Publications-Theses
Article View/Open
Publication Export
-
題名 結合隱私保護功能之GRU預測模型框架
A Study on Privacy-preserving GRU Inference Framework作者 蕭守晴
Hsiao, Shou-Ching貢獻者 左瑞麟
Tso, Ray-Lin
蕭守晴
Hsiao, Shou-Ching關鍵詞 隱私保護
Gated Recurrent Unit模型
秘密分享
Universal Composability架構
Privacy-preserving
Gated Recurrent Unit Model
Secret Sharing
Universal Composability Framework日期 2020 上傳時間 2-Sep-2020 12:15:48 (UTC+8) 摘要 Gated Recurrent Unit (GRU) 模型具有廣泛應用,包括情緒分析、語音辨識、惡意程式分析等領域。在提供服務階段,模型擁有者常選擇雲端機器學習服務 (Machine-learning-as-a-service, MLaaS) 作為系統架構,因其提供企業以低建置成本部屬模型且達到高效能機器學習服務;然而,資料上傳至雲端會產生隱私疑慮,包括模型隱私、使用者資料隱私以及預測結果隱私,無論是雲端代管商遭受外部入侵或內部員工竊取,都有可能造成隱私洩漏。本篇研究主要針對含有隱私資料的預測情境,如文字資料、網路封包資料、醫療心電圖等資料,並選用能學習時序關聯性的 GRU 模型來設計隱私保護預測框架。考量系統的準確度與效能,本文採用秘密分享 (Secret Sharing) 機制作為主要保護隱私方式,並設計基於秘密分享的 GRU 系統架構與演算法。由於所有雲端上的運算都針對分享秘密 (Secret Shares) 進行,任何一方都無法從部分秘密得知原本的模型參數、預測資料及預測結果,其安全性在半誠實攻擊者模型下可透過Universal Composability證明,並確保能安全地套用至不同架構之 GRU 模型。除此之外,本文也透過實作證實架構與演算法的正確性,並分別以時間與準確度呈現實驗結果。
Gated Recurrent Unit (GRU) has broad application fields, such as sentiment analysis, speech recognition, malware analysis, and other sequential data processing. For low-cost deployment and efficient machine learning services, a growing number of model owners choose to deploy the trained GRU models through Machine-learning-as-a-service (MLaaS). However, privacy has become a significant concern for both model owners and prediction clients, including model weights privacy, input data privacy, and output results privacy. The privacy leakage may be caused by either external intrusion or insider attacks. To address the above issues, this research designs a framework for privacy-preserving GRU models, which aims for privacy scenarios such as predicting on textual data, network packets, heart rate data, and so on. In consideration of accuracy and efficiency, this research uses additive secret sharing to design the basic operations and gating mechanisms of GRU. The protocols can meet the security requirements of privacy and correctness under the Universal Composability framework with the semi-honest adversary. Additionally, the framework and protocols are realized with a proof-of-concept implementation. The experimental results are presented with respect to time consumption and inference accuracy.參考文獻 [1] M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang. Deep\nlearning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on\nComputer and Communications Security, pages 308–318, 2016.\n[2] A. F. Agarap and F. J. H. Pepito. Towards Building an Intelligent Anti-Malware System: A Deep\nLearning Approach using Support Vector Machine (SVM) for Malware Classification. arXiv\npreprint arXiv:1801.00318, 2017.\n[3] G. Beigi, K. Shu, R. Guo, S. Wang, and H. Liu. Privacy Preserving Text Representation Learning.\nProceedings of the 30th on Hypertext and Social Media (HT’19). ACM, 2019.\n[4] S. Biswas, E. Chadda, and F. Ahmad. Sentiment Analysis with Gated Recurrent Units. Department\nof Computer Engineering. Annual Report Jamia Millia Islamia New Delhi, India, 2015.\n[5] G. R. Blakley. Safeguarding cryptographic keys. In 1979 International Workshop on Managing\nRequirements Knowledge (MARK), pages 313–318. IEEE, 1979.\n[6] R. Canetti. Security and Composition of Multiparty Cryptographic Protocols. Journal of CRYPTOLOGY,\n13(1):143–202, 2000.\n[7] R. Canetti. Universally Composable Security: A New Paradigm for Cryptographic Protocols.\nIn Proceedings 42nd IEEE Symposium on Foundations of Computer Science, pages 136–145.\nIEEE, 2001.\n[8] R. Canetti. Security and composition of cryptographic protocols: a tutorial (part i). ACM SIGACT\nNews, 37(3):67–92, 2006.\n[9] R. Canetti, A. Cohen, and Y. Lindell. A Simpler Variant of Universally Composable Security\nfor Standard Multiparty Computation. In Annual Cryptology Conference, pages 3–22. Springer,\n2015.\n[10] T. Capes, P. Coles, A. Conkie, L. Golipour, A. Hadjitarkhani, Q. Hu, N. Huddleston, M. Hunt,\nJ. Li, M. Neeracher, et al. Siri On-Device Deep Learning-Guided Unit Selection Text-to-Speech\nSystem. In INTERSPEECH, pages 4011–4015, 2017.\n[11] H. Chabanne, A. de Wargny, J. Milgram, C. Morel, and E. Prouff. Privacy-preserving Classification\non Deep Neural Network. IACR Cryptology ePrint Archive, 2017:35, 2017.\n[12] C.-C. Chiu, T. N. Sainath, Y. Wu, R. Prabhavalkar, P. Nguyen, Z. Chen, A. Kannan, R. J.\nWeiss, K. Rao, E. Gonina, et al. State-of-the-art Speech Recognition with Sequence-to-sequence\nModels. In 2018 IEEE International Conference on Acoustics, Speech and Signal Processing\n(ICASSP), pages 4774–4778. IEEE, 2018.\n[13] K. Cho, B. Van Merriënboer, C. Gulcehre, D. Bahdanau, F. Bougares, H. Schwenk, and Y. Bengio.\nLearning Phrase Representations using RNN Encoder-decoder for Statistical Machine\nTranslation. arXiv preprint arXiv:1406.1078, 2014.\n[14] J. Chung, C. Gulcehre, K. Cho, and Y. Bengio. Empirical Evaluation of Gated Recurrent Neural\nNetworks on Sequence Modeling. arXiv preprint arXiv:1412.3555, 2014.\n[15] M. De Cock, R. Dowsley, A. C. Nascimento, D. Reich, and A. Todoki. Privacy-Preserving\nClassification of Personal Text Messages with Secure Multi-Party Computation: An Application\nto Hate-Speech Detection. arXiv preprint arXiv:1906.02325, 2019.\n[16] W. Diffie and M. Hellman. New Directions in Cryptography. IEEE transactions on Information\nTheory, 22(6):644–654, 1976.\n[17] W. Du and M. J. Atallah. Protocols for Secure Remote Database Access with Approximate\nMatching. In E-Commerce Security and Privacy, pages 87–111. Springer, 2001.\n[18] C. Dwork. Differential Privacy. Encyclopedia of Cryptography and Security, pages 338–340,\n2011.\n[19] M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart. Privacy in pharmacogenetics:\nAn end-to-end case study of personalized warfarin dosing. In 23rd fUSENIXg Security\nSymposium (fUSENIXg Security 14), pages 17–32, 2014.\n[20] R. Fu, Z. Zhang, and L. Li. Using LSTM and GRU Neural Network Methods for Traffic Flow\nPrediction. In 2016 31st Youth Academic Annual Conference of Chinese Association of Automation\n(YAC), pages 324–328. IEEE, 2016.\n[21] R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing. Cryptonets:\nApplying neural networks to encrypted data with high throughput and accuracy. In International\nConference on Machine Learning, pages 201–210, 2016.\n[22] O. Goldreich. Foundations of Cryptography: volume 1, basic tools. Cambridge university press,\n2007.\n[23] O. Goldreich. Foundations of cryptography: volume 2, basic applications. Cambridge university\npress, 2009.\n[24] O. Goldreich, S. Micali, and A. Wigderson. How to Play Any Mental Game, or A Completeness\nTheorem for Protocols with Honest Majority. In Providing Sound Foundations for Cryptography:\nOn the Work of Shafi Goldwasser and Silvio Micali, pages 307–328. 2019.\n[25] Q. Gu, N. Lu, and L. Liu. A Novel Recurrent Neural Network Algorithm with Long Short-term\nMemory Model for Futures Trading. Journal of Intelligent & Fuzzy Systems, 37(4):1–8.\n[26] X. Hu, L. Liang, L. Deng, S. Li, X. Xie, Y. Ji, Y. Ding, C. Liu, T. Sherwood, and Y. Xie. Neural\nnetwork model extraction attacks in edge devices by hearing architectural hints. arXiv preprint\narXiv:1903.03916, 2019.\n[27] Y. Huang. Practical Secure Two-party Computation. PhD thesis, Citeseer, 2012.\n[28] T. Hunt, C. Song, R. Shokri, V. Shmatikov, and E. Witchel. Chiron: Privacy-preserving Machine\nLearning as a Service. arXiv preprint arXiv:1803.05961, 2018.\n[29] Z. Ji, Z. C. Lipton, and C. Elkan. Differential Privacy and Machine Learning: A Survey and\nReview. arXiv preprint arXiv:1412.7584, 2014.\n[30] C. Juvekar, V. Vaikuntanathan, and A. Chandrakasan. GAZELLE: A Low Latency Framework\nfor Secure Neural Network Inference. In 27th USENIX Security Symposium (USENIX Security\n18), pages 1651–1669, 2018.\n[31] R. Küsters and D. Rausch. A framework for universally composable diffie-hellman key exchange.\nIn 2017 IEEE Symposium on Security and Privacy (SP), pages 881–900. IEEE, 2017.\n[32] R. Küsters and M. Tuengerthal. Universally composable symmetric encryption. In 2009 22nd\nIEEE Computer Security Foundations Symposium, pages 293–307. IEEE, 2009.\n[33] Y. Li, T. Baldwin, and T. Cohn. Towards Robust and Privacy-preserving Text Representations.\narXiv preprint arXiv:1805.06093, 2018.\n[34] Y. Lindell. How to Simulate It–A Tutorial on the Simulation Proof Technique. In Tutorials on\nthe Foundations of Cryptography, pages 277–346. Springer, 2017.\n[35] J. Liu, M. Juuti, Y. Lu, and N. Asokan. Oblivious Neural Network Predictions via Minionn\nTransformations. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications\nSecurity, pages 619–631. ACM, 2017.\n[36] L. Ma, S. Liu, and Y. Wang. A DRM model based on Proactive Secret Sharing Scheme for P2P\nNetworks. In 9th IEEE International Conference on Cognitive Informatics (ICCI’10), pages\n859–862. IEEE, 2010.\n[37] A. L. Maas, R. E. Daly, P. T. Pham, D. Huang, A. Y. Ng, and C. Potts. Learning Word Vectors\nfor Sentiment Analysis. In Proceedings of the 49th annual meeting of the association for computational\nlinguistics: Human language technologies, volume 1, pages 142–150. Association for\nComputational Linguistics, 2011.\n[38] P. Mohassel and Y. Zhang. Secureml: A System for Scalable Privacy-preserving Machine Learning.\nIn 2017 IEEE Symposium on Security and Privacy (SP), pages 19–38. IEEE, 2017.\n[39] T. B. Pedersen, Y. Saygın, and E. Savaş. Secret Sharing vs. Encryption-based Techniques for\nPrivacy Preserving Data Mining. 2007.\n[40] P. Poomka, W. Pongsena, N. Kerdprasop, and K. Kerdprasop. Sms spam detection based on\nlong short-term memory and gated recurrent unit. International Journal of Future Computer\nand Communication, 8(1), 2019.\n[41] M. S. Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schneider, and F. Koushanfar.\nChameleon: A Hybrid Secure Computation Framework for Machine Learning Applications. In\nProceedings of the 2018 on Asia Conference on Computer and Communications Security, pages\n707–721. ACM, 2018.\n[42] M. Ribeiro, K. Grolinger, and M. A. Capretz. Mlaas: Machine learning as a service. In 2015\nIEEE 14th International Conference on Machine Learning and Applications (ICMLA), pages\n896–902. IEEE, 2015.\n[43] V. Rijmen and J. Daemen. Advanced encryption standard. Proceedings of Federal Information\nProcessing Standards Publications, National Institute of Standards and Technology, pages 19–\n22, 2001.\n[44] R. L. Rivest, L. Adleman, M. L. Dertouzos, et al. On Data Banks and Privacy Homomorphisms.\nFoundations of secure computation, 4(11):169–180, 1978.\n[45] B. D. Rouhani, M. S. Riazi, and F. Koushanfar. Deepsecure: Scalable Provably-secure Deep\nLearning. In Proceedings of the 55th Annual Design Automation Conference, page 2. ACM,\n2018.\n[46] S. van der Walt, S.C. Colbert, and G. Varoquaux. The NumPy Array: A Structure for Efficient\nNumerical Computation. Computing in Science Engineering, 13(2):22–30, March 2011.\n[47] N. Saleem, M. Irfan Khattak, and A. B. Qazi. Supervised Speech Enhancement based on Deep\nNeural Network. Journal of Intelligent & Fuzzy Systems, 37(4):5187–5201, 2019.\n[48] A. Shamir. How to Share a Secret. Communications of the ACM, 22(11):612–613, 1979.\n[49] D. Takabi, R. Podschwadt, J. Druce, C. Wu, and K. Procopio. Privacy Preserving Neural Network\nInference on Encrypted Data with GPUs. arXiv preprint arXiv:1911.11377, 2019.\n[50] S. Wagh, D. Gupta, and N. Chandran. SecureNN: 3-Party Secure Computation for Neural Network\nTraining. Proceedings on Privacy Enhancing Technologies, 1:24, 2019.\n[51] L. Wang, X. Shen, J. Li, J. Shao, and Y. Yang. Cryptographic Primitives in Blockchains. Journal\nof Network and Computer Applications, 127:43–58, 2019.\n[52] A. C.-C. Yao. How to Generate and Exchange Secrets. In 27th Annual Symposium on Foundations\nof Computer Science (SFCS 1986), pages 162–167. IEEE, 1986.\n[53] W. Yin, K. Kann, M. Yu, and H. Schütze. Comparative Study of CNN and RNN for Natural\nLanguage Processing. arXiv preprint arXiv:1702.01923, 2017.\n[54] Z. Ying, S. Cao, P. Zhou, S. Zhang, and X. Liu. Lightweight outsourced privacy-preserving heart\nfailure prediction based on gru. In International Conference on Algorithms and Architectures\nfor Parallel Processing, pages 521–536. Springer, 2019.\n[55] A. Zhang, Z. C. Lipton, M. Li, and A. J. Smola. Dive into Deep Learning. 2020. https:\n//d2l.ai. 描述 碩士
國立政治大學
資訊科學系
107753010資料來源 http://thesis.lib.nccu.edu.tw/record/#G0107753010 資料類型 thesis dc.contributor.advisor 左瑞麟 zh_TW dc.contributor.advisor Tso, Ray-Lin en_US dc.contributor.author (Authors) 蕭守晴 zh_TW dc.contributor.author (Authors) Hsiao, Shou-Ching en_US dc.creator (作者) 蕭守晴 zh_TW dc.creator (作者) Hsiao, Shou-Ching en_US dc.date (日期) 2020 en_US dc.date.accessioned 2-Sep-2020 12:15:48 (UTC+8) - dc.date.available 2-Sep-2020 12:15:48 (UTC+8) - dc.date.issued (上傳時間) 2-Sep-2020 12:15:48 (UTC+8) - dc.identifier (Other Identifiers) G0107753010 en_US dc.identifier.uri (URI) https://ah.lib.nccu.edu.tw/item?item_id=150604 - dc.description (描述) 碩士 zh_TW dc.description (描述) 國立政治大學 zh_TW dc.description (描述) 資訊科學系 zh_TW dc.description (描述) 107753010 zh_TW dc.description.abstract (摘要) Gated Recurrent Unit (GRU) 模型具有廣泛應用,包括情緒分析、語音辨識、惡意程式分析等領域。在提供服務階段,模型擁有者常選擇雲端機器學習服務 (Machine-learning-as-a-service, MLaaS) 作為系統架構,因其提供企業以低建置成本部屬模型且達到高效能機器學習服務;然而,資料上傳至雲端會產生隱私疑慮,包括模型隱私、使用者資料隱私以及預測結果隱私,無論是雲端代管商遭受外部入侵或內部員工竊取,都有可能造成隱私洩漏。本篇研究主要針對含有隱私資料的預測情境,如文字資料、網路封包資料、醫療心電圖等資料,並選用能學習時序關聯性的 GRU 模型來設計隱私保護預測框架。考量系統的準確度與效能,本文採用秘密分享 (Secret Sharing) 機制作為主要保護隱私方式,並設計基於秘密分享的 GRU 系統架構與演算法。由於所有雲端上的運算都針對分享秘密 (Secret Shares) 進行,任何一方都無法從部分秘密得知原本的模型參數、預測資料及預測結果,其安全性在半誠實攻擊者模型下可透過Universal Composability證明,並確保能安全地套用至不同架構之 GRU 模型。除此之外,本文也透過實作證實架構與演算法的正確性,並分別以時間與準確度呈現實驗結果。 zh_TW dc.description.abstract (摘要) Gated Recurrent Unit (GRU) has broad application fields, such as sentiment analysis, speech recognition, malware analysis, and other sequential data processing. For low-cost deployment and efficient machine learning services, a growing number of model owners choose to deploy the trained GRU models through Machine-learning-as-a-service (MLaaS). However, privacy has become a significant concern for both model owners and prediction clients, including model weights privacy, input data privacy, and output results privacy. The privacy leakage may be caused by either external intrusion or insider attacks. To address the above issues, this research designs a framework for privacy-preserving GRU models, which aims for privacy scenarios such as predicting on textual data, network packets, heart rate data, and so on. In consideration of accuracy and efficiency, this research uses additive secret sharing to design the basic operations and gating mechanisms of GRU. The protocols can meet the security requirements of privacy and correctness under the Universal Composability framework with the semi-honest adversary. Additionally, the framework and protocols are realized with a proof-of-concept implementation. The experimental results are presented with respect to time consumption and inference accuracy. en_US dc.description.tableofcontents 1 Introduction 1\n1.1 Motivations and Purposes 2\n1.2 Contributions 3\n2 Definitions and Preliminaries 5\n2.1 Additive Secret Sharing (ASS) 5\n2.2 Gated Recurrent Unit (GRU) Model 7\n2.3 Universal Composability (UC) Framework 8\n3 Technical Literature 11\n3.1 Privacy-preserving Techniques 11\n3.2 Privacy-preserving Deep Neural Network 12\n4 Privacy-preserving GRU Inference Framework 15\n4.1 Architecture 15\n4.2 Security Model 16\n4.2.1 Non-colluding Cloud Servers 17\n4.2.2 Prediction Clients 17\n4.2.3 Outsiders 17\n4.2.4 Network Transmission 17\n4.3 Basic Protocols 18\n4.3.1 Hadamard Product 19\n4.3.2 Division 21\n4.3.3 Share Re-generation 22\n4.3.4 Sigmoid Activation Function 22\n4.3.5 Tanh Activation Function 24\n4.4 Gating Protocols 25\n4.4.1 Update Gate and Reset Gate 25\n4.4.2 Current Memory 26\n4.4.3 Activation of Current Cell 26\n4.5 Putting It All Together 27\n5 Security Analysis 30\n5.1 Security of Basic Protocols 31\n5.2 Security of Gating Protocols 39\n5.3 Security of GRU Inference 41\n6 Experiments and Results 45\n6.1 Dataset 45\n6.2 Implementation 45\n6.3 Results 46\n7 Discussions and Future Works 50\n7.1 Discussions on Accuracy 50\n7.2 Discussions on Time Consumption 51\n7.3 Potential Collusion Problems 52\n7.4 Extended Future Works 53\n8 Conclusion 54\nReference 55 zh_TW dc.format.extent 4667550 bytes - dc.format.mimetype application/pdf - dc.source.uri (資料來源) http://thesis.lib.nccu.edu.tw/record/#G0107753010 en_US dc.subject (關鍵詞) 隱私保護 zh_TW dc.subject (關鍵詞) Gated Recurrent Unit模型 zh_TW dc.subject (關鍵詞) 秘密分享 zh_TW dc.subject (關鍵詞) Universal Composability架構 zh_TW dc.subject (關鍵詞) Privacy-preserving en_US dc.subject (關鍵詞) Gated Recurrent Unit Model en_US dc.subject (關鍵詞) Secret Sharing en_US dc.subject (關鍵詞) Universal Composability Framework en_US dc.title (題名) 結合隱私保護功能之GRU預測模型框架 zh_TW dc.title (題名) A Study on Privacy-preserving GRU Inference Framework en_US dc.type (資料類型) thesis en_US dc.relation.reference (參考文獻) [1] M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang. Deep\nlearning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on\nComputer and Communications Security, pages 308–318, 2016.\n[2] A. F. Agarap and F. J. H. Pepito. Towards Building an Intelligent Anti-Malware System: A Deep\nLearning Approach using Support Vector Machine (SVM) for Malware Classification. arXiv\npreprint arXiv:1801.00318, 2017.\n[3] G. Beigi, K. Shu, R. Guo, S. Wang, and H. Liu. Privacy Preserving Text Representation Learning.\nProceedings of the 30th on Hypertext and Social Media (HT’19). ACM, 2019.\n[4] S. Biswas, E. Chadda, and F. Ahmad. Sentiment Analysis with Gated Recurrent Units. Department\nof Computer Engineering. Annual Report Jamia Millia Islamia New Delhi, India, 2015.\n[5] G. R. Blakley. Safeguarding cryptographic keys. In 1979 International Workshop on Managing\nRequirements Knowledge (MARK), pages 313–318. IEEE, 1979.\n[6] R. Canetti. Security and Composition of Multiparty Cryptographic Protocols. Journal of CRYPTOLOGY,\n13(1):143–202, 2000.\n[7] R. Canetti. Universally Composable Security: A New Paradigm for Cryptographic Protocols.\nIn Proceedings 42nd IEEE Symposium on Foundations of Computer Science, pages 136–145.\nIEEE, 2001.\n[8] R. Canetti. Security and composition of cryptographic protocols: a tutorial (part i). ACM SIGACT\nNews, 37(3):67–92, 2006.\n[9] R. Canetti, A. Cohen, and Y. Lindell. A Simpler Variant of Universally Composable Security\nfor Standard Multiparty Computation. In Annual Cryptology Conference, pages 3–22. Springer,\n2015.\n[10] T. Capes, P. Coles, A. Conkie, L. Golipour, A. Hadjitarkhani, Q. Hu, N. Huddleston, M. Hunt,\nJ. Li, M. Neeracher, et al. Siri On-Device Deep Learning-Guided Unit Selection Text-to-Speech\nSystem. In INTERSPEECH, pages 4011–4015, 2017.\n[11] H. Chabanne, A. de Wargny, J. Milgram, C. Morel, and E. Prouff. Privacy-preserving Classification\non Deep Neural Network. IACR Cryptology ePrint Archive, 2017:35, 2017.\n[12] C.-C. Chiu, T. N. Sainath, Y. Wu, R. Prabhavalkar, P. Nguyen, Z. Chen, A. Kannan, R. J.\nWeiss, K. Rao, E. Gonina, et al. State-of-the-art Speech Recognition with Sequence-to-sequence\nModels. In 2018 IEEE International Conference on Acoustics, Speech and Signal Processing\n(ICASSP), pages 4774–4778. IEEE, 2018.\n[13] K. Cho, B. Van Merriënboer, C. Gulcehre, D. Bahdanau, F. Bougares, H. Schwenk, and Y. Bengio.\nLearning Phrase Representations using RNN Encoder-decoder for Statistical Machine\nTranslation. arXiv preprint arXiv:1406.1078, 2014.\n[14] J. Chung, C. Gulcehre, K. Cho, and Y. Bengio. Empirical Evaluation of Gated Recurrent Neural\nNetworks on Sequence Modeling. arXiv preprint arXiv:1412.3555, 2014.\n[15] M. De Cock, R. Dowsley, A. C. Nascimento, D. Reich, and A. Todoki. Privacy-Preserving\nClassification of Personal Text Messages with Secure Multi-Party Computation: An Application\nto Hate-Speech Detection. arXiv preprint arXiv:1906.02325, 2019.\n[16] W. Diffie and M. Hellman. New Directions in Cryptography. IEEE transactions on Information\nTheory, 22(6):644–654, 1976.\n[17] W. Du and M. J. Atallah. Protocols for Secure Remote Database Access with Approximate\nMatching. In E-Commerce Security and Privacy, pages 87–111. Springer, 2001.\n[18] C. Dwork. Differential Privacy. Encyclopedia of Cryptography and Security, pages 338–340,\n2011.\n[19] M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart. Privacy in pharmacogenetics:\nAn end-to-end case study of personalized warfarin dosing. In 23rd fUSENIXg Security\nSymposium (fUSENIXg Security 14), pages 17–32, 2014.\n[20] R. Fu, Z. Zhang, and L. Li. Using LSTM and GRU Neural Network Methods for Traffic Flow\nPrediction. In 2016 31st Youth Academic Annual Conference of Chinese Association of Automation\n(YAC), pages 324–328. IEEE, 2016.\n[21] R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing. Cryptonets:\nApplying neural networks to encrypted data with high throughput and accuracy. In International\nConference on Machine Learning, pages 201–210, 2016.\n[22] O. Goldreich. Foundations of Cryptography: volume 1, basic tools. Cambridge university press,\n2007.\n[23] O. Goldreich. Foundations of cryptography: volume 2, basic applications. Cambridge university\npress, 2009.\n[24] O. Goldreich, S. Micali, and A. Wigderson. How to Play Any Mental Game, or A Completeness\nTheorem for Protocols with Honest Majority. In Providing Sound Foundations for Cryptography:\nOn the Work of Shafi Goldwasser and Silvio Micali, pages 307–328. 2019.\n[25] Q. Gu, N. Lu, and L. Liu. A Novel Recurrent Neural Network Algorithm with Long Short-term\nMemory Model for Futures Trading. Journal of Intelligent & Fuzzy Systems, 37(4):1–8.\n[26] X. Hu, L. Liang, L. Deng, S. Li, X. Xie, Y. Ji, Y. Ding, C. Liu, T. Sherwood, and Y. Xie. Neural\nnetwork model extraction attacks in edge devices by hearing architectural hints. arXiv preprint\narXiv:1903.03916, 2019.\n[27] Y. Huang. Practical Secure Two-party Computation. PhD thesis, Citeseer, 2012.\n[28] T. Hunt, C. Song, R. Shokri, V. Shmatikov, and E. Witchel. Chiron: Privacy-preserving Machine\nLearning as a Service. arXiv preprint arXiv:1803.05961, 2018.\n[29] Z. Ji, Z. C. Lipton, and C. Elkan. Differential Privacy and Machine Learning: A Survey and\nReview. arXiv preprint arXiv:1412.7584, 2014.\n[30] C. Juvekar, V. Vaikuntanathan, and A. Chandrakasan. GAZELLE: A Low Latency Framework\nfor Secure Neural Network Inference. In 27th USENIX Security Symposium (USENIX Security\n18), pages 1651–1669, 2018.\n[31] R. Küsters and D. Rausch. A framework for universally composable diffie-hellman key exchange.\nIn 2017 IEEE Symposium on Security and Privacy (SP), pages 881–900. IEEE, 2017.\n[32] R. Küsters and M. Tuengerthal. Universally composable symmetric encryption. In 2009 22nd\nIEEE Computer Security Foundations Symposium, pages 293–307. IEEE, 2009.\n[33] Y. Li, T. Baldwin, and T. Cohn. Towards Robust and Privacy-preserving Text Representations.\narXiv preprint arXiv:1805.06093, 2018.\n[34] Y. Lindell. How to Simulate It–A Tutorial on the Simulation Proof Technique. In Tutorials on\nthe Foundations of Cryptography, pages 277–346. Springer, 2017.\n[35] J. Liu, M. Juuti, Y. Lu, and N. Asokan. Oblivious Neural Network Predictions via Minionn\nTransformations. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications\nSecurity, pages 619–631. ACM, 2017.\n[36] L. Ma, S. Liu, and Y. Wang. A DRM model based on Proactive Secret Sharing Scheme for P2P\nNetworks. In 9th IEEE International Conference on Cognitive Informatics (ICCI’10), pages\n859–862. IEEE, 2010.\n[37] A. L. Maas, R. E. Daly, P. T. Pham, D. Huang, A. Y. Ng, and C. Potts. Learning Word Vectors\nfor Sentiment Analysis. In Proceedings of the 49th annual meeting of the association for computational\nlinguistics: Human language technologies, volume 1, pages 142–150. Association for\nComputational Linguistics, 2011.\n[38] P. Mohassel and Y. Zhang. Secureml: A System for Scalable Privacy-preserving Machine Learning.\nIn 2017 IEEE Symposium on Security and Privacy (SP), pages 19–38. IEEE, 2017.\n[39] T. B. Pedersen, Y. Saygın, and E. Savaş. Secret Sharing vs. Encryption-based Techniques for\nPrivacy Preserving Data Mining. 2007.\n[40] P. Poomka, W. Pongsena, N. Kerdprasop, and K. Kerdprasop. Sms spam detection based on\nlong short-term memory and gated recurrent unit. International Journal of Future Computer\nand Communication, 8(1), 2019.\n[41] M. S. Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schneider, and F. Koushanfar.\nChameleon: A Hybrid Secure Computation Framework for Machine Learning Applications. In\nProceedings of the 2018 on Asia Conference on Computer and Communications Security, pages\n707–721. ACM, 2018.\n[42] M. Ribeiro, K. Grolinger, and M. A. Capretz. Mlaas: Machine learning as a service. In 2015\nIEEE 14th International Conference on Machine Learning and Applications (ICMLA), pages\n896–902. IEEE, 2015.\n[43] V. Rijmen and J. Daemen. Advanced encryption standard. Proceedings of Federal Information\nProcessing Standards Publications, National Institute of Standards and Technology, pages 19–\n22, 2001.\n[44] R. L. Rivest, L. Adleman, M. L. Dertouzos, et al. On Data Banks and Privacy Homomorphisms.\nFoundations of secure computation, 4(11):169–180, 1978.\n[45] B. D. Rouhani, M. S. Riazi, and F. Koushanfar. Deepsecure: Scalable Provably-secure Deep\nLearning. In Proceedings of the 55th Annual Design Automation Conference, page 2. ACM,\n2018.\n[46] S. van der Walt, S.C. Colbert, and G. Varoquaux. The NumPy Array: A Structure for Efficient\nNumerical Computation. Computing in Science Engineering, 13(2):22–30, March 2011.\n[47] N. Saleem, M. Irfan Khattak, and A. B. Qazi. Supervised Speech Enhancement based on Deep\nNeural Network. Journal of Intelligent & Fuzzy Systems, 37(4):5187–5201, 2019.\n[48] A. Shamir. How to Share a Secret. Communications of the ACM, 22(11):612–613, 1979.\n[49] D. Takabi, R. Podschwadt, J. Druce, C. Wu, and K. Procopio. Privacy Preserving Neural Network\nInference on Encrypted Data with GPUs. arXiv preprint arXiv:1911.11377, 2019.\n[50] S. Wagh, D. Gupta, and N. Chandran. SecureNN: 3-Party Secure Computation for Neural Network\nTraining. Proceedings on Privacy Enhancing Technologies, 1:24, 2019.\n[51] L. Wang, X. Shen, J. Li, J. Shao, and Y. Yang. Cryptographic Primitives in Blockchains. Journal\nof Network and Computer Applications, 127:43–58, 2019.\n[52] A. C.-C. Yao. How to Generate and Exchange Secrets. In 27th Annual Symposium on Foundations\nof Computer Science (SFCS 1986), pages 162–167. IEEE, 1986.\n[53] W. Yin, K. Kann, M. Yu, and H. Schütze. Comparative Study of CNN and RNN for Natural\nLanguage Processing. arXiv preprint arXiv:1702.01923, 2017.\n[54] Z. Ying, S. Cao, P. Zhou, S. Zhang, and X. Liu. Lightweight outsourced privacy-preserving heart\nfailure prediction based on gru. In International Conference on Algorithms and Architectures\nfor Parallel Processing, pages 521–536. Springer, 2019.\n[55] A. Zhang, Z. C. Lipton, M. Li, and A. J. Smola. Dive into Deep Learning. 2020. https:\n//d2l.ai. zh_TW dc.identifier.doi (DOI) 10.6814/NCCU202001474 en_US
