IP Library Granted Patent US 11,003,991
Granted Patent B2
US 11,003,991 · App. 15/722,490 · Granted May 11, 2021

Methods for secure learning of parameters of a convolution neural network, and for secure input data classification

Inventors: Herve Chabanne (Issy-les-Moulineaux, FR); Jonathan Milgram (Issy-les-Moulineaux, FR); Constance Morel (Issy-les-Moulineaux, FR); Emmanuel Prouff (Issy-les-Moulineaux, FR)
Assignee: Idemia Identity & Security France
G06N3/08G06F17/18G06N3/0454G06N3/0481H04L9/008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,003,991
App. No.
15/722,490
Granted
May 11, 2021
Kind
B2
Abstract

A method for secure learning of parameters of a convolution neural network, CNN, for data classification includes the implementation, by data processing of a first server, including receiving from a second server a base of already classified learning data, the learning data being homomorphically encrypted; learning in the encrypted domain, from the learning database, the parameters of a reference CNN including a non-linear layer (POLYNOMIAL) operating an at least two-degree polynomial function approximating an activation function; a batch normalization layer before each non-linear layer (POLYNOMIAL); and transmitting the learnt parameters to the second server, for decryption and use for classification.

Claims (35)

1. A method for secure learning of parameters of a convolution neural network, CNN, for input data classification, the method comprising the implementation, by data processing means of a first server, of steps of:

receiving from a second server a base of already classified learning data, said learning data being homomorphically encrypted;

learning in an encrypted domain, from said base of already classified learning data, the parameters of a reference CNN comprising at least:

a non-linear layer (POLYNOMIAL) operating an at least two-degree polynomial function approximating an activation function, and

a non-approximated batch normalization layer before each non-linear layer (POLYNOMIAL); and

transmitting the learnt parameters to said second server, for decryption and use for classification.

2. The method according to claim 1 , wherein said polynomial function is determined before learning via polynomial regression of said activation function from points randomly selected in a given distribution.

3. The method according to claim 1 , wherein said polynomial function is determined during learning, the coefficients of said at least two-degree polynomial function belonging to the learnt parameters.

4. The method according to claim 1 , wherein the reference CNN comprises a convolution layer before each batch normalization layer.

5. The method according to claim 1 , wherein the reference CNN comprises at least one pooling layer operating a function of (AVERAGEPOOL) type, after a non-linear layer (POLYNOMIAL).

6. The method according to claim 1 , wherein the reference CNN comprises at least one final, fully connected layer.

7. The method according to claim 4 , wherein the reference CNN comprises at least one pooling layer operating a function of (AVERAGEPOOL) type, after a non-linear layer (POLYNOMIAL), wherein the reference CNN comprises at least one final, fully connected layer, and wherein the architecture of the reference CNN is p →AVERAGEPOOL] n →FC→FC or p →AVERAGEPOOL] n →FC →FC.

8. The method according to claim 1 , wherein said activation function is of Rectified Linear Unit type, ReLU.

9. The method according to claim 1 , wherein said polynomial function is of degree two or three, preferably two.

10. The method according to claim 1 , wherein said input data or learning data represent images, said classification being object recognition.

11. A non-transitory storage means readable by computer equipment on which a computer programme product is installed comprising code instructions for execution of the method according to claim 1 for the secure learning of parameters of a convolution neural network CNN.

12. A method for secure input data classification, comprising:

learning, by data processing means of a first server from a base of already classified learning data, parameters of a reference convolution neural network CNN comprising at least:

a non-linear layer (POLYNOMIAL) operating an at least two-degree polynomial function approximating an activation function, and

a non-approximated batch normalization layer before each non-linear layer (POLYNOMIAL);

receiving said input data, homomorphically encrypted, by data processing means of a second server, from client equipment;

classifying said encrypted input data in an encrypted domain by the data processing means of the second server, with the reference CNN, so as to obtain an encrypted classification result; and

transmitting the obtained encrypted classification result to said client equipment, for decryption.

13. The method according to claim 12 , wherein said learning includes receiving from the second server the base of already classified learning data, said learning data being homomorphically encrypted, and the learning is performed in the encrypted domain.

14. A method for secure input data classification, comprising:

learning, by data processing means of a first server from a base of already classified learning data, parameters of a reference convolution neural network, CNN, comprising at least:

a non-linear layer operating an activation function, and

a non-approximated batch normalization layer before each non-linear layer,

the learning comprising the determination of an at least two-degree polynomial function approximating said activation function;

receiving said input data, homomorphically encrypted, by data processing means of a second server, from client equipment;

classifying said encrypted input data in an encrypted domain, by the data processing means of the second server, with a substitution CNN using the parameters learnt for the reference CNN and comprising, instead of each non-linear layer operating the activation function, a non-linear layer (POLYNOMIAL) operating said determined at least two-degree polynomial function, so as to obtain an encrypted classification result; and

transmitting said obtained encrypted classification result to said client equipment, for decryption.

15. The method according to claim 14 , wherein said polynomial function is determined via polynomial regression of said activation function from points randomly selected in a given distribution.

16. The method according to claim 14 , wherein said polynomial function is determined via polynomial regression of said activation function from points recovered at input of one or more non-linear layers of the reference CNN.

17. The method according to claim 14 , wherein the learning, after determination of the parameters of the reference CNN, comprises the implementation of at least one additional iteration of learning on the substitution CNN to adapt said parameters to said determined polynomial function.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER REPLACING 10158873 WITH 10185873 PREVIOUSLY RECORDED ON REEL 71930 FRAME 625. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Apr 1, 2026
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 075530/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 071930/0625 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
CHANGE OF NAME Recorded May 16, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 046169/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2018
From: CHABANNE, HERVE; MILGRAM, JONATHAN; MOREL, CONSTANCE; PROUFF, EMMANUEL
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 045755/0667 →
Priority Claims (1)
FR 16 59439 · Sep 30, 2016 · national
Continuity (1)
Related Publication 20180096248A1 · Apr 5, 2018