Inference and conversion method for encrypted deep neural network model
An inference method for encrypted deep neural network model is executed by a computing device and includes: encoding a message according to a quantization parameter to generate a plaintext, encrypting the plaintext according to a private key to generate a ciphertext, sending the ciphertext to a deep neural network model to generate a ciphertext result, decrypting the ciphertext result according to the private key to generate a plaintext result, and decoding the plaintext result according to the quantization parameter to generate an inference result.
1 . An inference method for encrypted deep neural network model, executing by a first computing device and a second computing device communicatively connected to the first computing device, comprising:
encoding, by the first computing device, a message according to a quantization parameter to generate a plaintext;
encrypting, by the first computing device, the plaintext according to a private key to generate a ciphertext;
sending, by the first computing device, the ciphertext to the second computing device, wherein a deep neural network model running on the second computing device is configured to perform an encrypted inference to generate a ciphertext result;
decrypting, by the first computing device, the ciphertext result according to the private key to generate a plaintext result; and
decoding, by the first computing device, the plaintext result according to the quantization parameter to generate an inference result;
wherein sending, by the first computing device, the ciphertext to the deep neural network model to generate the ciphertext result comprises:
calculating an encrypted inner product result according to the ciphertext and a model weight;
reducing a first modulus of the encrypted inner product result to a second modulus to generate a modulus switch result; and
inputting the modulus switch result into an activation function to generate the ciphertext result;
wherein inputting the modulus switch result into the activation function to generate the ciphertext result comprises:
calculating a first ratio of a message space size of the modulus switch result to the first modulus of the encrypted inner product result;
calculating a second ratio according to the first ratio, the message space size of the modulus switch result, and the quantization parameter; and
executing a function evaluation algorithm according to the second ratio, a lookup table, and the modulus switch result to generate the ciphertext result.
2 . The inference method for encrypted deep neural network model of claim 1 , wherein before encoding the message according to the quantization parameter to generate the plaintext, further comprises:
encoding the message according to a default value of the quantization parameter to generate an encoding result;
calculating an inner product result according to the encoding result and a weight of the deep neural network model; and
generating the quantization parameter according to a message space size of the plaintext and the inner product result.
3 . The inference method for encrypted deep neural network model of claim 1 , wherein calculating the encrypted inner product result according to the ciphertext and the model weight comprises:
calculating a plurality of scalar products according to a plurality of encrypted values contained in the ciphertext and a plurality of scalar values contained in the model weight; and
performing a homomorphic encryption addition according to the plurality of scalar products to generate the encrypted inner product result.
4 . The inference method for encrypted deep neural network model of claim 1 , wherein the lookup table is configured to implement a rectified linear unit, and the second ratio is configured to set a slope of the rectified linear unit.
5 . A conversion method for encrypted deep neural network model comprising:
inputting a training dataset into an integer model to extract a plurality of intermediate computation results from a plurality of layers;
adding a plurality of noise values to a plurality of outputs of the plurality of layers according to a numerical range of the plurality of intermediate computation results;
after the plurality of noise values is added to the plurality of outputs of the plurality of layers of the integer model, retraining the integer model with the training dataset to generate a floating-point fine-tuned model;
performing a model quantization according to the floating-point fine-tuned model to generate an integer fine-tuned model; and
inputting the training dataset into the integer fine-tuned model to extract a plurality of quantization parameters, wherein the plurality of quantization parameters is configured to control a plurality of output values of a plurality of activation functions of the integer fine-tuned model.
6 . The conversion method for encrypted deep neural network model of claim 5 , further comprising:
training a teacher model according to the training dataset before inputting the training dataset into the integer model to extract the plurality of intermediate computation results from the plurality of layers;
performing a knowledge distillation according to the teacher model to generate a student model; and
performing the model quantization according to the student model to generate the integer model before inputting the training dataset into the integer model to extract the plurality of intermediate computation results from the plurality of layers.