Secure MLaaS with Temper: Trusted and Efficient Model Partitioning and Enclave Reuse

N/ACitations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

Machine Learning as a Service (MLaaS) is becoming a highly available and cost-efficient way to embrace machine learning techniques in various domains. But it suffers from data privacy risks as user data must be uploaded to untrusted clouds. We propose a trusted and efficient MLaaS system, Temper, based on secure hardware enclaves such as Intel SGX. Temper significantly improves the performance without sacrificing the data security guarantees or the model inference accuracy. With the two key techniques of enclave reuse and model partitioning, it reduces the enclave initialization and model loading costs, and alleviates the secure paging overheads due to the limited hardware-protected memory capacity in SGX. We also provide rigorous security guarantees for enclave sharing and batched processing, by ensuring stateless, non-interference, and data-oblivious processing and data transfers across model partitions. Temper achieves on average 2.2 × and 1.8 × improvements over the state-of-the-art designs for latency and throughput, respectively, and within 2.1 × slowdown of untrusted native execution. Its distributed paradigm provides a more scalable way for future MLaaS with large models.

Cite

CITATION STYLE

APA

Li, F., Li, X., & Gao, M. (2023). Secure MLaaS with Temper: Trusted and Efficient Model Partitioning and Enclave Reuse. In ACM International Conference Proceeding Series (pp. 621–635). Association for Computing Machinery. https://doi.org/10.1145/3627106.3627145

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free