Large model privacy protection reasoning method and system based on secure multi-party computing
By adopting secure multi-party computing technology in the large model inference system, using homomorphic encryption and vector dazed linear evaluation and other technologies, an efficient and secure inference protocol was designed, which solved the problems of privacy leakage and high overhead in the large model inference system, and realized data privacy protection and efficient and accurate inference process.
Patent Information
- Application Number
- CN202510016707.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-06
AI Technical Summary
The current large-model inference system has serious privacy leakage problems. Users and model owners face the risk of data leakage during the inference process, and the communication overhead and calculation overhead are high when directly using secure multi-party computing technology.
Using a technical solution based on secure multi-party computing, using cryptographic techniques such as homomorphic encryption and vector blur linear evaluation, an efficient and secure inference protocol is designed, and privacy protection calculations are carried out for each operation layer in the big model through secret sharing and function calculation protocols.
It realizes data privacy protection for clients and model providers, reduces communication and computing overhead in the inference process, ensures semi-honest security, and prevents data leakage.
Smart Images

Figure CN119995821A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the intersection of information security and computer application technology, and in particular, relates to a privacy-preserving reasoning method and system for large models based on secure multi-party computing. Specifically, secure multi-party computing technologies such as homomorphic encryption (HE) and vector oblivious linear evaluation (VOLE) are used to achieve data privacy protection and efficient and accurate collaborative reasoning for clients and model providers. Background Art
[0002] Entering the 21st century, with the rapid development of technologies such as the Internet, cloud computing, big data, and artificial intelligence, the entire society is becoming more and more digital, networked, and intelligent. The big model reasoning service, which is increasingly attracting attention from the industry and academia, is more able to meet the needs of today's social development with its digital, networked, and intelligent features. Today, big model reasoning has very good application prospects in the fields of military, finance, the Internet of Things, cloud computing, artificial intelligence, communications, insurance, and medical care.
[0003] Models based on the Transformer architecture have demonstrated powerful computing capabilities when using the attention mechanism for representation, and have therefore achieved great success in both natural language processing (NLP) and computer vision (CV). For example, GPT and the proposed BERT model in NLP, ViT and Swin-Transformer models in CV, have achieved leading performance levels in tasks in various fields. In particular, the ChatGPT model's outstanding emergence capabilities in text translation, content generation, and knowledge question and answer have set off a wave of large-model online reasoning services.
[0004] However, the current large model reasoning system has a serious privacy leakage problem. On the user side, the client needs to provide its own privacy input to the model owner and may damage its own interests; on the model owner side, various attacks launched by malicious clients may cause the model weight parameters trained by the client side with a lot of computing resources and data to be leaked to malicious clients. One way to solve this problem is to use secure multi-party computing (MPC) and homomorphic encryption (HE) to protect the confidentiality of user data and model parameters during the reasoning service. However, the communication overhead when directly using MPC to evaluate a large number of nonlinear layers in the model is very expensive, and the computational overhead of HE in this regard is also very high. Therefore, how to combine multiple cryptographic primitives to design an efficient and secure reasoning protocol for large Transformer models is the key to the present invention. Summary of the invention
[0005] In response to the above problems, the present invention provides a large-model privacy-preserving reasoning method and system based on secure multi-party computing.
[0006] The technical solution adopted by the present invention is as follows:
[0007] A privacy-preserving reasoning method for a large model based on secure multi-party computing includes the following steps:
[0008] Obtain the clue words required for reasoning input by the client in the form of secret sharing;
[0009] Obtain the large model weight parameters input by the server in the form of secret sharing;
[0010] Obtain the public large model network structure and perform privacy-preserving calculations and model reasoning on each operation layer in the large model. The server and client obtain the shared values of the reasoning results respectively.
[0011] The server sends the shared value of the inference result to the client, and the client reconstructs the inference result based on the complete shared value.
[0012] Furthermore, the client can only obtain the model inference results but not the model parameter information, and the server cannot obtain the client's private prompt words and model inference results.
[0013] Furthermore, the large model is based on the Transformer architecture; the privacy protection calculation is performed on each operation layer in the large model, including:
[0014] Linear layer operations: All linear layer operations are reduced to matrix multiplications, and the matrix-secure multiplication protocol is run with the client and server's secret shares as input. And get the output of the current linear layer;
[0015] Non-linear layer operations: Non-linear operations include Softmax, GeLU, and LayerNorm, which are shared by the client and server using addition. <x>As input, call the function calculation protocol and output the addition share <y>=P Func ( <x>), where Func∈(Softmax,GeLU,LayerNorm); the function calculation protocol includes the secure calculation protocol Π of Softmax. Softmax 、LayerNorm's secure computing protocol Π LayerNorm and GeLU's secure computing protocol Π GeLU .
[0016] A large-model privacy-preserving reasoning system based on secure multi-party computing, comprising:
[0017] An input module is used to obtain the prompt words required for reasoning input by the client in the form of secret sharing, and to obtain the weight parameters of the large model and the public network structure of the large model input by the server in the form of secret sharing;
[0018] The privacy-preserving computing and reasoning module is used to perform privacy-preserving computing and model reasoning on each operation layer in the large model. The server and client obtain the shared value of the reasoning result respectively.
[0019] The output module is used for the server to send the shared value of the inference result to the client, and the client reconstructs the inference result based on the complete shared value.
[0020] The beneficial effects of the present invention are as follows:
[0021] Transformer-based large models (LLMs) have achieved great success in various tasks in the fields of natural language processing and computer vision. At the same time, secure multi-party computing ensures that the data privacy of users and servers in model reasoning service scenarios can be protected. However, existing solutions show high latency and high communication overhead when facing LLMs reasoning, which limits the further implementation of large model privacy protection reasoning services. The present invention uses cryptographic techniques such as homomorphic encryption, vector oblivious linear evaluation, and piecewise polynomial optimal approximation to construct a secure reasoning framework for large Transformer models. The framework can perform fast and accurate collaborative reasoning of large models and provide semi-honest security for clients and model owners, that is, both parties must accurately abide by the protocol and their privacy will not be leaked. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a functional description diagram of the underlying protocol called by the privacy protection reasoning system of the present invention.
[0023] Figure 2 This is the architecture diagram of the Transformer privacy protection reasoning system of the present invention.
[0024] Figure 3 Example diagram for encoding mapping and ciphertext compression. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0026] This paper uses cryptographic techniques such as vector oblivious linear evaluation, homomorphic encryption and secret sharing, and the underlying sub-protocols with excellent performance in previous work to build a large model privacy protection reasoning framework. Before introducing these technologies, we first explain the symbols in a unified way.
[0027] 1. Explanation of symbols
[0028] Represents from the set Sample r uniformly at random from the given vector. 1{x} returns 1 if x is true, and 0 otherwise. Where L = 2 l And, is the bit width. [N] represents the set {0, 1, ..., N-1}, where Respectively represent floor, ceiling and rounding. x>>f means arithmetic right shift of x by f bits. Column vectors and matrices are represented by lowercase bold letters. and uppercase bold letters express.
[0029] Polynomial indicates that, and Representing polynomials The jth item (i.e. X j ). For N (usually a power of 2) and make Represents a polynomial quotient ring Where X represents the polynomial variable. Given two polynomials Due to X N ≡-1mod(X N +1), so the polynomial product The coefficients can be expressed as follows:
[0030]
[0031] 2. Secret Sharing
[0032] The present invention uses a two-party addition secret sharing scheme: for the value It is split into two random shares Make When L = 2, Arithmetic sharing on <x> L It becomes a Boolean share and is denoted as <x> B This scheme can perfectly hide x, and local operations of each party can obtain the addition sharing of linear operations.
[0033] 3. Vector Perplexity Linear Evaluation
[0034] The two parties do not need any input, by calling the protocol Π VOLE So that P0 (server) gets and P1 (client) gets the scalar and and in The number domain is n-dimensional vector space, In order to make the VOLE protocol work in the ring Here we use the protocol instance proposed by Baum et al. and call it in a black box manner.
[0035] 4. Additive Homomorphic Encryption
[0036] Additive homomorphic encryption schemes can perform arbitrary linear homomorphic operations on ciphertexts. That is, given the ciphertext of message m, the ciphertext of L(m) can be calculated without decryption, where L is a linear function. The present invention adopts the BFV (Brakerski-Fan-Vercauteren) scheme and uses homomorphic automorphism (HA) technology to compress ciphertexts. The specific scheme consists of public parameters pp = {N, σ, q, p} and the following operations:
[0037] 1) Key generation: security parameter is 1 λ , the private key is The public key is Among them, the polynomial Sampling from ciphertext space Polynomial Polynomial The coefficients are uniformly randomly sampled from a discrete Gaussian distribution with standard deviation σ
[0038] 2) Plaintext encryption: given a plaintext message The ciphertext is RLWE represents the encryption of plaintext based on the lattice problem. The coefficients of the sampled self-distribution The coefficient of
[0039] 3) Ciphertext decryption: Given RLWE ciphertext Decrypted using the private key sk
[0040] 4) Linear operation: Suppose two plaintext polynomials The RLWE ciphertexts are CT0 and CT1 (the corresponding private keys are also sk), and there are plaintext polynomials Then the RLWE ciphertext Decrypted into in represents the homomorphic multiplication of ciphertext and plaintext, Represents homomorphic addition between ciphertexts.
[0041] 5) Homomorphic automorphism: Given a plaintext message RLWE ciphertext and odd number o≤2N-1, then the operation Decrypted to Auto means performing homomorphic automorphism operations on the ciphertext.
[0042] 5. Sub-protocols in the prior art
[0043] The secure calculation of nonlinear functions in the present invention mainly uses the underlying protocol in the prior art, such as the multiplexer protocol Π MUX , Security Comparison Protocol Π LT , Maximum value protocol Π max , truncation protocol Reciprocal Square Root Protocol H rSqrt , Multiplication Protocol and the cross-term multiplication protocol Π CT .exist Figure 1 The functional description of these protocols is given in , and the IKNP (Ishai-Kilian-Nissim-Petrank) type OT called by these protocols is replaced by VOLE type OT. OT stands for Oblivious Transfer.
[0044] The large-model privacy-preserving reasoning method based on secure multi-party computing in the present invention is described in detail below.
[0045] 1. Transformer model structure and reasoning scenarios
[0046] The GPT model only has a decoding layer, and the BERT model is a decoder-encoder structure. The decoder and encoder structures are roughly similar, so the present invention designs a protocol for the sub-layer in the encoder. Figure 2 As shown on the right side of the figure, the Transformer layer consists of sub-layers such as multi-head self-attention mechanism, feedforward network and LayerNorm (layer regularization), which also includes input embedding and residual connection operations.
[0047] Multi-head self-attention (fMHA): The multi-head self-attention mechanism is implemented by parallelizing a single attention layer. Before calculating the attention layer, the input token needs to be Perform linear projection to obtain Then the expression of the attention layer is:
[0048]
[0049] in, are query, key, and value matrices respectively, d is the public feature dimension, is the client's private input, The private weight of the model owner.
[0050] Feedforward Network (FFN): FFN consists of two linear layers and a GeLU activation layer, and the specific expression is:
[0051]
[0052] The server holds private parameters Client holds private input
[0053] Layer regularization: For the vector held by the client First calculate the mean of its components and variance The model owner holds private hyperparameters (γ, β), so the expression of layer regularization is:
[0054]
[0055] In addition, input embedding is also needed to transform the client's private input into a continuous feature vector representation, namely in The private weight held by the server.
[0056] 2. Building a privacy-preserving inference solution for large Transformer models
[0057] like Figure 2 As shown in the figure, the present invention names the proposed large-scale Transformer privacy-preserving reasoning framework CryptFormer. The reasoning framework consists of 4 sets of protocols: 1 set of matrix secure multiplication protocols And three sets of nonlinear layer calculation protocols (Π GeLU , Π Softmax , Π LayerNorm ). The specific structure of these protocols is as follows:
[0058] (1) Matrix secure multiplication protocol:
[0059] In order to use homomorphic encryption and its ciphertext compression technology to design a matrix multiplication protocol with low communication volume, we first need to construct the following two natural mapping functions:
[0060] Make
[0061]
[0062] and and The coefficients at other positions are all 0, so the matrix product The product of polynomials To give, that is, for i∈[m], j∈[k], there is a mapping Make exist Figure 3 A simple example is given in to illustrate these two mappings. It can be seen that the resulting polynomial contains a large number of coefficients that are irrelevant to the matrix multiplication result. Therefore, in order to eliminate the redundant protocol communication volume caused by these irrelevant coefficients, the present invention uses homomorphic automorphism technology to eliminate them, which is reflected in Figure 3 The compressed polynomial Since the direct use of homomorphic automorphism technology can only eliminate those coefficients that are not in the multiple position of 2r (r is a positive integer), the interval of the required coefficients in the final polynomial product result (i.e., n) must be a power of 2. However, this can be satisfied by the preprocessing step of the input matrix in the Strassen matrix product algorithm. Therefore, a secure matrix multiplication protocol (Algorithm 1) for two small square matrices (size is a power of 2) can be designed as a recursive export protocol for the general large matrix multiplication protocol (Algorithm 2). Algorithm 1 and Algorithm 2 are shown in Tables 1 and 2, where P0 represents the server and P1 represents the client.
[0063] Table 1
[0064]
[0065] Table 2
[0066]
[0067] (2) Softmax secure computation protocol:
[0068] The core operation in the attention layer is the Softrmax function. The Softrmax function expression is:
[0069]
[0070] The key lies in the efficient and safe calculation of negative exponents, for which a fast approximation formula for negative exponents and range clipping techniques are used:
[0071]
[0072] To determine the range of x, the comparison protocol Π can be used LT .for Using Π max Divide by 2 t The calculation can be done by truncation protocol Finally, we can call the t-squared protocol Π square To calculate the 2t power, we can then give the secure Softmax protocol in Algorithm 3, as shown in Table 3.
[0073] Table 3
[0074]
[0075] (3) LayerNorm’s secure computing protocol:
[0076] For vector The expression of the LayerNorm function is in And γ, β are the hyperparameters obtained by the model owner through early training. It can be seen that LayerNorm requires square, multiplication and reciprocal square root operations. For MPC, the most challenging operation is Because the computational costs of square root and reciprocal square root are similar, and the cost of division is significantly greater than the cost of multiplication, the reciprocal square root protocol Π can be used rsqrt and OT-based multiplication protocol To calculate σ -1 / 2 ·(x[i]-μ). The complete computational protocol Π LayerNorm As shown in Algorithm 4, see Table 4.
[0077] Table 4
[0078]
[0079] (4) Secure computation protocol of GeLU function:
[0080] The original expression of the GeLU function is in Considering the asymptotic properties of the GeLU function on both sides of the x-axis and the non-monotonicity of the intermediate interval, the piecewise polynomial optimal approximation of GeLU in the function space is performed, and its specific expression is:
[0081]
[0082] in The expression is:
[0083]
[0084] The error of the best square approximation above is Then we can construct the secure GeLU protocol Π as shown in Algorithm 5 GeLU , see Table 5.
[0085] Table 5
[0086]
[0087] The privacy-preserving reasoning framework of the large Transformer model of the present invention is based on a variety of efficient and secure multi-party computing tools such as homomorphic encryption and vector perplexity linear evaluation to achieve data privacy protection for clients and model providers and efficient and accurate two-party collaborative reasoning. Figure 2 , introduces the specific implementation of the framework:
[0088] 1) Both the client and the model owner (i.e., the server) first obtain the public parameters of the cryptographic primitives required by the framework;
[0089] 2) The client inputs the private input it needs to reason about into the privacy-preserving reasoning system CryptFormer in the form of secret sharing;
[0090] 3) The model owner makes the network structure of his large Transformer model public and inputs the model weight parameters into CryptFormer in the form of secret sharing;
[0091] 4) CryptFormer calculates the privacy protection of each operation in the Transformer model as follows:
[0092] i) Linear layer operations: All linear layer operations can be reduced to matrix multiplications. CryptFormer takes the client and the model owner’s respective secret shares as input (i.e. Running Protocol And get the output of the current linear layer
[0093]
[0094] ii) Non-linear layer operations: These non-linear operations include (Softmax, GeLU, LayerNorm), and the two sides share the addition As input, call the function calculation protocol (Π Softmax , Π GeLU , Π LayerNorm ) and output the addition share Where Func∈(Softmax,GeLU,LayerNorm).
[0095] 5) After both parties call the CryptFormer reasoning system, only the client gets the model reasoning result it wants and the client does not know any information about the model parameters. The server does not know the client's private input or the model's reasoning output.
[0096] Another embodiment of the present invention provides a large model privacy protection reasoning system based on secure multi-party computing, which includes:
[0097] An input module is used to obtain the prompt words required for reasoning input by the client in the form of secret sharing, and to obtain the weight parameters of the large model and the public network structure of the large model input by the server in the form of secret sharing;
[0098] The privacy-preserving computing and reasoning module is used to perform privacy-preserving computing and model reasoning on each operation layer in the large model. The server and client obtain the shared value of the reasoning result respectively.
[0099] The output module is used for the server to send the shared value of the inference result to the client, and the client reconstructs the inference result based on the complete shared value.
[0100] The division of the above modules is only an example. In actual applications, the above functions can be assigned to different functional modules as needed to complete all or part of the functions described in the above method. The specific working process of each module can refer to the corresponding process in the above method embodiment, which will not be repeated here.
[0101] Another embodiment of the present invention provides a computer device (computer, server, smart phone, etc.), which includes a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.
[0102] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk), wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the steps of the method of the present invention are implemented.
[0103] The above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit the same. A person skilled in the art may modify or make equivalent substitutions for the technical solutions of the present invention without departing from the spirit and scope of the present invention. The protection scope of the present invention shall be subject to the claims.< / x> < / x> < / x> < / y> < / x>
Claims
1. A privacy-preserving reasoning method for large models based on secure multi-party computation, characterized in that: The following steps are involved: Obtain the clue words required for reasoning input by the client in the form of secret sharing; Obtain the large model weight parameters input by the server in the form of secret sharing; Obtain the public large model network structure and perform privacy-preserving calculations on each operation layer to perform model reasoning. The server and client obtain the shared value of the reasoning result respectively. The server sends the shared value of the inference result to the client, and the client reconstructs the inference result based on the complete shared value.
2. The method according to claim 1, characterized in that The client can only obtain the model inference results but not the model parameter information, and the server cannot obtain the client's private prompt words and model inference results.
3. The method according to claim 1, characterized in that The large model is based on the Transformer architecture; The privacy protection calculation is performed on each operation layer in the large model, including: Linear layer operations: All linear layer operations are reduced to matrix multiplications, and the matrix-secure multiplication protocol is run with the client and server's secret shares as input. And get the output of the current linear layer; Non-linear layer operations: Non-linear operations include Softmax, GeLU, and LayerNorm, which are shared by the client and server using addition. <x>As input, call the function calculation protocol and output the addition share <y>=P Func ( <x>), where Func∈(Softmax, GeLU, LayerNorm); the function calculation protocol includes the secure calculation protocol Π of Softmax Softmax 、LayerNorm's secure computing protocol Π LayerNorm and GeLU's secure computing protocol Π GeLU .< / x> < / y> < / x> 4. The method according to claim 3, characterized in that The matrix-safe multiplication protocol Secure multiplication protocol using special matrices A recursive secure multiplication protocol as a general matrix Recursive export protocol; The secure multiplication protocol for the special matrix The following steps are included, where P0 represents the server and P1 represents the client: Input: P0, P1 hold matrices in k is a positive integer; Output: P0 and P1 get Where Z = X·Y; 1) P0 and P1 encode the matrix X and matrix Y into polynomials respectively 2) P1 converts the polynomial Encrypted as And send it to P0; 3) P0 uniformly randomly samples a polynomial Decoded as 4) After receiving the ciphertext CT from P1, P0 calculates the ciphertext locally in is homomorphic subtraction; 5) P0 command This step is to make scaling correction for the target position coefficient; 6) For values of i ranging from 0 to k-1, execute step 7); 7) P0 is calculated locally This step is to eliminate location coefficients that are irrelevant to the results; 8) P0 obtains the compressed ciphertext polynomial and send it to P1; 9) P0 output As Share <z> 0;< / z> 10) P1 decryption calculation And output The general recursive secure multiplication protocol for matrices include: Input: P0, P1 hold matrices respectively N is the polynomial order in the BFV scheme; Output: P0, P1 get Additive sharing; 1) P0 and P1 expand X and Y to the same size by filling them with zeros 2) If p≤(logN) / 3, execute steps 3) and 4), otherwise execute steps 5)-8); 3) P0&P1 calling protocol Get 4) P0 and P1 are respectively<A·B> Crop and return <z> =<X·Y> ;< / z> 5) P0 and P1 each split their filling matrices as follows: 6) P0, P1 recursive call To obtain the additive sharing of intermediate quantities (P, Q, R, S, T, U, V): 7) P0 and P1 can be obtained by local calculation Addition sharing: 〈C 11 >=〈P〉+〈S〉-<(T>+〈V>,〈C 12 >=〈R>+ <t>< / t> 〈C 21 〉=〈Q>+ <s>,〈C 22 〉=〈P〉+〈R〉-<Q〉+ < / s> <s> 8) P0 and P1 are each <c>Cut and return <z> =<X·Y> .< / z> < / c> 5. The method according to claim 4, characterized in that The secure computation protocol Π of the Softmax Softmax include: Input: P0, P1 hold in Output: P0, P1 are obtained respectively Where y = Softmax(x); 1) P0&P1 call the maximum value protocol ∏ max To calculate: 2) P0 and P1 each locally calculate 〈x[i]-x * 〉←〈x[i]>- <x * > 3) P0&P1 call comparison protocol ∏ LT To calculate: <c〉 B ←Π LT (T exp ,〈x[i]-x * >); 4) P0&P1 call truncation protocol To calculate: 5) For values of j ranging from 1 to t, execute step 6): 6) P0 & P1 call Π square Calculation: j 〉←Π square ( j-1 >); 7) P0, P1 local calculation And call Π Recip Calculate 8) P0 & P1 call multiplication protocol To obtain 9) P0 & P1 call Multiplexer protocol Π MUX Calculate and output 6. The method according to claim 5, characterized in that The LayerNorm secure computation protocol Π LayerNorm include: Input: P0, P1 hold in Output: P0, P1 are obtained respectively Where y = LayerNorm(x); 1) P0 and P1 calculate locally: where i∈[n]; 2) P0 & P1 call Π square Protocol to obtain <(x[i]-μ) 2 >←Π square (<x[i]-μ> ); 3) P0 and P1 are calculated locally: 4) P0 & P1 call the square root inverse protocol Π rSqrt To calculate: <σ -1 / 2 >←Π rSqrt (<σ>); 5) P0&P1 calling protocol To obtain 6) P0&P1 calling protocol Π MuloT To calculate 7. The method according to claim 3, characterized in that The secure computation protocol Π of GeLU GeLU include: Input: P0, P1 hold in Output: P0, P1 are obtained respectively Where y = GeLU(x); 1) P0 & P1 call comparison protocol Π LT To calculate: 〈b0> B ←Π LT ( <x> L ,-4), <b1> B ←Π LT ( <x> L ,-0.751792),<b2〉 B ←Π LT (3, <x> L );< / x> < / x> < / x> 2) P0, P1 local calculation <c2> B = <b2> B ;< / b2> < / c2> 3) P0&P1 call the square protocol Π square To calculate 〈x 2 〉 L ←Π square ( <x〉 L ), <x 4 > L ←Π square ( <x 2 > L ), And call To obtain 4) Based on { <x> L , <x 2 > L , <x 3 > L , <x 4 > L } and the above optimal approximation to calculate < / x> 5) P0&P1 calling protocol MUX To calculate and output:
8. A large-model privacy-preserving reasoning system based on secure multi-party computing, characterized in that: include: An input module is used to obtain the prompt words required for reasoning input by the client in the form of secret sharing, and to obtain the weight parameters of the large model and the public network structure of the large model input by the server in the form of secret sharing; The privacy-preserving computing and reasoning module is used to perform privacy-preserving computing and model reasoning on each operation layer in the large model. The server and client obtain the shared value of the reasoning result respectively. The output module is used for the server to send the shared value of the inference result to the client, and the client reconstructs the inference result based on the complete shared value.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented. < / s>
Citation Information
Patent Citations
Large security model, electronic equipment and computer readable storage medium
CN117852081A
Transform model secret state reasoning method and system based on secret sharing
CN118174856A
Lightweight privacy protection ViT reasoning framework based on secret sharing
CN118196603A
Sandstone microscopic image classification method and system based on improved Swin Transform
CN118570797A
Multi-party joint neural network training method and apparatus for achieving security defense
WO2021082633A1
Cited By
Safety evaluation method, device and equipment for multi-modal large model and storage medium
CN120321041A