Abstract
With the extensive deployment of deep neural networks in key areas such as image recognition, natural language processing, medical decision-making and financial risk control, issues of data security and privacy protection have become increasingly prominent. During the processes of training and inference, models often need to directly access highly sensitive data, while traditional encryption and access-control mechanisms cannot effectively prevent data leakage in open or untrusted computing environments, revealing a trust gap in the practical deployment of deep learning. Confidential computing technology establishes a protected execution environment at the hardware or cryptographic level, in which data remain usable but invisible, thus providing new ideas and fundamental support for the privacy protection of neural networks. This technology enables secure model training and inference without revealing plaintext data, thereby realising trustworthy artificial intelligence across cloud, edge and multi-party collaborative settings. However, confidential computing still faces challenges such as large performance overheads, high programming complexity and limited compatibility, and its application in the field of neural networks requires a balance between security, efficiency and deployability. This paper systematically reviews the core technological pathways and evolutionary trends of confidential computing in neural-network training and inference, providing a comprehensive overview ranging from hardware-based security schemes built on trusted execution environments to software-based secure computation frameworks grounded in cryptographic primitives. At the hardware level, the paper focuses on the system architectures and security mechanisms of confidential-computing technologies such as Intel SGX, AMD SEV and NVIDIA GPU privacy extensions in supporting deep-learning tasks, and compares performance-optimisation strategies and system-design differences between CPU and GPU environments. From the cryptographic perspective, this paper discusses in depth the main homomorphic-encryption schemes used in neural-network inference, analysing their issues in numerical precision, latency and ciphertext expansion, as well as secure multi-party computation applied in joint training and distributed inference, examining their communication complexity and fault-tolerance mechanisms; it also introduces the latest explorations of zero-knowledge proofs in verifiable model computation and privacy-preserving inference. Furthermore, the paper reviews hybrid frameworks combining homomorphic encryption and multi-party computation, elucidating their design trade-offs and representative applications in terms of efficiency, security and scalability, and explores the latest advances in improving confidential-computing performance through hardware acceleration and system-level optimisation. Finally, the paper summarises the currently available confidential-computing framework systems for artificial neural networks, compares and analyses their advantages and limitations in terms of security models, functional capabilities, system performance and applicable scenarios, and proposes strategies and considerations for framework selection in different application scenarios including training, inference, federated learning and cross-domain collaboration. The comprehensive analysis indicates that although confidential computing has made significant progress in both theoretical research and engineering practice, existing solutions still find it difficult to achieve a full balance among efficiency, security and generality in the context of rapidly increasing model complexity, hardware constraints and growing demands for multi-party trust collaboration. Future development requires breakthroughs through the collaborative design of basic theory, cryptographic protocols and hardware architectures, and the promotion of standardized interfaces, verifiable execution and programmable security systems, so as to build a highly efficient and trustworthy ecosystem for next-generation secure intelligent computing.
| Translated title of the contribution | 神经网络训练与推理中的机密计算技术综述: 从 TEE 到密码学原语 |
|---|---|
| Original language | English |
| Pages (from-to) | 885-917 |
| Number of pages | 33 |
| Journal | Jisuanji Xuebao/Chinese Journal of Computers |
| Volume | 49 |
| Issue number | 4 |
| DOIs | |
| State | Published - Apr 2026 |
| Externally published | Yes |
Keywords
- confidential computing
- deep learning
- homomorphic encryption
- neural network
- privacy computing
- secure multi-party computation
Fingerprint
Dive into the research topics of 'Confidential Computing Techniques in Neural Network Training and Inference: From TEE to Cryptographic Foundations'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver