector-matrix multiplication-friendly random share tuples. ii) We design the filter packing approach that enables parallel convolution. iii) We further extend all non-linear protocols based on Shamir secret sharing to the PSS-based protocols for achieving parallel non-linear operations. Extensive experiments across various datasets and neural networks demonstrate the superiority of our approach in WAN. Compared to Liu et al. (USENIX Security'24), our scheme reduces the communication upto 5.85x, 11.17x, and 6.83x in offline, online and total communication overhead, respectively. In addition, our scheme is upto 1.59x, 2.61x, and 1.75x faster in offline, online and total running time, respectively.