arrow
Return

FlexBNN: Fast Private Binary Neural Network Inference With Flexible Bit-Width

delete2023-01-01
delete6
PRE
AI
Y
Ye Dong
X
Xiaojun Chen *
X
Xiangfu Song
K
Kaiyun Li
DOI:10.1109/TIFS.2023.3265342delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Advancements in deep learning enable neural network (NN) inference to be a service, but service providers and clients want to keep their inputs secret for privacy protection. Private Inference is the task of evaluating NN without leaking private inputs. Existing secure multiparty computation (MPC)based solutions mainly focus on fixed bit-width methodology, such as 32 and 64 bits. Binary Neural Network (BNN) is efficient when evaluated in MPC and has achieved reasonable accuracy for commonly used datasets, but prior private BNN inference solutions, which focus on Boolean Circuits, are still costly in communication and run-time. In this paper, we introduce FLEXBNN, a fast private BNN inference framework using three-party computation (3PC) in Arithmetic Circuits against semi-honest adversaries with honest-majority. In FLEXBNN, we propose to employ flexible and small bit-width equipped with a seamless bit-width conversion method and design several specific optimizations towards the basic operations: i) We propose bit-width determination methods for Matrix Multiplication and Sign-based Activation function. ii) We integrate Batch Normalization and Max-Pooling into the Sign-based Activation function for better efficiency. iii) More importantly, we achieve seamless bit-width conversion within the Sign-based Activation function with no additional cost. Extensive experiments illustrate that FLEXBNN outperforms stateof-the-art solutions in communication, run-time, and scalability. On average, FLEXBNN is 11x faster than XONN (USENIX Security'19) in LAN, 46x (resp. 9.3x) faster than QUOTIENT (ACM CCS'19) in LAN (resp. WAN), 10x faster than BANNERS (ACM IH&MMSec'21) in LAN, and 1.1-2.9x (resp. 1.5-2.7x) faster than FALCON (semi-honest, PoPETs'21) in LAN (resp. WAN), and improves the respective communication by 500x, 127x, and 1.3-1.5x compared to XONN, BANNERS, and FALCON.
Keywords:
Cryptography
Protocols
Local area networks
Artificial neural networks
Arithmetic
Costs
Optimization
Secure multiparty computation
privacy-preserving
deep learning
binary neural network

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

N
National University of Singapore
Scholars:
7.5W
Papers: 6.5W
Citations: 11.4W
C
chinese academy of sciences
Scholars:
56.5W
Papers: 44.9W
Citations: 704