System for securely determining a decrypted prediction result of a machine learning model

The MPHE framework addresses the security challenges in VFL by using a multi-party homomorphic encryption system to securely determine decrypted prediction results, ensuring the confidentiality of the ML model and preventing data exposure in multi-party environments.

WO2025104487A1PCT designated stage expired Publication Date: 2025-05-22TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Patent Information

Application Number
PCT/IB2023/061654
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

Existing secure inference protocols for vertical federated learning (VFL) face challenges in protecting the confidentiality of model parameters and inputs, especially in multi-party settings, where the central server hosting the inference model should remain untouched, and each participating entity should not know the outcome of the inference model.

Method used

A multi-party homomorphic encryption (MPHE) framework is designed to securely determine decrypted prediction results. This framework involves a system of computing devices with vertically partitioned data, where each device encodes input feature variables, transmits ciphertexts to a first server for evaluation, and then converts and transmits the prediction results to a second server for decryption.

Benefits of technology

The MPHE framework provides an end-to-end secure protocol for conducting inference processing using vertical federated machine learning (vFML) among multi-party environments, ensuring the confidentiality of the ML model and preventing any entity from accessing raw data or intermediate results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2023061654_22052025_PF_FP_ABST
    Figure IB2023061654_22052025_PF_FP_ABST
Patent Text Reader

Abstract

A system for securely determining a decrypted prediction result is disclosed. The system includes a plurality of computing devices, wherein each computing device encodes input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, transmit the ciphertext feature subset to a first server, receive a ciphertext prediction result, convert the ciphertext predication result to obtain a target ciphertext prediction result. The first server comprises a machine learning model that receives the ciphertext feature subset from the computing devices, concatenates the ciphertext feature subsets to determine a complete ciphertext, evaluate the complete ciphertext to output a ciphertext prediction result, and transmit the same to the computing devices. The second server receives the target ciphertext prediction results, aggregates the respective target ciphertext prediction results to obtain an aggregated target ciphertext prediction result, and decrypts the same to obtain a decrypted prediction result.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM FOR SECURELY DETERMINING A DECRYPTED PREDICTION RESULT OF A MACHINE LEARNING MODELTECHNICAL FIELD[1] The present disclosure relates generally to communications, and more particularly to communication methods and related devices and network nodes configured to securely determine decrypted prediction results of a machine learning model.BACKGROUND[2] A common problem with machine learning (ML) algorithm development is data scarcity. A single party may not have sufficient data to build an accurate model, so building a model with data from multiple sources has many benefits. For example, a hospital may want to collaborate with other medical institutions on a diagnostic system. Vertical Federated Learning (VFL) has been utilized to allow multiple parties to collaboratively train inference machine learning models, such that each individual party can keep its own data. In addition to VFL, data and model security issues existing in the inference phase can be a cause of significant concern. Encryption protocols are often used to protect data and model privacy.[3] Single-Party Homomorphic Encryption based Secure Neural Network Inference Protocol[4] Cryptographic tools, such as Homomorphic Encryption (HE) which allows for computation on encrypted data, have been widely applied in building a secure neural network (NN) inference protocol. A pure HE-based protocol typically protects the model parameters as well as the architecture of the model. CryptoNets was the earliest work to use HE on neural network inference. In particular, CryptoNets replaced the HE-incompatible rectified linear unit (ReLU) activations with a quadratic function, which provides low accuracy results. Other similar works focus on the optimization of the approximated polynomials for activation functions. One such work uses different HE schemes for ReLU functions and other linear functions, and needs to switch between two HE schemes to evaluate the model, thus leading to high computational costs. Such pure HE-based secure inference protocols have been well studied when the input to the model is provided by a single party. However, single party HE cannot be easily extended to multi-party HE (MPHE).[5] Multi-Party Encryption-based Vertical Federated Learning Protocol[6] Existing encryption-based secure vertical federated learning (VFL) protocols (not including MPHE) naturally support the inference, but are characterized by several limitations.For example, a secure logistic regression training protocol can be used when training data is distributed across two clients. There are typically three parties, two data holders and one coordinator (e.g., a central server provides limited operation / coordination) in its system, which increases the system complexity. This protocol relies on the plain HE schemes. So, if the secret key holder compromises to the attacker, all the encrypted messages can be decrypted and there is no privacy at all. In other systems, it designed an N-client vertical federated learning framework relying on functional encryption scheme. The protocol is model-specific and can be applied to linear model and a support vector machine (SVM) with non-linear kernels. Additionally, the protocol does not provide strong security guarantees. For example, it requires the server to share the plaintext model parameters with all clients, which undermines the confidentiality of the model. Furthermore, the protocol reveals intermediate results of the computation to the server. Eastly, the server can easily perform mix-and-match attacks where the server uses the secret key of tthiteration to decrypt the ciphertext of some other iteration t' t. This can leak a potentially unbounded amount of information about client data to the server.[7] Multi-Party HE-based Federated learning Framework[8] One study proposed the MPHE based system, called POSEIDON, which is only applied for horizontal federated Machine learning. The system proposes an alternative packing approach for the efficient use of single instruction, multiple data (SIMD) operations on encrypted data and provides a generic protocol for evaluating neural networks in the encrypted domain. POSEIDON utilizes a server to send an encrypted model to all the clients in its system to enable the clients to locally perform training on the same model using its own dataset. More precisely, settings in POSEIDON include the following:[9] A central server sends the encrypted ML model (e.g., via ciphertext) to all the participating clients.

[0010] At the client side, the ML model is "ciphertext". The ML model is locally trained using a plaintext dataset.

[0011] The ciphertext model (e.g., gradient or weight) is sent to the central server for a global model update and these parameters (e.g., via ciphertext) are redistributed to all the involved clients.

[0012] The trained ML model (ciphertext) can be pushed to the client for performing the inference or prediction.SUMMARY

[0013] There currently exist certain challenge(s). To design a multi-party secured inference protocol for vertical partitioned data (e.g., the server holding the ML model parameters and clients holding a subset of features), a number of issues need to be properly addressed to protect the confidentiality of model parameters and inputs. For security reasons, the ML model hosted and / or stored in the central server should remain untouched. Further, each participating entity and / or computing device (e.g., client) only contributes and does not know how ML model uses the client’s data. In addition, each participating entity is unaware of the outcome or output of the inference model. The central server hosting the inference model must not know the result(s) of the inference model as well. Only a dedicated predictor server should have knowledge of the inference result, yet should not possess any raw data that is used for the prediction.

[0014] Moreover, existing HE-based secure NN inference models currently being implemented are only applied to a “one client to one server” scenario. In addition, an encryption-based (other than HE) VFL inference models are limited such that they cannot be extended to multiparty setting and cannot protect the confidentiality of model, the input data, and intermediate result. Notably, they apply only to limited models, such as simple ML models.

[0015] Notably, the POSEIDON solution mentioned above was designed for a multi-party client and server setting using MPHE and for horizontal Federated ML. In contrast, the disclosed subject matter is constructed for use of VFL. In addition, the POSEIDON solution pushes the ML model to all clients, and then each client locally trains the received model using its own raw data. But to fulfill the requirements to address the issues list above, it requires the model to be persisted and impacted in a central server. Finally, POSEIDON is a framework designed for secure training purposes, while the disclosed subject matter is designed to provide a protocol that affords only secure inference services.

[0016] To date, no solution can be found to address the security requirements listed above. Hence, a new design of MPHE for the inference application using VFL is needed.

[0017] In one embodiment, the disclosed subject matter includes a system for securely determining a decrypted prediction result via a multi-party homomorphic framework. The system comprises a plurality of computing devices having vertically partitioned data across the plurality of computing devices, wherein a respective computing device from the plurality of computing devices is configured to (i) receive, from a second server, a target public key, (ii) encode a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, (iii) transmit the ciphertext feature subset to afirst server, (iv) receive a ciphertext prediction result from the first server, (v) convert the ciphertext predication result with the target public key to obtain a target ciphertext prediction result, and (vi) transmit the target ciphertext prediction result to the second server.

[0018] The system further includes the first server, which comprises a machine learning (ML) model and configured to (i) receive the ciphertext feature subset from the respective computing devices, (ii) concatenate the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set, (iii) evaluate the complete ciphertext on the ML model with a common rotation key and relinearization key to output a ciphertext prediction result, and (iv) transmit the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

[0019] The system also includes the second server, which is configured to (i) generate a target key pair comprising the target public key and a target private key, (ii) transmit the target public key to the plurality of computing devices, (iii) receive the target ciphertext prediction result from the respective computing devices, (iv) aggregate the respective target ciphertext prediction results received from respective computing devices to obtain an aggregated target ciphertext prediction result, and (v) decrypt the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result

[0020] In one embodiment, the disclosed subject matter includes a method performed by a computing device comprising: receiving, from a second server, a target public key, encoding a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, transmitting the ciphertext feature subset to a first server, receiving a ciphertext prediction result from the first server, converting the ciphertext predication result with the target public key to obtain a target ciphertext prediction result, and transmitting the target ciphertext prediction result to the second server.

[0021] In one embodiment, the disclosed subject matter includes a method performed by a first server comprising a ML model comprising: receiving (1401) a cipher feature subset from respective computing devices from a plurality of computing devices (106-110, 1200), concatenating (1402) the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set, evaluating (1403) the complete ciphertext on the ML model with a common rotation key and relinearization key to output a ciphertext prediction result, and transmitting the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

[0022] In one embodiment, the disclosed subject matter includes a method performed by a second server comprising: generating a target key pair comprising a target public key and a targetprivate key, transmitting the target public key to the plurality of computing devices, receiving the target ciphertext prediction result from respective computing devices from the plurality of computing devices, aggregating the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result, and decrypting the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

[0023] In one embodiment, the disclosed subject matter includes a computing device comprising: processing circuitry and memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the computing device to perform operations comprising: receive, from a second server, a target public key, encode a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, transmit the ciphertext feature subset to a first server, receive a ciphertext prediction result from the first server, convert the ciphertext predication result with the target public key to obtain a target ciphertext prediction result, and transmit the target ciphertext prediction result to the second server.

[0024] In one embodiment, the disclosed subject matter includes a non-transitory computer readable medium including program code to be executed by processing circuitry of a computing device, whereby execution of the program code causes the program code to perform operations comprising: receive, from a second server, a target public key, encode a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, transmit the ciphertext feature subset to a first server, receive a ciphertext prediction result from the first server, convert the ciphertext predication result with the target public key to obtain a target ciphertext prediction result, and transmit the target ciphertext prediction result to the second server.

[0025] In one embodiment, the disclosed subject matter includes a first server comprising processing circuitry and memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the first server to perform operations comprising: receive a cipher feature subset from respective computing devices from a plurality of computing devices, concatenate the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set, evaluate the complete ciphertext on a ML model with a common rotation key and relinearization key to output a ciphertext prediction result, transmit the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

[0026] In one embodiment, the disclosed subject matter includes a non-transitory computer readable medium including program code to be executed by processing circuitry of a first server, whereby execution of the program code causes the program code to perform operations comprising: receive a cipher feature subset from respective computing devices from a plurality of computing devices, concatenate the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set, evaluate the complete ciphertext on a ML model with a common rotation key and relinearization key to output a ciphertext prediction result, and transmit the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

[0027] In one embodiment, the disclosed subject matter includes a second server comprising processing circuitry and memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the second server to perform operations comprising: generate a target key pair comprising a target public key and a target private key, transmit the target public key to the plurality of computing devices, receive the target ciphertext prediction result from respective computing devices from the plurality of computing devices, aggregate the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result, and decrypt the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

[0028] In one embodiment, the disclosed subject matter includes a non-transitory computer readable medium including program code to be executed by processing circuitry of a second server, whereby execution of the program code causes the program code to perform operations comprising: generate a target key pair comprising a target public key and a target private key, transmit the target public key to the plurality of computing devices, receive the target ciphertext prediction result from respective computing devices from the plurality of computing devices, aggregate the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result, and decrypt the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

[0029] Certain embodiments may provide one or more of the following technical advantage(s). Notably, the disclosed subject matter provides an end-to-end secure protocol to conduct the inference processing using vertical federated ML (vFML) among multi-party environments. Significant advantages include the collection of data from multiple data sources owned by different service providers for vFML, without disclosing data to any entity or party. Further, thedisclosed subject matter decouples the model (vFML) from the data source, thereby providing high confidentiality of the ML model.

[0030] In the disclosed secure inference application, the ML model (either plaintext or ciphertext) is deployed on a central server (i.e., a ‘first server’). The model information is highly confidential and extensive measures are taken to protect it. Further, the ML model is left untouched on the central server, thereby preventing any participating entity from inferring any information about the ML model beyond the structure of the first layer. As such, each participating entity only contributes input data and is unaware of the kind of model that uses its data. Furthermore, the disclosed subject matter also provides an alternative configuration wherein the parameters are encrypted in ciphertext. In such a scenario, even the server cannot access the parameters, thereby ensuring the utmost security.

[0031] In some embodiments, the disclosed subject matter decouples the coordinator and / or predictor from the ML model (vFML), thereby affording full privacy of the prediction results. During the distribution decryption, the central server first broadcasts the ciphertext of the prediction result to all the participated entities. Each entity (e.g.., computing device or client device) generates a partial decryption based on the resulting ciphertext and its own secret key. The coordinator / predictor collects all the partial decryptions to obtain the actual result. Even if the decryption involves all the parties operating in the system, the privacy of the result is well- preserved. Namely, each participating entity does not know the prediction result, and the central server that hosts the inference model does not know the prediction result of such a model. Only the coordinator server (e.g., dedicated predictor server) knows the prediction result without knowing the raw data carried by each entity.BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The accompanying drawings, which are included to provide a further understanding of the disclosure and are incorporated in and constitute a part of this application, illustrate certain nonlimiting embodiments of inventive concepts. In the drawings:

[0033] Figure 1 is a block diagram of an example system that includes a machine learning (ML) model configured to conduct multi-party vertical federated machine learning to securely determine decrypted prediction results according to some embodiments;

[0034] Figure 2 is a block diagram of an example health professional application system configured to securely determine decrypted prediction results according to some embodiments;

[0035] Figure 3 is a flow chart illustrating an example key generation activity setup according to some embodiments;

[0036] Figure 4 is a flow chart illustrating an example computing device side inference model activity diagram according to some embodiments;

[0037] Figure 5 is a flow chart illustrating an example first server-side inference model activity diagram according to some embodiments;

[0038] Figure 6 is a flow chart illustrating a distributed decryption activity diagram according to some embodiments;

[0039] Figure 7 depicts an example packing scheme for convolutional layers according to some embodiments.

[0040] Figure 8 depicts an example packing scheme for vertical partitioned data with a first neural network layer that is a convolutional layer according to some embodiments;

[0041] Figures 9A and 9B depict an example sequential signaling diagram according to some embodiments;

[0042] Figure 10 is a block diagram of an example first server in accordance with some embodiments;

[0043] Figure 11 is a block diagram of an example second server in accordance with some embodiments

[0044] Figure 12 is a block diagram of an example computing device in accordance with some embodiments;

[0045] Figure 13 depicts a flow diagram of steps performed at a computing device in accordance with some embodiments;

[0046] Figure 14 depicts a flow diagram of steps performed at a first server in accordance with some embodiments;

[0047] Figure 15 depicts a flow diagram of steps performed at a second server in accordance with some embodiments;

[0048] Figure 16 depicts an exemplary sample model setting in accordance with some embodiments; and

[0049] Figure 17 depicts an example plot illustrating key setup time versus a number of clients during a setup phase in accordance with some embodiments;

[0050] Figure 18 depicts an example plot illustrating key setup communication cost versus a number of clients during a setup phase in accordance with some embodiments;

[0051] Figure 19 depicts an example plot illustrating encrypted concatenation time versus a number of clients during a setup phase in accordance with some embodiments;

[0052] Figure 20 depicts an example plot illustrating encrypted concatenation communication cost versus a number of clients during a setup phase in accordance with some embodiments;

[0053] Figure 21 depicts an example plot illustrating distribution decryption time versus a number of clients during a setup phase in accordance with some embodiments; and

[0054] Figure 22 depicts an example plot illustrating distribution decryption communication cost versus a number of clients during a setup phase in accordance with some embodiments.DETAILED DESCRIPTION

[0055] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art, in which examples of embodiments of inventive concepts are shown. Inventive concepts may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of present inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be tacitly assumed to be present / used in another embodiment.

[0056] The disclosed subject matter may be implemented as a kind of “prediction-as-a-service solution,” which refers to a scenario in which a service provider deploys its neural network model in the central cloud, and its users who have their own datasets available across different locations. Based on these various user datasets, the prediction of certain feature can be securely provided using the disclosed solution. In the setting of prediction-as-a-service, a secure inference protocol enables the service provider and users to securely interact to conduct the prediction or inference using the model, while still preserving the privacy of both the model and the user’s sensitive data.

[0057] In some embodiments, the disclosed subject matter is conducted with the following assumptions: i) the network communication is fully secure via a suitable security service or protocol, including but not limited to use of: a virtual private network (VPN), hypertext transfer protocol secure (HTTPS), and / or transport layer security (TLS) protocol, ii) the data communicated within the network is encrypted using the existing encryption framework (e.g., public and private keys), and iii) a pre-trained model is deployed in the central server in a secure manner. Notably, the model can be present in one of two forms, either ciphertext or plaintext. If the model owner and service provider are the same, a plaintext model can be used. Otherwise, a ciphertext model is recommended.

[0058] Relying on the MPHE scheme, a privacy-preserving neural network inference protocol for vertically partitioned data is provided by the disclosed subject matter. A novel packing scheme is designed for clients that have a subset of features, which enables the clients generate ciphertexts in a specific format, and allowing servers to form ciphertexts for a complete set of features by aggregating them, regardless of order. Although other solutions may push the model to the client (e.g., a “computing device”), the disclosed subject matter instead reuses the concept for model training on encrypted data and adapts and applies the mechanism to conduct the prediction and / or inference operation using encrypted data as input through the ML model deployed in a cloud-based central server (e.g., a “first server”). The complete set of features is used as an input for the inference model that is built based on VFL. Notably, the input (e.g., complete feature dataset) is ciphertext, but the model may be ciphertext or plaintext, as highlighted above. After the inference phase is completed, the central server will generate a ciphertext of the prediction result, which requires the client and a coordinator server (e.g., a “second server”) to participate in distributed decryption. In the process of distributed decryption, only the coordinator server knows the decryption result, guaranteed by the security feature of MPHE.

[0059] The disclosed subject matter provides a number of key contributions including the introduction of a coordinator and / or predictor server (e.g., frequently referred to herein as a “second server”) in the architecture of a “prediction-as-a-service” system. In some embodiments, the coordinator server is configured to send queries to client devices (e.g., frequently referred to herein as “computing devices”) so that the client devices know i) which data sample(s) is provided to the prediction service as partial input and / or ii) what kind of dataset is expected in order to construct the input for the prediction / inference model deployed in central server. In particular, a query can include recording identifiers, such as names or universal identification numbers. The coordinator server is further configured to decrypt the prediction result. During the procedure, no entity or party except for the coordinator obtains the actual value of the prediction result, thereby ensuring end-to-end security.

[0060] Another key contribution afforded by the disclosed subject matter is that "Public Key Switching" is applied to Full Secure Decryption between the client devices and the coordinator server. Notably, homomorphic encryption allows ciphertext to be transformed and / or converted from one public key to another public key without revealing the plaintext. In some embodiments, the prediction result ciphertext is initially encrypted with a common public key provided by all client devices, while the corresponding common secret keys are distributedamong the client devices. As such, there is no way to decrypt the prediction result ciphertext directly.

[0061] To address the information leakage issue that may occur during the decryption phase, the coordinator server is configured to generate a target key pair (e.g., a target public key and a target private key) and broadcasts a target public key to the client devices. In the distributed decryption process, the central server broadcasts the ciphertext of the prediction result to the client devices, wherein each client device uses the target public key of the coordinator server to convert the obtained ciphertext into a new ciphertext encrypted under the target public key. The new ciphertexts from all clients are then forwarded to and aggregated by the coordinator server, which decrypts the encrypted prediction result using the target private key.

[0062] This approach is advantageous over traditional approaches because the disclosed system is not vulnerable to eavesdropping attacks, such as where a malicious attacker can recover messages from transmitted ciphertexts by eavesdropping on all client-side coordinator channels.

[0063] Another key contribution is that the disclosed system applies an MPHE scheme to build a N-party secure inference protocol for vertical partitioned data. In addition, the disclosed subject matter provides a novel packing scheme for vertical partitioned data. In some embodiments, the new packing scheme allows client devices to generate unique formatted ciphertexts. These ciphertexts from the client device can be added together (e.g., concatenated) to form the ciphertext for the complete sample, regardless of order. One advantage afforded by the packing scheme include anonymity of the ciphertext. In particular, anonymity ensures the ciphertext does not contain any information about the identity and / or feature structure of the clients. Further, the disclosed packing scheme provides flexible modularity. More specifically, it is easy to plug the packing scheme in other HE-based secure inference protocols, with input from single client, to enable secure inference with input that is vertically distributed among multiple clients.

[0064] In some embodiments, the disclosed solution system components broadly include N clients (e.g., computing devices), one central server (e.g., a first server), and one coordinator / predictor server (e.g., a second server), as shown in Figure 1. Figure 1 depicts a communication system 100 that depicts a multi-party vertical federated ME being used to conduct a prediction using the multi-layer ML model deployed in the central server. More specifically, Figure 1 depicts communication system 100 that includes a first server 104 that is communicatively connected to a plurality of computing devices 106-110. Although only three computing devices are depicted in Figure 1, more or less computing devices may be utilized without departing from the scope of the disclosed subject matter. In some embodiments, first server 104 may be configured to host and / or store ML model 114. Computing devices 106-110 may be client devices that arecommunicatively connected to a second server 112. In some embodiments, second server 112 may be configured to host and / or store target ciphertext decryption engine 120 (e.g., a software component configured to decrypt encrypted target prediction result ciphertexts as described below). In some embodiments, each of the first sever and second server are hosted and / or located on separate physical servers. In other embodiments, the first server and second server are hosted and / or located on a single physical server. System 101 may also include a model owner entity 102, which may be a third-party model provider or a server itself that is configured to deploy a pretrained ML model to first server 104 with two model options: plaintext or ciphertext.

[0065] In some embodiments, each of the computing devices 106-110 owns subset of features A,. The complete feature set X = [Xo11 ... 112d / v_x] is the concatenation of subsets of features. Notably, first server 104 may be configured to receive the subset of features from computing devices 106-110 and perform the concatenation of subsets in order to derive an encrypted prediction outcome. The encrypted prediction outcome is then sent by the first server 104 back to all the computing devices 106-110 through MPHE mechanisms. Further, second server 112 (e.g., the coordinator / predictor) works with multi-party computing devices 106-110 to decrypt the prediction outcome.

[0066] The goal of the disclosed subject matter is to enable parties and / or entities to collaboratively compute predictions of deployed models in a privacy-preserving manner. In one exemplary embodiment, an online medical diagnosis platform, which requires multi-party collaboration, may be constructed. As shown in the Figure 2, system 200 includes three MPHE clients 206-210 that function as information sources providing user / patient data. For example, MPHE client 206 may be a computing device that hosts patient history hospital archive (e.g., medical record archives), MPHE client 208 may be a computing device that hosts a cloud-based clinic archive repository, and MPHE client 210 may be a computing device that hosts a cloudbased personal daily monitoring data collection (e.g., data collected by personal sports equipment). Each MPHE client does not know what the other client’s data is and does not know what ML model 220 is on a central server (e.g., represented as a V-FML framework server 204). In some embodiments, ML model 220 is pretrained, such as a pretrained convolutional neural network (CNN). MPHE clients 206-210 will collect and encrypt data using the proposed secure MPHE framework before sending the encrypted data to framework server 204 (e.g., ciphertext based vFML framework). Framework server 204 collects all the information to conduct the secure inference and sends the final encrypted results to MPHE V-FML predictor server 212 via secure MPHE framework 202. Notably, the final diagnosis result will only be decrypted byMPHE V-FML predictor server 212 and subsequently provided to a remote device (e.g., a remote server and / or computing device) associated with the service provider, such as a health professional online service 214 shown in Figure 2. Moreover, users 216 and / or patients 218 utilizing this health professional online service 214 may subsequently discover if they have been characterized as being in either a good or bad health condition.

[0067] Protocol Description

[0068] Privacy-preserving inference can be achieved by applying a multi-party homomorphic encryption scheme to neural network operations. Notably, there are three phases: the key setting phase, the inference phase, and the distribution decryption phase.

[0069] In some embodiments, the system initially conducts a target key generation and delivery operation. For example, the coordinator and / or prediction server (e.g., second server) generates a pair of target keys (tpk, tsk ) and transmits the target public key, tpk, to all the clients (e.g., computing devices) in the system.

[0070] Figure 3 depicts a flow chart illustrating an example method 300 for key generation activity setup according to some embodiments. After the target key generation and delivery operation is conducted, the system executes method 300 for conducting a client key generation and delivery operation. In step 301 of Figure 3, each client executes an MPHE key-generation algorithm to obtain common HE keys: secret key ski, public key pki, rotation key rtki, and relinearization key rlki. In step 302, these keys are then transmitted by each client to the central server (e.g., first server).

[0071] In step 303, a determination is made as to whether all of the clients provided their respective key share set to the central server. If the clients did so, then the method 300 proceeds to step 304 to initiate the common key generation and delivery process. If not, method 300 loops back to step 302.

[0072] In step 304, the central server aggregates the public keys to generate a common public key by cpk =pk, (i.e., N is the client number). The central server also conducts this same process to aggregate a common rotation key crtk and a common relinearization key crlk for the first round, which involves a round of first-time interaction between the central server and the clients. Afterwards, the central server broadcasts the common public key, common rotation key, and common relinearization key to all clients. In step 305, each client receives the common public keys and the first-round relinearization key share aggregation. In step 306, each client generates a relinearization key share for the second round and sends the generated key share to the central server. In step 307, the central server will receive the second-round relinearization key share from each of the clients. In step 308, a determination is made as towhether all of the clients provided their second round relinearization key share to the central server. If the clients did so, then the method 300 proceeds to step 309. If not, method 300 loops back to step 307.

[0073] In step 309, the central server generates a common relinearization key. The setup phase is only performed once at the beginning of the protocol.

[0074] After the system conducts the key generation activity processing described in Figure 3, the system may be configured to conduct prediction / inference processing using MPHE and vFML. In some embodiments, the system conducts a pre- setup phase for the prediction / inference processing. A first step of pre-setup processing includes transformation of the ML model. Since Homomorphic Encryption does not support nonlinear operations, all nonlinear layers of the model (e.g., ReLU) are replaced with approximate polynomial functions (e.g., (%) = x2). The transformed model is then trained and may achieve similar accuracy to the original model with nonlinear layers.

[0075] Afterwards, the system executes a second step of pre-setup processing includes deployment of the ML model on the central server. In some embodiments, there are two model deployment options for model owner: 1) a plaintext model deployment or 2) a ciphertext model deployment. The first option involves a plaintext model deployed on the central server, resulting in faster execution. In some embodiments, the model owner may transmit the plaintext model via existing traditional secure communication protocols, such as TLS. If the model owner and service provider are the same entity, the plaintext model can be used. Otherwise, the ciphertext model is recommended. The second option involves a ciphertext model deployed on the central server, leading to end-to-end security of framework. In this scenario, model parameters are not leaked to the central server.

[0076] While the plaintext model deployment is largely described herein, execution of a ciphertext model deployment may be easily implemented and extendable without departing from the scope of the disclosed subject matter. In a plaintext model deployment, the pre-trained plaintext model is deployed on the central server for purposes of executing the inference / prediction functionality. During the inference phase, the weights of the deployed ML model are never provided to clients.

[0077] In a ciphertext model deployment, the ciphertext model (which is encrypted using the common public key) is deployed on the central server for purposes of executing the inference / prediction functionality. During the inference phase, the ciphertext model is never shared with the clients and the model parameters are not leaked to the central server.

[0078] In some embodiments, the disclosed subject matter includes a unique packing scheme for vertical partitioned data. For example, the central server notifies each client of its respective packaging scheme (i.e., feature index held by that client). This packaging scheme allows clients to generate specially formatted ciphertexts. In some embodiments, the clients generate ciphertext according to the instruction / packaging scheme. The central server collects these ciphertexts from the clients and performs a ciphertext assembly to form the ciphertext of the complete sample, which is in no particular order (e.g., as discussed in greater detail below).

[0079] Figure 4 is a flow chart illustrating an example computing device side (e.g., client side) inference model activity method diagram of method 400 according to some embodiments. In some embodiments, there is an assumption that a complete data sample is partitioned by columns. In such instances, each client only holds ‘n’ columns of the complete data sample, and there is no overlap between the column indexes held by each client. In step 401, a feature vector is generated using the packing scheme. For example, each client may be configured to encode the features in a feature vector using the disclosed “Packing Scheme for Vertical Partitioned Data.”

[0080] In step 402, the feature vector is encrypted. In some embodiments, each client subsequently uses the common public key to encrypt the plaintext of the subset features.

[0081] In step 403, the ciphertext is transmitted to the server. In some embodiments, after each client completes the data encryption step 402, each client then transmits the ciphertext of the packaged subset features to the central server.

[0082] After the central server receives the ciphertext from each of the clients, the central server executes a number of server-side activities. This is represented in Figure 5, which depicts an example method 500 for delivering the prediction result to all of the clients.

[0083] In step 501, the cipher text is received from one or more clients. In step 502, the central server conducts a check to determine if all clients have provided their own ciphertexts. If so, each client's ciphertexts can be concatenated together (in step 503) by the central server to form a complete sample (including all features) ciphertext, regardless of order.

[0084] In step 504, the neural network is evaluated on the ciphertext. For example, the central server may evaluate the complete sample ciphertext on the neural network with a common rotation key and a common relinearization key. The central server ultimately outputs the prediction result ciphertext.

[0085] In step 505, the central server transmits the ciphertext of the prediction result to all clients. Notably, this step does not decrypt the prediction result. The semantic security of the MPHE scheme ensures that the server will not discover and / or learn intermediate prediction results.

[0086] In some embodiments, the disclosed subject matter is configured to execute distribution decryption activities. To ensure that the inference results are only known to the coordinator server and resist eavesdropping attacks (e.g., by eavesdropping on every communication channel in the system, the attacker obtains all the ciphertexts transmitted from the clients and can recover the original messages), the disclosed subject matter applies a distributed prediction result decryption mechanism. For example, the system may utilize public-key-switching and distribute-decryption functionalities involving every client, which decrypts and only permits the coordinator server to decrypt and / or learn the inference results.

[0087] More specifically, the public-key-switching technique allows the conversion of ciphertext from one public key to another public key without revealing the plaintext to perform decryption. The prediction result ciphertext is initially encrypted using a common public key contributed by all clients. The disclosed subject matter involves the coordinator server generating a target key pair (e.g., a target public key and a target private key) and broadcasting the target public key to the clients. In the distributed decryption process, the central server initially broadcasts the ciphertext of the prediction result to all clients. The subsequent distribution decryption activity process is depicted in the flow chart of method 600 in Figure 6. In step 601 of Figure 6, a client generates a ciphertext by key switching using a target public key from the coordinator server. In some embodiments, each of the clients use the coordinator server's target public key to convert the prediction result ciphertext to a new and different prediction result ciphertext. In step 602, the coordinator server receives the ciphertext from the clients. In step 603, the coordinator server determines if it has received a prediction result ciphertext from all of the clients. If the coordinator server has received a prediction result from each of the clients, method 600 continues to step 604. Otherwise, method 600 loops bac to step 602.

[0088] In step 604, the coordinator server is configured to aggregate the prediction result ciphertexts received from the clients. More specifically, the new converted prediction result ciphertexts from all of the clients are aggregated by the coordinator server, which then decrypts the result using the target private key (i.e., a target secret key). Hence, this method affords an advantage over traditional methods of safely revealing predicted results to a designated entity (i.e., the coordinator server and / or a subscribed entity communicating with the coordinator server).

[0089] As previously indicated, the disclosed subject matter includes and / or utilizes a novel packing scheme for vertical partitioned data. The disclosed packing scheme permits each client to convert raw data input into a special format ciphertext to execute the proposed protocol. The central server (e.g., first server) collects these ciphertexts generated by the client(s) using thispackaging scheme, and then aggregates the ciphertexts (in no particular order) to form the ciphertext of the complete sample.

[0090] In some embodiments, the packing scheme is dependent on the first layer type of the deployed model. For example, an example neural network used for the disclosed solution may be a CNN. The CNN is never shared with the clients (i.e., the CNN only prepares and sends data to the clients), and the first layer in the central server side is a convolutional layer. Notably, this packing scheme can be extended to the case where the first layer of the deployed ML model is a fully connected layer or other types of layers.

[0091] In some embodiments, it may be assumed that the data is non-distributed and is a single complete sample that may be processed by the disclosed Packing Scheme for Convolutional Layers.

[0092] In some embodiments, the packing scheme for convolutional layers is applied to a complete sample (e.g., with width Fwand height FH), filter shape ( , ), stride s and padding. As shown in Figure 7, the single sample 700 is decomposed into p shares 702 (e.g., Figure 7 depicts p = 25 shares) according to the size of a filter 708. The shares 702 are then vectorized and packed into ciphertext vectors 706 in order. The ciphertext vector 706 is then padded with 0s at the end to extend it to a power-of-two length. As for the filter 708, it is first vectorized into vectorized filter 710. Afterwards, vectorized filter 708 is replicated p times and extended with 0s to a power-of- two length.

[0093] Since the data is vertically partitioned across clients, rather than a full sample, an additional step is required on top of the 2-packing scheme described above.

[0094] In some embodiments, the Packing Scheme for Vertical Partitioned Data further includes, for each client, the padding the subset features with 0s (i.e., ‘zeros’) according to the feature index the client holds to form the complete sample format. Assuming the first layer of the ML machine on the central server is convolutional layer, the same steps of the Packing Scheme for Convolutional Layer are repeated to generate a subset feature ciphertext. As such, the central server only needs to add and / or aggregate the ciphertexts from the client(s) in no particular order to form a ciphertext with complete features.

[0095] Figure 8 depicts how each client packs its subset features assuming the first layer of the ML model on the central server is convolutional layer and a single sample is partitioned by columns c = [c0, c1;. . . C / v- , 0 < Cj < Fw. Each client knows the indexes of the columns the client can access. For example, client i may have access to= X |c, : ci+1] while client ‘N-l’ (where N is equal to the total number of clients) may have access to Xo= X [cN-t: Fw], where the variable ‘X’ represents a column index. Notably, there is no overlap between the columnindexes each client can access. Each client first pads the feature subset (e.g., feature subset 812) to complete the sample and follows the packing scheme to pack the complete sample. After packing the subset features, clients can encrypt the feature subset with a common public key, cpk, generated in the setup phase. Afterwards, each client may send the ciphertext (e.g., encrypted subset feature) to the central server.

[0096] More specifically in Figure 8, N=3 (i.e., three client computing devices are used), F»-5 (i.e., Fii is the data sample width, e.g., 5*5 matrix of samples 802, 804, and 806), and c=[co,ci,C2]. Suppose co=O, ci=2, C2=4 (i.e., data sample division boundary is column 2 and 4) and X is the complete data sample, e.g., sample 802. Further, Xo=X[co:c;]=X[O:2] which indicates that the first client gets access to the first two columns, X7=X[c;:c2]=X[2:4] which indicates that the second client gets access to the third and fourth columns, and X2=X[c2: Fu'|=X|4:51 which indicates that the third client gets access to the last column of sample 802. Notably, sample 802 is a subset feature, e.g., the first two columns X[0:2] that are owned by a first client + zero padding to form a 5x5 matrix to keep the same structure (i.e., 5x5) as the full data sample. The same is true for sample 804 (where the second client owns X[2:4]) and sample 806 (where the third client owns X[4:5]).

[0097] In short, samples 802, 804, 806 represent subset features + zero padding, and they must remain in the same format as the full data sample to generate the complete data streams 812, 814 and 816. Notably, the order in which data streams 812, 814 and 816 are added and / or aggregated is irrelevant as a result of the disclosed packing scheme.

[0098] The disclosed packing scheme may be extended to the case where the first layer of the deployed ME model is a fully-connected layer (or another type of layer). The deployed model can be a generalized linear ML model, such as logistic regression ML model. The packing scheme for a fully connected layer is straightforward. First, the sample is flattened to a vector that is extended with 0s at the end to power-of-two dimensions (e.g., 8192). Weights are also flattened and padded with 0s at the end to form a vector with the same length. Notably, the packing scheme for convolutional layers is a slightly more complicated than the packing scheme for fully connected layers because for convolutional layers, the filter needs to be considered (e.g., decompose the sample into p shares according to the filter size, and then vectorize and pack these shares into ciphertext vectors in order). However, for a fully connected layer, the shares may be directly vectorized and packed. Thus, the packing scheme for a fully connected layer can be considered as a simplified version of the convolutional layer packing scheme. After receiving the ciphertexts from all the clients, the central server may be configured to add theciphertext regardless of the order to generate the ciphertext of the complete features (e.g., adding feature subsets 812, 814, and 816).

[0099] In some embodiments, the disclosed subject matter is also configured to execute serverside cryptographic NN operations (e.g., cryptographic neural network operations used on the central server side). For example, the disclosed subject matter may be used to form the ciphertext of the complete features. This step is performed after receiving the ciphertexts from all the clients. For example, the central server may be configured to add and / or aggregate the ciphertexts received from the clients (i.e., regardless of the order) to generate the ciphertext of the complete features.

[0100] In some embodiments, the server-side cryptographic NN operations further includes determining an inner sum, which is a necessary encryption operation for a convolutional and fully connected layer. To perform an inner-sum homomorphically, the property of HE schemes that allows SIMD and supports basic operations including element-wise addition, element-wise multiplication, and slot rotation is relied upon. Assuming the computation of inner-sum over k slots is desired, the basic operations to perform homomorphically inner-sum on encrypted data are combined as follows: 1) element- wise multiplication between the ciphertext of the packed features and the plaintext of the packed weights to obtain the ciphertext of the multiplication result; 2) homomorphically rotating the ciphertext of the multiplication result to the left by p steps and adding the rotated ciphertext to itself iteratively log2(k) times, where p G { 1, 2, 4, 8, ... }, leading to log2(k) rotations in total.

[0101] In some embodiments, the server-side cryptographic NN operations also includes implementing a Fully Connected Layer. For a fully connected layer, an Inner sum operation is conducted over k slots where k = f (i.e., f is the total number of features). To complete a fully connected layer computation and eliminate the junk values generated during the Inner-sum operation, a masking step may be used to precede the Inner-sum operation. In some embodiments, the central server can generate a masking vector m = [1, 0, 0, ..., 0, 1, 0, ...] where the first element of every f elements is set to “1” while other elements are set to “0”. The central server can encode the masking vector to plaintext. Afterwards, element-wise multiplication between the result ciphertext of Inner-sum and the masking plaintext is performed to complete fully connected layer evaluation.

[0102] In some embodiments, the server-side cryptographic NN operations further includes the use of a Convolutional Layer. To perform a homomorphic evaluation, a convolutional layer may follow the same pipeline as a fully connected layer. First, an Inner sum operation is performed over k slots, where k = h ~x. h (i.e., the filter size). Afterwards, the central server may generatethe masking plaintext, which is generated from a masking vector m = [1, 0, 0, 1, 0, ...] where the first element of every k elements is set to “1” while other elements are set to “0”. Then, element-wise multiplication of the masking plaintext and the result ciphertext of Inner-sum is performed to preserve the result value and eliminate the junk value(s).

[0103] In some embodiments, the server-side cryptographic NN operations also includes the use of Activation Layer. Notably, non-linear activation functions not supported by the HE schemes. Several works have investigated the approximating of non-linear functions to polynomials for a trade-off between accuracy and computational cost.

[0104] For example, ReLU may be approximated to / (x) = x2and / or a least-squares approximation can be used to rely on an optimized polynomial evaluation. For better inference accuracy, a non-linear activation function can be replaced with an approximate activation function when training the ML model.

[0105] Figures 9A and 9B depict an example sequential signaling diagram according to some embodiments of the disclosed subject matter. Notably, the proposed solution may be classified as three distinct phases that are collectively executed by computing devices 960 (e.g., clients), a first server 951 (e.g., a central server), and a second server 952 (e.g., coordination server). The first phase is a key setup phase that includes steps 901-910 in Figure 9 A. The second phase is an inference phase that includes steps 911-914 and the third phase is a distribution decryption phase that includes steps 915-918 as shown in Figure 9B.

[0106] The key setup phase begins at step 901, where second server 952 sends a request to each computing device 960 (e.g., computing device i=l...N, wherein N is the total number of computing devices) for key generation. In step 902, each computing device 960 generates a private / secret key, a public key, a rotation key, and a relinearization key share. As used herein, the relinearization key share refers to a share and / or portion of a relinearization key that the first server 951 requires to create a complete common relinearization key.

[0107] In step 903, each computing device sends the generated public key, rotation key, and relinearization key share to first server 951. In step 904, the first server 951 utilizes the received computing device keys to generate a common public key, a common rotation key, and common relinearization key aggregation for a first round, which refers to a round of first-time interaction between the first server (e.g., central server) and all the computing devices (e.g., clients).

[0108] In step 905, the first server 951 sends the generated common public key and common relinearization key aggregation of the first round to each of the computing devices 960. In step 906, each of the computing devices 960 generates a relinearization key share for a second round.

[0109] In step 907, each of the computing devices 960 sends a common relinearization key share of second round to first server 951. In response, the first server 951 utilizes the received key shares to generate a common relinearization key in step 908.[HO] In step 909, the second server 952 is configured to generate a target key pair that includes a target public key (for encryption) and a target secret / private key (for decryption). After generating the target key pair, the second server sends the target public key to each computing device 960 in step 910.

[0111] The inference phase begins at step 911 where each computing device 960 encodes subset features and subsequently encrypts the encoded features with a common public key to generate ciphertext of the subset features. In step 912, each computing device 960 sends ciphertext of subset features to the first server 951.

[0112] In step 913, the first server 951 is configured to aggregate and / or add the subset feature ciphertext received from all the clients to derive the ciphertext for the complete feature.

[0113] In step 914, the first server 951 evaluates the ciphertext on the neural network (i.e., plaintext or ciphertext) with the common rotation key, and common relinearization key. The first server also outputs the prediction result ciphertext.

[0114] The distribution decryption phase begins at step 915 where the first server 951 is configured to send the prediction result ciphertext to each computing device 960.

[0115] After receiving the prediction result ciphertext, each computing device 960 converts the result ciphertext with the target public key to produce a target prediction result ciphertext in step 916.

[0116] In step 917, each of the computing devices 960 sends the target prediction result ciphertexts to the second server 952. In step 918, the second server 952 adds and / or aggregates the target prediction result ciphertexts to produce a complete target prediction result ciphertext. Afterwards, the second server 952 utilizes the target private key to decrypt the complete target prediction result ciphertext to obtain the decrypted target prediction result.

[0117] Figure 10 is a block diagram of a first server 1000, which may be an embodiment of the first server 104 of Figure 1, in accordance with various aspects described herein. As used herein, the first server 1000 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The first server 1000 may provide one or more services to one or more computing devices and / or clients.

[0118] The first server 1000 includes processing circuitry 1002 that is operatively coupled via a bus 1004 to an input / output interface 1006, a network interface 1008, a power source 1010, and a memory 1012. Other components may be included in other embodiments.

[0119] In some embodiments, processing circuitry 1002 may include a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, any other type of electonic circuitry, or any combination of one or more of the preceding. The processing circuitry 1002 may comprise one or more processor cores. In particular embodiments, some or all of the functionality described herein as being provided by first server 1000 may be implemented by processing circuitry 1002 executing software instructions, either alone or in conjunction with other first server components, such as memory 1012.

[0120] Memory 1012 may store code (which is composed of software instructions and which is sometimes referred to as computer program code or a computer program) and / or data using non- transitory machine-readable (e.g., computer-readable) media, such as machine-readable storage media (e.g., magnetic disks, optical disks, solid state drives, read only memory (ROM), flash memory devices, phase change memory) and machine-readable transmission media (e.g., electrical, optical, radio, acoustical or other form of propagated signals - such as carrier waves, infrared signals). For instance, memory 1012 may comprise non-volatile memory containing code to be executed by processing circuitry 1002. Where memory 1012 is non-volatile, the code and / or data stored therein can persist even when the network device is turned off (when power is removed). In some instances, while first server 1000 is turned on that part of the code that is to be executed by the processing circuitry 1002 may be copied from non-volatile memory into volatile memory (e.g., dynamic random access memory (DRAM), static random access memory (SRAM)) of first server 1000. As shown in Figure 10, memory 1012 may include one or more computer program applications including machine learning (ML) inference model 1014 and ciphertext packing scheme engine 1016. In some embodiments, machine learning inference model 1014 may be a ciphertext encrypted ML model or a plaintext ML model. ML inference model 1014 may be similar in functionality to ML model 114 and ML model 220 as described in Figure 1 and Figure 2, respectively. Moreover, ciphertext packing scheme engine 1016 may be a software program configured to execute the packing scheme for vertical partitioned data as described herein and depicted in Figures 7 and 8.

[0121] Figure 11 is a block diagram of a second server 1100, which may be an embodiment of the second server 112 of Figure 1, in accordance with various aspects described herein. As used herein, the second server 1100 may be or comprise various combinations hardware and / orsoftware, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The second server 1100 may provide one or more services to one or more computing devices and / or clients.

[0122] The second server 1100 includes processing circuitry 1102 that is operatively coupled via a bus 1104 to an input / output interface 1106, a network interface 1108, a power source 1110, and a memory 1112. Other components may be included in other embodiments.

[0123] In some embodiments, processing circuitry 1102 may include a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, any other type of electronic circuitry, or any combination of one or more of the preceding. The processing circuitry 1102 may comprise one or more processor cores. In particular embodiments, some or all of the functionality described herein as being provided by second server 1100 may be implemented by processing circuitry 1102 executing software instructions, either alone or in conjunction with other second server components, such as memory 1112.

[0124] Memory 1112 may store code (which is composed of software instructions and which is sometimes referred to as computer program code or a computer program) and / or data using non- transitory machine-readable (e.g., computer-readable) media, such as machine-readable storage media (e.g., magnetic disks, optical disks, solid state drives, read only memory (ROM), flash memory devices, phase change memory) and machine-readable transmission media (e.g., electrical, optical, radio, acoustical or other form of propagated signals - such as carrier waves, infrared signals). For instance, memory 1112 may comprise non-volatile memory containing code to be executed by processing circuitry 1102. Where memory 1112 is non-volatile, the code and / or data stored therein can persist even when the network device is turned off (when power is removed). In some instances, while second server 1100 is turned on that part of the code that is to be executed by the processing circuitry 1102 may be copied from non-volatile memory into volatile memory (e.g., dynamic random access memory (DRAM), static random access memory (SRAM)) of second server 1100. As shown in Figure 11, memory 1112 may include one or more computer program applications including a target key manager 1114 and a target ciphertext decryption engine 1116. In some embodiments, target key manager 1114 is a software application that allows second server 1100 to generate a target key pair including a target public key and a target private key. Target key manager 1114 may also be configured to distribute the target public key to a plurality of computing devices and / or clients. In some embodiments, target ciphertext decryption engine 1116 is configured to add or aggregate the target ciphertextprediction results and utilize the target private key to decrypt the same to obtain a combined target prediction result.

[0125] Figure 12 is a block diagram of a computing device 1200, which may be an embodiment of any one of the computing devices 106-120 of Figure 1 or clients 206-210 in Figure 2, in accordance with various aspects described herein. As used herein, the computing device 1200 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The computing device 1200 may provide one or more services to one or more computing devices and / or clients.

[0126] The computing device 1200 includes processing circuitry 1202 that is operatively coupled via a bus 1204 to an input / output interface 1206, a network interface 1208, a power source 1210, and a memory 1212. Other components may be included in other embodiments.

[0127] In some embodiments, processing circuitry 1202 may include a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, any other type of electronic circuitry, or any combination of one or more of the preceding. The processing circuitry 1202 may comprise one or more processor cores. In particular embodiments, some or all of the functionality described herein as being provided by computing device 1200 may be implemented by processing circuitry 1202 executing software instructions, either alone or in conjunction with other computing device components, such as memory 1212.

[0128] Memory 1212 may store code (which is composed of software instructions and which is sometimes referred to as computer program code or a computer program) and / or data using non- transitory machine-readable (e.g., computer-readable) media, such as machine-readable storage media (e.g., magnetic disks, optical disks, solid state drives, read only memory (ROM), flash memory devices, phase change memory) and machine-readable transmission media (e.g., electrical, optical, radio, acoustical or other form of propagated signals - such as carrier waves, infrared signals). For instance, memory 1212 may comprise non-volatile memory containing code to be executed by processing circuitry 1202. Where memory 1212 is non-volatile, the code and / or data stored therein can persist even when the network device is turned off (when power is removed). In some instances, while computing device 1200 is turned on that part of the code that is to be executed by the processing circuitry 1202 may be copied from non-volatile memory into volatile memory (e.g., dynamic random access memory (DRAM), static random access memory (SRAM)) of computing device 1200. As shown in Figure 12, memory 1212 may include one or more computer program applications including ciphertext manager 1216. In some embodiments,ciphertext manager 1216 is a software application that allows computing device 1200 to encode and encrypt subtext features with a common public key to produce encrypted subset feature ciphertext. Computing device 1200 may also utilize ciphertext manager 1216 to direct the subset feature ciphertext to a first server. In some embodiments, ciphertext manager 1216 may also be configured to utilize a target public key to convert the prediction result ciphertext (received from the first server) into target prediction result ciphertext that can be provided to the second server.

[0129] Figure 13 is a flow chart diagram depicting an example method 1300 for obtaining a target ciphertext prediction result according to some embodiments. In some embodiments, method 1300 may be a process or algorithm (e.g., ciphertext manager 1216 in Figure 12) that is stored in memory and executed by processing circuitry of one or more computing devices.

[0130] In step 1301, the method 1300 includes receiving, from a second server (e.g., a coordination or prediction server), a target public key.

[0131] In step 1302, the method 1300 includes encoding a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset. In some embodiments, encoding the ciphertext feature subset comprises using a ciphertext packing scheme for the vertically partitioned data. In addition, the ciphertext packing scheme may comprise padding a feature subset with zeros according to a feature index and a single sample of the vertically partitioned data is partitioned by columns.

[0132] In step 1303, the method 1300 includes transmitting the ciphertext feature subset to a first server (e.g., a central server).

[0133] In step 1304, the method 1300 includes receiving a ciphertext prediction result from the first server.

[0134] In step 1305, the method 1300 includes converting the ciphertext predication result with the target public key to obtain a target ciphertext prediction result.

[0135] In step 1306, the method 1300 includes transmitting the target ciphertext prediction result to the second server.

[0136] Figure 14 is a flow chart diagram depicting an example method 1400 for deriving and providing a ciphertext prediction result according to some embodiments. In some embodiments, method 1400 may be a process or algorithm (e.g., machine learning inference model 1014 and / or ciphertext packing scheme engine 1016 in Figure 10) that is stored in memory and executed by processing circuitry of a first server. In some embodiments, the first server is a central server that hosts an ML model. The ML model can either be a ciphertext model encrypted using a common public key, or a plaintext model. In some embodiments, the ML model is a neural network (e.g., a convolutional neural network).

[0137] In step 1401, the method 1400 includes receiving a ciphertext feature subset from respective computing devices from a plurality of computing devices.

[0138] In step 1402, the method 1400 includes concatenating the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set;

[0139] In step 1403, the method 1400 includes evaluating the complete ciphertext on the ML model with a common rotation key and relinearization key to output a ciphertext prediction result.

[0140] In step 1404, the method 1400 includes transmitting the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

[0141] Figure 15 is a flow chart diagram depicting an example method 1400 for deriving and providing a ciphertext prediction result according to some embodiments. In some embodiments, method 1500 may be a process or algorithm (e.g., target key manager 1114 or target ciphertext decryption engine 1116 in Figure 11) that is stored in memory and executed by processing circuitry of a second server (e.g., a coordination or prediction server). In step 1501, the method 1500 includes generating a target key pair comprising a target public key and a target private key. In some embodiments, the second server is a coordinator server and / or a prediction server.

[0142] In step 1502, the method 1500 includes transmitting the target public key to the plurality of computing devices.

[0143] In step 1503, the method 1500 includes receiving the target ciphertext prediction result from respective computing devices from the plurality of computing devices.

[0144] In step 1504, the method 1500 includes aggregating the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result.

[0145] In some embodiments, the method 1500 may include transmitting the decrypted prediction result to a remote device.

[0146] In step 1505, the method 1500 includes decrypting the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

[0147] EXPIREMENTAL RESULTS

[0148] In some embodiments, the disclosed subject matter is executed to produce example experimental results. In particular, experimentation can be conducted to determine the execution time and communication cost for each of the key setup phase, inference phase, and distribution decryption phase.

[0149] In some embodiments, a Lattigo library may be used to implement all proposed algorithms, including key generation, cryptographic cascades, encrypted neural network operations, and distributed decryption. Further, the net package of Golang may be used to build a communication system, such that the experiments can run on one computing machine (e.g., equipped with 8 processing cores andl6 GB RAM).

[0150] Further, the entire protocol may be evaluated with a 2-convolutional layer CNN as shown in Figure 16, which depicts an exemplary sample model setting 1600 in accordance with some embodiments. In some embodiments, the inference performance of this model is evaluated in the ciphertext form and in the plaintext form. Notably, use of the plaintext model may result in faster inference processing while use of the ciphertext model can provide end-to-end security such that even the service provider and / or the central server will not possess knowledge about the deployed model parameters.

[0151] In some embodiments, the dataset used in the experimentation is a Modified National Institute of Standards and Technology (MNIST) dataset. Each MNIST sample is vertically divided into three pieces and distributed among three clients (or computing devices).

[0152] The execution time and communication cost of each phase are shown in the Tables 1 and 2 below. Notably, the generating of the four keys can be parallelized and the setup phase is a onetime execution for the same set of clients, coordinator, and server.Table 1. Cost for the Key Setup PhaseTime cost municotion cost |Inference with 30.64s1542 MB| Plaintext Model | i |Table 2. Cost for Inference and Distribution Decryption Phase

[0153] The main cost is from the setup phase, but is a one-time cost. The time of inference depends on the type (e.g., ciphertext or plaintext) and structure of the deployed Neural Network and is independent of number of clients, while other costs increase as the number of clients increases. Notably, the time required for the various steps involved in the two solutions (whether using the plaintext model or the ciphertext model) will be the same except for the inference time. This is because the replacement of the model (e.g., ciphertext model or plaintext model) only affects the encrypted neural network operations, thus affecting the total inference time.

[0154] Scalability Performance Evaluation

[0155] For each phase, the "key generation" and "ciphertext operations" are closely monitored in order to calculate the scalability performance in terms of execution time and communication cost as the number of clients (e.g., computing devices) increases.

[0156] Key generation can be considered a one-time overhead for the disclosed subject matter. This is because key generation processing only occurs at the deployment phase. It is rarely changed during the prediction service.

[0157] For a ciphertext operation, this is applied in the model inference for every prediction service request.

[0158] In some instances, the hardware and software configuration used to execute the experimentations may comprise four local machines, two that include 8 cores and 16 GB RAM and two that include 8 cores and 32 GB RAM. The library used in this section may be Eattigo.

[0159] With regard to data setup, each full MINIST sample is split into ‘chunks’ based on the number of customers, such that each customer holds a chunk. The customers / parties cooperate to implement the agreement. In the context of vertical federated learning, the data is usuallyvertically partitioned among several large organizations, such as a hospital the aforementioned example. Therefore, the number of such organizations is limited.

[0160] With regard to test cases, experiments can be run with the number of clients ranging from 2 to 14. The time and communication cost of different numbers of clients from the following 6 aspects (6 cases / figures) are evaluated: i) Key Setup Time, ii) Key Setup Communication Cost, iii) Encrypted Concatenation Time, iv) Encrypted Concatenation Communication Cost, v) Distribution decryption Time, and vi) Distribution decryption Communication Cost.

[0161] Referring to plots 1700-2200 depicted Figures 17-22, it can be seen that the time for key setup, the encrypted concatenation, and distribution decryption linearly increase as the number of clients (e.g., client computing devices) increases. Notably, the key setup phase includes the generations of a common public key, common rotation key, and common relinearization key. More specifically, plot 1700 in Figure 17 depicts that as the number of clients increase, the key setup execution time increases. Similarly, plot 1800 in Figure 18 depicts that as the number of clients increase, the key setup communication cost (in megabytes) increases. Figure 19 depicts plot 1900, which shows that as the number of clients increases, the encrypted concatenation execution time increases. Similarly, plot 2000 in Figure 20 depicts that as the number of clients increase, the encrypted concatenation communication cost (in megabytes) increases. Eikewise, plot 2100 in Figure 21 depicts that as the number of clients increase, the distribution decryption execution time increases. Similarly, plot 2200 in Figure 22 depicts that as the number of clients increase, the distribution decryption communication cost (in megabytes) increases.

[0162] It is also assumed that the clients are not resource-constrained, and that all client computing devices being considered are enterprise level (i.e., not iPhone-like devices). As such, client-side resource is not a primary concern.

[0163] Inference Accuracy: Encrypted Inference vs. Non-Encrypted Inference

[0164] In some embodiments, the test accuracy of the Neural Network operating using a i) nonencrypted inference vs. ii) HE-based inference performance (as depicted below in Table 3) are compared.

[0165] For example, the neural network with ReLU is implemented as an activation function. After training on 50,000 MNIST images, the test accuracy on 10,000 MINIST images reaches 98.04%. Afterwards, this model and its parameters is converted to an encrypted model. Since homomorphic encryption does not support non-linear functions, the accuracy dropped to 68.93% for the test dataset.

[0166] Notably, two steps can be used to achieve the reasonable accuracy degradation for HE- based Inference: i) training the model using polynomial approximate activation function (e.g.,f (x2)) to achieve the similar accuracy as the original ReLU activation function and ii) applying HE-operations to the trained model with polynomial approximate activation function.

[0167] Results show that encrypted inference does not degrade the accuracy of models using linear activation functions. Further, the encrypted inference of the model with a polynomial approximation active function reached 97.75% accuracy. Compared to the Non-encrypted Inference accuracy result, the accuracy degradation is very small and acceptable ss shown in Table 3 below.Table 3: Non-encrypted Inference vs. HE-based Inference Performance

[0168] The accuracy of the inference afforded by the plaintext model and ciphertext model may be compared. For example, the same well-retrained model obtained above is used to generate a plaintext version and a ciphertext version that may be tested with the same set of the encrypted images. Results are shown in Table 4.Table 4. HE-based Inference Performance of plaintext model and ciphertext model

[0169] The disclosed subject matter may also be assessed to determine the time complexity of encrypted operations as opposed to runtime. For example, the overhead of the encrypted operations, such as addition, element-wise multiplication, and rotation, is shown below in Table 5. A comparison for the time cost for addition and multiplication between i) ciphertext and plaintext, ii) ciphertext and ciphertext, and iii) two Numpy arrays (all with 8192 slots) is conducted. We also compare the time cost of rotation operated on a ciphertext and a Numpy array (i.e., a rotation to a plaintext vector is not conducted). In Table 5 below, ‘*100’ denotesthat the Numpy operation is performed 100 times, and the operation time is the sum of time for 100 times.Table 5. Operation Complexity

[0170] As indicated in Table 5 above, the rotation operation of the ciphertext takes the longest time. Ciphertext rotation is an essential part of encrypted neural network operations, such as convolution functions and fully connected functions.

[0171] Although the various computer processing devices (e.g., computing devices, clients, central server, coordination server, etc.) described herein may include the illustrated combination of hardware components, other embodiments may comprise computer processing devices with different combinations of components. It is to be understood that these computer processing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions, and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computer processing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0172] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computer processing device, but are enjoyed by the computer processing device as a whole, and / or by end users and a wireless network generally.

Claims

CLAIMSWhat is claimed is:

1. A system (101) for securely determining a decrypted prediction result via a multi-party homomorphic framework, the system comprising: a plurality of computing devices (106-110, 1200) having vertically partitioned data across the plurality of computing devices, wherein a respective computing device from the plurality of computing devices is configured to (i) receive, from a second server (112, 1100), a target public key, (ii) encode a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset, (iii) transmit the ciphertext feature subset to a first server (104, 1000), (iv) receive a ciphertext prediction result from the first server, (v) convert the ciphertext predication result with the target public key to obtain a target ciphertext prediction result, and (vi) transmit the target ciphertext prediction result to the second server; the first server (104, 1000) comprising a machine learning, ML, model (114) and configured to (i) receive the ciphertext feature subset from the respective computing devices, (ii) concatenate the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set, (iii) evaluate the complete ciphertext on the ML model with a common rotation key and relinearization key to output a ciphertext prediction result, and (iv) transmit the ciphertext prediction result to the respective computing devices from the plurality of computing devices; and the second server (112, 1100) configured to (i) generate a target key pair comprising the target public key and a target private key, (ii) transmit the target public key to the plurality of computing devices, (iii) receive the target ciphertext prediction result from the respective computing devices, (iv) aggregate the respective target ciphertext prediction results received from respective computing devices to obtain an aggregated target ciphertext prediction result, and (v) decrypt the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

2. The system of claim 1, wherein the first server is a central server that hosts the ML model.

3. The system of any of claims 1-2, wherein the ML model is either a ciphertext model encrypted using a common public key or a plaintext model.

4. The system of any of claims 1-3, wherein the second server is a coordinator and / or prediction server.

5. The system of any of claims 1-4, wherein a respective computing device from the plurality of computing devices generates the ciphertext feature subset with a ciphertext packing scheme for the vertically partitioned data.

6. The system of any of claims 1-5, wherein the ciphertext packing scheme comprises padding a feature subset with zeros according to a feature index and a single sample of the vertically partitioned data is partitioned by columns.

7. The system of any of claims 1-6, wherein the second server is further configured to transmit the decrypted prediction result to a remote device.

8. The system of any of claims 1-7, wherein the ML model comprises a neural network.

9. A method performed by a computing device (106-110, 1200), the method comprising: receiving (1301), from a second server (112, 1100), a target public key; encoding (1302) a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset; transmitting (1303) the ciphertext feature subset to a first server (104, 1000); receiving (1304) a ciphertext prediction result from the first server; converting (1305) the ciphertext predication result with the target public key to obtain a target ciphertext prediction result; and transmitting (1306) the target ciphertext prediction result to the second server.

10. The method of claim 9, wherein encoding the ciphertext feature subset comprises using a ciphertext packing scheme for the vertically partitioned dataset.

11. The method of claim 10, wherein the ciphertext packing scheme comprises padding a feature subset with zeros according to a feature index and a single sample of the vertically partitioned data is partitioned by columns.

12. A method performed by a first server (104, 1000) comprising a machine learning, ML,model (114), the method comprising: receiving (1401) a ciphertext feature subset from respective computing devices from a plurality of computing devices (106-110, 1200); concatenating (1402) the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of the complete feature set; evaluating (1403) the complete ciphertext on the ML model with a common rotation key and relinearization key to output a ciphertext prediction result; and transmitting (1404) the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

13. The method of claim 13, wherein the first server is a central server that hosts the ML model.

14. The method of any of claims 12-13, wherein the ML model is either a ciphertext model encrypted using a common public key or a plaintext model.

15. The method of any of claims 12-14, wherein the ML model comprises a neural network.

16. A method performed by a second server (112, 1100), the method comprising: generating (1501) a target key pair comprising a target public key and a target private key; transmitting (1502) the target public key to the plurality of computing devices; receiving (1503) a target ciphertext prediction result from respective computing devices from the plurality of computing devices; aggregating (1504) the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result; and decrypting (1505) the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

17. The method of Claim 16, wherein the second server is a coordinator and / or prediction server.

18. The method of any one of Claims 16 to 17, further comprising: transmitting the decrypted prediction result to a remote device.

19. A computing device (106-110, 1200) comprising: processing circuitry (1102); and memory (1112) coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the computing device to perform operations comprising: receive (1301), from a second server (112, 1100), a target public key; encode (1302) a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset; transmit (1303) the ciphertext feature subset to a first server (104, 1000); receive (1304) a ciphertext prediction result from the first server; convert (1305) the ciphertext predication result with the target public key to obtain a target ciphertext prediction result; and transmit (1306) the target ciphertext prediction result to the second server.

20. The computing device of Claim 19, wherein the operations further comprise any of the operations of Claims 10 to 11.

21. A non-transitory computer readable medium including program code to be executed by processing circuitry (1202) of a computing device (106-110, 1200), whereby execution of the program code causes the program code to perform operations comprising: receive (1301), from a second server (112, 1100), a target public key; encode (1302) a plurality of input feature variables from a vertically partitioned dataset with a common public key to generate a ciphertext feature subset; transmit (1303) the ciphertext feature subset to a first server (104, 1000); receive (1304) a ciphertext prediction result from the first server; convert (1305) the ciphertext predication result with the target public key to obtain a target ciphertext prediction result; and transmit (1306) the target ciphertext prediction result to the second server.

22. The non-transitory computer readable medium of Claim 21, the operations further comprising any of the operations of Claims 10 to 11.

23. A first server (104, 1000) comprising: processing circuitry (1002); andmemory (1012) coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the first server to perform operations comprising: receive (1401) a ciphertext feature subset from respective computing devices from a plurality of computing devices (106-110, 1200); concatenate (1402) the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of a complete feature set; evaluate (1403) the complete ciphertext on a machine learning, ML, model (114) with a common rotation key and relinearization key to output a ciphertext prediction result; and transmit (1404) the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

24. The first server of Claim 23, wherein the operations further comprise any of the operations of Claims 13 to 15.

25. A non-transitory computer readable medium including program code to be executed by processing circuitry (1002) of a first server (104, 1000), whereby execution of the program code causes the program code to perform operations comprising: receive (1401) a ciphertext feature subset from respective computing devices (106-110, 1200) from a plurality of computing devices; concatenate (1402) the ciphertext feature subsets received from the respective computing devices to determine a complete ciphertext of a complete feature set; evaluate (1403) the complete ciphertext on a machine learning, ML, model (114) with a common rotation key and relinearization key to output a ciphertext prediction result; and transmit (1404) the ciphertext prediction result to the respective computing devices from the plurality of computing devices.

26. The non-transitory computer readable medium of Claim 25, the operations further comprising any of the operations of Claims 13 to 15.

27. A second server (112, 1100) comprising: processing circuitry (1102); and memory (1112) coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the second server to performoperations comprising: generate (1501) a target key pair comprising a target public key and a target private key; transmit (1502) the target public key to the plurality of computing devices (106-110, 1200); receive (1503) the target ciphertext prediction result from respective computing devices from the plurality of computing devices; aggregate (1504) the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result; and decrypt (1505) the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

28. The second server of claim 27, wherein the operations further comprise any of the operations of Claims 17 to 18.

29. A non-transitory computer readable medium including program code to be executed by processing circuitry (1102) of a second server (112, 1100), whereby execution of the program code causes the program code to perform operations comprising: generate (1501) a target key pair comprising a target public key and a target private key; transmit (1502) the target public key to the plurality of computing devices (106-110, 1200); receive (1503) the target ciphertext prediction result from respective computing devices from the plurality of computing devices; aggregate (1504) the respective target ciphertext prediction results received from the respective computing devices to obtain an aggregated target ciphertext prediction result; and decrypt (1505) the aggregated target ciphertext prediction result with the target private key to obtain a decrypted prediction result.

30. The non-transitory computer readable medium of claim 29, wherein the operations further comprise any of the operations of Claims 17 to 18.

Citation Information

Patent Citations

  • System and method for privacy-preserving distributed training of neural network models on distributed datasets

    WO2022042848A1

Cited By

  • Positive reporting processing method for pathogen targeted high-throughput sequencing data, computer equipment and readable storage medium

    CN121687189A

  • Pathogen-targeted high-throughput sequencing data positive report processing method, computer device and readable storage medium

    CN121687189B