Privacy-Preserving Inference for Quantized BERT Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lu, Tianpei, Zhang, Bingsheng, Peng, Lekun, Zheng, Bowen, Li, Lichun, Ren, Kui
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908477025157120
author Lu, Tianpei
Zhang, Bingsheng
Peng, Lekun
Zheng, Bowen
Li, Lichun
Ren, Kui
author_facet Lu, Tianpei
Zhang, Bingsheng
Peng, Lekun
Zheng, Bowen
Li, Lichun
Ren, Kui
contents With the increasing deployment of generative machine learning models in privacy-sensitive domains such as healthcare and personalized services, ensuring secure inference has become a critical challenge. Secure multi-party computation (MPC) enables privacy-preserving model inference but suffers from high communication and computation overhead. The main bottleneck lies in the expensive secure evaluation of floating-point operations. Quantization offers a promising solution by converting floating-point operations into lower-precision integer computations, significantly reducing overhead. However, existing MPC-based quantized inference methods either rely on public quantization parameters-posing privacy risks-or suffer from inefficiencies, particularly in handling nonlinear functions such as activations and softmax. In this work, we propose a fine-grained, layer-wise quantization scheme and support 1-bit weight fully connected layers in a secure setting. We design a multi-input lookup table protocol to evaluate softmax efficiently and securely. Furthermore, we use dual secret sharing schemes and perform precision conversions via lookup tables, eliminating truncation overhead entirely. Experimental evaluation on BERT-base models demonstrates that our approach achieves up to $8\times$ speedup compared to Lu \emph{et al}. (NDSS 25), $9\times$ speedup compared to Gupta \emph{et al}. (PETS 24) and $22 \times$ speedup compared to Knott \emph{et al}. (NeurIPS 21).
format Preprint
id arxiv_https___arxiv_org_abs_2508_01636
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Privacy-Preserving Inference for Quantized BERT Models
Lu, Tianpei
Zhang, Bingsheng
Peng, Lekun
Zheng, Bowen
Li, Lichun
Ren, Kui
Machine Learning
Cryptography and Security
With the increasing deployment of generative machine learning models in privacy-sensitive domains such as healthcare and personalized services, ensuring secure inference has become a critical challenge. Secure multi-party computation (MPC) enables privacy-preserving model inference but suffers from high communication and computation overhead. The main bottleneck lies in the expensive secure evaluation of floating-point operations. Quantization offers a promising solution by converting floating-point operations into lower-precision integer computations, significantly reducing overhead. However, existing MPC-based quantized inference methods either rely on public quantization parameters-posing privacy risks-or suffer from inefficiencies, particularly in handling nonlinear functions such as activations and softmax. In this work, we propose a fine-grained, layer-wise quantization scheme and support 1-bit weight fully connected layers in a secure setting. We design a multi-input lookup table protocol to evaluate softmax efficiently and securely. Furthermore, we use dual secret sharing schemes and perform precision conversions via lookup tables, eliminating truncation overhead entirely. Experimental evaluation on BERT-base models demonstrates that our approach achieves up to $8\times$ speedup compared to Lu \emph{et al}. (NDSS 25), $9\times$ speedup compared to Gupta \emph{et al}. (PETS 24) and $22 \times$ speedup compared to Knott \emph{et al}. (NeurIPS 21).
title Privacy-Preserving Inference for Quantized BERT Models
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2508.01636