SecFormer: Fast and Accurate Privacy-Preserving Inference for Transformer Models via SMPC

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Luo, Jinglong, Zhang, Yehong, Zhang, Zhuo, Zhang, Jiaqi, Mu, Xin, Wang, Hui, Yu, Yue, Xu, Zenglin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912418332934144
author Luo, Jinglong
Zhang, Yehong
Zhang, Zhuo
Zhang, Jiaqi
Mu, Xin
Wang, Hui
Yu, Yue
Xu, Zenglin
author_facet Luo, Jinglong
Zhang, Yehong
Zhang, Zhuo
Zhang, Jiaqi
Mu, Xin
Wang, Hui
Yu, Yue
Xu, Zenglin
contents With the growing use of Transformer models hosted on cloud platforms to offer inference services, privacy concerns are escalating, especially concerning sensitive data like investment plans and bank account details. Secure Multi-Party Computing (SMPC) emerges as a promising solution to protect the privacy of inference data and model parameters. However, the application of SMPC in Privacy-Preserving Inference (PPI) for Transformer models often leads to considerable slowdowns or declines in performance. This is largely due to the multitude of nonlinear operations in the Transformer architecture, which are not well-suited to SMPC and difficult to circumvent or optimize effectively. To address this concern, we introduce a comprehensive PPI framework called SecFormer to achieve fast and accurate PPI for Transformer models. We successfully eliminate the high-cost exponential and maximum operations in PPI without sacrificing model performance and develop a suite of efficient SMPC protocols by employing suitable numerical computation methods to boost other complex nonlinear functions in PPI, including GeLU, LayerNorm, and a redesigned Softmax. Our extensive experiments reveal that SecFormer outperforms MPCFormer in performance, showing improvements of $3.4\%$ and $24.7\%$ for BERT$_{\text{BASE}}$ and BERT$_{\text{LARGE}}$, respectively. In terms of efficiency, SecFormer is 3.57 and 3.58 times faster than PUMA for BERT$_{\text{BASE}}$ and BERT$_{\text{LARGE}}$, demonstrating its effectiveness and speed.
format Preprint
id arxiv_https___arxiv_org_abs_2401_00793
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle SecFormer: Fast and Accurate Privacy-Preserving Inference for Transformer Models via SMPC
Luo, Jinglong
Zhang, Yehong
Zhang, Zhuo
Zhang, Jiaqi
Mu, Xin
Wang, Hui
Yu, Yue
Xu, Zenglin
Machine Learning
Computation and Language
Cryptography and Security
With the growing use of Transformer models hosted on cloud platforms to offer inference services, privacy concerns are escalating, especially concerning sensitive data like investment plans and bank account details. Secure Multi-Party Computing (SMPC) emerges as a promising solution to protect the privacy of inference data and model parameters. However, the application of SMPC in Privacy-Preserving Inference (PPI) for Transformer models often leads to considerable slowdowns or declines in performance. This is largely due to the multitude of nonlinear operations in the Transformer architecture, which are not well-suited to SMPC and difficult to circumvent or optimize effectively. To address this concern, we introduce a comprehensive PPI framework called SecFormer to achieve fast and accurate PPI for Transformer models. We successfully eliminate the high-cost exponential and maximum operations in PPI without sacrificing model performance and develop a suite of efficient SMPC protocols by employing suitable numerical computation methods to boost other complex nonlinear functions in PPI, including GeLU, LayerNorm, and a redesigned Softmax. Our extensive experiments reveal that SecFormer outperforms MPCFormer in performance, showing improvements of $3.4\%$ and $24.7\%$ for BERT$_{\text{BASE}}$ and BERT$_{\text{LARGE}}$, respectively. In terms of efficiency, SecFormer is 3.57 and 3.58 times faster than PUMA for BERT$_{\text{BASE}}$ and BERT$_{\text{LARGE}}$, demonstrating its effectiveness and speed.
title SecFormer: Fast and Accurate Privacy-Preserving Inference for Transformer Models via SMPC
topic Machine Learning
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2401.00793