IP Library › Granted Patent US 12,632,734
Granted Patent B2
US 12,632,734 · App. 17/423,088 · Granted May 19, 2026

Oblivious binary neural networks

Inventors: Mohammad Sadegh Riazi (San Diego, CA); Farinaz Koushanfar (San Diego, CA); Mohammad Samragh Razlighi (San Diego, CA)
Assignee: The Regents of the University of California
G06N3/082G06F21/71G06N3/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,734
App. No.
17/423,088
Granted
May 19, 2026
Kind
B2
Abstract

A framework is presented that provides a shift in the conceptual and practical realization of privacy-preserving interference on deep neural networks. The framework leverages the concept of the binary neural networks (BNNs) in conjunction with the garbled circuits protocol. In BNNs, the weights and activations are restricted to binary (e.g., ±1) values, substituting the costly multiplications with simple XNOR operations during the inference phase. The XNOR operation is known to be free in the GC protocol; therefore, performing oblivious inference on BNNs using GC results in the removal of costly multiplications. The approach consistent with implementations of the current subject matter provides for oblivious inference on the standard DL benchmarks being performed with minimal, if any, decrease in the prediction accuracy.

Claims (13)

1 . A system, comprising: at least one data processor; and at least one memory storing instructions which, when executed by the at least one data processor, provide operations comprising: receiving input data; providing the input data to security protocol comprising a garbled circuits protocol configured to provide an oblivious inference protocol, wherein the input data is modified, via the security protocol, to a neural network architecture, which generates an output; modifying parameters of the neural network architecture to operate and provide the output using the such that the modified neural network architecture implements an oblivious inference protocol, wherein the modifying further comprises binarizing the neural network architecture to create a binary neural network architecture having weights and activations of a binary value, the binary neural network architecture comprising layers including channels and neurons, adjusting the binary neural network architecture by applying a factor variable to the channels and to the neurons of the layers of the binary neural network architecture, and removing redundant channels and neurons from each layer of the binary neural network architecture; wherein modifying the parameters further comprises transforming the input data parameters such that the input data is not discernible to a server executing the modified neural network architecture binary neural network architecture.

2 . The system of claim 1 wherein removing redundant channels and neurons from each layer of the binary neural network architecture comprises: ranking the channels and neurons based on a magnitude of gradient values of each of the channels and neurons; and removing, from each layer of the binary neural network architecture, the channels and neurons having a lowest magnitude of the ranked channels and/or neurons.

3 . The system of claim 2 , wherein removing the channels and neurons having the lowest magnitude is repeated until an accuracy falls below a predefined threshold value.

4 . The system of claim 1 , wherein the at least one memory storing instructions which, when executed by the at least one data processor, provide operations further comprising: executing a first layer of the binary neural network architecture by executing a vector dot product with the input data and a vector comprising binary values based on oblivious transfer.

5 . The system of claim 1 , wherein the at least one memory storing instructions which, when executed by the at least one data processor, provide operations further comprising: creating a Boolean circuit representation of each layer of the binary neural network architecture, wherein each Boolean circuit representation is created separately, and wherein each layer comprises a plurality of micro-circuits forming the Boolean circuit representation.

6 . The system of claim 1 , wherein implementing the security protocol to generate the output comprises a randomizing operation and a decrypting operation for each layer, wherein the randomizing operation and the decrypting operation are performed in succession such that after one layer is randomized, the one layer is successively decrypted, wherein the randomizing operation comprises creating a randomized table for each gate in the Boolean circuit representation for each layer of the binary neural network architecture, wherein random output labels are encrypted using input labels according to a truth table of the gate.

7 . A method, comprising: receiving input data; providing the input data to security protocol comprising a garbled circuits protocol configured to provide an oblivious inference protocol, wherein the input data is modified, via the security protocol, to a neural network architecture, which generates an output; modifying parameters of the neural network architecture to operate and provide the output using the such that the modified neural network architecture implements an oblivious inference protocol, wherein the modifying further comprises binarizing the neural network architecture to create a binary neural network architecture having weights and activations of a binary value, the binary neural network architecture comprising layers including channels and neurons, adjusting the binary neural network architecture by applying a factor variable to the channels and to the neurons of the layers of the binary neural network architecture, and removing redundant channels and neurons from each layer of the binary neural network architecture; wherein modifying the parameters further comprises transforming the input data parameters such that input data is not discernible to a server executing the binary neural network architecture modified neural network architecture.

8 . The method of claim 7 , wherein removing redundant channels and neurons from each layer of the binary neural network architecture comprises: ranking the channels and neurons based on a magnitude of gradient values of each of the channels and neurons; and removing, from each layer of the binary neural network architecture, the channels and neurons having a lowest magnitude of the ranked channels and/or neurons.

9 . The method of claim 8 , wherein removing the channels and neurons having the lowest magnitude is repeated until an accuracy falls below a predefined threshold value.

10 . The method of claim 7 , further comprising: executing a first layer of the binary neural network architecture by executing a vector dot product with the input data and a vector comprising binary values based on oblivious transfer.

11 . The method of claim 7 , further comprising: creating a Boolean circuit representation of each layer of the binary neural network architecture, wherein each Boolean circuit representation is created separately, and wherein each layer comprises a plurality of micro-circuits forming the Boolean circuit representation.

12 . The method of claim 7 , wherein implementing the security protocol to generate the output comprises a randomizing operation and a decrypting operation for each layer, wherein the randomizing operation and the decrypting operation are performed in succession such that after one layer is randomized, the one layer is successively decrypted, wherein the randomizing operation comprises creating a randomized table for each gate in the Boolean circuit representation for each layer of the binary neural network architecture, wherein random output labels are encrypted using input labels according to a truth table of the gate.

13 . A non-transitory computer-readable storage medium including program code, which when executed by at least one data processor, causes operations comprising: receiving input data; providing the input data to security protocol comprising a garbled circuits protocol configured to provide an oblivious inference protocol, wherein the input data is modified, via the security protocol, to a neural network architecture, which generates an output; modifying parameters of the neural network architecture to operate and provide the output using the such that the modified neural network architecture implements an oblivious inference protocol, wherein the modifying further comprises binarizing the neural network architecture to create a binary neural network architecture having weights and activations of a binary value, the binary neural network architecture comprising layers including channels and neurons, adjusting the binary neural network architecture by applying a factor variable to the channels and to the neurons of the layers of the binary neural network architecture, and removing redundant channels and neurons from each layer of the binary neural network architecture; wherein modifying the parameters further comprises transforming the input data parameters such that input data is not discernible to a server executing the binary neural network architecture modified neural network architecture.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2021
From: RIAZI, MOHAMMAD SADEGH; KOUSHANFAR, FARINAZ; SAMRAGH RAZLIGHI, MOHAMMAD
To: THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
Reel/Frame 058329/0509 →
Continuity (2)
Provisional Application 62794474 · Jan 18, 2019
Related Publication 20220083865A1 · Mar 17, 2022
References Cited (41)
US 20160350648A1 · Gilad-Bachrach et al. · 2016 [cited by applicant]
US 20170372226A1 · Costa et al. · 2017 [cited by applicant]
US 20210209247A1 · Mohassel · 2021 [cited by examiner]
Abdelouahab, “Accelerating CNN inference on FPGAs: A Survey”, 2018 (Year: 2018). [cited by examiner]
Abadi, M. et al., “Tensorflow: A system for large-scale machine learning.” In Operating Systems Design and Implementation (OSDI), 2016. [cited by applicant]
Asharov, G. et al., “More efficient oblivious transfer and extensions for faster secure computation.” In CCS, 2013. [cited by applicant]
Beaver, D. “Correlated pseudorandomness and the complexity of private computations.” In STOC, 1996. [cited by applicant]
Bellare, M. et al., “Efficient garbling from a fixed-key blockcipher.” In IEEE S&P, 2013. [cited by applicant]
Brakerski, Z. et al., “(Leveled) fully homomorphic encryption without bootstrapping.” ACM Transactions on Computation Theory (TOCT), 6(3):13, 2014. [cited by applicant]
Brakerski, Z. et al., “Efficient fully homomorphic encryption from (standard) 1we.” SIAM journal on Computing, 43(2):831-871, 2014. [cited by applicant]
Chandran, N. et al., “EzPC: Programmable, efficient, and scalable secure two-party computation.” IACR Cryptology ePrint Archive, Nov. 9, 2017, 2017. [cited by applicant]
Courbariaux, M. et al., “Binarized neural networks: Training deep neural networks with weights and activations constrained to+ 1 or−1.” arXiv preprint arXiv:1602.02830, 2016. [cited by applicant]
Dowlin, N. et al., “CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy.” In ICML, 2016. [cited by applicant]
Fredrikson, M. et al., “Model inversion attacks that exploit confidence information and basic countermeasures.” In CCS. ACM, 2015. [cited by applicant]
Goldreich, O. et al., “How to play any mental game.” In Proceedings of the nineteenth annual ACM symposium on Theory of computing, pp. 218-229. ACM, 1987. [cited by applicant]
Huang, Y. et al., “Amortizing garbled circuits.” In International Cryptology Conference, pp. 458-475. Springer, 2014. [cited by applicant]
Huang, Y. et al., “Efficient secure two-party computation using symmetric cut-and-choose.” In Advances in Cryptology—Crypto 2013, pp. 18-35. Springer, 2013. [cited by applicant]
Ishai, Y. et al., “Extending oblivious transfers efficiently.” In Annual International Cryptology Conference, pp. 145-161. Springer, 2003. [cited by applicant]
Kingma, D. P. et al., “Adam: A method for stochastic optimization.” arXiv preprint arXiv:1412.6980, 2014. [cited by applicant]
Kolesnikov, V. et al., “Duplo: unifying cut-and-choose for garbled circuits.” In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 3-20. ACM, 2017. [cited by applicant]
Kolesnikov, V. et al., “Improved garbled circuit: Free XOR gates and applications.” In ICALP, 2008. [cited by applicant]
Lindell, Y. “Fast cut-and-choose-based protocols for malicious and covert adversaries.” Journal of Cryptology, 29(2):456-490, 2016. [cited by applicant]
Lindell, Y. et al., “A proof of security of Yao's protocol for two-party computation.” Journal of Cryptology, 22(2):161-188, 2009. [cited by applicant]
Lindell, Y. et al., “Secure two-party computation via cut-and-choose oblivious transfer.” Journal of Cryptology, 25(4):680-722, 2012. [cited by applicant]
Liu, J. et al., “Oblivious neural network predictions via MiniONN transformations.” In CCS, 2017. [cited by applicant]
Mohassel, P. et al., “SecureML: A system for scalable privacy-preserving machine learning.” In IEEE S&P, 2017. [cited by applicant]
Molchanov et al., “Pruning Convolutional Neural Networks for Resource Efficient Transfer Learning.” In Cornell University Library/Computer Science/Computer Vision and Pattern Recognition. Nov. 19, 2016. [cited by applicant]
Naor, M. et al., “Privacy preserving auctions and mechanism design.” In ACM Conference on Electronic Commerce, 1999. [cited by applicant]
Paillier, P. “Public-key cryptosystems based on composite degree residuosity classes.” In International Conference on the Theory and Applications of Cryptographic Techniques, pp. 223-238. Springer, 1999. [cited by applicant]
Rabin, M. O. “How to exchange secrets with oblivious transfer.” IACR Cryptology ePrint Archive, 2005:187, 2005. [cited by applicant]
Rastegari et al., “XNOR-Net: ImageNet Classification Using Binary Convolutional Neural Networks.” In Cornell University Library/Computer Science/Computer Vision and Pattern Recognition. Mar. 16, 2016. [cited by applicant]
Riazi, M. S. et al., “Chameleon: A hybrid secure computation framework for machine learning applications.” In ASIACCS'18, 2018. [cited by applicant]
Romero, A. et al., “Fitnets: Hints for thin deep nets.” arXiv preprint arXiv:1412.6550, 2014. [cited by applicant]
Rouhani, B. D. et al., “DeepSecure: Scalable provably-secure deep learning.” DAC, 2018. [cited by applicant]
Shokri, R. et al., “Membership inference attacks against machine learning models.” In S&P. IEEE, 2017. [cited by applicant]
Simonyan, K. et al., “Very deep convolutional networks for large-scale image recognition.” arXiv preprint arXiv:1409.1556, 2014. [cited by applicant]
Songhori, E. M. et al., “TinyGarble: Highly compressed and scalable sequential garbled circuits.” In IEEE S&P, 2015. [cited by applicant]
Szegedy, C. et al., “Going deeper with convolutions.” Cvpr, 2015. [cited by applicant]
Tramer, F. et al., “Stealing machine learning models via prediction APIs.” In USENIX Security, 2016. [cited by applicant]
Yao, A. “How to generate and exchange secrets.” In FOCS, 1986. [cited by applicant]
Zahur, S. et al., “Two halves make a whole.” In Eurocrypt, 2015. [cited by applicant]