Secure Transformer Inference Protocol

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yuan, Mu, Zhang, Lan, Li, Xiang-Yang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916238412742656
author Yuan, Mu
Zhang, Lan
Li, Xiang-Yang
author_facet Yuan, Mu
Zhang, Lan
Li, Xiang-Yang
contents Security of model parameters and user data is critical for Transformer-based services, such as ChatGPT. While recent strides in secure two-party protocols have successfully addressed security concerns in serving Transformer models, their adoption is practically infeasible due to the prohibitive cryptographic overheads involved. Drawing insights from our hands-on experience in developing two real-world Transformer-based services, we identify the inherent efficiency bottleneck in the two-party assumption. To overcome this limitation, we propose a novel three-party threat model. Within this framework, we design a semi-symmetric permutation-based protection scheme and present STIP, the first secure Transformer inference protocol without any inference accuracy loss. Experiments on representative Transformer models in real systems show that STIP has practical security and outperforms state-of-the-art secure two-party protocols in efficiency by millions of times.
format Preprint
id arxiv_https___arxiv_org_abs_2312_00025
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Secure Transformer Inference Protocol
Yuan, Mu
Zhang, Lan
Li, Xiang-Yang
Cryptography and Security
Machine Learning
Security of model parameters and user data is critical for Transformer-based services, such as ChatGPT. While recent strides in secure two-party protocols have successfully addressed security concerns in serving Transformer models, their adoption is practically infeasible due to the prohibitive cryptographic overheads involved. Drawing insights from our hands-on experience in developing two real-world Transformer-based services, we identify the inherent efficiency bottleneck in the two-party assumption. To overcome this limitation, we propose a novel three-party threat model. Within this framework, we design a semi-symmetric permutation-based protection scheme and present STIP, the first secure Transformer inference protocol without any inference accuracy loss. Experiments on representative Transformer models in real systems show that STIP has practical security and outperforms state-of-the-art secure two-party protocols in efficiency by millions of times.
title Secure Transformer Inference Protocol
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2312.00025