Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

PyCrCNN

PyCrCNN is the implementation of a privacy-respectful Machine Learning as a Service (MLaaS) which use Homomorphic Encryption (HE). The application has been tailored on Convolutional Neural Networks (CNNs).

PyCrCNN has been introduced in the paper "A Privacy-Preserving Distributed Architecture for Deep-Learning-as-a-Service".

For an introduction to Homomorphic Encryption, check out our new work!

Disclaimer: we are working on the topic, so, expect changes in this repo.

Introduction

PyCrCNN is a client/server application in which the server can run a Convolutional Neural Network on some data coming from a client. The peculiarity of this application is that Homomorphic Encryption is used: the data coming from the client (in this case, an image) is encrypted and the server doesn't have the keys to decrypt it.

Computation on encrypted data is still allowed by the mathematical properties of this kind of encryption which is, in fact, homomorphic with respect to addition and multiplication. This means that the models have to be approximated, in order to contain only additions and multiplications.

External libraries used

You can install them using the provided requirements.txt file. WARNING: to install Pyfhel a small modification is needed (check this issue). It is suggested to clone Pyfhel using the instructions on their repo (to correctly crone all the submodules), modify pyproject.toml to set the SEAL_THROW_ON_TRANSPARENT_CIPHERTEXT to OFF and install from there with pip install ..

How to use

Clone the repo, install the dependencies and try to run the notebook HE-ML/HE-ML_CKKS.ipynb. It will give you a fair introduction to the package.

Docker

We provide a devcontainer file, that will let you use VSCode and devcontainers to recreate the needed environment.

Package organization

  • convolutional: Code for convolutional layers
  • crypto: Code for crypyographic operations, like encrypting matrix, encoding matrix, etc
  • functional: Code for functional operations like Square Layers, AvgPool layers, etc
  • linear: Code for linear layers
  • net_builder: Code for building encoded model, starting from a PyTorch model
  • network: Client and server code
  • parameters_tester: Code to let user test the encryption parameters, given a model and such parameters. Statistics will be put in output.
  • tests

Functionalities

Encoded layers

Encoded layers are layers with the same characteristics of a normal PyTorch layer, but their weights have been encoded: this means that they are good to work on encrypted data.

In fact, in a normal forward on a normal CNN, computations between numbers are of the type:

(Float, Float) -> Float

In an HE environment, computations between numbers are of the type:

(EncryptedFrac, EncodedFrac) -> EncryptedFrac

In general, layers have been made with an eye on PyTorch definition: the reason is to be quite similar in the use to the correspondent PyTorch objects, without many differences. For example, an encoded convolutional layer can be built with:

ConvolutionalLayer(HE, weights=torchLayer.weight.detach().numpy(),
stride=torchLayer.stride, padding=torchLayer.padding, bias=torchLayer.bias)

The weights will be automatically encoded in Encoded Fractionals.

Furthermore, like in PyTorch, layers are callable objects: that means that, if we have an image (of the form of a numpy.array of EncryptedFrac), we can call the forward function off the layer just with

results=encodedLayer(encrypted_image)

Net builder

The code provided in the net_builder subpackage can retrieve a PyTorch model with some restrictions and build an encoded model with the same layers/weights: that is, an equivalent model able to work on encrypted data.

PyTorch model have to respect these constraints:

If they are satisfied, the model can be built with:

build_from_pytorch(HE, net, rencrypt_positions=[])

Where

  • HE is a Pyfhel object
  • net is the PyTorch object, loaded with the load() function
  • rencrypt_positions can be used to put some rencryption layers in the resulting encoded model, i.e layers in which the input image is re-encrypted in order to restore the Noise Budget to the original level: in a real scenario, the server should send the partial results back to the client which will re-encrypt them and re-send them to the server to continue.

The function will return an ordered list of encoded layers.

Parameter tester

The parameter tester loads a set of encryption parameters in JSON, a PyTorch model, and tests that model against its encoded corrispective on an image. An example of input may be:

{
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2,
"rencrypt_positions": [ ]
}
],
"debug" : "y"
}

After the computation, a JSON results will be procuded: it will contain variouos information like the maximum error (that is the maximum difference between a value in the plain case and its corrispective encrypted value), the average error, the noise budget consumption etc.

REST Client/Server

Built with flask, the server proides a REST endpoint to let client send requests for computations. image.png

An example of client parameters is:

{
"address" : "http://127.0.0.1:5000/compute",
"encryption_parameters" : [
{
"m": 2048,
"p": 13513511,
"sec": 128,
"base": 2
}
],
"net" : "MNIST",
"layers" : [0, 1, 2, 3]
}

In this example, the client is asking to forward the image on the net called "MNIST", only on layers from 0 to 3. The client has encrypted the image with such parameters: the server will encode the model with them as well.

About

Privacy-Preserving Convolutional Neural Networks using Homomorphic Encryption

Topics

Resources

Stars

83 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages