OCCLUMENCY: Privacy-preserving Remote Deep-learning Inference Using SGX

被引:0
|
作者
Lee, Taegyeong [1 ,4 ]
Lin, Zhiqi [2 ,4 ]
Pushp, Saumay [1 ]
Li, Caihua [3 ,4 ]
Liu, Yunxin [4 ]
Lee, Youngki [5 ]
Xu, Fengyuan [4 ,6 ]
Xu, Chenren [4 ,7 ]
Zhang, Lintao [4 ]
Song, Junehwa [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[2] Univ Sci & Technol China, Hefei, Peoples R China
[3] Rice Univ, Houston, TX USA
[4] Microsoft Res, Redmond, WA USA
[5] Seoul Natl Univ, Seoul, South Korea
[6] Nanjing Univ, Natl Key Lab Novel Software Technol, Nanjing, Peoples R China
[7] Peking Univ, Beijing, Peoples R China
基金
新加坡国家研究基金会;
关键词
Mobile deep learning; privacy; trusted execution environment; cloud offloading;
D O I
10.1145/3300061.3345447
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Deep-learning (DL) is receiving huge attention as enabling techniques for emerging mobile and IoT applications. It is a common practice to conduct DNN model-based inference using cloud services due to their high computation and memory cost. However, such a cloud-offloaded inference raises serious privacy concerns. Malicious external attackers or untrustworthy internal administrators of clouds may leak highly sensitive and private data such as image, voice and textual data. In this paper, we propose OCCLUMENCY, a novel cloud-driven solution designed to protect user privacy without compromising the benefit of using powerful cloud resources. OCCLUMENCY leverages secure SGX enclave to preserve the confidentiality and the integrity of user data throughout the entire DL inference process. DL inference in SGX enclave, however, impose a severe performance degradation due to limited physical memory space and inefficient page swapping. We designed a suite of novel techniques to accelerate DL inference inside the enclave with a limited memory size and implemented Occlumency based on Caffe. Our experiment with various DNN models shows that Occlumency improves inference speed by 3.6x compared to the baseline DL inference in SGX and achieves a secure DL inference within 72% of latency overhead compared to inference in the native environment.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Privacy-Preserving Deep Learning and Inference
    Riazi, M. Sadegh
    Koushanfar, Farinaz
    [J]. 2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [2] Privacy-preserving Deep-learning Models for Fingerprint Data Using Differential Privacy
    Mohammadi, Maryam
    Sabry, Farida
    Labda, Wadha
    Malluhi, Qutaibah
    [J]. PROCEEDINGS OF THE 9TH ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, IWSPA 2023, 2023, : 45 - 53
  • [3] EPIDL: Towards efficient and privacy-preserving inference in deep learning
    Nie, Chenfei
    Zhou, Zhipeng
    Dong, Mianxiong
    Ota, Kaoru
    Li, Qiang
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (14):
  • [4] Privacy-Preserving Deep Learning
    Shokri, Reza
    Shmatikov, Vitaly
    [J]. 2015 53RD ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2015, : 909 - 910
  • [5] Privacy-Preserving Deep Learning
    Shokri, Reza
    Shmatikov, Vitaly
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1310 - 1321
  • [6] Privacy-preserving and verifiable deep learning inference based on secret sharing
    Duan, Jia
    Zhou, Jiantao
    Li, Yuanman
    Huang, Caishi
    [J]. NEUROCOMPUTING, 2022, 483 : 221 - 234
  • [7] Privacy-Preserving Neural Network Inference Framework via Homomorphic Encryption and SGX
    Xiao, Huizi
    Zhang, Qingyang
    Pei, Qingqi
    Shi, Weisong
    [J]. 2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 751 - 761
  • [8] A Secure, Privacy-Preserving IoT Middleware Using Intel SGX
    Gremaud, Pascal
    Durand, Arnaud
    Pasquier, Jacques
    [J]. IOT'17: PROCEEDINGS OF THE SEVENTH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS, 2017, : 165 - 166
  • [9] Privacy-Preserving IoT Cloud Data Processing Using SGX
    Gremaud, Pascal
    Durand, Arnaud
    Pasquier, Jacques
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS ( IOT 2019), 2019,
  • [10] ReDCrypt: Real-Time Privacy-Preserving Deep Learning Inference in Clouds Using FPGAs
    Rouhani, Bita Darvish
    Hussain, Siam Umar
    Lauter, Kristin
    Koushanfar, Farinaz
    [J]. ACM TRANSACTIONS ON RECONFIGURABLE TECHNOLOGY AND SYSTEMS, 2018, 11 (03)