Skip to main navigation Skip to search Skip to main content

Antelope: Fast and Secure Neural Network Inference

  • Xiaoyuan Liu
  • , Hongwei Li
  • , Guowen Xu*
  • , Shengmin Xu
  • , Xinyi Huang
  • , Tianwei Zhang
  • , Yijing Lin
  • , Jianying Zhou
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

In this paper, we present Antelope, a semi-honest large-scale secure inference system without revealing either clients' data or model parameters. The main contributions of Antelope are new two-party computation (2PC) protocols over a ring Z2ℓ for non-linear layers, which optimize the online computation and communication overhead thus outperforming the state-of-the-art 2PC systems. Specifically, we reformulate the comparison function as an Equality-to-Zero test followed by multiplication, decoupling the bit-wise rounding dependency in traditional secret sharing-based bit extraction. With this technique, the evaluation of the ReLU non-linear activation function is 1.7×-84.5× faster than existing solutions in online communication cost. We also develop a suite of optimizations that improve the efficiency of secure division protocols, which are tailored to different divisor settings in the neural networks. We extend our protocols to construct efficient implementations for several building blocks such as ReLU, Maxpool, truncation, and Softmax. End-to-end evaluation on realistic ImageNet-scale networks demonstrates that Antelope achieves over 22.3× and 23.0× online runtime speedups in LAN and WAN settings, respectively, without accuracy loss, compared to the state-of-the-art works. © 2025 IEEE.
Original languageEnglish
Pages (from-to)7334-7347
Number of pages14
JournalIEEE Transactions on Dependable and Secure Computing
Volume22
Issue number6
Online published7 Aug 2025
DOIs
Publication statusPublished - Nov 2025
Externally publishedYes

Funding

This work was supported in part by Beijing Natural Science Foundation under Grant L251038 and Grant QY24203, in part by CCF-Huawei Populus Grove Fund under Grant TC202418, in part by the Fellowship of China National Postdoctoral Program for Innovative Talents under Grant BX20240045, and in part by China Postdoctoral Science Foundation General Program under Grant 2025M773481.

Research Keywords

  • Neural network inference
  • secure two-party protocol

Fingerprint

Dive into the research topics of 'Antelope: Fast and Secure Neural Network Inference'. Together they form a unique fingerprint.

Cite this