IP Library › Granted Patent US 12,634,116
Granted Patent B2
US 12,634,116 · App. 18/409,595 · Granted May 19, 2026

Inference and conversion method for encrypted deep neural network model

Inventors: Yu-Te Ku (Taipei City, TW); Chih-Fan Hsu (Taipei City, TW); Wei-Chao Chen (Taipei City, TW); Feng-Hao Liu (Taipei City, TW); Ming-Ching Chang (Taipei City, TW); Shih-Hao Hung (Taipei City, TW)
Assignees: INVENTEC (PUDONG) TECHNOLOGY CORPORATION; INVENTEC CORPORATION
H04L9/0618G06N3/0495H04L9/008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,116
App. No.
18/409,595
Granted
May 19, 2026
Kind
B2
Abstract

An inference method for encrypted deep neural network model is executed by a computing device and includes: encoding a message according to a quantization parameter to generate a plaintext, encrypting the plaintext according to a private key to generate a ciphertext, sending the ciphertext to a deep neural network model to generate a ciphertext result, decrypting the ciphertext result according to the private key to generate a plaintext result, and decoding the plaintext result according to the quantization parameter to generate an inference result.

Claims (32)

1 . An inference method for encrypted deep neural network model, executing by a first computing device and a second computing device communicatively connected to the first computing device, comprising:

encoding, by the first computing device, a message according to a quantization parameter to generate a plaintext;

encrypting, by the first computing device, the plaintext according to a private key to generate a ciphertext;

sending, by the first computing device, the ciphertext to the second computing device, wherein a deep neural network model running on the second computing device is configured to perform an encrypted inference to generate a ciphertext result;

decrypting, by the first computing device, the ciphertext result according to the private key to generate a plaintext result; and

decoding, by the first computing device, the plaintext result according to the quantization parameter to generate an inference result;

wherein sending, by the first computing device, the ciphertext to the deep neural network model to generate the ciphertext result comprises:

calculating an encrypted inner product result according to the ciphertext and a model weight;

reducing a first modulus of the encrypted inner product result to a second modulus to generate a modulus switch result; and

inputting the modulus switch result into an activation function to generate the ciphertext result;

wherein inputting the modulus switch result into the activation function to generate the ciphertext result comprises:

calculating a first ratio of a message space size of the modulus switch result to the first modulus of the encrypted inner product result;

calculating a second ratio according to the first ratio, the message space size of the modulus switch result, and the quantization parameter; and

executing a function evaluation algorithm according to the second ratio, a lookup table, and the modulus switch result to generate the ciphertext result.

2 . The inference method for encrypted deep neural network model of claim 1 , wherein before encoding the message according to the quantization parameter to generate the plaintext, further comprises:

encoding the message according to a default value of the quantization parameter to generate an encoding result;

calculating an inner product result according to the encoding result and a weight of the deep neural network model; and

generating the quantization parameter according to a message space size of the plaintext and the inner product result.

3 . The inference method for encrypted deep neural network model of claim 1 , wherein calculating the encrypted inner product result according to the ciphertext and the model weight comprises:

calculating a plurality of scalar products according to a plurality of encrypted values contained in the ciphertext and a plurality of scalar values contained in the model weight; and

performing a homomorphic encryption addition according to the plurality of scalar products to generate the encrypted inner product result.

4 . The inference method for encrypted deep neural network model of claim 1 , wherein the lookup table is configured to implement a rectified linear unit, and the second ratio is configured to set a slope of the rectified linear unit.

5 . A conversion method for encrypted deep neural network model comprising:

inputting a training dataset into an integer model to extract a plurality of intermediate computation results from a plurality of layers;

adding a plurality of noise values to a plurality of outputs of the plurality of layers according to a numerical range of the plurality of intermediate computation results;

after the plurality of noise values is added to the plurality of outputs of the plurality of layers of the integer model, retraining the integer model with the training dataset to generate a floating-point fine-tuned model;

performing a model quantization according to the floating-point fine-tuned model to generate an integer fine-tuned model; and

inputting the training dataset into the integer fine-tuned model to extract a plurality of quantization parameters, wherein the plurality of quantization parameters is configured to control a plurality of output values of a plurality of activation functions of the integer fine-tuned model.

6 . The conversion method for encrypted deep neural network model of claim 5 , further comprising:

training a teacher model according to the training dataset before inputting the training dataset into the integer model to extract the plurality of intermediate computation results from the plurality of layers;

performing a knowledge distillation according to the teacher model to generate a student model; and

performing the model quantization according to the student model to generate the integer model before inputting the training dataset into the integer model to extract the plurality of intermediate computation results from the plurality of layers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: KU, YU-TE; HSU, CHIH-FAN; CHEN, WEI-CHAO; LIU, FENG-HAO; CHANG, MING-CHING; HUNG, SHIH-HAO
To: INVENTEC (PUDONG) TECHNOLOGY CORPORATION; INVENTEC CORPORATION
Reel/Frame 066103/0314 →
Priority Claims (1)
CN 202311109960.7 · Aug 30, 2023 · national
Continuity (1)
Related Publication 20250080320A1 · Mar 6, 2025
References Cited (85)
US 10075289B2 · Laine · 2018 [cited by examiner]
US 11188817B2 · Dikici · 2021 [cited by examiner]
US 11243743B2 · Johnson · 2022 [cited by examiner]
US 11410410B2 · Ha · 2022 [cited by examiner]
US 11430124B2 · Li · 2022 [cited by examiner]
US 11468313B1 · Naumov · 2022 [cited by examiner]
US 11475352B2 · Zhang · 2022 [cited by examiner]
US 11481608B2 · Ha · 2022 [cited by examiner]
US 11522671B2 · Hiromasa · 2022 [cited by examiner]
US 12001577B1 · Xiong · 2024 [cited by examiner]
US 12061988B1 · Sather · 2024 [cited by examiner]
US 12106209B1 · Kim · 2024 [cited by examiner]
US 12165290B1 · Cheng · 2024 [cited by examiner]
US 12170718B2 · Micciancio · 2024 [cited by examiner]
US 12238199B2 · Cheng · 2025 [cited by examiner]
US 12307217B1 · Dellinger · 2025 [cited by examiner]
US 12348609B2 · Shin · 2025 [cited by examiner]
US 12399713B2 · Bajic · 2025 [cited by examiner]
US 12406169B2 · Sakr · 2025 [cited by examiner]
US 12443841B2 · Sun · 2025 [cited by examiner]
US 12450490B2 · Kao · 2025 [cited by examiner]
US 12475388B2 · Yu · 2025 [cited by examiner]
US 12499353B1 · Diamant · 2025 [cited by examiner]
US 20170286830A1 · El-Yaniv · 2017 [cited by examiner]
US 20180107451A1 · Harrer · 2018 [cited by examiner]
US 20190188554A1 · Ma · 2019 [cited by examiner]
US 20190311267A1 · Qin · 2019 [cited by examiner]
US 20190318260A1 · Yasutomi · 2019 [cited by examiner]
US 20190363871A1 · Cheon · 2019 [cited by examiner]
US 20200019867A1 · Nandakumar · 2020 [cited by examiner]
US 20200036510A1 · Gomez · 2020 [cited by examiner]
US 20200104636A1 · Halevi · 2020 [cited by examiner]
US 20200202213A1 · Darvish Rouhani · 2020 [cited by examiner]
US 20200252198A1 · Nandakumar · 2020 [cited by examiner]
US 20200264876A1 · Lo · 2020 [cited by examiner]
US 20200302295A1 · Tung · 2020 [cited by examiner]
US 20200358611A1 · Hoang · 2020 [cited by examiner]
US 20200364552A1 · Guo · 2020 [cited by examiner]
US 20210110048A1 · Guo · 2021 [cited by examiner]
US 20210383237A1 · Tan · 2021 [cited by examiner]
US 20220083855A1 · Choi · 2022 [cited by examiner]
US 20220156982A1 · Idelbayev · 2022 [cited by examiner]
US 20220172052A1 · Bunandar · 2022 [cited by examiner]
US 20220245447A1 · Liu · 2022 [cited by examiner]
US 20220300784A1 · Kawabe · 2022 [cited by examiner]
US 20220366223A1 · Fathallah-Shaykh · 2022 [cited by examiner]
US 20230087864A1 · Cheng · 2023 [cited by examiner]
US 20230153632A1 · Solinas · 2023 [cited by examiner]
US 20230237308A1 · Sakr · 2023 [cited by examiner]
US 20230325529A1 · Sav · 2023 [cited by examiner]
US 20230325658A1 · Chen · 2023 [cited by examiner]
US 20230327856A1 · Lu · 2023 [cited by examiner]
US 20230368019A1 · Son · 2023 [cited by examiner]
US 20240062102A1 · Lal · 2024 [cited by examiner]
US 20240070266A1 · Chai · 2024 [cited by examiner]
US 20240126896A1 · Elfadel · 2024 [cited by examiner]
US 20240195618A1 · Paul · 2024 [cited by examiner]
US 20240211763A1 · Trusov · 2024 [cited by examiner]
US 20240256850A1 · Soceanu · 2024 [cited by examiner]
US 20240259181A1 · Chevallier-Mames · 2024 [cited by examiner]
US 20240273218A1 · No · 2024 [cited by examiner]
US 20240305785A1 · Van Rozendaal · 2024 [cited by examiner]
US 20240347043A1 · Qiu · 2024 [cited by examiner]
US 20250005200A1 · Javaheripi · 2025 [cited by examiner]
US 20250029489A1 · Cao · 2025 [cited by examiner]
US 20250030536A1 · Soriente · 2025 [cited by examiner]
US 20250045589A1 · Rengasamy · 2025 [cited by examiner]
US 20250055671A1 · Soriente · 2025 [cited by examiner]
US 20250077861A1 · Shen · 2025 [cited by examiner]
US 20250080768A1 · Filippov · 2025 [cited by examiner]
US 20250131339A1 · Anghel · 2025 [cited by examiner]
US 20250158802A1 · Lam · 2025 [cited by examiner]
US 20250167979A1 · Nanjo · 2025 [cited by examiner]
US 20250184116A1 · Moon · 2025 [cited by examiner]
US 20250200348A1 · Lin · 2025 [cited by examiner]
US 20250217654A1 · Jin · 2025 [cited by examiner]
US 20250272551A1 · Knoops · 2025 [cited by examiner]
Al Badawi, Ahmad, et al. “Privft: Private and fast text classification with homomorphic encryption.” IEEE Access 8 (Dec. 2020) (Year: 2020). [cited by examiner]
Nandakumar, Karthik, et al. “Towards deep neural network training on encrypted data.” Proceedings of the IEEE/CVF conference on computer vision and pattern recognition workshops. 2019. (Year: 2019). [cited by examiner]
Liu, Zeyu, Daniele Micciancio, and Yuriy Polyakov. “Large-precision homomorphic sign evaluation using FHEW/TFHE bootstrapping.” International Conference on the Theory and Application of Cryptology and Information Securi… [cited by examiner]
Legiest, Wouter, et al. “Neural network quantisation for faster homomorphic encryption.” 2023 IEEE 29th International Symposium on On-Line Testing and Robust System Design (IOLTS). IEEE, 2023 (Year: 2023). [cited by examiner]
Tayaranian, Mohammadreza, et al. “Towards fine-tuning pre-trained language models with integer forward and backward propagation.” arXiv preprint arXiv:2209.09815 (Feb. 2023). (Year: 2023). [cited by examiner]
Lou, Qian, and Lei Jiang. “She: A fast and accurate deep neural network for encrypted data.” Advances in neural information processing systems 32 (2019). (Year: 2019). [cited by examiner]
Chen, Hao, et al. “Efficient multi-key homomorphic encryption with packed ciphertexts with application to oblivious neural network inference.” Proceedings of the 2019 ACM SIGSAC conference on computer and communications… [cited by examiner]
Stoian, A., Frery, J., Bredehoft, R., Montero, L., Kherfallah, C., Chevallier-Mames, B. Deep Neural Networks for Encrypted Inference with TFHE. CSCML 2023. Lecture Notes in Computer Science, vol. 13914. Springer, Cham. … [cited by examiner]