Model service providing method and apparatus capable of protecting data privacy

By performing segmented fitting of activation functions and approximation of higher-order polynomial functions, combined with secure multi-party computing technology, the problem of large computing overhead in existing model inference solutions is solved, and efficient data privacy protection and model inference efficiency are achieved.

WO2025139250A1PCT designated stage expired Publication Date: 2025-07-03ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/125976
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-10-21
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The existing model inference scheme based on secure multi-party computing (MPC) technology is difficult to meet the requirements of efficient data privacy protection and model inference efficiency in practical applications.

Method used

By performing segment fitting of the activation function, using higher-order polynomial functions to approximate the target activation function, and using safe multi-party computing (MPC) technology for calculation, reducing the number of segments of the segment function and reducing the calculation amount.

Benefits of technology

While protecting data privacy, it significantly reduces the computational overhead in the model inference process and improves inference efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024125976_03072025_PF_FP_ABST
    Figure CN2024125976_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present description provide a model service providing method and apparatus capable of protecting data privacy, and relates to a client and a server, wherein the server deploys a prediction model, and the prediction model comprises a first hidden layer provided with an activation function. The method comprises: on the basis of a first shard of a function input of an activation function, n-1 demarcation values of n segmentation intervals, and a second shard correspondingly hold by a client, a server performs MPC size comparison calculation n-1 times, so as to obtain n first shards of n hit results of the function input for the n segmentation intervals; on the basis of total n+1 first shards respectively corresponding to the function input and the n hit results, n interval functions corresponding to the n segmentation intervals, and n+1 second shards correspondingly hold by the client, the server performs MPC to obtain a first shard of a function output of a segmentation function formed by the n interval functions, wherein the segmentation function is used for fitting the activation function, and at least one of the n interval functions is in a high-order polynomial form.
Need to check novelty before this filing date? Find Prior Art

Description

Model service providing method and device for protecting data privacy

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on December 26, 2023, with application number 202311824253.6 and application name “Model Service Providing Method and Apparatus for Protecting Data Privacy”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] One or more embodiments of this specification relate to the field of machine learning technology, and in particular, to a method and apparatus for providing a model service that protects data privacy, a computer-readable storage medium, and a computing device. Background Art

[0003] An increasing number of applications and services are using large models, such as neural network models (also known as predictive models), to improve computational accuracy or enhance user experience. For example, predictive models are used for various risk assessments, or to assist programmers in improving their coding efficiency. These predictive model-based applications require user input, such as text, images, code snippets, and code vulnerabilities, which are then processed by the server.

[0004] To protect the privacy of user input data, a solution is needed to ensure that the server, the provider of the model service, does not know the true content of the user input data. Therefore, we propose to execute a model inference program based on secure multi-party computation (MPC) between the client and the server, allowing the client to obtain model inference results without the server knowing its private data.

[0005] However, current model inference solutions based on MPC technology are difficult to meet the higher requirements of practical applications. Therefore, an improved solution is needed that can improve model inference efficiency while protecting user data privacy, so as to better meet the needs of practical applications.

[0006] Summary of the Invention

[0007] The embodiments of this specification describe a method and device for providing model services that protect data privacy, which can effectively reduce the computational overhead in the model reasoning process and improve reasoning efficiency.

[0008] According to a first aspect, a method for providing a model service that protects data privacy is provided, which is executed by a server that deploys a prediction model, wherein the prediction model includes a first hidden layer having an activation function. The method includes:

[0009] Based on the first slice of the function input of the activation function and the n-1 predetermined boundary values ​​of the n segmented intervals, a first secure multi-party MPC calculation is performed n-1 times to achieve size comparison with the second slice of the function input held by the client, thereby obtaining n first slices of the n hit results of the function input for the n segmented intervals. Based on the n+1 first slices corresponding to the function input and the n hit results, respectively, and the n interval functions corresponding to the n segmented intervals, a second MPC calculation is performed with the n+1 second slices held by the client, thereby obtaining a first slice of the function output of the piecewise function formed by the n interval functions, which serves as the first slice of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0010] In one embodiment, the piecewise function is determined by the server based on the following steps: obtaining the n segmented intervals obtained by dividing the domain of the activation function; for a first segmented interval selected from the n segmented intervals, based on multiple sample points determined on the interval using the activation function, fitting a corresponding high-order polynomial function as the interval function corresponding to the interval.

[0011] In a specific embodiment, the activation function is a modified function of a ReLU (rectified linear unit) function; wherein obtaining the n segmented intervals obtained by segmenting the domain of the activation function includes: receiving two boundary values ​​located on either side of the origin of the number axis, and another boundary value located between the two boundary values, selected based on the modified function. The selection of the first segmented interval includes: based on the four segmented intervals formed by the two boundary values ​​and the other boundary value, selecting the two middle segmented intervals as the first segmented intervals.

[0012] Furthermore, in one example, the determination of the piecewise function also includes the following steps: receiving a constant function set for the piecewise interval at the left end of the four piecewise intervals, and a linear function set for the piecewise interval at the right end, as corresponding interval functions respectively.

[0013] In one example, the deformation function includes an exponential linear unit (ELU), a sigmoid linear unit (SiLU), or a Gaussian error linear unit (GeLU).

[0014] In one example, n is equal to 4.

[0015] In one embodiment, based on multiple sample points determined on the interval using the activation function, a corresponding high-order polynomial function is fitted, including: based on the multiple sample points, determining the fitting values ​​of the undetermined coefficients in the high-order polynomial function by the least squares method.

[0016] On the other hand, in a specific embodiment, the determining of the piecewise function further includes the following step: for a second piecewise interval selected from the plurality of piecewise intervals, receiving an interval function set for the second piecewise interval.

[0017] In one embodiment, the second MPC calculation includes: performing a first sub-MPC calculation based on the first shard of the function input and the n interval functions with the second shard of the function input held by the client, to obtain n first shards of n segmented outputs obtained by the n interval functions respectively processing the function input; performing a second sub-MPC calculation based on a total of 2n first shards corresponding to the n hit results and the n segmented outputs, respectively, with the 2n second shards held by the client, to obtain the first shard of the function output.

[0018] In a specific embodiment, the first interval function among the n interval functions is a high-order polynomial function, and the first interval function includes a first power expression with an even exponent; wherein the second sub-MPC calculation includes: performing an MPC power operation based on the first slice of the function input and the second power expression with the second slice of the function input held by the client to obtain a first slice of the power operation result; the second power expression is obtained by halving the exponent of the first power expression; performing an MPC square operation based on the first slice of the power operation result with the second slice of the power operation result held by the client to obtain a first slice of the square of the power operation result, which is used as the first slice of the power operation result.

[0019] In a specific embodiment, the second interval function and the third interval function of the plurality of interval functions are high-order polynomial functions, wherein the first monomial in the second interval function and the second monomial in the third interval function have the same high-order power factor; wherein the second sub-MPC calculation includes:

[0020] Based on the first shard of the function input and the high-order power factor, a secure multi-party exponentiation operation is performed with the second shard of the function input held by the client to obtain a first shard of the factorization result of the high-order power factor. Based on the first shard of the factorization result and the first monomial, a first secure multi-party multiplication operation is performed with the second shard of the factorization result held by the client to obtain a first shard of the operation result of the first monomial. Based on the first shard of the factorization result and the second monomial, a second secure multi-party multiplication operation is performed with the second shard of the factorization result held by the client to obtain a first shard of the operation result of the second monomial.

[0021] In one embodiment, the first hidden layer also includes a linear transformation function; before performing the first MPC calculation, the method further includes: based on the first shard corresponding to the input of the first hidden layer and the linear transformation function, performing a third MPC calculation on the second shard held by the client to obtain the first shard of the function input.

[0022] In one embodiment, the method further includes: performing a fourth MPC calculation based on the first slice of the output of the last hidden layer in the prediction model and the calculation formula corresponding to the output layer and the second slice held by the client, to obtain the first slice of the model output of the prediction model, which is provided to the client for restoring the model output.

[0023] According to a second aspect, a method for providing a model service for protecting data privacy is provided, which is executed by a client, and a server corresponding to the client deploys a prediction model, wherein the prediction model includes a first hidden layer having an activation function; the method includes:

[0024] Based on the second slice of the function input of the activation function, the first slice of the function input held by the server, and the n-1 boundary values ​​of the predetermined n segmented intervals, n-1 first secure multi-party MPC calculations are performed to achieve size comparison, thereby obtaining n second slices of the n hit results of the function input for the n segmented intervals. Based on the n+1 second slices corresponding to the function input and the n hit results, respectively, the second MPC calculation is performed with the n+1 first slices held by the server, and the n interval functions corresponding to the n segmented intervals, thereby obtaining a second slice of the function output of the piecewise function formed by the n interval functions, as the second slice of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0025] In one embodiment, the second MPC calculation includes: performing a first sub-MPC calculation based on the second shard of the function input, the first shard of the function input held by the server, and the n interval functions, to obtain n second shards of n segmented outputs obtained by the n interval functions processing the function input respectively. Performing a second sub-MPC calculation based on a total of 2n second shards corresponding to the n hit results and the n segmented outputs, and the 2n first shards held by the server, to obtain the second shard of the function output.

[0026] In one embodiment, the first interval function among the n interval functions is a high-order polynomial function, and the first interval function includes a first power expression with an even exponent; wherein the second sub-MPC calculation includes: performing a secure multi-party exponentiation operation based on the second slice of the function input, the first slice of the function input and the second power expression held by the server, to obtain a second slice of the power operation result; the second power expression is obtained by halving the exponent of the first power expression; performing a secure multi-party square operation based on the second slice of the power operation result, and the first slice of the power operation result held by the server, to obtain a second slice of the square of the power operation result, as the second slice of the power operation result.

[0027] In one embodiment, the second interval function and the third interval function among the multiple interval functions are high-order polynomial functions, wherein the first monomial in the second interval function and the second monomial in the third interval function have the same high-order power factor; wherein the second sub-MPC calculation includes: performing a secure multi-party exponentiation operation based on the second shard of the function input, the first shard of the function input held by the server and the high-order power factor, to obtain a second shard of the factorization result of the high-order power factor. Performing a first secure multi-party multiplication operation based on the second shard of the factorization result, the first shard of the factorization result held by the server and the first monomial, to obtain a second shard of the operation result of the first monomial. Performing a second secure multi-party multiplication operation based on the second shard of the factorization result, the first shard of the factorization result held by the server and the second monomial, to obtain a second shard of the operation result of the second monomial.

[0028] In one embodiment, the first hidden layer also includes a linear transformation function; before performing the first MPC calculation, the method further includes: performing a third MPC calculation based on the second shard corresponding to the input of the first hidden layer, the first shard held by the server, and the linear transformation function to obtain the second shard of the function input.

[0029] In one embodiment, the method further includes: performing a fourth MPC calculation based on the second slice of the output of the last hidden layer in the prediction model and the calculation formula corresponding to the first slice held by the server and the output layer to obtain the second slice of the model output of the prediction model; restoring the model output based on the second slice of the model output and the first slice of the model output received from the server.

[0030] According to an embodiment of the third aspect, a model service providing device for protecting data privacy is provided, which is integrated into a server, wherein the server deploys a prediction model, wherein the prediction model includes a first hidden layer having an activation function; the device includes:

[0031] The first MPC calculation module is configured to perform n-1 first secure multi-party MPC calculations to achieve size comparison based on the first shard of the function input of the activation function and n-1 predetermined boundary values ​​of the n segmented intervals, and the second shard of the function input held by the client, to obtain n first shards of the n hit results of the function input for the n segmented intervals. The second MPC calculation module is configured to perform a second MPC calculation based on a total of n+1 first shards corresponding to the function input and the n hit results, and n interval functions corresponding to the n segmented intervals, and the n+1 second shards held by the client, to obtain a first shard of the function output of the piecewise function formed by the n interval functions as the first shard of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0032] According to an embodiment of a fourth aspect, a model service providing apparatus for protecting data privacy is provided, which is integrated with a client, wherein a server corresponding to the client deploys a prediction model, wherein the prediction model includes a first hidden layer having an activation function; the apparatus includes:

[0033] The first MPC calculation module is configured to perform n-1 first secure multi-party MPC calculations for size comparison based on the second shard of the function input of the activation function, the first shard of the function input held by the server, and n-1 predetermined boundary values ​​of the n segmented intervals, to obtain n second shards of the n hit results of the function input for the n segmented intervals. The second MPC calculation module is configured to perform a second MPC calculation based on a total of n+1 second shards corresponding to the function input and the n hit results, the n+1 first shards held by the server, and n interval functions corresponding to the n segmented intervals, to obtain a second shard of the function output of the piecewise function formed by the n interval functions as the second shard of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0034] According to a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method of the first aspect or the second aspect.

[0035] According to a sixth aspect, a computing device is provided, comprising a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method of the first aspect or the second aspect is implemented.

[0036] In the above-mentioned method and device provided in the embodiments of this specification, multiple segments of high-order polynomials are used to approximate the activation functions involved in the calculation model, and a method for efficiently calculating polynomials in different segments is proposed, which can effectively reduce the computational overhead in the model inference process while protecting data privacy and improve inference efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0038] FIG1 shows the function curves of GeLU function, SiLU function and ELU function;

[0039] FIG2 is a schematic diagram of the process steps for determining a piecewise function that approximates a target activation function disclosed in an embodiment of this specification;

[0040] FIG3 illustrates the model structure of the prediction model;

[0041] FIG4 is a schematic diagram of interaction between two ends of a model service for protecting data privacy disclosed in an embodiment of this specification;

[0042] FIG5 is a schematic diagram of the structure of a model service providing device integrated in a server according to an embodiment of this specification;

[0043] FIG6 is a schematic diagram of the structure of a model service providing device integrated in a client according to an embodiment of this specification. DETAILED DESCRIPTION

[0044] The solution provided in this specification is described below in conjunction with the accompanying drawings.

[0045] As mentioned above, to protect user data privacy and security, we propose that a large-scale model inference program based on MPC computing be executed between the client and server. As you can see, MPC computing is composed of various data tools such as cryptography. Its function is to enable all participating parties to collaborate on a calculation without revealing their own data to others.

[0046] MPC computing supports limited operators, including addition, multiplication, size comparison, set intersection and other basic operators, but does not support exponential operations (such as e x ), integral operations and other complex operations. However, in order to achieve better prediction results, many prediction models are configured with more complex activation functions in the hidden layer of the model, which involve calculation types that MPC technology does not support. Especially in large models, several types of activation functions that are often used to improve learning effects contain calculation types that MPC technology does not support. For example, the Exponential Linear Unit (ELU) function and the Sigmoid Linear Unit (SiLU) function both involve exponential operations. For another example, see the following formula (1), the Gaussian Error Linear Unit (GeLU) function involves integral operations.

[0047] Where erf represents the Gaussian error function, which is defined as

[0048] To address this issue, we propose converting activation functions containing operator types unsupported by MPC. The resulting approximate function only includes operator types supported by MPC. This approximate function can then be calculated using MPC technology, and the result used as the approximate calculation result of the activation function, achieving equivalent reasoning for the model. For simplicity, the following section will refer to activation functions involving operator types unsupported by MPC as target activation functions.

[0049] Generally, a Taylor expansion can be performed on the target activation function, and the resulting Taylor expansion can be used as the corresponding approximate function. However, the subsequent MPC calculation for the Taylor expansion consumes a lot of resources.

[0050] Furthermore, by observing the three function curves shown in Figure 1, which correspond to the GeLU function, SiLU function, and ELU function mentioned above, it is proposed that the target activation function can be piecewise fitted to obtain a piecewise function that approximates the target activation function. It can be understood that each sub-function in the piecewise function only involves the calculation type supported by MPC technology.

[0051] In implementation A, considering that the MPC technology is used to calculate the piecewise function, it is necessary to calculate the ciphertext of the operation result of each sub-function in the piecewise function. In order to reduce the amount of calculation in this regard, it is proposed to fit each sub-function into a constant function or a first-order polynomial function. At the same time, in order to make the calculation result of the piecewise function close enough to the target activation function, it is necessary to divide it into a sufficient number of segments. For example, the GeLU function shown in formula (1) above is fitted into the following piecewise function:

[0052] The above formula (2) includes 13 segments in total, and the omitted parts are all first-order polynomials.

[0053] Although a single sub-function in the piecewise function obtained by sampling implementation method A, such as a 0,0 +a 0,1 The computational complexity of x for ciphertext calculation is not high. However, because there are many segments, such as 13 or even more, the cumulative computational complexity of multiple sub-functions is large. Moreover, it greatly increases the overhead of performing MPC size comparison calculation. The number of times the MPC size comparison calculation is performed depends on the number of segments of the piecewise function. This is because when using MPC technology to calculate piecewise functions, it is also necessary to perform ciphertext size comparison on the function variable value and each segmentation point involved in multiple segmentation intervals. For example, for the value of variable x in formula (2) and the 12 segmentation points, namely -T, T, p0-p 10 The ciphertext size comparison calculations are performed 12 times respectively, which means that for every additional segment in the piecewise function (that is, every additional split point), the cost of the ciphertext comparison calculation will be increased once.

[0054] Based on the above observations and analysis, the present specification proposes another embodiment B. In embodiment B, in order to reduce the number of segments of the piecewise function, it is proposed to fit at least some of the sub-functions in the piecewise function to a high-order polynomial function. This can greatly reduce the number of segments required while ensuring calculation accuracy. For example, it can be reduced to 4 segments. For this, please refer to the following formula:

[0055] It should be understood that, from the perspective of calculating the ciphertext of the operation result of a single sub-function, the amount of calculation for the sub-function in the form of a high-order polynomial is greater than the amount of calculation for the sub-function in the form of a first-order polynomial. However, combined with the number of sub-functions associated with the number of segmented segments and the number of MPC size comparison calculations, compared with implementation method A, implementation method B can greatly reduce the number of segmented segments, thereby effectively reducing the overall amount of calculation for calculating piecewise functions using MPC technology.

[0056] Next, we will first describe the specific implementation steps for fitting the target activation function to a piecewise function using Implementation B described above, with reference to Figures 2 and 3. We will then describe the interactive process by which the server provides model services to the client based on the prediction model and the piecewise function fitted to the target activation function.

[0057] Figure 2 is a schematic diagram of the process steps for determining a piecewise function that approximates a target activation function disclosed in an embodiment of this specification. It should be understood that the determination of the piecewise function can be performed by the server or by other devices or equipment, and the determined piecewise function is then provided to the server.

[0058] As shown in FIG2 , determining the piecewise function corresponding to the target activation function using the above-mentioned implementation B includes the following steps:

[0059] In step S210, n segmented intervals are obtained by dividing the domain of the target activation function. In step S220, for the first segmented interval selected from the n segmented intervals, a corresponding high-order polynomial function is fitted based on multiple sample points determined on the interval using the target activation function as the interval function corresponding to the interval.

[0060] The above steps are expanded as follows:

[0061] First, in step S210, n segmented intervals obtained by segmenting the domain of the target activation function are obtained.

[0062] In one embodiment, n segmentation intervals may be received. In another embodiment, n-1 segmentation points (or cutoff values) may be received, thereby automatically forming n segmentation intervals. It should be understood that the received n segmentation intervals or n-1 segmentation points are set by staff based on expert knowledge, experience, or experimental data.

[0063] In a specific embodiment, the target activation function is a variant function (or deformation function) of the rectified linear unit (ReLU) function, such as the aforementioned GeLU function, SiLU function, or ELU function. Observing the curve of any of the variant functions illustrated in FIG1 , the portion of the curve near the x-axis origin has a large curvature, while the portion of the curve away from the x-axis origin approaches a straight line, that is, the curvature is close to 0. Therefore, in this step, two boundary values ​​selected based on the deformation function and located on both sides of the number axis origin can be received, denoted as B0 and B2.

[0064] Furthermore, the curvature of the curve portion located near the origin of the x-axis changes greatly. Therefore, in this step, one or more boundary values ​​located between the two boundary values ​​B0 and B2 can also be received. After experimental verification, by setting another decomposition value B1 between B0 and B2, a piecewise function with sufficiently high accuracy can be solved. It can be understood that the curvature change value of the curve near the boundary value B1 is the largest. In this way, when the target activation function is a deformation function of ReLU, the selected three boundary values ​​B0, B1 and B2 can be received to obtain four segmentation intervals, namely, x<B0, B0≤x<B1, B1≤x<B2, x≥B2. It should be understood that the interval to which the boundary value belongs can be flexibly set as needed.

[0065] Exemplarily, assuming that the target activation function is a GeLU function, in this case, three selected boundary values ​​-T, p, and T based on the target activation function can be received in this step, where -T and T are opposite numbers of each other, and p is between -T and T, such as -T=-3, p=-2, and T=3. Thus, the four segmented intervals shown in formula (3) can be obtained, namely, x<-T, -T≤x<p, p≤x<T, and x≥T.

[0066] From this, we can obtain n segmented intervals by partitioning the domain of the target activation function (usually the domain of real numbers). It should be noted that by using computational accuracy (mainly the error between the target activation function and the piecewise function) and computational effort as metrics, and through multiple experiments with different activation functions, n is generally an integer not exceeding 6.

[0067] Based on the n segmented intervals received above, step S220 can be executed. For the first segmented interval selected from the n segmented intervals, a corresponding high-order polynomial function is fitted based on multiple sample points determined in the interval using the target activation function as the interval function corresponding to the interval.

[0068] It should be noted that the "first" in the above-mentioned first segmented interval, as well as similar terms such as first and second elsewhere in the text, are all for distinguishing similar things and do not have other limiting functions such as sorting; in addition, the two names of interval function and subfunction in the text can be used interchangeably.

[0069] In this step, a first segmented interval selected by a staff member from among the n segmented intervals may be received. It is understood that high-order polynomials are suitable for fitting complex curves, and the staff member may select the first segmented interval based on the complexity of the target activation function in each segmented interval, such as the curvature.

[0070] In one embodiment, assuming that the target activation function is a variant of the ReLU function, the corresponding n segmented intervals received are four segmented intervals formed by the three boundary values ​​B0, B1, and B2. In this case, because the curvature of the curve portion corresponding to the target activation function is larger in the two middle segmented intervals, i.e., -B0≤x<B1 and B1≤x<B2, these two intervals can be selected as the first segmented intervals. For example, assuming that the variant function is a GeLU function, the two intervals -T≤x<p and p≤x<T in formula (3) can be selected as the first segmented intervals.

[0071] Accordingly, in this step, a selection operation for the first segmented interval may be received. Furthermore, a target activation function may be used to generate multiple sample points on the selected first segmented interval. For example, a predetermined number of x values ​​may be randomly or evenly spaced from the first segmented interval, and then the target activation function may be used to calculate the y values ​​corresponding to each of the sampled x values, where a pair of x and y values ​​forms a sample point.

[0072] Afterwards, the generated multiple sample points are used as observation data, and the function to be fitted is set to a high-order polynomial form, which can be seen in the following formula (4): n (x) = a n x n +a n-1 x n-1 +…+a1x 1 +a0 (4)

[0073] And receive the setting value H of the highest term, that is, set n = H, so as to determine the unknown coefficient {a i The fitting value of |i∈[0,n]} is used to obtain the interval function in the form of a fitted high-order polynomial. For example, see formula (3), which includes the interval functions P(x) and Q(x) in the form of high-order polynomials. The degrees of the highest terms in P(x) and Q(x) are D0 and D1, respectively, where D0 and D1 are generally set to 3 to 6 orders.

[0074] As described above, by executing step S220 , the fitting of the interval function in the form of a high-order polynomial corresponding to at least a part of the n segmented intervals can be completed.

[0075] According to another embodiment, assuming that the n segmented intervals include a second segmented interval that was not selected as the first segmented interval, in this case, because the function curve corresponding to the target activation function for the second segmented interval approaches a straight line, the corresponding interval function can be directly fitted to a linear function. For example, a linear function directly set by a staff member for the second segmented interval by observing the function curve or other methods can be received. In another example, a linear function corresponding to the second segmented interval can be fitted.

[0076] In a specific embodiment, it is assumed that the target activation function is a variant function of the above-mentioned ReLU function, and the two segmented intervals at the two ends of the x-axis in the corresponding four segmented intervals, namely x<B0 and x≥B2, can receive two interval functions set by the staff, including a constant function (or constant function, constant function) set for the segmented interval x<-B0, and a linear function set for the segmented interval x≥B2. For example, see formula (3) for the constant function corresponding to the segmented interval x<-T, namely GeLU(x)≈0, and the linear function corresponding to the segmented interval x≥T, namely GeLU(x)≈x.

[0077] The above, combined with Figure 2, provides an exemplary description of the steps for approximating a target activation function using a piecewise function, where at least one of the n interval functions of the piecewise function is a high-order polynomial function. It should be understood that the steps for determining the piecewise function are not unique; the logical flow of data is sufficient. For example, the interval function can be set or fitted for each received segmented interval before the next segmented interval is received, and so on.

[0078] After obtaining the piecewise function that approximates the target activation function in the prediction model, the server can use it to efficiently provide model services. Next, we will describe the steps for the server to interact with the client during the model service process.

[0079] To facilitate understanding, we first briefly introduce the structure of the prediction model (or neural network model) deployed on the server. As shown in Figure 3, the neural network model includes a sequentially connected input layer, several (m in Figure 3) hidden layers, and an output layer. The input layer is used to receive the input data z0 of the model. Any hidden layer (the i-th hidden layer in Figure 3) includes a linear sublayer and a nonlinear sublayer, where the linear sublayer is used to transform the input z of the i-th hidden layer. i Perform linear transformation, which can be recorded as x i =wi *z i +b i , the output x of the linear sublayer i It is used as the input of the nonlinear sublayer, or as the input of the activation function; the nonlinear sublayer uses the activation function (such as GeLU function) to input x i Perform nonlinear transformation, and the activation function is shown as z in Figure 3 i+1 =σ(x i The output layer processes the output z of the last hidden layer (shown as the mth hidden layer in Figure 3). m , and obtain the output data Y of the prediction model.

[0080] The activation functions in some or all of the above hidden layers are target activation functions. For simplicity, any hidden layer with the target activation function among the hidden layers is referred to as the first hidden layer.

[0081] FIG4 is a schematic diagram of the interaction between two ends of the model service for providing data privacy protection disclosed in an embodiment of this specification, wherein the two ends refer to the client and the server. FIG4 mainly illustrates the MPC calculation of the target activation function included in the first hidden layer during the model service process. In summary, the server is based on a piecewise function that approximates the target activation function and a first slice of the function input x of the target activation function. <x> s , with the second shard of the function input x held by the client <x> c Perform MPC calculations, so that the server obtains the first slice of the function output z <z> s , the client gets the second slice of the function output z <z> c It should be understood that all the shards mentioned in this article are Secret Sharing shards. Secret Sharing is a cryptographic tool in MPC technology. Only when a certain number of participants collaborate based on the Secret Sharing shards they hold can the original data be restored to its original plaintext. A single party cannot restore the data to its original plaintext based on a single shard it holds. For example, the server can restore the data to its original plaintext based on the first shard. <x> s The function input x cannot be recovered.

[0082] As shown in Figure 4, the calculation of the target activation function involves the following three stages of MPC calculation:

[0083] 1) In the first stage

[0084] The server inputs the first slice of x based on the target activation function <x> s , and n-1 dividing values ​​of n segment intervals {b i } [n-1] , with the second shard of the function input x held by the client <x> c , perform n-1 MPC calculations to achieve size comparison, where the subscript [n-1] indicates that i takes integer values ​​from 1 to n-1. Thus, the server obtains n hit results {q i } [n] The first n fragments of { i > s } n , the client gets n hit results {q i } n The n second fragments { i >c} n .

[0085] For any of the n-1 MPC calculations for size comparison, the following exemplary description is given:

[0086] ① The server is based on the first shard of x it holds <x> s and the cutoff value b i , local computing <e i > s = <x> s -b i / 2;

[0087] ② The client’s second shard [x] based on its holdings of x c and the cutoff value b i , local computing <e i > c = <x> c -b i / 2;

[0088] ③The server and client are based on e i shards, i.e. <e i > s and <e i > c , perform MPC calculations together and obtain e i The sign bit p i The server gets <p i > s , the client gets <p i > c . Need to understand, e i =xb i , and e i In the computer, it is represented as a binary bit string, the highest bit of which is the sign bit. i =1, indicating e i is a negative number, that is, x<b i , if p i =0, indicating e i is a natural number, that is, x ≥ b i .

[0089] In this way, the ciphertext and the boundary value b for the function input x can be realized i The server and client each obtain the size comparison result p i One of the two shards of <p i > s and <p i > c .

[0090] Note that based on n-1 cutoff values ​​{b i } [n-1] Perform n-1 MPC size comparisons and obtain n-1 size comparison results {p i } [n-1] But the final result is n hit results for n segment intervals {q i } n It should be understood that the server and client can each implement the mapping conversion between these two types of shards locally.

[0091] For example, let us assume that b1<b2<……<b n-1 At this time, the server uses the comparison result sharding to calculate the hit result q i The first shard i > s This can include: ​

[0092] It can be understood that when i=1, p1 indicates the size comparison result between x and b1, which is equivalent to the hit result q1 indicating whether x falls into the interval x<b1. i-1 <b i , if p i-1 =1, that is, x<b i-1 , then x must also be smaller than b i , that is, p i =1, but x can only fall into one of the n segmented intervals, that is, only one of the n hit results will be 1. Therefore, an exclusive OR operation ^ can be used to make the 1 corresponding to the minimum boundary value involved in the multiple size comparison results 1 be regarded as the hit result, and the others are set to 0. For example, if q1=p1=1, then q2=1^p1=0. This section introduces the principle of formula (5) based on the plaintext data to help understanding. In fact, the relevant calculation is based on the ciphertext fragmentation. In addition, formula (5) is a local calculation performed on the server. The client can refer to it for inference. In fact, replacing the subscript s in formula (5) from s to c can obtain the formula for calculating the hit result fragmentation on the client.

[0093] Above, through the first stage of MPC calculation, the server can obtain the hit result of the function input x compared with n segment intervals {q i } [n] The first n fragments of { i > s } n , the client can get the corresponding n second fragments { i > c } n .

[0094] 2) In the second stage

[0095] The server inputs the first shard based on the function x <x> s and n interval functions, with the second shard of the function input x held by the client <x> c Perform MPC calculation. Then, the server obtains n segmented outputs {y i } n The corresponding n first fragments { <y i > s } n , the client gets n segment outputs {y i } n n second shards of { <y i > c } n .

[0096] It should be understood that the server and client can each perform MPC calculations for n interval functions based on the slices of the function input x, thereby obtaining n segmented outputs {y i } n Since the operators involved in each interval function are all supported by MPC calculation, for example, for the above formula (3), that is:

[0097] Each piecewise function only involves multiplication and addition operations. Therefore, the calculation of each interval function can be completed by using MPC multiplication and MPC addition.

[0098] Furthermore, for the higher-order polynomial functions among the n interval functions, such as P(x) and Q(x) in formula (3), considering the high computational complexity of conventional MPC calculations, we propose the following two optimizations to effectively reduce the computational complexity. It should be understood that both optimizations can be used, or one or the other.

[0099] 1) Optimization of point 1

[0100] For even terms in a high-order polynomial function, such as x 2 、x 4 and x 6 , proposed to use MPC square to calculate, for example, to calculate x 6 Using the formula x 6 =(x 3 ) 2 Rather than x 6 =x 2 *x 4 This is because the cost of squaring an integer in MPC is 50% lower than multiplying two integers.

[0101] Specifically, for the first interval function of the n interval functions that is a high-order polynomial function, it includes a first power operation expression with an even exponent. For example, if D1=6 in formula (3), the high-order polynomial function Q(x) includes a power operation expression x with an exponent of 6. 6 Accordingly, when both ends perform MPC calculations on the output of the first interval function, including sub-MPC calculations on the first power expression therein, the specific implementation can be as follows:

[0102] First, the server inputs the first shard of x based on the function <x> s and the second power expression, with the second shard of the function input x held by the client <x> c Perform MPC power operation, so the server and client get the first slice of the power operation result r <r> s and the second shard <r> c . The second power operation (such as x 3 ) is the first power operation (such as x 6 ) by halving the exponent.

[0103] Then, the server performs the first shard based on the power operation result r <r> s , corresponding to the second shard held by the client <r> c , perform MPC square operation, so the server and client get the square of the power operation result r 2 The first shard <r 2 > s and the second shard <r 2 > c , as the slice of the result of the first power operation.

[0104] As mentioned above, by using MPC squares to replace MPC multiplications as much as possible, the computational complexity of high-order polynomial functions can be effectively reduced.

[0105] 2) Optimization of point 2

[0106] For the same high-order power factors contained in multiple high-order polynomials, it only needs to be calculated once and then reused multiple times. For example, assuming that D0=3, D1=6 in formula (3), then the high-order power factor x in the quadratic term 2 and the higher power factors x in the cubic terms 3 It only needs to be calculated once and can then be reused when calculating the interval functions P(x) and Q(x), effectively reducing the amount of calculation.

[0107] Specifically, for a second interval function and a third interval function that are high-order polynomial functions among the n interval functions, where a first monomial in the second interval function and a second monomial in the third interval function have the same high-order power factor, the MPC calculation for the first monomial and the second monomial may include:

[0108] First, the server inputs the first shard of x based on the function <x> s and the above high-order power factors, with the second shard of the function input x held by the client <x> c Perform MPC power operation, so the server and client get the first slice of the factor operation result g of the high-order power factor <g> s and the second shard <g> c .

[0109] Next, the server calculates the first shard based on the factorization result. <g> s and the first monomial above, corresponding to the second shard held by the client <g> c The MPC multiplication operation is performed, and thus the server and the client obtain the first fragment and the second fragment of the operation result of the first monomial respectively.

[0110] And, the server's first shard based on the factored result <g> s and the second monomial above, corresponding to the second shard held by the client <g> c The MPC multiplication operation is performed, and thus the server and the client obtain the first fragment and the second fragment of the operation result of the second monomial respectively.

[0111] The above describes the reuse of MPC calculation results for high-order power factors in terms of the same degree contained in two or more high-order polynomial functions in n interval functions, thereby effectively reducing the computational complexity of the high-order polynomial functions.

[0112] By adopting the above two optimizations, the computational complexity of interval functions in the form of high-order polynomials can be effectively reduced in the second-stage MPC calculation.

[0113] Above, after the first stage of MPC calculation, both ends get n hit results corresponding to n segment intervals {q i } [n] After the second stage of MPC calculation, both ends of the two slices get n segmented outputs corresponding to n interval functions {y i } n It should be understood that the two-stage MPC calculation can be executed in any order or in parallel.

[0114] Both ends perform the third stage of MPC calculation based on the shards obtained in the above two stages.

[0115] 3) In the third stage

[0116] The server outputs 2n first fragments corresponding to the n hit results and n segment outputs, namely { i > s , <y i > s } n , corresponding to the 2n second shards held by the client, that is, { i > c , <y i > c } n Performing MPC calculations, for example, the following formula can be calculated together:

[0117] Thus, the server can obtain the first slice of the function output z′ of the target piecewise function<z′> s , the client gets the second slice of the function output z′<z′> c .

[0118] The above, combined with Figure 4, introduces the prediction model deployed in the server. By performing MPC calculation on the target piecewise function, the approximate calculation of the target activation function in the first hidden layer is achieved. ​​

[0119] It can be understood that the output of the target activation function is the output of the first hidden layer, which can then serve as the input to the next layer in the prediction model. Furthermore, the MPC calculations for the linear functions in each hidden layer shown in Figure 3, as well as the MPC calculations involved in the output layer, can be implemented using existing technologies. To facilitate understanding, a brief introduction is provided below.

[0120] 1) MPC calculation for the linear transformation function in the hidden layer

[0121] The first hidden layer also includes a linear transformation function: x = w*z + b (7)

[0122] Exemplarily, before performing the MPC calculation for the target activation function, the server and the client further perform the following interactions:

[0123] The server side is based on the first shard corresponding to the input z of the first hidden layer <z> s and a linear transformation function with the second shard held in the client <z> c , so the server can get the first slice of the output x of the linear transformation function <x> s , the client can get the second shard <x> c The output x of the linear transformation function is the function input x of the target activation function.

[0124] Regarding the first shard <z> s and the second shard <z> c In one implementation, the first hidden layer is not the first hidden layer. In this case, the input z of the first hidden layer corresponds to the output of the previous hidden layer. By jointly calculating the output of the previous hidden layer, the server and the client obtain the first shard <z> s and the second shard <z> c .

[0125] In another implementation, the first hidden layer is the first hidden layer. In this case, the input z of the first hidden layer corresponds to the output z0 of the input layer, that is, the original data z0 input by the user through the client. The client can use secret sharing technology to split the user's input data z0 into two fragments and send one to the server. In this case, <z> s = <z0> s 、 <z> c = <z0> c .

[0126] 2) MPC calculation for the output layer

[0127] The server performs MPC calculation based on the first slice of the output of the last hidden layer in the prediction model and the calculation formula corresponding to the output layer, and the second slice of the last hidden layer output held by the client. Thus, the server can obtain the first slice of the model output Y of the prediction model. <y> s , the client can get the second shard of the model output Y <y> c .

[0128] After that, the client can receive the first fragment sent by the server <y> s , thus based on the first shard <y> s and the second shard <y> c Restore the model output Y. In this way, the client can obtain the model's processing result Y for the user input data x0. At the same time, the server cannot obtain the plaintext of private data including model input, output, and intermediate calculation results.

[0129] In summary, the method and device for providing model services for protecting data privacy disclosed in the embodiments of this specification can effectively reduce the computational overhead in the model reasoning process and improve reasoning efficiency.

[0130] Corresponding to the above method, the embodiments of this specification also disclose the following device integrated in the server or client.

[0131] FIG5 is a schematic diagram of the structure of a model service providing device integrated into a server according to an embodiment of the present specification, wherein the server deploys a prediction model, and the prediction model includes a first hidden layer with an activation function. As shown in FIG5 , the device 500 includes:

[0132] The first MPC calculation module 510 is configured to perform n-1 first secure multi-party MPC calculations for size comparison based on the first shard of the function input of the activation function and the predetermined n-1 boundary values ​​of the n segmented intervals, and the second shard of the function input held by the client, to obtain n first shards of the n hit results of the function input for the n segmented intervals.

[0133] The second MPC calculation module 520 is configured to perform a second MPC calculation on the n+1 first shards corresponding to the function input and the n hit results, and the n interval functions corresponding to the n segmented intervals, and the n+1 second shards held by the client, to obtain a first shard of the function output of the piecewise function formed by the n interval functions as the first shard of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0134] In one embodiment, the apparatus 500 further includes a piecewise function determination module 530, which specifically includes a piecewise interval acquisition unit 531 configured to acquire the n piecewise intervals obtained by segmenting the domain of the activation function. An interval function determination unit 532 configured to fit a corresponding high-order polynomial function to a first piecewise interval selected from the n piecewise intervals based on a plurality of sample points determined in the first piecewise interval using the activation function as the interval function corresponding to the first piecewise interval.

[0135] In a specific embodiment, the activation function is a modified function of a ReLU (rectified linear unit) function; and the segmented interval acquisition unit 531 is specifically configured to receive two cutoff values ​​located on either side of the origin of the number axis, and another cutoff value located between the two cutoff values, selected based on the modified function. The selection of the first segmented interval includes: selecting two intermediate segmented intervals from among four segmented intervals formed by the two cutoff values ​​and the other cutoff value as the first segmented intervals.

[0136] Furthermore, in one example, the interval function determination unit 532 is further configured to receive a constant function set for the segmented interval at the left end of the four segmented intervals, and a linear function set for the segmented interval at the right end, as the corresponding interval functions. In one example, the deformation function includes an exponential linear unit (ELU), a sigmoid linear unit (SiLU), or a Gaussian error linear unit (GeLU). In one example, n is equal to 4.

[0137] In a specific embodiment, the interval function determination unit 532 is specifically configured to determine, based on the multiple sample points, the fitting values ​​of the undetermined coefficients in the high-order polynomial function by the least squares method.

[0138] In a specific embodiment, the interval function determining unit 532 is further configured to: for a second segmented interval selected from the plurality of segmented intervals, receive an interval function set for the second segmented interval.

[0139] In one embodiment, the second MPC calculation module 520 includes: a first sub-MPC calculation unit 521, configured to perform a first sub-MPC calculation based on the first shard of the function input and the n interval functions, and the second shard of the function input held by the client, to obtain n first shards of n segmented outputs obtained by the n interval functions respectively processing the function input; a second sub-MPC calculation unit 522, configured to perform a second sub-MPC calculation based on a total of 2n first shards corresponding to the n hit results and the n segmented outputs, and the 2n second shards held by the client, to obtain the first shard of the function output.

[0140] In a specific embodiment, the first interval function among the n interval functions is a high-order polynomial function, and the first interval function includes a first power expression with an even exponent. The second sub-MPC calculation unit 522 is specifically configured to: perform an MPC power operation based on the first slice of the function input and the second power expression, and the second slice of the function input held by the client, to obtain a first slice of the power operation result; the second power expression is obtained by halving the exponent of the first power expression. Perform an MPC square operation based on the first slice of the power operation result and the second slice of the power operation result held by the client, to obtain a first slice of the square of the power operation result, as the first slice of the power operation result.

[0141] In a specific embodiment, the second interval function and the third interval function among the multiple interval functions are high-order polynomial functions, wherein the first monomial in the second interval function and the second monomial in the third interval function have the same high-order power factor; wherein the second sub-MPC calculation unit 522 is specifically configured as follows:

[0142] Based on the first shard of the function input and the high-order power factor, a secure multi-party exponentiation operation is performed with the second shard of the function input held by the client to obtain a first shard of the factorization result of the high-order power factor. Based on the first shard of the factorization result and the first monomial, a first secure multi-party multiplication operation is performed with the second shard of the factorization result held by the client to obtain a first shard of the operation result of the first monomial. Based on the first shard of the factorization result and the second monomial, a second secure multi-party multiplication operation is performed with the second shard of the factorization result held by the client to obtain a first shard of the operation result of the second monomial.

[0143] In one embodiment, the first hidden layer also includes a linear transformation function; the device 500 also includes a third MPC calculation module 540, which is configured to: based on the first shard corresponding to the input of the first hidden layer and the linear transformation function, perform a third MPC calculation on the second shard held by the client to obtain the first shard of the function input.

[0144] In one embodiment, the device 500 also includes a fourth MPC calculation module 550, which is configured to: perform a fourth MPC calculation based on the first slice of the output of the last hidden layer in the prediction model and the calculation formula corresponding to the output layer and the second slice held by the client, to obtain the first slice of the model output of the prediction model, which is provided to the client for restoring the model output.

[0145] FIG6 is a schematic diagram of the structure of a model service providing device integrated into a client according to an embodiment of this specification. The server corresponding to the client deploys a prediction model, and the prediction model includes a first hidden layer with an activation function. As shown in FIG6 , the device 600 includes:

[0146] The first MPC calculation module 610 is configured to perform n-1 first secure multi-party MPC calculations for size comparison based on the second shard of the function input of the activation function, the first shard of the function input held by the server, and n-1 boundary values ​​of the predetermined n segmented intervals, to obtain n second shards of the n hit results of the function input for the n segmented intervals.

[0147] The second MPC calculation module 620 is configured to perform a second MPC calculation based on a total of n+1 second shards corresponding to the function input and the n hit results, the n+1 first shards held by the server, and the n interval functions corresponding to the n segmented intervals, to obtain a second shard of the function output of the piecewise function formed by the n interval functions as the second shard of the output data of the first hidden layer; wherein the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

[0148] In one embodiment, the second MPC calculation module 620 includes: a first sub-MPC calculation unit 621 configured to perform a first sub-MPC calculation based on the second shard of the function input, the first shard of the function input held by the server, and the n interval functions, to obtain n second shards of n segmented outputs obtained by the n interval functions processing the function input respectively. A second sub-MPC calculation unit 622 configured to perform a second sub-MPC calculation based on a total of 2n second shards corresponding to the n hit results and the n segmented outputs, and the 2n first shards held by the server, to obtain second shards of the function output.

[0149] In one embodiment, the first interval function among the n interval functions is a high-order polynomial function, and the first interval function includes a first power operation formula with an even exponent. The second sub-MPC calculation unit 622 is specifically configured as follows:

[0150] Based on the second shard of the function input, a secure multi-party exponentiation operation is performed with the first shard of the function input and the second power operation formula held by the server to obtain a second shard of the power operation result; the second power operation formula is obtained by halving the exponent of the first power operation formula; based on the second shard of the power operation result, a secure multi-party square operation is performed with the first shard of the power operation result held by the server to obtain a second shard of the square of the power operation result, as the second shard of the operation result of the first power operation formula.

[0151] In one embodiment, the second interval function and the third interval function of the plurality of interval functions are high-order polynomial functions, wherein the first monomial in the second interval function and the second monomial in the third interval function have the same high-order power factor. The second sub-MPC calculation unit 622 is specifically configured as follows:

[0152] Based on the second shard of the function input, a secure multi-party exponentiation operation is performed with the first shard of the function input held by the server and the high-order power factor to obtain a second shard of the factorization result of the high-order power factor. Based on the second shard of the factorization result, a first secure multi-party multiplication operation is performed with the first shard of the factorization result held by the server and the first monomial to obtain a second shard of the operation result of the first monomial. Based on the second shard of the factorization result, a second secure multi-party multiplication operation is performed with the first shard of the factorization result held by the server and the second monomial to obtain a second shard of the operation result of the second monomial.

[0153] In one embodiment, the first hidden layer also includes a linear transformation function; the device 600 also includes: a third MPC calculation unit 630, configured to perform a third MPC calculation based on the second slice corresponding to the input of the first hidden layer, the first slice held by the server and the linear transformation function, to obtain the second slice of the function input.

[0154] In one embodiment, the device 600 also includes: a fourth MPC calculation unit 640, configured to perform a fourth MPC calculation based on the second slice of the output of the last hidden layer in the prediction model, the first slice held by the server and the calculation formula corresponding to the output layer, to obtain the second slice of the model output of the prediction model; based on the second slice of the model output and the first slice of the model output received from the server, restore the model output.

[0155] According to another embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method described in conjunction with FIG. 2 or FIG. 4 .

[0156] According to another embodiment, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in conjunction with FIG. 2 or FIG. 4 is implemented. Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the present invention may be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions may be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0157] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.< / y> < / y> < / y> < / y> < / y> < / z> < / z0> < / z> < / z> < / z> < / z> < / z> < / x> < / x> < / z> < / z> < / g> < / g> < / g> < / g> < / g> < / g> < / x> < / x> < / r> < / r> < / r> < / r> < / x> < / x> < / x> < / x> ​​< / x> < / x> < / x> ​​< / x> < / x> < / x> < / z> < / z> < / x> < / x>

Claims

1. A method for providing model services to protect data privacy, which is executed by a server. The server deploys a prediction model, and the prediction model includes a first hidden layer with an activation function. The method includes: Performing n - 1 first secure multi - party MPC calculations for size comparison based on the first shard of the function input of the activation function, the n - 1 boundary values of the pre - determined n segmentation intervals, and the second shard of the function input held by the client, to obtain n first shards of the n hit results of the function input for the n segmentation intervals. Based on a total of n + 1 first shards corresponding to the function input and the n hit results respectively, and n interval functions corresponding to the n segmentation intervals, performing a second MPC calculation with n + 1 second shards held by the client corresponding thereto, to obtain a first shard of the function output of the piece - wise function formed by the n interval functions as the first shard of the output data of the first hidden layer; wherein, the piece - wise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high - order polynomial.

2. The method according to claim 1, wherein, The piece - wise function is determined by the server based on the following steps: Obtaining the n segmentation intervals obtained by dividing the domain of the activation function. For the first selected segmentation interval among the n segmentation intervals, fitting a corresponding high - order polynomial function based on a plurality of sample points determined by the activation function in this interval as the interval function corresponding to this interval.

3. The method according to claim 2, wherein, The activation function is a variant function of the rectified linear unit ReLU; wherein, obtaining the n segmentation intervals obtained by dividing the domain of the activation function includes: Receiving two boundary values selected based on the variant function on both sides of the origin of the number axis, and another boundary value between the two boundary values. Among them, the selection of the first segmentation interval includes: Based on the four segmentation intervals formed by the two boundary values and the other boundary value, taking the two middle segmentation intervals as the first segmentation intervals respectively.

4. The method according to claim 3, wherein The determination of the piece - wise function further includes the following steps: Receiving a constant function set for the left - most segmentation interval among the four segmentation intervals and a linear function set for the right - most segmentation interval as the corresponding interval functions respectively.

5. The method according to claim 3, wherein, The variant function includes the exponential linear unit ELU, the Sigmoid linear unit SiLU, or the Gaussian error linear unit GeLU.

6. The method according to claim 3, wherein The n is equal to 4.

7. The method according to claim 2, wherein Fitting a corresponding high - order polynomial function based on a plurality of sample points determined by the activation function in this interval, including: Based on the plurality of sample points, determining the fitting values of the undetermined coefficients in the high - order polynomial function by the least - squares method.

8. The method according to claim 2, wherein, The determination of the piece - wise function further includes the following steps: For the second selected segmentation interval among the plurality of segmentation intervals, receiving the interval function set for this second segmentation interval.

9. The method according to claim 1, wherein The second MPC calculation includes: Perform a first sub-MPC calculation on the first shard of the function input and the n interval functions, and the second shard of the function input held by the client, to obtain n first shards of the n piecewise outputs obtained by processing the function input by the n interval functions respectively; Perform a second sub-MPC calculation on the total 2n first shards corresponding to the n hit results and the n piecewise outputs respectively, and the 2n second shards held by the client correspondingly, to obtain the first shard of the function output.

10. The method according to claim 9, wherein, The first interval function among the n interval functions is a high-order polynomial function, and the first interval function includes a first power operation formula with an even exponent; wherein, the second sub-MPC calculation includes: Perform an MPC power operation on the first shard of the function input and the second power operation formula, and the second shard of the function input held by the client, to obtain the first shard of the power operation result; the second power operation formula is obtained by halving the exponent of the first power operation formula. Perform an MPC square operation on the first shard of the power operation result and the second shard of the power operation result held by the client, to obtain the first shard of the square of the power operation result, as the first shard of the operation result of the first power operation formula.

11. The method according to claim 9, wherein, The second interval function and the third interval function among the multiple interval functions are high-order polynomial functions, and the first monomial in the second interval function and the second monomial in the third interval function have the same high-degree power factor; wherein, the second sub-MPC calculation includes: Perform a secure multi-party power operation on the first shard of the function input and the high-degree power factor, and the second shard of the function input held by the client, to obtain the first shard of the factor operation result of the high-degree power factor; Perform a first secure multi-party multiplication operation on the first shard of the factor operation result and the first monomial, and the second shard of the factor operation result held by the client, to obtain the first shard of the operation result of the first monomial; Perform a second secure multi-party multiplication operation on the first shard of the factor operation result and the second monomial, and the second shard of the factor operation result held by the client, to obtain the first shard of the operation result of the second monomial.

12. The method according to claim 1, wherein The first hidden layer further includes a linear transformation function; before performing the first MPC calculation, the method further includes: Perform a third MPC calculation on the first shard corresponding to the input of the first hidden layer and the linear transformation function, and the second shard held by the client correspondingly, to obtain the first shard of the function input.

13. The method according to claim 1, the method further includes: Perform a fourth MPC calculation on the first shard of the output of the last hidden layer in the prediction model and the calculation formula corresponding to the output layer, and the second shard held by the client correspondingly, to obtain the first shard of the model output of the prediction model, for providing to the client for restoring the model output.

14. A method for providing model services to protect data privacy, which is executed by a client. A prediction model is deployed on the server corresponding to the client, and the prediction model includes a first hidden layer with an activation function; The method includes: Perform \(n - 1\) first secure multi-party MPC computations for size comparison on the second shard of the function input based on the activation function, the first shard of the function input held by the server, and the \(n - 1\) boundary values of the \(n\) predetermined segmentation intervals, to obtain \(n\) second shards of the \(n\) hit results of the function input for the \(n\) segmentation intervals; Perform a second MPC computation on the total of \(n + 1\) second shards corresponding to the function input and the \(n\) hit results respectively, the \(n + 1\) first shards held by the server correspondingly, and the \(n\) interval functions corresponding to the \(n\) segmentation intervals, to obtain a second shard of the function output of the piecewise function formed by the \(n\) interval functions, as the second shard of the output data of the first hidden layer; wherein, the piecewise function is used to fit the activation function, and at least one of the \(n\) interval functions is in the form of a high-order polynomial.

15. The method according to claim 14, wherein The second MPC computation includes: Perform a first sub-MPC computation on the second shard of the function input, the first shard of the function input held by the server, and the \(n\) interval functions, to obtain \(n\) second shards of the \(n\) piecewise outputs obtained by the \(n\) interval functions processing the function input respectively; Perform a second sub-MPC computation on the total of \(2n\) second shards corresponding to the \(n\) hit results and the \(n\) piecewise outputs respectively, and the \(2n\) first shards held by the server correspondingly, to obtain the second shard of the function output.

16. The method according to claim 14, wherein, The first interval function among the \(n\) interval functions is a high-order polynomial function, and the first interval function includes a first power operation expression with an even exponent; wherein, the second sub-MPC computation includes: Perform a secure multi-party power operation on the second shard of the function input, the first shard of the function input held by the server, and the second power operation expression, to obtain a second shard of the power operation result; the second power operation expression is obtained by halving the exponent of the first power operation expression; Perform a secure multi-party square operation on the second shard of the power operation result and the first shard of the power operation result held by the server, to obtain a second shard of the square of the power operation result, as the second shard of the operation result of the first power operation expression.

17. The method according to claim 14, wherein, The second interval function and the third interval function among the multiple interval functions are high-order polynomial functions, and the first monomial in the second interval function and the second monomial in the third interval function have the same high-degree power factor; wherein, the second sub-MPC computation includes: Perform a secure multi-party power operation on the second shard of the function input, the first shard of the function input held by the server, and the high-degree power factor, to obtain a second shard of the factor operation result of the high-degree power factor; Perform a first secure multi-party multiplication operation on the second shard of the factor operation result, the first shard of the factor operation result held by the server, and the first monomial, to obtain a second shard of the operation result of the first monomial; Based on the second shard of the factorization operation result, perform a second secure multi-party multiplication operation with the first shard of the factorization operation result held by the server and the second monomial to obtain the second shard of the operation result of the second monomial.

18. The method according to claim 14, wherein The first hidden layer further includes a linear transformation function; before performing the first MPC calculation, the method further includes: Based on the second shard corresponding to the input of the first hidden layer, perform a third MPC calculation with the first shard held by the server correspondingly and the linear transformation function to obtain the second shard of the function input.

19. The method according to claim 14, the method further includes: Based on the second shard of the output of the last hidden layer in the prediction model, perform a fourth MPC calculation with the first shard held by the server correspondingly and the calculation formula corresponding to the output layer to obtain the second shard of the model output of the prediction model; Based on the second shard of the model output and the first shard of the model output received from the server, restore the model output.

20. A model service providing device for protecting data privacy, integrated into a server, where the server deploys a prediction model, and the prediction model includes a first hidden layer with an activation function; The apparatus includes: A first MPC calculation module, configured to perform n - 1 first secure multi-party MPC calculations for size comparison based on the first shard of the function input of the activation function, n - 1 boundary values of n predetermined segmentation intervals, and the second shard of the function input held by the client, to obtain n first shards of the n hit results of the function input for the n segmentation intervals; A second MPC calculation module, configured to perform a second MPC calculation with a total of n + 1 first shards corresponding to the function input and the n hit results respectively, n interval functions corresponding to the n segmentation intervals, and n + 1 second shards held by the client correspondingly, to obtain the first shard of the function output of the piecewise function formed by the n interval functions as the first shard of the output data of the first hidden layer; wherein, the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

21. A model service providing device for protecting data privacy, integrated in a client, where a prediction model is deployed on a server corresponding to the client, and the prediction model includes a first hidden layer with an activation function; The apparatus includes: A first MPC calculation module, configured to perform n - 1 first secure multi-party MPC calculations for size comparison based on the second shard of the function input of the activation function, the first shard of the function input held by the server, and n - 1 boundary values of n predetermined segmentation intervals, to obtain n second shards of the n hit results of the function input for the n segmentation intervals; A second MPC calculation module, configured to perform a second MPC calculation with a total of n + 1 second shards corresponding to the function input and the n hit results respectively, n + 1 first shards held by the server correspondingly, and n interval functions corresponding to the n segmentation intervals, to obtain the second shard of the function output of the piecewise function formed by the n interval functions as the second shard of the output data of the first hidden layer; wherein, the piecewise function is used to fit the activation function, and at least one of the n interval functions is in the form of a high-order polynomial.

22. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed on a computer, the computer is caused to execute the method according to any one of claims 1-19.

23. A computing device, comprising a memory and a processor, wherein, Executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1-19 is implemented.

Citation Information

Patent Citations

  • Data processing method, device and equipment

    CN109919318A

  • Privacy protection data processing method, device and equipment and machine learning system

    CN112000990A

  • Device and method for accelerating activation function operation and storage medium

    CN113902089A

  • Privacy calculation method and device, electronic equipment and readable storage medium

    CN115062342A

  • Model service providing method and device for protecting data privacy

    CN117807628A