High-Throughput and Scalable Secure Inference Protocols for Deep Learning with Packed Secret Sharing

📅 2026-01-19
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of existing secure multi-party computation (MPC)-based neural network inference protocols in wide-area networks, which suffer from restricted participant scalability, high communication overhead, and substantial latency. Focusing on the honest-majority setting, we propose an efficient inference framework built upon packed Shamir secret sharing (PSS). The framework introduces a communication-efficient vector-matrix multiplication protocol, an optimized packing strategy for convolutional filters, and seamless integration of nonlinear operations into the PSS paradigm, enabling end-to-end parallelization. Experimental results demonstrate that, in wide-area network environments, our approach reduces total communication by 6.83× and accelerates runtime by 1.75× compared to the state-of-the-art protocol by Liu et al., significantly enhancing both efficiency and scalability for secure deep neural network inference.

Technology Category

Machine Learning: Hardware-aware MLComputer Vision: Multi-modal VisionSearch and Optimization: Distributed Search

Application Category

Security and Privacy: Large-scale security measurementsSystems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsEconomics, Online Markets and Human Computation: Incentives in network design for Web infrastructures and ecosystems
📝 Abstract
Most existing secure neural network inference protocols based on secure multi-party computation (MPC) typically support at most four participants, demonstrating severely limited scalability. Liu et al. (USENIX Security'24) presented the first relatively practical approach by utilizing Shamir secret sharing with Mersenne prime fields. However, when processing deeper neural networks such as VGG16, their protocols incur substantial communication overhead, resulting in particularly significant latency in wide-area network (WAN) environments. In this paper, we propose a high-throughput and scalable MPC protocol for neural network inference against semi-honest adversaries in the honest-majority setting. The core of our approach lies in leveraging packed Shamir secret sharing (PSS) to enable parallel computation and reduce communication complexity. The main contributions are three-fold: i) We present a communication-efficient protocol for vector-matrix multiplication, based on our newly defined notion of vector-matrix multiplication-friendly random share tuples. ii) We design the filter packing approach that enables parallel convolution. iii) We further extend all non-linear protocols based on Shamir secret sharing to the PSS-based protocols for achieving parallel non-linear operations. Extensive experiments across various datasets and neural networks demonstrate the superiority of our approach in WAN. Compared to Liu et al. (USENIX Security'24), our scheme reduces the communication upto 5.85x, 11.17x, and 6.83x in offline, online and total communication overhead, respectively. In addition, our scheme is upto 1.59x, 2.61x, and 1.75x faster in offline, online and total running time, respectively.
Problem

Research questions and friction points this paper is trying to address.

secure inference
scalability
communication overhead
deep neural networks
wide-area network
Innovation

Methods, ideas, or system contributions that make the work stand out.

Packed Secret Sharing
Secure Neural Network Inference
Communication-Efficient MPC
Parallel Convolution
Vector-Matrix Multiplication
🔎 Similar Papers
No similar papers found.
Q
Qinghui Zhang
Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
X
Xiaojun Chen
Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Y
Yansong Zhang
Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Xudong Chen
Xudong Chen
Electrical and Systems Engineering, Washington University in St. Louis
System and Control