TY - GEN
T1 - SEAF
T2 - 34th USENIX Security Symposium, USENIX Security 2025
AU - Guo, Hao
AU - Liu, Zhaoqian
AU - Fu, Ximing
AU - Liu, Zhusen
N1 - Publisher Copyright:
© 2025 by The USENIX Association All Rights Reserved.
PY - 2025
Y1 - 2025
N2 - Secure evaluation of non-linear functions is one of the most expensive operations in secure two-party computation, particularly for activation functions in privacy preserving machine learning (PPML). This work introduces SEAF, a novel framework for efficient Secure Evaluation on Activation Functions. SEAF is based on the linear approximation approach, but enhances it by introducing two key innovations: Trun-Eq based interval test protocols and linear approximation with dynamic precision, which have the potential for broader applicability. Furthermore, we classify common activation functions into several categories, and present specialized methods to evaluate them using our enhanced techniques. Our implementation of SEAF demonstrates 3.5× to 5.9× speedup on activation functions Tanh and Sigmoid compared to SirNN (S&P’21). When applied on GELU, SEAF outperforms Iron (NeurIPS’22) by more than 10× and Bolt (S&P’24) by up to 3.4×. For end-to-end secure inference on BERT, the original GELU accounts for 31.3% and 22.5% of the total runtime in Iron and Bolt, respectively. In contrast, our optimized GELU reduces these proportions to 4.3% and 9.8%, eliminating GELU as a bottleneck in secure inference.
AB - Secure evaluation of non-linear functions is one of the most expensive operations in secure two-party computation, particularly for activation functions in privacy preserving machine learning (PPML). This work introduces SEAF, a novel framework for efficient Secure Evaluation on Activation Functions. SEAF is based on the linear approximation approach, but enhances it by introducing two key innovations: Trun-Eq based interval test protocols and linear approximation with dynamic precision, which have the potential for broader applicability. Furthermore, we classify common activation functions into several categories, and present specialized methods to evaluate them using our enhanced techniques. Our implementation of SEAF demonstrates 3.5× to 5.9× speedup on activation functions Tanh and Sigmoid compared to SirNN (S&P’21). When applied on GELU, SEAF outperforms Iron (NeurIPS’22) by more than 10× and Bolt (S&P’24) by up to 3.4×. For end-to-end secure inference on BERT, the original GELU accounts for 31.3% and 22.5% of the total runtime in Iron and Bolt, respectively. In contrast, our optimized GELU reduces these proportions to 4.3% and 9.8%, eliminating GELU as a bottleneck in secure inference.
UR - https://www.scopus.com/pages/publications/105021352420
M3 - 会议稿件
AN - SCOPUS:105021352420
T3 - Proceedings of the 34th USENIX Security Symposium
SP - 3417
EP - 3435
BT - Proceedings of the 34th USENIX Security Symposium
PB - USENIX Association
Y2 - 13 August 2025 through 15 August 2025
ER -