SinoTechIntel Academic Portal
Open AccessDOI: 10.1631/FITEE_2400371Original Research

Efficient privacy-preserving scheme for secure neural network inference

Liquan CHEN¹,Zixuan YANG¹,Peng ZHANG¹,Yang MA¹

School of Cyber Science and Engineering, Southeast University, Nanjing 210096, China

Read Executive PreviewQuick FAQ
Efficient privacy-preserving scheme for secure neural network inference
Graphical Abstract / Figure
Published In
Frontiers of Information Technology & Electronic Engineering
Published:November 5, 2025Edition:Vol. 32, Issue 11 • pp. 506-518Citation:Liquan CHEN et al. (2025), Frontiers of Information Technology & Electronic Engineering
Impact Factor2.7 (Q2 - Springer)
Sponsored Research Partner
Keywords & Index Terms:Secure neural network inferenceConvolutional neural networkPrivacy-preservingHomomorphic encryptionSecret sharingSecure multi-party computationCiphertext inference

Key Takeaways & Executive Findings

  • • Proposes a three-stage privacy-preserving inference scheme combining homomorphic encryption and secure multi-party computation to protect both user data and model parameters. • Introduces network parameter merging to reduce multiplication levels and ciphertext–plaintext operations, enhancing efficiency. • Develops a fast convolution algorithm that significantly boosts computational performance in ciphertext inference. • Achieves at least 11% reduction in online stage linear operation time compared to state-of-the-art methods, cutting inference time and communication overhead.
Sponsored Research Highlight

Abstract

The increasing adoption of smart devices and cloud services, coupled with limitations in local computing and storage resources, prompts numerous users to transmit private data to cloud servers for processing. However, the transmission of sensitive data in plaintext form raises concerns regarding users' privacy and security. To address these concerns, this study proposes an efficient privacy-preserving secure neural network inference scheme based on homomorphic encryption and secure multi-party computation, which ensures the privacy of both the user and the cloud server while enabling fast and accurate ciphertext inference. First, we divide the inference process into three stages, including the merging stage for adjusting the network structure, the preprocessing stage for performing homomorphic computations, and the online stage for floating-point operations on the secret sharing of private data. Second, we propose an approach of merging network parameters, thereby reducing the cost of multiplication levels and decreasing both ciphertext–plaintext multiplication and addition operations. Finally, we propose a fast convolution algorithm to enhance computational efficiency. Compared with other state-of-the-art methods, our scheme reduces the linear operation time in the online stage by at least 11%, significantly reducing inference time and communication overhead.

1. Introduction

With the rapid development of smart devices, multimedia data such as images are playing an increasingly prominent role in various fields, and many users choose to outsource their data to cloud servers for processing and storage (Chai et al., 2022). Although the cloud servers provide convenient services, they also introduce additional security concerns. When the users upload private data containing sensitive information to the cloud servers, the latter ones may stealthily access the former ones’ data, leading to the leakage of sensitive information (Riazi et al., 2018; Ng and Chow, 2021). Furthermore, the parameters of intelligent models (e.g., neural networks) stored on the cloud servers are considered private, posing a risk of the model parameters inferred by the users, thus requiring protection (Chaudhari et al., 2020; Ma et al., 2021; Wang Y et al., 2023).

To protect the users’ privacy and ensure the cloud servers’ security, homomorphic encryption technology for computations under ciphertext has emerged as a preferable solution (Li JS et al., 2020). The users encrypt their private data before uploading them to the cloud servers for inference calculations, and the cloud servers return the encrypted prediction results for decryption by the users, thereby achieving inference while protecting the privacy of both the users and servers (Liu et al., 2017). In recent years, convolutional neural networks (CNNs) have flourished, demonstrating their capability to extract more abstract and complex features from data (Schroff et al., 2015) and further enhancing inference accuracy. This advancement has led to widespread applications in encrypted image prediction (Li Y et al., 2024).

Dowlin et al. (2016) proposed CryptoNets, which encrypts multiple inputs into a single ciphertext for parallel computation, replacing max pooling with average pooling and employing the square function as the activation function, marking the first instance of using CNN for encrypted image prediction. Hesamifard et al. (2017) proposed CryptoDL, which replaces the activation functions in neural network models with polynomial functions and provides mathematical expressions for low-degree polynomial approximation activation functions. Chou et al. (2018) devised Faster CryptoNets, accelerating inference by integrating neural network pruning methods to reduce the number of parameters in the original model. Chabanne et al. (2017) attempted to integrate batch normalization (BN) layers commonly used in deep learning with existing encryption schemes, effectively deepening the network layers. Ishiyama et al. (2020) proposed a scheme for normalizing inputs using BN layers and approximating the Swish and rectified linear unit (ReLU) with polynomial functions. They mitigated multiplication levels to reduce the multiplication cost in the ciphertext domain by preprocessing the coefficients of the highest-order terms in the polynomial. They provided evaluation results for different fitting intervals. However, despite the advancements made by the aforementioned studies, which leverage polynomial approximation and square function for nonlinear operations, they often suffer from a notable drawback: the loss of inference accuracy (Li QF et al., 2020; Iha et al., 2021; Lou et al., 2021).

SinoTechIntel Interactive Document Reader
Page 1–5 of Preview
100%
Download Full PDF

Loading authentic research manuscript (Pages 1–5)...

Sponsored Research Partner
Cite This Research Paper
Liquan CHEN, Zixuan YANG, Peng ZHANG, Yang MA (2025). Efficient privacy-preserving scheme for secure neural network inference. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2400371
SinoTechIntel Academic & Legal Disclaimer

Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.

Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.

Frequently Asked Questions

What is the main contribution of this paper?

The paper proposes an efficient privacy-preserving scheme for secure neural network inference based on homomorphic encryption and secure multi-party computation, ensuring both user data and model parameters remain private while enabling fast and accurate ciphertext inference.

How does the proposed scheme reduce computational overhead?

The scheme reduces multiplication levels and ciphertext–plaintext operations via network parameter merging, and introduces a fast convolution algorithm to enhance efficiency, achieving at least 11% reduction in online stage linear operation time.

What are the three stages of the inference process?

The three stages are the merging stage for adjusting the network structure, the preprocessing stage for performing homomorphic computations, and the online stage for floating-point operations on the secret sharing of private data.

What is the significance of using homomorphic encryption in this context?

Homomorphic encryption allows computations to be performed on encrypted data, enabling cloud servers to conduct inference without accessing the raw private data, thereby protecting user privacy and server model parameters.

How does this scheme compare with existing methods?

Compared with state-of-the-art methods, the proposed scheme reduces linear operation time in the online stage by at least 11%, significantly decreasing inference time and communication overhead.

Recommended Scientific Literature & Research Partners

Related Technical Papers & Translations

Research Paper
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.

Read Abstract & PDF
Research Paper
A cohesion loss model for determining residual strength of deep bedded sandstone

A cohesion loss model for determining residual strength of deep bedded sandstone

Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s

Read Abstract & PDF
Research Paper
Federated model with contrastive learning and adaptive control variates for human activity recognition

Federated model with contrastive learning and adaptive control variates for human activity recognition

Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena

Read Abstract & PDF