Aller au contenu principal
2025 article

SMLaaS: Secure Machine Learning as a Service Ensuring Data and Model Parameter Privacy

1Citations signalées, ce qui n’est pas une note de qualité
1Institutions déclarées
1Pays d’affiliation déclarés

Rattachement africain : in. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

ABSTRACT Attacks against machine learning (ML) models are serious concerns in the case of adapting ML as a Service (MLaaS) for security‐critical applications. Hence, privacy‐preserving ML is an important area of research to protect ML intellectual properties (IPs) like training data, prediction data, and model parameters. Homomorphic encryption (HE) is instrumental in this case, which supports encrypted ML computations, and thus data and model parameter confidentiality can be maintained. However, homomorphic computations are inherently time‐consuming. Hence, few existing HE‐supported ML solutions mainly consider private data public model frameworks, which ensure data privacy but do not include model parameter privacy to avoid a large number of encrypted operations. Significant performance degradation can be alleviated by replacing a huge number of encrypted multiplications with less costly encrypted additions, with this assumption. Thus, the main challenge to allow data as well as model privacy is to realize the intermediate algorithmic steps with suitable encrypted gates in such a way that the design tricks can save/reduce the costly encrypted gate operations, which is non‐trivial. Few other existing isolated encrypted ML implementations mostly incorporate distinct optimizations suitable for a particular model to reduce encrypted computations and, in turn, timing overhead. However, such specific optimizations may be inadequate to meet the requirements of multiple complex models while used together in an ensemble framework as part of encrypted MLaaS. Few models even consider offloading complex operations to the client side, which demands client‐cloud communication and intermediate decryption. Moreover, most of the reported works do not explore encrypted training. Hence, the design of an encrypted ensemble learning framework (EELF) is more challenging and requires a generalized representation of encrypted data. To enable this, we show that specific fully homomorphic encryption (FHE) schemes are suitable compared to previously used somewhat homomorphic schemes, which are limited in terms of homomorphic operations to support costly ML model implementations. We also explore designing the FHE counterpart of various ML models and propose suitable encrypted operators to implement the same. Added to that, our framework ensures both data and model parameter privacy. Starting from encrypted Support Vector Machines (SVM), K‐Nearest Neighbors (KNN), and Logistic Regression (LR), our proposed framework can also include encrypted Neural Network (NN) processing. In addition to this, we explore approximate computing support for encrypted machine learning at the cost of negligible accuracy loss. Our experimental results show that with suitable operator translation to the encrypted domain and data‐bit packing, proposed encrypted ensemble prediction can be completed within 7.98 min without any approximation, 7.1 min with approximation, and further reduced to 14 s with hardware‐software (HW‐SW) co‐design, maintaining encrypted AUC around 0.9 compared to plaintext AUC 0.94.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
SMLaaS: Secure Machine Learning as a Service Ensuring Data and Model Parameter Privacy
Date Crossref
23/05/2025
Éditeur
Wiley
Type
journal-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Les institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Privacy-Preserving Technologies in DataCryptography and Data SecurityCloud Data Security Solutions

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.