Safety reasoning method and device based on fully homomorphic encryption and electronic equipment
By preprocessing and encryption on the user side, using improved convolutional neural networks for ciphertext inference on the cloud server side, combined with all-homomorphic encryption technology, the privacy protection and efficient inference of deep neural networks in a fully-homomorphic encryption environment is achieved, and the problem of difficulty in achieving both accuracy and efficiency is solved.
Patent Information
- Application Number
- CN202510314566.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-07-22
AI Technical Summary
In a cloud computing environment with fully homomorphic encryption, it is difficult to achieve both accuracy and computing efficiency when inference in deep neural networks. The existing technology has the problem of large computing volume and low efficiency, and cannot support complex computing types.
Fully homomorphic encryption technology is used to preprocess and encrypt sensitive data on the user side, and the improved convolutional neural network is used to perform ciphertext inference on the cloud server side. The plaintext inference results are obtained by decrypting on the user side, and combined with the full homomorphic encryption algorithm and the improved convolutional neural network architecture, data privacy protection and efficient inference are achieved.
It realizes privacy protection for deep neural networks in a fully homomorphic encryption environment, ensures data security and privacy protection, and improves the accuracy and computing efficiency of reasoning, solving the problem of difficulty in taking into account both accuracy and efficiency.
Smart Images

Figure CN120354933A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and in particular, to a secure inference method and apparatus based on fully homomorphic encryption, and an electronic device. Background Art
[0002] With the wide popularization of information networks, the collection, storage, use, and processing of data are becoming increasingly frequent. In the big data era, the importance of data security and privacy protection has become increasingly prominent. On the one hand, the storage, use, and processing of data require a large amount of computing resources, and the consumption of storage computing power resources is huge. On the other hand, during the process of data storage, calculation, and use, there are often risks of data leakage, information theft, and privacy leakage. Therefore, how to ensure data privacy security during the calculation and processing process is an urgent problem to be solved.
[0003] The inference method based on homomorphic encryption can avoid data leakage during the calculation process and ensure data security. Traditional homomorphic encryption algorithms mainly include semi-homomorphic encryption algorithms and fully homomorphic encryption algorithms. The fully homomorphic encryption algorithm is a homomorphic encryption algorithm constructed based on the fully homomorphic encryption algorithm, enabling any encryption operation to be completed in the encrypted domain, which is a more secure homomorphic encryption method. In the inference method based on homomorphic encryption, the plaintext data is encrypted before calculation, and the plaintext result is obtained through the inverse algorithm for the calculation result. The plaintext information is not exposed during the whole process, thus greatly reducing the risk of data leakage.
[0004] However, the inference method based on homomorphic encryption has the following problems in practical applications:
[0005] First, the homomorphic encryption method has a large amount of calculation and low efficiency, and as the encryption key increases, the calculation amount corresponding to the encryption key will increase exponentially.
[0006] Second, in the inference method based on homomorphic encryption, the fully homomorphic encryption algorithm uses binary operations and unary operations, that is, only addition and multiplication operations can be performed after encryption processing. However, in practical applications, the calculation complexity usually involves non-linear operations. For example, a neural network using the ReLU function as the activation function needs to support multi-element operations and non-linear operations, such as addition, subtraction, multiplication, division, and exponential operations, etc. The fully homomorphic encryption method that only supports addition and multiplication cannot meet practical applications.
[0007] Third, in the inference method based on homomorphic encryption, a traditional neural network is usually used as the inference model, and the activation function used in the traditional neural network is the ReLU function. However, the second-order polynomial function is used in the inference method based on homomorphic encryption. Therefore, the ReLU function cannot meet practical applications.
[0008] In summary, in the existing inference methods based on homomorphic encryption, there are problems such as large computational complexity, low efficiency, few supported operation types, and inability to perform fast and accurate inference on neural network models with high complexity.
[0009] For the above problems, no effective solution has been proposed yet. Summary of the Invention
[0010] The embodiments of the present invention provide a secure inference method, device, and electronic device based on fully homomorphic encryption, so as to at least solve the technical problem that it is difficult to balance the accuracy and computational efficiency during the inference of deep neural networks in the cloud computing environment with fully homomorphic encryption in the related art.
[0011] According to one aspect of the embodiments of the present invention, a secure inference method based on fully homomorphic encryption is provided, which includes: receiving sensitive data to be inferred uploaded by the user side, and preprocessing the sensitive data; invoking a pre-generated key pair, encrypting the preprocessed sensitive data based on the public key in the key pair to obtain ciphertext data to be inferred; uploading the ciphertext data to a cloud server, and the cloud server performing ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result; downloading the ciphertext inference result from the cloud server, and decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result.
[0012] Further, the step of preprocessing the sensitive data includes: normalizing the sensitive data; flattening the normalized sensitive data to obtain sensitive data in the form of a one-dimensional vector; partitioning the one-dimensional vector according to the plaintext space size of the fully homomorphic encryption algorithm to obtain M data block vectors, where M is a positive integer.
[0013] Further, the step of generating the key pair includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm, and sampling a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; determining the public key and private key of the user side based on the first random polynomial and the first noise amount to obtain the key pair.
[0014] Further, the step of encrypting the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial, and sampling two noise amounts from a specified error distribution to obtain a second noise amount and a third noise amount; for each data block vector in the preprocessed sensitive data, calculating an encrypted data block vector based on the public key, the second random polynomial, the second noise amount, the third noise amount, and a predetermined scaling factor according to the fully homomorphic encryption algorithm; combining the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and using this ciphertext matrix as the ciphertext data to be inferred.
[0015] Further, the step of the cloud server performing ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result includes: the cloud server invoking the improved convolutional neural network, where the activation function applied by this convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N; the cloud server inputting the ciphertext data into the improved convolutional neural network, performing a convolution operation on the ciphertext data using a convolutional layer, and performing a non-linear transformation operation on the ciphertext data using the activation function to obtain a convolution result; the cloud server integrating the convolution result through a fully connected layer in the convolutional neural network to obtain the ciphertext inference result.
[0016] Further, at least two variable learning parameters are included in the activation function. After applying this preset activation function, it further includes: during each process of using the improved convolutional neural network for data inference, training and updating the variable learning parameters in the activation function based on the backpropagation algorithm and the gradient descent method.
[0017] Further, after decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result, it further includes: performing post-processing on the plaintext inference result, where the post-processing operation at least includes: a rounding operation and a scaling operation.
[0018] According to another aspect of the embodiments of the present invention, a secure inference system based on fully homomorphic encryption is further provided, which includes: a user side for executing any one of the above secure inference methods based on fully homomorphic encryption; a cloud service side for receiving the ciphertext data uploaded by the user side and performing ciphertext inference on the ciphertext data using an improved convolutional neural network, where the activation function applied by the convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N.
[0019] According to another aspect of the embodiments of the present invention, a secure inference device based on fully homomorphic encryption is further provided, which includes: a receiving unit, configured to receive sensitive data to be inferred uploaded by the user side and preprocess the sensitive data; an encryption unit, configured to call a pre-generated key pair and encrypt the preprocessed sensitive data based on the public key in the key pair to obtain ciphertext data to be inferred; an uploading unit, configured to upload the ciphertext data to a cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result; a downloading unit, configured to download the ciphertext inference result from the cloud server and decrypt the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result.
[0020] Further, the receiving unit includes: a normalization processing module, configured to perform normalization processing on the sensitive data; a flattening processing module, configured to flatten the normalized sensitive data to obtain sensitive data in a one-dimensional vector form; a block division module, configured to divide the one-dimensional vector into M data block vectors according to the plaintext space size of the fully homomorphic encryption algorithm, where M is a positive integer.
[0021] Further, the secure inference device based on fully homomorphic encryption includes: a first sampling module, configured to randomly select a polynomial in the plaintext space of the fully homomorphic encryption algorithm and sample a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; a determination module, configured to determine the public key and private key of the user side based on the first random polynomial and the first noise amount to obtain the key pair.
[0022] Further, the encryption unit includes: a second sampling module, configured to randomly select a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial and sample two noise amounts from a specified error distribution to obtain a second noise amount and a third noise amount; a calculation module, configured to, for each data block vector in the preprocessed sensitive data, calculate an encrypted data block vector according to the fully homomorphic encryption algorithm based on the public key, the second random polynomial, the second noise amount, the third noise amount, and a pre-determined scaling factor; a combination module, configured to combine the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and use the ciphertext matrix as the ciphertext data to be inferred.
[0023] Further, the secure inference device based on fully homomorphic encryption further includes: a calling module, configured to be called by the cloud server to call the improved convolutional neural network, where the activation function applied by the convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N; an input module, configured to be used by the cloud server to input the ciphertext data into the improved convolutional neural network, perform a convolutional operation on the ciphertext data using a convolutional layer, and perform a non-linear transformation operation on the ciphertext data using the activation function to obtain a convolutional result; an integration module, configured to be used by the cloud server to integrate the convolutional result through a fully connected layer in the convolutional neural network to obtain the ciphertext inference result.
[0024] Further, at least two variable learning parameters are included in the activation function, and the secure inference device based on fully homomorphic encryption further includes: a training and updating module, configured to, after applying the preset activation function, during each process of using the improved convolutional neural network for data inference, train and update the variable learning parameters in the activation function based on the backpropagation algorithm and the gradient descent method.
[0025] Further, the secure inference device based on fully homomorphic encryption further includes: a post-processing module, configured to, after decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result, perform post-processing on the plaintext inference result, where the post-processing operation at least includes: a rounding operation and a scaling operation.
[0026] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, where the computer-readable storage medium includes a stored computer program, and when the computer program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above-mentioned secure inference methods based on fully homomorphic encryption.
[0027] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement any one of the above-mentioned secure inference methods based on fully homomorphic encryption.
[0028] In the present invention, a secure inference method based on fully homomorphic encryption is proposed. First, sensitive data to be inferred uploaded by the user side is received, and the sensitive data is preprocessed. Then, a pre-generated key pair is called, and the preprocessed sensitive data is encrypted based on the public key in the key pair to obtain the ciphertext data to be inferred. Then, the ciphertext data is uploaded to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result. Finally, the ciphertext inference result is downloaded from the cloud server, and the ciphertext inference result is decrypted based on the private key in the key pair to obtain a plaintext inference result.
[0029] In the present invention, a method of separating the processing between the user side and the cloud server side is adopted, and privacy protection for the deep learning inference process of sensitive data in the cloud computing environment is realized by combining the fully homomorphic encryption technology with an improved convolutional neural network. Specifically, after receiving the sensitive data to be inferred uploaded by the user side, the present invention first performs necessary preprocessing on the data at the user side to ensure that the data format is compatible with subsequent encryption steps. Subsequently, the preprocessed sensitive data is encrypted using the public key in the pre-generated key pair to obtain the ciphertext data to be inferred. This process is completely completed in a closed manner at the user side, ensuring the privacy of the data. The encrypted data is uploaded to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture. This improved convolutional neural network architecture can effectively process the encrypted data without decryption, thereby completing the deep learning inference task without exposing the original data. Finally, the inference result is downloaded from the cloud server, and the ciphertext inference result is decrypted using the private key in the key pair at the user side to obtain the plaintext inference result, enabling the user to obtain a secure and privacy-protected inference result.
[0030] Through the "preprocessing - encryption - ciphertext inference - decryption" process of the present invention, privacy protection for deep neural network inference in the fully homomorphic encryption cloud computing environment is effectively realized. This solution not only ensures the security and privacy protection of sensitive data, but also achieves high accuracy and computational efficiency in deep learning inference, thereby solving the technical problem in the related art that it is difficult to achieve both high accuracy and computational efficiency in deep neural network inference in the fully homomorphic encryption cloud computing environment, and providing strong technical support for deep learning applications in data-sensitive scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0032] Figure 1 is an architecture diagram of an optional secure inference method based on fully homomorphic encryption according to an embodiment of the present invention;
[0033] Figure 2 is a flowchart of an optional secure inference method based on fully homomorphic encryption according to an embodiment of the present invention;
[0034] Figure 3 is a specific deployment plan diagram of an optional secure inference method based on fully homomorphic encryption at the user side according to an embodiment of the present invention;
[0035] Figure 4 is an architecture diagram of an optional improved VGG-16 convolutional neural network applied to a cloud server according to an embodiment of the present invention;
[0036] Figure 5 is a schematic diagram of an optional secure inference system based on fully homomorphic encryption according to an embodiment of the present invention;
[0037] Figure 6 is a schematic diagram of an optional secure inference device based on fully homomorphic encryption according to an embodiment of the present invention;
[0038] Figure 7 is a structural block diagram of an electronic device for executing a secure inference method based on fully homomorphic encryption according to an embodiment of the present invention. Detailed implementation manners
[0039] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0040] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0041] To facilitate the understanding of the present invention by those skilled in the art, the following explains some terms or nouns involved in the embodiments of the present invention:
[0042] Fully Homomorphic Encryption, FHE, is a cryptographic technique that allows direct computations on encrypted data without first decrypting the data. The computation results can then be decrypted and are consistent with the results of performing the same computations on the original plaintext data. The present invention uses the YASHE algorithm in FHE as the data encryption method to ensure that the privacy and security of data are not violated during the ciphertext inference process.
[0043] Deep Neural Network, DNN, is a multi-layer neural network architecture that contains multiple hidden layers to achieve high-level abstraction and feature learning of complex data. In the present invention, the improved convolutional neural network is a specific type of deep neural network that is used for ciphertext inference on the cloud server side to balance computational efficiency and accuracy.
[0044] Convolutional Neural Network, CNN, is a network architecture used in deep learning to process image and video data, which extracts the spatial hierarchical features of the input data through convolutional layers. The present invention improves the activation function of the CNN to meet the inference requirements in the fully homomorphic encryption environment.
[0045] Activation Function is a function used in neural networks to introduce non-linear characteristics and determines the output of neurons. In the present invention, the traditional ReLU activation function is replaced by a second-order polynomial designed for the fully homomorphic encryption environment to ensure inference accuracy and computational efficiency in the ciphertext state.
[0046] Cloud Computing Service is a computing model that provides computing resources (such as servers, storage, networks, etc.) through the Internet, enabling users to use these resources on demand without understanding the underlying technical details. In the present invention, the cloud computing service is used as a platform for performing deep neural network inference, which needs to process encrypted data and output inference results without decryption.
[0047] The following embodiments of the present invention can be applied to various systems / applications / devices that require deep neural network inference and sensitive data privacy protection, and can implement the deep learning inference function in the cloud computing environment based on fully homomorphic encryption. The present invention uses the fully homomorphic encryption algorithm YASHE to preprocess and encrypt the user-side data, and then uploads the encrypted data to the cloud server. The cloud server performs ciphertext inference based on the improved convolutional neural network architecture VGG-16, which can better maintain the accuracy and computational efficiency of inference while ensuring data privacy and security.
[0048] Specifically, the present invention performs data preprocessing on the user side, including steps such as normalization, flattening, and chunking, to ensure that the data format meets the requirements of the fully homomorphic encryption algorithm YASHE; encrypts sensitive data through the YASHE public key and uploads it to the cloud server in ciphertext form; uses an improved deep neural network (with VGG-16 as the backbone, and its activation function is customized as a second-order polynomial compatible with YASHE) on the cloud server to perform inference calculations on the uploaded ciphertext data; after the inference is completed, the cloud server returns the ciphertext inference result to the user side; and the user side then decrypts the ciphertext inference result using the YASHE private key to finally obtain the plaintext inference result, that is, the deep neural network inference task is completed without decrypting the data.
[0049] The core of the present invention is that by using the fully homomorphic encryption technology YASHE to encrypt sensitive data to be inferred on the user side, and using a customized convolutional neural network architecture for ciphertext inference on the cloud server, the goal of performing deep learning inference while protecting data privacy is effectively achieved, providing a safe and reliable solution for institutions involving sensitive data to deploy and use deep learning models in the cloud computing environment.
[0050] The following will detail the present invention in conjunction with each embodiment.
[0051] Embodiment 1
[0052] According to an embodiment of the present invention, there is provided an embodiment of a secure inference method based on fully homomorphic encryption. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0053] An embodiment of the present invention is as follows Figure 2The secure reasoning method based on fully homomorphic encryption shown in the invention is implemented by a cloud computing service system, especially the user end in the secure reasoning system based on fully homomorphic encryption in the present invention. It is combined with fully homomorphic encryption technology for deep neural network reasoning scenarios, especially to solve the problem that it is difficult to achieve both accuracy and computational efficiency in deep neural network reasoning under fully homomorphic encryption scenarios. The purpose of protecting the privacy of sensitive data and performing efficient and accurate deep neural network reasoning is achieved by using the YASHE fully homomorphic encryption algorithm to encrypt sensitive data on the user end and using an improved convolutional neural network architecture to perform ciphertext reasoning on the cloud service end.
[0054] Figure 1 is an architecture diagram of an optional secure reasoning method based on fully homomorphic encryption according to an embodiment of the present invention, such as Figure 1 As shown in Figure 1, the reasoning architecture of this method is divided into the user side (technology companies as service users) and the cloud service side (cloud computing companies provide cloud server services). On the user side, the technology company first encrypts the sensitive data to be inferred based on the key pair generated by itself and the fully homomorphic encryption algorithm YASHE, and uploads the encrypted ciphertext data to the cloud server. On the cloud service side, the cloud computing company service provider uses an improved convolutional neural network ( Figure 1 After the deep neural network performs inference, the encrypted result is sent back to the user, and the user uses the private key to decrypt it to obtain the plaintext inference result.
[0055] Figure 2 is a flowchart of an optional secure reasoning method based on fully homomorphic encryption according to an embodiment of the present invention. Figure 2 As shown, the method comprises the following steps:
[0056] Step S201: receiving sensitive data to be inferred uploaded by the user, and preprocessing the sensitive data.
[0057] It should be noted that step S201 is an important starting point for the entire deep neural network security reasoning solution based on fully homomorphic encryption, ensuring the smooth progress of subsequent encryption and cloud computing reasoning processes. After receiving the sensitive data to be reasoned uploaded by the user, the data is preprocessed, including three key steps: normalization, flattening, and block division according to the plaintext space size of the fully homomorphic encryption algorithm, which together create the necessary conditions for subsequent ciphertext reasoning.
[0058] Optionally, the steps for preprocessing sensitive data include: normalizing the sensitive data; flattening the normalized sensitive data to obtain sensitive data in the form of a one-dimensional vector; partitioning the one-dimensional vector into M data block vectors according to the plaintext space size of the fully homomorphic encryption algorithm, where M is a positive integer.
[0059] First, normalization is to scale the values of sensitive data to a fixed range, such as the common interval [0, 1] or [-1, 1]. Scaling the data to a reasonable range can significantly reduce the problem of ciphertext expansion during fully homomorphic encryption, that is, the amount of encrypted data increases significantly, thereby reducing storage and communication costs. In addition, normalization can also avoid the problems of gradient explosion or gradient disappearance caused by differences in data magnitudes during the training and inference of neural networks, ensuring the stability and convergence speed of the model.
[0060] Subsequently, flattening converts the normalized sensitive data from a multi-dimensional structure to a one-dimensional vector. This step is essential in deep learning, especially when dealing with complex structured data such as images and videos. Flattening not only helps to input the data into the deep neural network model but also ensures that the data is correctly processed in the fully homomorphic encryption algorithm. Since the fully homomorphic encryption algorithm is designed to process numerical data, the flattened data can be encrypted in the form of a vector, facilitating subsequent encryption operations and neural network inference on the cloud server.
[0061] Finally, the step of partitioning according to the plaintext space size of the fully homomorphic encryption algorithm involves dividing the flattened one-dimensional vector sensitive data into multiple small blocks, and the size of each data block must match the plaintext space size of the fully homomorphic encryption algorithm YASHE. It should be noted that since the computational efficiency and security of the YASHE algorithm depend to a certain extent on the size of the ciphertext, data partitioning can optimize the encryption efficiency. At the same time, since the YASHE algorithm has a limit on the number of operations, data partitioning also ensures that the operations of each data block do not exceed this limit, thus avoiding decryption errors. In addition, data partitioning helps with parallel processing, which can improve the overall speed of encryption and the inference efficiency on the cloud server side. Through the preprocessing process in step S201, namely normalization, flattening, and partitioning according to the plaintext space size, not only is the data prepared for subsequent fully homomorphic encryption and remote cloud computing inference, but also a series of beneficial technical effects are brought, including but not limited to reducing communication and storage costs, ensuring the stability and computational efficiency of the deep neural network model, and optimizing the security in the data encryption and decryption process, jointly promoting efficient and accurate deep neural network inference while protecting the privacy of user sensitive data.
[0062] Figure 3 FIG. 1 is a specific deployment scheme diagram of an optional secure reasoning method based on fully homomorphic encryption at the user end according to an embodiment of the present invention, such as Figure 3 As shown, assuming that the sensitive image data to be inferred by the user of the technology company is recorded as F, F needs to be preprocessed before the encryption data process is carried out and converted into a format suitable for YASHE encryption.
[0063] Specifically, the embodiment of the present invention first normalizes the pixel values of the sensitive image data F (the normalization range may be [0, 1] or [-1, 1]), and then performs flattening processing to convert them into one-dimensional vectors. Taking a 28×28 grayscale single-channel image as an example, it can be converted into a 784-dimensional one-dimensional vector. Assuming that the sensitive image data F is a multi-channel color image, the two-dimensional matrix of each channel is first flattened into a one-dimensional vector, and then the one-dimensional vectors corresponding to each channel are spliced together. Finally, the flattened one-dimensional vector is divided into multiple smaller data blocks, and the size of each data block must match the plaintext space of YASHE. At this point, the preprocessing work for the sensitive image F is completed, and each obtained data block vector is recorded as f i (i=0,1,...,k), waiting for each data block vector f in the subsequent process i Execute YASHE algorithm encryption.
[0064] Alternatively, the preprocessing step also includes but is not limited to: data cleaning, missing value processing, outlier detection, etc., to further improve data quality and inference accuracy.
[0065] Step S202: call the pre-generated key pair, encrypt the pre-processed sensitive data based on the public key in the key pair, and obtain the ciphertext data to be inferred.
[0066] It should be noted that step S202 plays a key role in bridging the sensitive data on the user side and the deep neural network reasoning on the cloud server side in the embodiment of the present invention. The pre-processed sensitive data is encrypted by the fully homomorphic encryption algorithm YASHE to ensure that the data always remains in a ciphertext state during transmission and reasoning, thereby protecting data privacy. Next, we will analyze this step and its preceding key generation process in detail.
[0067] Optionally, the step of generating a key pair includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm, and sampling a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; determining the public key and private key of the user based on the first random polynomial and the first noise amount to obtain the key pair.
[0068] On the user side, it is first necessary to generate a key pair for fully homomorphic encryption. This process follows the key generation steps of the fully homomorphic encryption algorithm YASHE, specifically as follows: In the plaintext space (i.e., polynomial ring) of the YASHE fully homomorphic encryption algorithm, a polynomial is randomly selected and a noise quantity is sampled from a specified error distribution to obtain a first random polynomial and a first noise quantity. Based on these two parameters and specific mathematical operations (such as operations of the Ring-LWE problem), the public key (for encryption) and private key (for decryption) of the user side are determined, thus obtaining a complete key pair. The key generation steps ensure the security and efficiency of the subsequent encryption process. Among them, the public key is used to encrypt data, while the private key is used in the decryption process to ensure the integrity and privacy protection of the data.
[0069] It should be noted that the key pair generation of the fully homomorphic encryption algorithm is the basis of secure inference. By randomly selecting a polynomial and sampling a noise quantity in the plaintext space, the generated public key and private key ensure the security of data encryption and decryption. The introduction of the noise quantity is one of the key features of the fully homomorphic encryption algorithm, which increases the randomness of the encrypted data, improves the security of encryption, and also enables the decryption process to correctly recover the original data. This process is not only applicable to data inference scenarios, but also applicable to scenarios that require data security protection, including but not limited to data storage and data transmission, providing a strong guarantee for data security.
[0070] Continue to explain the above Figure 3 in the specific embodiments mentioned, use the YASHE algorithm to encrypt each data block vector f i For encryption, it is first necessary to generate a public key pk=(a,b) and a private key sk = s that satisfy the condition b = a·s + e. Among them, a is a random polynomial in the plaintext space R q in (R q =Z q [x] / (x n +1) represents the polynomial ring plaintext space of the YASEH algorithm, where n is the polynomial degree and q is the modulus), that is, the first random polynomial, and e is a tiny noise sampled from a specific error distribution, that is, the first noise quantity. This error distribution comes from the security assumption of the Ring-LWE problem (Ring Learning with Errors problem).
[0071] Subsequently, the preprocessed sensitive data is encrypted based on the generated public key to obtain the ciphertext data to be inferred. Optionally, the step of encrypting the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial, and sampling two noise quantities from a specified error distribution to obtain a second noise quantity and a third noise quantity; for each data block vector in the preprocessed sensitive data, based on the public key, the second random polynomial, the second noise quantity, the third noise quantity, and a predetermined scaling factor, calculate the encrypted data block vector according to the fully homomorphic encryption algorithm; combine the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and use this ciphertext matrix as the ciphertext data to be inferred.
[0072] Specifically, for each data block vector in the preprocessed sensitive data, the user side randomly selects a random polynomial in the plaintext space of the fully homomorphic encryption algorithm and samples two noise quantities from a specified error distribution, and combines each data block vector with the public key, the random polynomial, the two noise quantities, and a predetermined scaling factor using the encryption formula in the YASHE algorithm to calculate the encrypted data block vector. The above encryption process increases the anti-decryption ability of the data in the ciphertext state by adding noise quantities, and at the same time, the use of the scaling factor ensures the accuracy of the encrypted data during decryption, thus ensuring the reliability of the inference result while protecting data privacy.
[0073] As Figure 3 shown, after generating the public key pk = (a, b), for each data block f i , select a random polynomial u (i.e., the second random polynomial) and noises e1 (i.e., the second noise quantity), e2 (i.e., the third noise quantity), and calculate the ciphertext c = (c0, c1) that satisfies: c0 = b·u + e1 + f i ·δ and c1 = a·u + e2, where δ is a scaling factor used to control the accuracy of the plaintext.
[0074] Next, combine the M encrypted data block vectors according to the regulations of the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and this ciphertext matrix will be uploaded to the cloud computing platform as the ciphertext data to be inferred for deep neural network inference. The combination between data blocks can effectively manage and transmit the encrypted data, reducing the data processing overhead during the communication process. At the same time, the form of the ciphertext matrix is convenient for the cloud server to perform batch processing, improving the calculation efficiency of deep neural network inference.
[0075] As Figure 3 shown, repeating the above encryption for all data blocks of the image F can obtain a set of ciphertexts {c (0) , c (1) , …, c(k) +, where k is the number of data blocks. The group of ciphertexts is rearranged to form a ciphertext matrix C, which is uploaded to the cloud server as the encrypted information for deep neural network inference, thereby preventing the leakage of sensitive data.
[0076] Through the above step S202 and its detailed description of key generation and data encryption, the embodiment of the present invention achieves the goal of remote deep neural network inference without exposing the plaintext of sensitive data, and solves the technical problem that it is difficult to balance data privacy protection and computing efficiency. The application of noise amount sampling and scaling factor in the encryption process not only enhances the data security, but also improves the accuracy of the inference result. At the same time, uploading the encrypted data in the form of a ciphertext matrix reduces the data transmission and processing overhead in the cloud computing environment, achieving a double optimization of data security and computing efficiency.
[0077] Step S203: Upload the ciphertext data to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain the ciphertext inference result.
[0078] It should be noted that step S203 involves uploading the sensitive data encrypted by the user side to the cloud server. The cloud server calls the specially designed improved convolutional neural network architecture that supports the fully homomorphic encryption environment to perform ciphertext inference, and then obtains the ciphertext inference result. On the cloud server side, the improved convolutional neural network architecture is used to process the uploaded ciphertext data. The key of this architecture lies in the selection of its activation function - a preset second-order polynomial function with the number of terms being the specified value N. This second-order polynomial is specially designed for the characteristics of fully homomorphic encryption to overcome the limitations of traditional non-linear activation functions in the encryption scenario.
[0079] Optionally, the step of the cloud server performing ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain the ciphertext inference result includes: the cloud server calls the improved convolutional neural network, where the activation function applied by the convolutional neural network is a preset second-order polynomial function for the fully homomorphic encryption environment with the number of terms being the specified value N; the cloud server inputs the ciphertext data into the improved convolutional neural network, performs a convolution operation on the ciphertext data using the convolutional layer, and performs a non-linear transformation operation on the ciphertext data using the activation function to obtain the convolution result; the cloud server integrates the convolution result through the fully connected layer in the convolutional neural network to obtain the ciphertext inference result.
[0080] The embodiment of the present invention preferably uses the application network architecture VGG-16 as the improved convolutional neural network. Different from the standard VGG-16, the activation function of the improved network is replaced by a second-order polynomial function, which can perform operations in the fully homomorphic encryption environment, and its design takes into account the balance between computing efficiency and inference accuracy.
[0081] The improved convolutional neural network first uses a convolutional layer to perform a convolution operation on the ciphertext data to extract features from the encrypted data. Subsequently, the above-mentioned preset second-order polynomial activation function is used to perform a non-linear transformation on the convolution result. This process does not require decryption, but directly operates on the ciphertext in a fully homomorphic encryption environment. The design of the second-order polynomial function can approximately achieve the effect of traditional activation functions, while avoiding the problem of a sharp increase in the amount of computation brought by high-degree polynomials, maintaining the accuracy of inference while ensuring computational efficiency.
[0082] After the convolution operation and non-linear transformation are completed, the cloud server integrates the convolution result through the fully connected layer in the convolutional neural network. This layer is responsible for mapping the extracted features to the space of categories. Under the calculation of the fully connected layer, the ciphertext data is converted into a ciphertext inference result, that is, the classification or prediction result of the network on the encrypted data, which still exists in the form of ciphertext.
[0083] In a specific embodiment, Figure 4 is an architecture diagram of an improved VGG-16 convolutional neural network optionally applied to a cloud server according to an embodiment of the present invention. As Figure 4 shown, the VGG-16 convolutional neural network includes 16 neural network layers (i.e., convolutional layers and fully connected layers) with learnable weight parameters. Among them, the specifications of the convolution kernels of all convolutional layers are 3×3, the stride is 1, and the padding is 1. As the depth of the VGG-16 network continues to increase, the number of convolution kernels also increases: in the first and second convolutional layers, the number of convolution kernels is 64; in the third and fourth convolutional layers, the number of convolution kernels is 128; in the fifth to seventh convolutional layers, the number of convolution kernels is 256; in the eighth to thirteenth convolutional layers, the number of convolution kernels is 512. Finally, VGG-16 flattens the convolution results of layers 1-13 through 3 fully connected layers and outputs the inference result through the calculation of the neuron linear layer.
[0084] In the prior art, due to the unique properties of the fully homomorphic encryption algorithm, it cannot directly support non-linear operations such as comparison and exponentiation, that is, the fully homomorphic encryption algorithm only supports addition and multiplication operations. The ReLU activation function used in the traditional VGG-16 cannot be used in the ciphertext data inference scenario of the present invention. The embodiment of the present invention makes improvements and uses a special second-order polynomial to approximate the non-linear activation function. Specifically, in the VGG-16 network architecture on the cloud server, the embodiment of the present invention replaces the original ReLU activation function with the following activation function: p(x) = αx 2 + βx, where α and β represent the learnable parameters of the activation function, and x represents the input of the activation function layer.
[0085] Optionally, the activation function includes at least two variable learning parameters (α and β). After applying the preset activation function, it further includes: during each data inference using the improved convolutional neural network, training and updating the variable learning parameters in the activation function based on the backpropagation algorithm and the gradient descent method.
[0086] It should be noted that during each data inference using the improved convolutional neural network, the learning parameters need to be trained and updated through the backpropagation algorithm and the gradient descent method. Specifically, when the cloud server receives the ciphertext form of the training data, it directly calculates the loss function of the network on the ciphertext data, and then uses the backpropagation algorithm to calculate the gradients during the ciphertext inference process. These gradients are encrypted, but through the properties of fully homomorphic encryption, addition and multiplication operations can be effectively performed. Then, the gradient descent method is used to update the parameters in the activation function, which can ensure that the model can accurately infer the encrypted data. This process is also carried out in the ciphertext state, avoiding the exposure of plaintext data.
[0087] The specific operation process is as follows: Assume that the objective function followed during neural network training is θ. Then, for the parameters α and β, the updated gradients according to the chain rule should be:
[0088]
[0089] On this basis, the update of the two parameters of this activation layer can be realized by using the gradient descent algorithm.
[0090] Through the above steps, the embodiments of the present invention have achieved remarkable technical effects in the process of solving technical problems: not only protecting the privacy of sensitive data on the user side, but also maintaining the accuracy and computational efficiency of deep neural network inference under the limitations of fully homomorphic encryption through the optimized second-order polynomial activation function.
[0091] In addition, by performing gradient calculation and parameter update in the ciphertext state, the embodiments of the present invention additionally achieve the high efficiency of model training, reduce the computational overhead caused by processing encrypted data, and provide a more feasible and efficient solution for privacy-preserving data inference in the cloud computing environment.
[0092] Step S204: Download the ciphertext inference result from the cloud server, and decrypt the ciphertext inference result based on the private key in the key pair to obtain the plaintext inference result.
[0093] Step S204 is the last step of the technical solution of the present invention, which means that the ciphertext inference result received from the cloud needs to be decrypted on the user side to restore its plaintext form for the user to understand and utilize the inference result. This step not only completes the conversion from encryption to plaintext, but also further improves the usability and accuracy of the inference result through post-processing operations.
[0094] At the user side, first, decrypt the ciphertext inference result downloaded from the cloud server based on the private key in the key pair. Since in step S202, the data is uploaded and inferred in ciphertext form, the decryption process ensures that the user can correctly interpret the inference result. The decryption operation follows the decryption formula of the fully homomorphic encryption algorithm YASHE, and uses the private key held by the user to decrypt the ciphertext inference result to obtain a preliminary plaintext inference result. This operation is the last link in the entire technical solution to ensure data privacy and security, ensuring the encrypted state of the data throughout the transmission and processing process until the final result is safely returned to the user's hands.
[0095] Continuing with the Figure 3 specific deployment plan of the secure inference method based on fully homomorphic encryption mentioned above at the user side. After the neural network is used to complete the inference on the remote cloud server side, the user side downloads the ciphertext inference result from the cloud platform and performs a decryption operation through the private key. Assume that the ciphertext of the image classification result is Then decrypt it with the private key sk = s privately held by the user side, and calculate where f res is the decrypted plaintext inference result.
[0096] After obtaining the preliminary plaintext inference result, post-processing operations need to be performed to improve the quality and readability of the inference result. Optionally, after decrypting the ciphertext inference result based on the private key in the key pair to obtain the plaintext inference result, it further includes: performing post-processing on the plaintext inference result, where the post-processing operation at least includes: rounding operation and scaling operation.
[0097] It should be noted that the post-processing step is to convert the decrypted inference result into a final interpretable and applicable form. The rounding operation and scaling operation ensure the accuracy and applicability of the inference result. Since the precision of the data may be affected by the scaling factor during the fully homomorphic encryption process, the preliminary plaintext inference result after decryption may contain a decimal part, which is unnecessary in some inference tasks (such as classification tasks). The rounding operation can convert the decimal result into an integer; during the encryption stage, the data may be scaled to adapt to the requirements of the fully homomorphic encryption algorithm. After decryption, the preliminary plaintext inference result may need to be adjusted back to the original numerical range through a scaling operation to restore its original scale and precision. As Figure 3 shown, rounding and scaling operations can be performed on f res to obtain the final result of image classification.
[0098] Through the above-mentioned step S204 and the post-processing operation, the embodiments of the present invention achieve the following technical effects in the process of solving technical problems: privacy protection for the entire data life cycle from data encryption, transmission, reasoning to final decryption, accurately converting the ciphertext reasoning result into a plaintext reasoning result in the complex environment of fully homomorphic encryption, and simplifying the user's understanding and utilization of the reasoning result through post-processing operations such as rounding and scaling.
[0099] The above technical effects not only solve the problems of the accuracy and efficiency of deep neural network reasoning in the fully homomorphic encryption scenario, but also ensure the privacy security of the entire reasoning process, providing a comprehensive, efficient, and secure solution for privacy-protected data reasoning in the cloud computing environment. In addition, through the post-processing operation, the embodiments of the present invention additionally achieve the optimization and adjustment of the reasoning result, improve the usability and user satisfaction of the reasoning result, and further promote the application potential of deep learning technology in the field of classified data processing.
[0100] Through the above steps S201 to S204, it is possible to first receive the sensitive data to be reasoned uploaded by the user side, preprocess the sensitive data, then call the pre-generated key pair, encrypt the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be reasoned, then upload the ciphertext data to the cloud server, and the cloud server performs ciphertext reasoning on the ciphertext data based on the improved convolutional neural network architecture to obtain the ciphertext reasoning result, and finally download the ciphertext reasoning result from the cloud server and decrypt the ciphertext reasoning result based on the private key in the key pair to obtain the plaintext reasoning result.
[0101] In the embodiments of the present invention, a method of separating the processing between the user side and the cloud service side is adopted, and privacy protection for the deep learning reasoning process of sensitive data in the cloud computing environment is realized by combining the fully homomorphic encryption technology with the improved convolutional neural network. Specifically, after receiving the sensitive data to be reasoned uploaded by the user side, the embodiments of the present invention first perform necessary preprocessing on the data at the user side to ensure that the data format is compatible with the subsequent encryption steps, and then use the public key in the pre-generated key pair to encrypt the preprocessed sensitive data to obtain the ciphertext data to be reasoned. This process is completely completed in a closed manner at the user side, ensuring the privacy of the data; the encrypted data is uploaded to the cloud server, and the cloud server performs ciphertext reasoning on the ciphertext data based on the improved convolutional neural network architecture. This improved convolutional neural network architecture can effectively process the encrypted data without decryption, so as to complete the deep learning reasoning task without exposing the original data. Finally, the reasoning result is downloaded from the cloud server, and the private key in the key pair is used at the user side to decrypt the ciphertext reasoning result to obtain the plaintext reasoning result, enabling the user to obtain a secure and privacy-protected reasoning result;
[0102] Through the "preprocessing - encryption - ciphertext inference - decryption" process of the embodiments of the present invention, the privacy protection of deep neural network inference in a fully homomorphic encrypted cloud computing environment is effectively achieved. This solution not only ensures the security and privacy protection of sensitive data, but also realizes the high accuracy and computational efficiency of deep learning inference, thus solving the technical problem in the related art that it is difficult to achieve both high accuracy and computational efficiency during deep neural network inference in a fully homomorphic encrypted cloud computing environment, and providing strong technical support for deep learning applications in data - sensitive scenarios.
[0103] The following describes the present invention in conjunction with another optional embodiment.
[0104] Embodiment 2
[0105] A secure inference system based on fully homomorphic encryption provided in this embodiment includes multiple implementation components for implementing each implementation step in Embodiment 1 above.
[0106] Figure 5 is a schematic diagram of an optional secure inference system based on fully homomorphic encryption according to an embodiment of the present invention. As Figure 5 shown, the device may include: a user - side 51 and a cloud - service side 52.
[0107] Among them, the user - side 51 is used to execute any one of the secure inference methods based on fully homomorphic encryption, and at least includes the following steps:
[0108] Step S201: Receive the sensitive data to be inferred uploaded by the user side, and preprocess the sensitive data.
[0109] Further, the step of preprocessing the sensitive data includes: normalizing the sensitive data; flattening the normalized sensitive data to obtain sensitive data in a one - dimensional vector form; and partitioning the one - dimensional vector according to the plaintext space size of the fully homomorphic encryption algorithm to obtain M data - block vectors, where M is a positive integer.
[0110] Step S202: Invoke the pre - generated key pair, and encrypt the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred.
[0111] Further, the step of generating the key pair includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm, and sampling a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; and determining the public key and private key of the user side based on the first random polynomial and the first noise amount to obtain the key pair.
[0112] Further, the step of encrypting the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred includes: randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial, and sampling two noise quantities from a specified error distribution to obtain a second noise quantity and a third noise quantity; for each data block vector in the preprocessed sensitive data, calculating an encrypted data block vector based on the public key, the second random polynomial, the second noise quantity, the third noise quantity, and a predetermined scaling factor according to the fully homomorphic encryption algorithm; combining the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and using this ciphertext matrix as the ciphertext data to be inferred.
[0113] Step S203: Upload the ciphertext data to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result.
[0114] Further, the step of the cloud server performing ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result includes: the cloud server calls the improved convolutional neural network, where the activation function applied by this convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N; the cloud server inputs the ciphertext data into the improved convolutional neural network, performs a convolution operation on the ciphertext data using the convolutional layer, and performs a non-linear transformation operation on the ciphertext data using the activation function to obtain a convolution result; the cloud server integrates the convolution result through the fully connected layer in the convolutional neural network to obtain a ciphertext inference result.
[0115] Further, at least two variable learning parameters are included in the activation function. After applying this preset activation function, it further includes: during each process of using the improved convolutional neural network for data inference, training and updating the variable learning parameters in the activation function based on the backpropagation algorithm and the gradient descent method.
[0116] Step S204: Download the ciphertext inference result from the cloud server, and decrypt the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result.
[0117] Further, after decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result, it further includes: performing post-processing on the plaintext inference result, where the post-processing operation at least includes: rounding operation and scaling operation.
[0118] The cloud server 52 is used to receive the ciphertext data uploaded by the user side and perform ciphertext inference on the ciphertext data using the improved convolutional neural network, where the activation function applied by the convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N.
[0119] In the embodiments of the present invention, a method of separating the client and the cloud server is adopted, and a means of combining the fully homomorphic encryption technology with an improved convolutional neural network is used to achieve privacy protection for the deep learning inference process of sensitive data in a cloud computing environment. Specifically, in the embodiments of the present invention, after receiving the sensitive data to be inferred uploaded by the user side, the data is first preprocessed on the client side to ensure that the data format is compatible with subsequent encryption steps. Subsequently, the public key in the pre-generated key pair is used to encrypt the preprocessed sensitive data to obtain the ciphertext data to be inferred. This process is completely completed in a closed manner on the client side, ensuring the privacy of the data. The encrypted data is uploaded to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture. This improved convolutional neural network architecture can effectively process the encrypted data without decryption, thereby completing the deep learning inference task without exposing the original data. Finally, the inference result is downloaded from the cloud server, and the private key in the key pair is used on the client side to decrypt the ciphertext inference result to obtain the plaintext inference result, enabling the user to obtain a secure and privacy-protected inference result;
[0120] Through the "preprocessing-encryption-ciphertext inference-decryption" process of the embodiments of the present invention, the privacy protection of deep neural network inference in a fully homomorphic encrypted cloud computing environment is effectively realized. This solution not only ensures the security and privacy protection of sensitive data, but also realizes high accuracy and computational efficiency of deep learning inference, thereby solving the technical problem in the related art that it is difficult to achieve both high accuracy and computational efficiency during deep neural network inference in a fully homomorphic encrypted cloud computing environment, providing strong technical support for deep learning applications in data-sensitive scenarios.
[0121] Embodiment III
[0122] A secure inference device based on fully homomorphic encryption provided in this embodiment includes multiple implementation units, and each implementation unit corresponds to each implementation step in Embodiment I above.
[0123] Figure 6 is a schematic diagram of an optional secure inference device based on fully homomorphic encryption according to the embodiments of the present invention, as Figure 6 shown, the device may include: a receiving unit 61, an encryption unit 62, an uploading unit 63, and a downloading unit 64.
[0124] Among them, the receiving unit 61 is used to receive the sensitive data to be inferred uploaded by the user side and preprocess the sensitive data.
[0125] The encryption unit 62 is used to call the pre-generated key pair and encrypt the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred.
[0126] An upload unit 63 for uploading ciphertext data to a cloud server, where the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result.
[0127] A download unit 64 for downloading the ciphertext inference result from the cloud server and decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result.
[0128] The above-mentioned secure inference device based on fully homomorphic encryption can first receive the sensitive data to be inferred uploaded by the user side through the receiving unit 61, preprocess the sensitive data, then call the pre-generated key pair through the encryption unit 62, and encrypt the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred. Then, the ciphertext data is uploaded to the cloud server through the upload unit 63, and the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result. Finally, the ciphertext inference result is downloaded from the cloud server through the download unit 64, and the ciphertext inference result is decrypted based on the private key in the key pair to obtain a plaintext inference result.
[0129] In the embodiment of the present invention, a method of separating the processing between the user side and the cloud service side is adopted, and privacy protection for the deep learning inference process of sensitive data in a cloud computing environment is achieved by combining the fully homomorphic encryption technology with an improved convolutional neural network. Specifically, in the embodiment of the present invention, after receiving the sensitive data to be inferred uploaded by the user side, necessary preprocessing is first performed on the data at the user side to ensure that the data format is compatible with subsequent encryption steps. Subsequently, the preprocessed sensitive data is encrypted based on the public key in the pre-generated key pair to obtain the ciphertext data to be inferred. This process is completely completed in a closed manner at the user side, ensuring the privacy of the data. The encrypted data is uploaded to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture. This improved convolutional neural network architecture can effectively process the encrypted data without decryption, thereby completing the deep learning inference task without exposing the original data. Finally, the inference result is downloaded from the cloud server, and the ciphertext inference result is decrypted using the private key in the key pair at the user side to obtain a plaintext inference result, enabling the user to obtain a secure and privacy-protected inference result.
[0130] Through the "preprocessing - encryption - ciphertext inference - decryption" process of the embodiments of the present invention, the privacy protection of deep neural network inference in a fully homomorphic encryption cloud computing environment is effectively achieved. This solution not only ensures the security and privacy protection of sensitive data, but also realizes the high accuracy and computational efficiency of deep learning inference, thus solving the technical problem in the related art that it is difficult to achieve both high accuracy and computational efficiency during deep neural network inference in a fully homomorphic encryption cloud computing environment, and providing strong technical support for deep learning applications in data - sensitive scenarios.
[0131] Further, the receiving unit includes: a normalization processing module for normalizing sensitive data; a flattening processing module for flattening the normalized sensitive data to obtain sensitive data in the form of a one - dimensional vector; and a chunking module for chunking the one - dimensional vector according to the plaintext space size of the fully homomorphic encryption algorithm to obtain M data block vectors, where M is a positive integer.
[0132] Further, the secure inference device based on fully homomorphic encryption includes: a first sampling module for randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm and sampling a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; and a determination module for determining the public key and private key of the user side based on the first random polynomial and the first noise amount to obtain a key pair.
[0133] Further, the encryption unit includes: a second sampling module for randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial and sampling two noise amounts from a specified error distribution to obtain a second noise amount and a third noise amount; a calculation module for, for each data block vector in the pre - processed sensitive data, calculating an encrypted data block vector based on the public key, the second random polynomial, the second noise amount, the third noise amount, and a pre - determined scaling factor according to the fully homomorphic encryption algorithm; and a combination module for combining the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and using this ciphertext matrix as the ciphertext data to be inferred.
[0134] Further, the secure inference device based on fully homomorphic encryption further includes: a calling module for the cloud server to call an improved convolutional neural network, where the activation function applied by this convolutional neural network is a preset second - order polynomial function for the fully homomorphic encryption environment with the number of terms being a specified value N; an input module for the cloud server to input the ciphertext data into the improved convolutional neural network, performing a convolution operation on the ciphertext data using the convolutional layer, and performing a non - linear transformation operation on the ciphertext data using the activation function to obtain a convolution result; and an integration module for the cloud server to integrate the convolution result through the fully - connected layer in the convolutional neural network to obtain a ciphertext inference result.
[0135] Furthermore, the activation function includes at least two variable learning parameters. The secure inference device based on fully homomorphic encryption further includes: a training and updating module, configured to, after applying the preset activation function, during each data inference process using the improved convolutional neural network, train and update the variable learning parameters in the activation function based on the backpropagation algorithm and the gradient descent method.
[0136] Furthermore, the secure inference device based on fully homomorphic encryption further includes: a post-processing module, configured to, after decrypting the ciphertext inference result using the private key in the key pair to obtain the plaintext inference result, perform post-processing on the plaintext inference result, where the post-processing operations at least include: rounding operation and scaling operation.
[0137] The above-mentioned secure inference device based on fully homomorphic encryption may further include a processor and a memory. The above-mentioned receiving unit 61, encryption unit 62, uploading unit 63, downloading unit 64, etc. are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions.
[0138] The above-mentioned processor includes a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set. By adjusting the kernel parameters, the ciphertext data is uploaded to the cloud server, and the cloud server performs ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result, downloads the ciphertext inference result from the cloud server, and decrypts the ciphertext inference result using the private key in the key pair to obtain the plaintext inference result.
[0139] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash RAM (flash RAM), and the memory includes at least one storage chip.
[0140] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program initialized with the following method steps: receiving sensitive data to be inferred uploaded by a user party; preprocessing the sensitive data, then calling a pre-generated key pair, encrypting the preprocessed sensitive data using the public key in the key pair to obtain ciphertext data to be inferred; uploading the ciphertext data to the cloud server, and the cloud server performing ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result; downloading the ciphertext inference result from the cloud server, and decrypting the ciphertext inference result using the private key in the key pair to obtain the plaintext inference result.
[0141] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the secure inference method based on fully homomorphic encryption according to any one of the above-mentioned Embodiment 1.
[0142] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, which includes one or more processors and a memory. The memory is used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the secure inference method based on fully homomorphic encryption according to any one of the above-mentioned Embodiment 1.
[0143] Figure 7 is a structural block diagram of an electronic device for executing the secure inference method based on fully homomorphic encryption according to an embodiment of the present invention. As Figure 7 shown, the electronic device may include: one or more ( Figure 7 only one is shown in the figure) processors 702, a memory 704, a storage controller, and a peripheral interface. The peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0144] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the secure inference method and device based on fully homomorphic encryption in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned secure inference method based on fully homomorphic encryption. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0145] Those of ordinary skill in the art can understand that Figure 7 the structure shown is only schematic. The electronic device may also be a terminal device such as a smart phone, a tablet computer, a handheld computer, and a mobile Internet device (MID), a PAD, etc. Figure 7 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than Figure 7 shown in the figure, or have a different configuration from Figure 7 shown in the figure.
[0146] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0147] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0148] In the above embodiments of the present invention, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0149] In the several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in an electrical or other form.
[0150] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0151] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0152] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc.
[0153] The foregoing are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A secure inference method based on fully homomorphic encryption, characterized in that Including: Receiving sensitive data to be inferred uploaded by the user side, and preprocessing the sensitive data; Invoking a pre-generated key pair, encrypting the preprocessed sensitive data based on the public key in the key pair to obtain ciphertext data to be inferred; Uploading the ciphertext data to a cloud server, and the cloud server performing ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result; Downloading the ciphertext inference result from the cloud server, and decrypting the ciphertext inference result based on the private key in the key pair to obtain a plaintext inference result.
2. The security inference method according to claim 1, wherein The step of preprocessing the sensitive data includes: Performing normalization processing on the sensitive data; Performing flattening processing on the normalized sensitive data to obtain sensitive data in the form of a one-dimensional vector; Partitioning the one-dimensional vector according to the plaintext space size of the fully homomorphic encryption algorithm to obtain M data block vectors, where M is a positive integer.
3. The security inference method according to claim 1, characterized in that The generation step of the key pair includes: Randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm, and sampling a noise amount from a specified error distribution to obtain a first random polynomial and a first noise amount; Determining the public key and private key of the user side based on the first random polynomial and the first noise amount to obtain the key pair.
4. The security inference method according to claim 1, wherein The step of encrypting the preprocessed sensitive data based on the public key in the key pair to obtain ciphertext data to be inferred includes: Randomly selecting a polynomial in the plaintext space of the fully homomorphic encryption algorithm to obtain a second random polynomial, and sampling two noise amounts from a specified error distribution to obtain a second noise amount and a third noise amount; For each data block vector in the preprocessed sensitive data, calculating an encrypted data block vector based on the public key, the second random polynomial, the second noise amount, the third noise amount, and a pre-determined scaling factor according to the fully homomorphic encryption algorithm; Combining the M encrypted data block vectors according to the fully homomorphic encryption algorithm to obtain a ciphertext matrix, and using the ciphertext matrix as the ciphertext data to be inferred.
5. The security inference method according to claim 1, wherein The step that the cloud server performs ciphertext inference on the ciphertext data based on an improved convolutional neural network architecture to obtain a ciphertext inference result includes: The cloud server invoking the improved convolutional neural network, where the activation function applied by the convolutional neural network is a second-order polynomial function preset for the fully homomorphic encryption environment, and the number of terms is a specified value N; The cloud server inputting the ciphertext data into the improved convolutional neural network, performing a convolution operation on the ciphertext data using a convolutional layer, and performing a non-linear transformation operation on the ciphertext data using the activation function to obtain a convolution result; The cloud server integrating the convolution result through a fully connected layer in the convolutional neural network to obtain the ciphertext inference result.
6. The security inference method according to claim 5, wherein At least two variable learning parameters are included in the activation function, and after applying the preset activation function, it further includes: In the process of each data inference using the improved convolutional neural network, the variable learning parameters in the activation function are trained and updated based on the backpropagation algorithm and the gradient descent method.
7. The security inference method according to claim 1, wherein After decrypting the ciphertext inference result using the private key in the key pair to obtain the plaintext inference result, it further includes: Performing post-processing on the plaintext inference result, where the post-processing operation at least includes: rounding operation and scaling operation.
8. A secure inference system based on fully homomorphic encryption, characterized in that, It includes: A client for executing the secure inference method based on fully homomorphic encryption according to any one of claims 1 to 7; A cloud server for receiving the ciphertext data uploaded by the client and performing ciphertext inference on the ciphertext data using an improved convolutional neural network, where the activation function applied by the convolutional neural network is a preset second-order polynomial function for the fully homomorphic encryption environment, and the number of terms is a specified value N.
9. A secure inference device based on fully homomorphic encryption, characterized in that, It includes: A receiving unit for receiving the sensitive data to be inferred uploaded by the user side and preprocessing the sensitive data; An encryption unit for calling the pre-generated key pair and encrypting the preprocessed sensitive data based on the public key in the key pair to obtain the ciphertext data to be inferred; An uploading unit for uploading the ciphertext data to the cloud server, and the cloud server performing ciphertext inference on the ciphertext data based on the improved convolutional neural network architecture to obtain a ciphertext inference result; A downloading unit for downloading the ciphertext inference result from the cloud server and decrypting the ciphertext inference result based on the private key in the key pair to obtain the plaintext inference result.
10. An electronic device, characterized in that, It includes one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the secure inference method based on fully homomorphic encryption according to any one of claims 1 to 7.
Citation Information
Cited By
Productivity collaborative optimization method and system based on knowledge graph
CN121168947A