Secure Quantized Training for Deep Learning
Marcel KellerKe Sun
Demonstrates practical deep neural network training within secure multi-party computation by introducing optimized protocols for exponentiation and inverse square roots that achieve near-plaintext accuracy on standard image benchmarks across various threat models.
Organizations in regulated domains such as healthcare and finance increasingly seek to train deep learning models collaboratively without exposing private underlying datasets. Secure multi-party computation enables multiple parties to jointly evaluate functions on private inputs while keeping the data confidential. However, prior attempts to train deep neural networks within this framework have suffered from severe performance bottlenecks, practical instability, or substantial drops in model accuracy due to poor approximations of complex mathematical functions and high communication overhead.
The article demonstrates an extensible framework for end-to-end neural network training entirely within secure multi-party computation. It evaluates how low-precision fixed-point representation combined with optimized cryptographic subroutines can achieve classification accuracy comparable to standard, unencrypted training while remaining computationally practical across diverse security setups.
To achieve this, the authors implemented neural network training using fixed-point arithmetic in native CPU code based on the open-source MP-SPDZ library. They developed novel mixed-circuit cryptographic protocols for exponentiation and inverse square root operations, which are essential for evaluating softmax functions and modern adaptive optimizers such as AMSGrad and Adam. The evaluation benchmarked standard image classification tasks—including MNIST and CIFAR-10—across multiple network architectures and security models, testing configurations with up to ten parties under both honest-majority and dishonest-majority assumptions.
The findings show that training purely within secure multi-party computation can match standard unencrypted performance within tight margins. On the MNIST dataset, a convolutional neural network achieved 99.2% accuracy in 3.5 hours (reaching 99.0% within one hour), trailing unencrypted training accuracy by less than 0.2 percentage points. The newly developed exponentiation protocol reduced communication overhead by roughly 30% compared to prior art, while the inverse square root protocol halved communication costs. Furthermore, theoretical analysis and empirical results confirmed that probabilistic rounding delivers unbiased matrix multiplication and injects useful noise, allowing a 16-bit precision parameter to perform as well as higher-precision configurations while minimizing data transfer. On CIFAR-10 using an AlexNet-style architecture with batch normalization, secure training converged within a few hours to 64.9% accuracy, tracking closely with unencrypted baselines.
These results demonstrate that privacy-preserving machine learning does not require sacrificing model accuracy or resorting to oversimplified, unstable mathematical replacements. By moving critical computations into native execution and minimizing communication rounds, secure multi-party computation becomes a viable alternative to trusted hardware or slower homomorphic encryption systems. The findings also highlight that network communication, rather than raw floating-point computing power, is the primary performance bottleneck in secure training, making optimized CPU architectures more effective than graphics processors in these environments.
Decision-makers considering collaborative, privacy-preserving machine learning should focus on implementations using native CPU execution and exact mathematical representations rather than unverified approximations. When designing systems, teams should adopt probabilistic rounding at 16-bit fixed-point precision to optimize both network bandwidth and classification performance. For architectures requiring adaptive gradient methods or normalization layers, incorporating optimized mixed-circuit protocols will prevent divergence and improve throughput.
The primary limitation of this work is that evaluations were conducted in local area network environments on small-to-moderate image datasets rather than massive industrial datasets containing millions of samples. While confidence in the mathematical correctness and stability of the system is high, performance will vary depending on network latency and bandwidth across wider geographic areas. Further pilot deployments on real-world distributed infrastructure are recommended to evaluate operational communication limits.
- Paper: Deep Learning with Limited Numerical Precision, Suyog Gupta et al. (2015). Its demonstration that stochastic rounding makes 16-bit fixed-point neural-network training accurate provides the numerical-precision foundation for this paper’s secure quantized training.
- Paper: CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy, Nathan Dowlin et al. (2016). This early encrypted-neural-network study establishes why cryptographic limits on nonlinear operations motivate the secure computation design developed here.
- Paper: Communication-Efficient Learning of Deep Networks from Decentralized Data, H. B. McMahan et al. (2016). Its FedAvg work introduces collaborative training that avoids raw-data pooling, clarifying the distributed-learning setting this paper protects with secure computation.
No sufficiently relevant recommendations were found.
