Abstract
In this paper, we present Antelope, a semi-honest large-scale secure inference system without revealing either clients' data or model parameters. The main contributions of Antelope are new two-party computation (2PC) protocols over a ring Z2ℓ for non-linear layers, which optimize the online computation and communication overhead thus outperforming the state-of-the-art 2PC systems. Specifically, we reformulate the comparison function as an Equality-to-Zero test followed by multiplication, decoupling the bit-wise rounding dependency in traditional secret sharing-based bit extraction. With this technique, the evaluation of the ReLU non-linear activation function is 1.7×-84.5× faster than existing solutions in online communication cost. We also develop a suite of optimizations that improve the efficiency of secure division protocols, which are tailored to different divisor settings in the neural networks. We extend our protocols to construct efficient implementations for several building blocks such as ReLU, Maxpool, truncation, and Softmax. End-to-end evaluation on realistic ImageNet-scale networks demonstrates that Antelope achieves over 22.3× and 23.0× online runtime speedups in LAN and WAN settings, respectively, without accuracy loss, compared to the state-of-the-art works. © 2025 IEEE.
| Original language | English |
|---|---|
| Pages (from-to) | 7334-7347 |
| Number of pages | 14 |
| Journal | IEEE Transactions on Dependable and Secure Computing |
| Volume | 22 |
| Issue number | 6 |
| Online published | 7 Aug 2025 |
| DOIs | |
| Publication status | Published - Nov 2025 |
| Externally published | Yes |
Funding
This work was supported in part by Beijing Natural Science Foundation under Grant L251038 and Grant QY24203, in part by CCF-Huawei Populus Grove Fund under Grant TC202418, in part by the Fellowship of China National Postdoctoral Program for Innovative Talents under Grant BX20240045, and in part by China Postdoctoral Science Foundation General Program under Grant 2025M773481.
Research Keywords
- Neural network inference
- secure two-party protocol
Fingerprint
Dive into the research topics of 'Antelope: Fast and Secure Neural Network Inference'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver