METHOD AND SYSTEM FOR SECURELY STORING DATA FOR USE WITH ARTIFICIAL NEURAL NETWORKS
Systems and methods are disclosed for encrypting data such that artificial neural networks may be trained directly on the encrypted data and may be performed directly on the encrypted data. For use with artificial neural networks, original feature sets of input vectors are programmatically subjected to a sequence of encryption steps: a method for fixed padding of the feature set with a randomly chosen set of values that are fixed across the feature set (adding a fixed number of dimensions to each input vector); a method for fixed perturbation of the data by perturbing of each element in the feature set (the value stored in each dimension of an input vector) such that all examples of the feature set are perturbed in the same way; a method that applies a fixed shuffle of the data elements in the feature set; and a method for applying convolutions (filters) and pooling (downsampling) to the shuffled data such that informational structure is preserved.
1 . A method for using modified data with a neural network, said method comprising:
determining an algorithm to modify a plurality of examples, where each example of the plurality of examples includes an array of values, and where each example is a training example or a test example;
training the neural network by:
obtaining a plurality of training examples,
modifying each training example of said plurality of training examples according to said algorithm to form a plurality of modified training examples, and
forming a trained neural network by training a neural network with said plurality of modified training examples; and
forming predictions using the trained neural network by:
accepting a test example,
modifying the test example according to said algorithm to form a modified test example, and
forming a prediction from the output of the trained neural network by providing said trained neural network with the modified test example as input, such that the same algorithm modifies each training example and the test example.
2 . The method of claim 1 , further comprising:
prior to forming predictions using the trained neural network, encrypting said algorithm to form an encrypted algorithm, and
where said forming predictions using the trained neural network further includes accepting said encrypted algorithm and decrypting said encrypted algorithm.
3 . The method of claim 1 ,
where said algorithm includes a first pad of values,
where said modifying each training example includes increasing the size of each training example by appending the first pad of values to each training example, and
where said modifying the test example includes increasing the size of the test example by appending the first pad of values to the test example,
such that the same pad of values is applied to each training example and the test example.
4 . The method of claim 1 ,
where said algorithm includes a plurality of perturbation functions, where each perturbation function of the plurality of perturbation functions corresponds to a position in the array of each training example and to a position in the array of the test example,
where said modifying each training example includes is the mathematical equivalent of applying each perturbation function to the value in the corresponding position in the training example, and
where said modifying the test example is the mathematical equivalent of applying each perturbation function to the value in the corresponding position in the test example,
such that the same perturbation function is applied to corresponding array values of each training example and of the test example.
5 . The method of claim 1 ,
where said algorithm includes an index shuffling,
where said modifying each training example includes applying the index shuffling to the training example, and
where said modifying the test example includes applying the index shuffling to the test example,
such that the same index shuffling is applied to each training example and to the test example.
6 . The method of claim 1 , where said algorithm is the mathematical equivalent to two or more modifications performed sequentially, where the two or more modifications include two or more of:
a) one or more paddings each including a pad of values, where said modifying each training example and said modifying the test example includes appending the pad of values to each example or previously modified example;
b) one or more perturbations each including an array of perturbation functions, where each perturbation function corresponds to a position in the array of the training example and to a position in the array of the test example, where said modifying each training example and modifying the test example applies each perturbation function to the value in the corresponding position in each example or previously modified example; and
c) one or more index shuffles each including an index shuffling for each index shuffle, where said modifying each training example and said modifying the test example includes applying the index shuffling to each example or previously modified example.
7 . The method of claim 1 , where said forming the trained neural network includes using a mathematical representation of the modifying of each training example.
8 . The method of claim 1 , where said steps of said training the neural network are performed by two or more parties.
9 . The method of claim 1 , where said steps of said forming predictions using the trained neural network are performed by two or more parties.
10 . The method of claim 1 , further including storing, in a ledger, the occurrence of said modifying a test example or the occurrence of said providing said trained neural network with a modified test example to form a prediction.
11 . A system for using modified data with a neural network, said system including networked memory and processors programmed to:
determine an algorithm to modify a plurality of examples, where each example of the plurality of examples includes an array of values, and where each example is a training example or a test example;
train the neural network by the processors programmed to:
obtain a plurality of training examples,
modify each training example of said plurality of training examples according to said algorithm to form a plurality of modified training examples, and
form a trained neural network by training a neural network with said plurality of modified training examples; and
form predictions using the trained neural network by the processors programmed to:
accept a test example,
modify the test example according to said algorithm to form a modified test example, and
form a prediction from the output of the trained neural network by providing said trained neural network with the modified test example as input,
such that the same algorithm is used to modify each training example and the test example.
12 . The system of claim 11 , where said processors are further programmed to prior to said form predictions, encrypt said algorithm to form an encrypted algorithm, and
where said form predictions further includes accept said encrypted algorithm and where said processors are further programmed to decrypt said encrypted algorithm.
13 . The system of claim 11 , where said algorithm is the mathematical equivalent to one or more modifications performed sequentially, where the one or more modifications include one or more of:
a) one or more paddings each including a pad of values, where said modify each training example and said modify the test example includes said processors further programmed to append the pad of values to each example or previously modified example;
b) one or more perturbations each including an array of perturbation functions, where each perturbation function corresponds to a position in the array of the training example and to a position in the array of the test example, where said modify each training example and said modify the test example includes said processors further programmed to apply each perturbation function to the value in the corresponding position in each example or previously modified example; and
c) one or more index shuffles each including an index shuffling for each index shuffle, where said modify each training example and said modify the test example includes said processors further programmed to apply the index shuffling to each example or previously modified example.
14 . The system of claim 11 , where said form the trained neural network includes said processors further programmed to use a mathematical representation of the modifying of each training example.
15 . The system of claim 11 , where said processors are further programmed to store, in a ledger, the occurrence of said modify a test example or the occurrence of said provide said trained neural network with a modified test example to form a prediction.
16 . A method for using modified data with a neural network, where the neural network is trained using a plurality of modified training examples, where each training example of the plurality of training examples is modified using an algorithm, said method comprising:
accepting a test example,
accepting the algorithm used for modifying each training example of the plurality of training examples,
modifying the test example using the algorithm, and
forming a prediction from the output of the trained neural network by providing said trained neural network with the modified test example as input,
such that the same algorithm is used to modify each training example and the test example.
17 . The method of claim 16 , where the algorithm is an encrypted algorithm, and where said accepting the algorithm includes accepting the encrypted algorithm and decrypting said encrypted algorithm.
18 . The method of claim 16 ,
where the algorithm includes a first pad of values, and
where said modifying the test example includes increasing the size of the test example by appending the first pad of values to the test example,
such that the same pad of values is applied to each training example and the test example.
19 . The method of claim 16 ,
where the algorithm includes a plurality of perturbation functions, where each perturbation function of the plurality of perturbation functions corresponds to a position in the array of the test example, and
where said modifying the test example is the mathematical equivalent of applying each perturbation function to the value in the corresponding position in the test example,
such that the same perturbation function is applied to corresponding array values of each training example and of the test example.
20 . The method of claim 16 ,
where the algorithm includes an index shuffling, and
where said modifying the test example includes applying the index shuffling to the test example,
such that the same index shuffling is applied to each training example and to the test example.
21 . The method of claim 16 , where said algorithm is the mathematical equivalent to two or more modifications performed sequentially, where the two or more modifications include two or more of:
a) one or more paddings each including a pad of values, where said modifying the test example includes appending the pad of values to the test example or to a previously modified test example,
b) one or more perturbations each including an array of perturbation functions, where each perturbation function corresponds to a position in the array of the test example, where said modifying applies each perturbation function to the value in the corresponding position in the test example or to a previously modified test example, and
c) one or more index shuffles each including an index shuffling, where said modifying the test example includes applying the index shuffling to the test example or to a previously modified test example.
22 . The method of claim 16 , where said forming the trained neural network includes using a mathematical representation of the modifying of each training example.
23 . The method of claim 16 , further including recording, in a ledger, the occurrence of said modifying each test example or the occurrence of said providing said trained neural network with one or more modified test examples.
24 . A system for using modified data with a neural network, where the neural network is trained using a plurality of modified training examples, where each training example of the plurality of training examples is modified using an algorithm, said system including networked memory and processors programmed to:
accept a test example,
accept the algorithm used to modify each training example of the plurality of training examples,
modify the test example using the algorithm, and
form a prediction from the output of the trained neural network by providing said trained neural network with the modified test example as input,
such that the same algorithm is used to modify each training example and the test example.
25 . The system of claim 24 , where the algorithm is an encrypted algorithm, and where said processor is further programmed to accept the algorithm by decrypting said encrypted algorithm.
26 . The system of claim 24 , where said algorithm is the mathematical equivalent to one or more modifications performed sequentially, where the one or more modifications include one or more of:
a) one or more paddings each including a pad of values, where said modify the test example includes said processors further programmed to append the pad of values to each test example or previously modified test example;
b) one or more perturbations each including an array of perturbation functions, where each perturbation function corresponds to a position in the array of the test example, where said modify the test example includes said processors further programmed to apply each perturbation function to the value in the corresponding position in each test example or previously modified test example; and
c) one or more index shuffles each including an index shuffling for each index shuffle, where said modify the test example includes said processors further programmed to apply the index shuffling to each test example or previously modified test example.
27 . The system of claim 24 , where said form the trained neural network includes using a mathematical representation of the modifying of each training example.
28 . The system of claim 24 , where said processors are further programmed to store, in a ledger, the occurrence of said modify a test example or the occurrence of said provide said trained neural network with a modified test example to form a prediction.