Salted Inference: Enhancing Privacy while Maintaining Efficiency of Split Inference in Mobile Computing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Malekzadeh, Mohammad, Kawsar, Fahim
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916097406533632
author Malekzadeh, Mohammad
Kawsar, Fahim
author_facet Malekzadeh, Mohammad
Kawsar, Fahim
contents In split inference, a deep neural network (DNN) is partitioned to run the early part of the DNN at the edge and the later part of the DNN in the cloud. This meets two key requirements for on-device machine learning: input privacy and computation efficiency. Still, an open question in split inference is output privacy, given that the outputs of the DNN are observable in the cloud. While encrypted computing can protect output privacy too, homomorphic encryption requires substantial computation and communication resources from both edge and cloud devices. In this paper, we introduce Salted DNNs: a novel approach that enables clients at the edge, who run the early part of the DNN, to control the semantic interpretation of the DNN's outputs at inference time. Our proposed Salted DNNs maintain classification accuracy and computation efficiency very close to the standard DNN counterparts. Experimental evaluations conducted on both images and wearable sensor data demonstrate that Salted DNNs attain classification accuracy very close to standard DNNs, particularly when the Salted Layer is positioned within the early part to meet the requirements of split inference. Our approach is general and can be applied to various types of DNNs. As a benchmark for future studies, we open-source our code.
format Preprint
id arxiv_https___arxiv_org_abs_2310_13384
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Salted Inference: Enhancing Privacy while Maintaining Efficiency of Split Inference in Mobile Computing
Malekzadeh, Mohammad
Kawsar, Fahim
Machine Learning
Distributed, Parallel, and Cluster Computing
In split inference, a deep neural network (DNN) is partitioned to run the early part of the DNN at the edge and the later part of the DNN in the cloud. This meets two key requirements for on-device machine learning: input privacy and computation efficiency. Still, an open question in split inference is output privacy, given that the outputs of the DNN are observable in the cloud. While encrypted computing can protect output privacy too, homomorphic encryption requires substantial computation and communication resources from both edge and cloud devices. In this paper, we introduce Salted DNNs: a novel approach that enables clients at the edge, who run the early part of the DNN, to control the semantic interpretation of the DNN's outputs at inference time. Our proposed Salted DNNs maintain classification accuracy and computation efficiency very close to the standard DNN counterparts. Experimental evaluations conducted on both images and wearable sensor data demonstrate that Salted DNNs attain classification accuracy very close to standard DNNs, particularly when the Salted Layer is positioned within the early part to meet the requirements of split inference. Our approach is general and can be applied to various types of DNNs. As a benchmark for future studies, we open-source our code.
title Salted Inference: Enhancing Privacy while Maintaining Efficiency of Split Inference in Mobile Computing
topic Machine Learning
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2310.13384