REVIEW 3 cited by
On Polynomial Approximations for Privacy-Preserving and Verifiable ReLU Networks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Outsourcing deep neural networks (DNNs) inference tasks to an untrusted cloud raises data privacy and integrity concerns. While there are many techniques to ensure privacy and integrity for polynomial-based computations, DNNs involve non-polynomial computations. To address these challenges, several privacy-preserving and verifiable inference techniques have been proposed based on replacing the non-polynomial activation functions such as the rectified linear unit (ReLU) function with polynomial activation functions. Such techniques usually require polynomials with integer coefficients or polynomials over finite fields. Motivated by such requirements, several works proposed replacing the ReLU function with the square function. In this work, we empirically show that the square function is not the best degree-2 polynomial that can replace the ReLU function even when restricting the polynomials to have integer coefficients. We instead propose a degree-2 polynomial activation function with a first order term and empirically show that it can lead to much better models. Our experiments on the CIFAR and Tiny ImageNet datasets on various architectures such as VGG-16 show that our proposed function improves the test accuracy by up to 10.4% compared to the square function.
Forward citations
Cited by 3 Pith papers
-
ReBoot: Encrypted Training of Deep Neural Networks with CKKS Bootstrapping
ReBoot adapts CKKS homomorphic encryption, local-loss blocks, and a polynomial ReLU to train MLPs on encrypted data, but only one of its dataset results was produced by actually encrypted training.
-
Robust and Secure Code Watermarking for Large Language Models via ML/Crypto Codesign
RoSeMary embeds recoverable signatures in LLM-generated code and uses zero-knowledge proofs to verify ownership without revealing the signature.
-
A Training Framework for Optimal and Stable Training of Polynomial Neural Networks
Boundary loss plus selective gradient clipping lets polynomial neural networks train stably at high degrees and match ReLU accuracy on seven datasets.
Discussion (0). Continue with ORCID to comment.