<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Low-Latency Privacy-Preserving Deep Learning Design via Secure MPC</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ke Lin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yasir Glani</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ping Luo</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Tsinghua University</institution>
          ,
          <addr-line>30 Shuangqing Rd., Haidian District, Beijing, 100084</addr-line>
          ,
          <country country="CN">China</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Secure multi-party computation (MPC) facilitates privacy-preserving computation between multiple parties without leaking private information. While most secure deep learning techniques utilize MPC operations to achieve feasible privacy-preserving machine learning on downstream tasks, the overhead of the computation and communication still hampers their practical application. This work proposes a low-latency secret-sharing-based MPC design that reduces unnecessary communication rounds during the execution of MPC protocols. We also present a method for improving the computation of commonly used nonlinear functions in deep learning by integrating multivariate multiplication and coalescing diferent packets into one to maximize network utilization. Our experimental results indicate that our method is efective in a variety of settings, with a speedup in communication latency of 10 ∼ 20%.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Multi-party computation</kwd>
        <kwd>deep learning</kwd>
        <kwd>privacy-preserving</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Secure multi-party computation (MPC) [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ] enables
parties to compute securely over their private data without
revealing the data to each other. Secure MPC ofers
privacypreserving property, which makes it suitable for most
privacy-sensitive domains, such as medical research and
ifnance. Upon the development of deep learning techniques,
the ability to capture important information from large
datasets of neural models raises concerns regarding the
surveillance of individuals [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. In this case, the prospects of
secure MPC demonstrate its application to secure machine
learning and deep learning. While MPC-based deep
learning frameworks have achieved significant performance in
general scenarios, most works sufer from the limitations
caused by 1. network communication due to the nature of
exchanging intermediate information during MPC execution,
2. excessive computation introduced by complex MPC
protocols. Since the computation of MPC protocols is largely
determined by their sophisticated design, optimizing the
protocol itself would seem to be dificult and infeasible. Thus,
some studies [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] are concerned with improving the
communication stage of MPC protocols to make them more
practical. In this paper, we present an approach to reduce
the communication latency of the MPC protocol through
optimized multivariate multiplication.
      </p>
      <p>
        In general, privacy-preserving deep learning frameworks
usually adopt secret-sharing-based techniques to avoid
extensive computational overheads [
        <xref ref-type="bibr" rid="ref5 ref6 ref7 ref8">5, 6, 7, 8</xref>
        ]. Consequently,
secret-sharing-based methods require multiple exchanges
of intermediate results to achieve collaborative MPC
operations. As these MPC techniques are based on linear
computations, such as addition and multiplication, modern deep
learning techniques that inherently rely on linear algebra
benefit significantly from them. Considering the heavy
dependency on linear operations, our research aims to reduce
unnecessary communication rounds following [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] during
the execution of MPC protocols.
      </p>
      <p>Our main contributions are as follows:
• We propose a low-latency secret-sharing-based
method for computing multivariate multiplications
and univariate polynomials using network
communication that is eficient and reduces unnecessary
communication rounds on the fly.
• We improve the computation of nonlinear functions
by integrating the proposed multivariate
multiplication and coalescing diferent packets into one single
packet to maximize network utilization.
• We conducted experiments to evaluate the
efectiveness of our method in the context of models
with varying sizes, networks with diferent latency
and bandwidth, the accuracy of downstream
classification tasks, and the number of participants
involved. The results indicate an overall improvement
of 10 ∼ 20% in communication latency.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <sec id="sec-2-1">
        <title>2.1. Arithmetic Secret Sharing Based</title>
      </sec>
      <sec id="sec-2-2">
        <title>Scheme</title>
        <p>Our setup is primarily focused on arithmetic operations, so
we represent all inputs and intermediate results in terms
of linear secret sharing between  parties, especially in the
context of additive secret-sharing schemes.</p>
        <p>
          Apart from the general (, )-Shamir secret sharing
scheme [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ], which relies on the degree- polynomials over
 parties, we adopt the simple arithmetic secret sharing
scheme based on (, 0)-Shamir secret sharing. In other
words, we share a scalar value  ∈ Z/Z across  parties
, where Z/Z denotes a ring with  elements,
following the notations of [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. The sharing of  is defined as
[] = {[]}∈ , where [] is the party ’s share of .
The ground-truth value  could be reconstructed from the
sum of the shares of each party, i.e.  = ∑︀∈ [].
        </p>
        <p>When parties wish to share a value , they generate a
pseudorandom zero-share that sums to 0. The party that
possesses the value adds  to their share in secret. To represent
lfoating-point numbers, we adopt a fixed-point encoding
to encode any floating-point number  into a fixed-point
representation, . Alternatively, we consider that each  is
the result of multiplying a floating-point number  by a
scaling factor  = 2 and rounding to the nearest integer,
i.e.  = ⌊ ⌉. Here  is the precision of the fixed-point
encoding. To decode a ground-truth floating-point value
 from , we compute as follows:  ≈ /.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.2. Arithmetic Secret Sharing Based MPC</title>
        <p>It is noteworthy that arithmetic secret shares are
homomorphic and can be used to implement secure MPC, especially
in the context of linear computation in most cases.
Addition. The sum of two secret shared values [] and
[] could be directly computed as [] = [] + [], where
each party  ∈  computes [] = [] + [] without
multi-party communications.</p>
        <p>
          Multiplication. Two secret shared values [] and [] are
multiplied using a random Beaver triple [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] generated by
the Trusted Third Party (TTP): a triplet ([], [], []). It
should be noted that the Beaver triple could be shared in
advance by each party. The parties first calculate [ ] =
[] − [] and [ ] = [] − []. In this way, the [ ] and [ ] are
then revealed to all parties (denoted as Reveal(· )) without
compromising information since the ground-truth values
,  remain unknown to each party except for the TTP. The
ifnal results could be computed as [] = [] +  [] + [] +
 . Algorithm 1 illustrates the multiplication using Beaver
triples.
        </p>
        <p>Linear functions. It is possible to implement functions
that consist of linear operations by combining additions and
multiplications. Common operations in deep learning, such
as element-wise product and convolution, are allowed in a
linear paradigm.</p>
        <p>Nonlinear functions. Due to the inherent infeasibility
of nonlinear functions in the standard arithmetic
secretsharing scheme, most works use approximation methods
to simulate the outcome of nonlinear functions. In
particular, Taylor Expansion, Newton-Rhapson, and Householder
methods are commonly used to approximate nonlinear
functions using only linear operations. All reciprocal functions,
exponential functions, loss functions, kernel functions, and
other useful functions in deep learning are calculated this
way, for example.</p>
        <p>Algorithm 1 Beaver Multiplication Mul([], [])
Input: Secret-shared inputs [], [],</p>
        <p>([], [], []).</p>
        <p>Output: [].</p>
        <p>1: ◁ Compute masked values
2: [ ] ← [ − ] = [] − []
3: [ ] ← [ − ] = [] − []
4: ◁ Reveal  and  through one-round communications
5:  ← Reveal([ ])
6:  ← Reveal([ ])
7: return  +  [] + [] + []
Beaver triple</p>
      </sec>
      <sec id="sec-2-4">
        <title>2.3. Notations</title>
        <p>This section summarizes the notations used throughout this
work. We denote [] as a secret sharing of . Reveal([])
means that the ground-truth value  is revealed to every
party involved in the computation through one-round
communications. Since most linear operations are also
applicable to element-wise operations and matrix operations, 
can also represent a vector, matrix, or even a tensor if there
is no confusion and ambiguity.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Related Work</title>
      <p>
        To achieve communication-eficient MPC, various
approaches have been developed to optimize the
communication rounds and the throughput of communication. Ishai
and Kushilevitz [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] proposes a new representation of
polynomials for round-eficient secure computation, dividing
high-degree polynomials into multiple low-degree
polynomials that are easy to solve. Mohassel and Franklin [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
performs operations directly on polynomials, such as
polynomial multiplication and division. Dachman-Soled et al.
[
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] improves the evaluation of multivariate polynomials
with diferent variables being held as private inputs by each
party. Then, Lu et al. [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] proposes an eficient method for
evaluating high-degree polynomials with arbitrary
numbers of variables. While the current research has focused on
improving the calculation of polynomials, our study aims
to develop a communication-eficient and efective MPC
system for use in modern deep learning frameworks by
leveraging arithmetic tuples computation from Krips et al.
[
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. This system is not confined to only computing
polynomials within finite rings, as seen in previous studies.
      </p>
      <p>
        In recent years, several deep learning frameworks that
preserve privacy have emerged to enable the secure
inference of neural network models. Wagh et al. [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]
implements a maliciously secure 3-party MPC protocol from
SecureNN [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] and ABY3 [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Knott et al. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] provides
flexible machine-learning APIs with a rich set of functions for
secure deep learning. Li et al. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] presents a fast and
performant MPC Transformer inference framework designed to be
privacy-preserving. Our low-latency linear MPC
implementation is built on top of Knott et al.’s CrypTen framework
and provides a significant improvement in communication
latency.
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Methodology</title>
      <sec id="sec-4-1">
        <title>4.1. Multivariate Multiplication</title>
        <p>Since Beaver triples illustrate how to multiply two variables
with pre-shared triplets, a classic multiplication between
multiple variables, such as [], requires several rounds
of binary multiplication, i.e. Mul(Mul([], []), []). This
naive implementation, however, introduces additional
communication rounds during the on-the-fly Reveal process.
In general, a -ary multiplication requires  − 1 rounds of
communication.</p>
        <p>To reduce the communication rounds involved in the
multivariate multiplications, the basic binary Beaver triple
is extended into a general -ary Beaver triple. This results
in only one round of communication required throughout
the entire process.</p>
        <p>Assume the  inputs could be represented as {[]}=1.
The precomputation and preshared information required by
the extended protocol is {}=1. Here 1 := {[ ]}=1

is defined as the set of  auxiliary shared values used to
blind the the inputs {[]}=1, which is also similar to the
Beaver’s idea. Then ( ≥ 2) is defined as the set of
shared degree- cross-terms consisting of the variables in
1. For example, 2 could be defined as
2 := {[ ] |
 ̸=  ∧ 1 ≤
 ∧ 1 ≤ , ,  ≤
,  ≤</p>
        <p>}, and 3 := {[ ] |  ̸=  ̸=
}, and so on. Similar to the construction
of [ ] and [ ] in Section 2.2, we define the diference between
the inputs and the masks as [ ] := [] −
shared [ ] is then made public across all parties without
leakage to the ground-truth value of both [] and []. The
improvement of our method originates from the following
[]. The
secretequation:

=1
∏︁  = ∏︁(  + )

=1
+ · · ·
= ∏︁   + ∑︁</p>
        <p>+ ∏︁ .</p>
        <p>∏︀  +

∑︁   
,,̸=
∏︀ 

(1)
follows:

=1
[∏︁ ] = ∏︁   + ∑︁</p>
        <p>[
+ · · ·</p>
        <p>+ [∏︁ ].
which is preshared across all parties.</p>
        <p>Here we informally use the fractional representation, such
as ∏︀  , to denote the products of all the terms except
for certain ones. Note that this fractional form does not
involve any actual division. Also, each secret-shared term
of [ ∏︀... ] could be found in the auxiliary sets {}=1,
Adaptation of Equation 1 in secret-sharing scheme is as
∏︀  ] +

∑︁    [
,,̸=
∏︀  ]

Since Equation 2 is linear to the secret-sharing terms, all
communications could be conducted in parallel, i.e. in a
single round of communications. In this case, we could

simply reveal all the secret-sharing terms in {}=1 and
compute the sharing of final results in constant complexity.
The protocol is formally described in Algorithm 2.
Algorithm 2 Multivariate Beaver Multiplication of  inputs
Mul([1], [2], . . . , [])
Input: Secret-shared inputs {[]}=1, auxiliary sets
5: ◁ Reveal   through one-round communications
{}=1.</p>
        <p>Output: [∏︀ ].</p>
        <p>1: ◁ Compute masked values
2: for  ∈ [1, ] do
3:
7:
4: end for
6: parallel for  ∈ [1, ] do
  ←</p>
        <p>Reveal([ ])</p>
        <p>[ − ] = [] − []
· · ·</p>
        <p>+ [∏︀ ]
8: end parallel for

9: ◁ Compute results using preshared {}=1
10: return ∏︀   + ∑︀  [</p>
        <p>∏︀  ] + ∑︀
,,̸=
   [ 
∏︀  ] +</p>
        <p>The total rounds of communications are indeed reduced
from 
is performed, but the overall size of communication data
− 1 to constant 1 when a regular -ary multiplication
increases from linear to exponential. In a naïve
implementation, the data size of -ary multiplication is only 3( − 1)
for a total transmission of  −
to a multivariate implementation, it is 2 − 1 to transmit
1 Beaver triples. As opposed
the auxiliary sets {}=1. Therefore, in practice, there is a
trade-of between communication latency and throughput.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Univariate Polynomials</title>
        <p>The formal form of univariate polynomials is defined as
 () = ∑︀</p>
        <p>
          =0 , where  refers to the coeficients of
the degree- term. The use of univariate polynomials
enables eficient evaluation and manipulation of polynomial
expressions. According to Damgård et al. [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ], we can
compute all required [] in parallel using multivariate
multiplications, then multiply them with corresponding plaintext
coeficients. Despite its benefits, this trick has the
disadvantage of exponentially increasing the size of transmitted data,
which becomes unbearable when the exponent exceeds 5.
        </p>
        <p>This method can be implemented in practice by
computing a tuple of base terms and then multiplying the tuple by
a certain term iteratively, as in the exponentiating by
squaring method or the fast modulo algorithm. In other words,
a tuple  = (1, , . . . , − 1
multiplied by ‖‖ repeatedly to iterate all the  terms. The
overview of the implementation of univariate polynomials
is described in Algorithm 3. Note that : is the subvector
) of size ‖‖ =  could be
of  from position  to .</p>
        <p>Algorithm 3 Univariate Polynomial Poly([], )</p>
        <sec id="sec-4-2-1">
          <title>Input: Secret-shared input [],</title>
          <p>coeficients

=
Output: ∑︀
=0 [].</p>
        </sec>
        <sec id="sec-4-2-2">
          <title>1: ◁ Construct base terms</title>
          <p>2: parallel for  ∈ [1, ‖‖] do
(0, 1, . . . , ), base terms size ‖‖.</p>
          <p>Mul([], . . . , []) ◁ multiplied by [] of</p>
        </sec>
      </sec>
      <sec id="sec-4-3">
        <title>4.3. Nonlinear Approximations</title>
        <p>In this section, we take one step further to optimize the
commonly used nonlinear functions by leveraging the property
of parallelization of our proposed multivariate
multiplication.</p>
        <p>Exponentiation.</p>
        <p>Since exponential functions grow in
geometrical speed, approximations based on series expansion
generally sufer from a significant reduction in accuracy
since we do not know the exact value of the input.
Consequently, we resort to the naive iterative approximation,
which is capable of utilizing multivariate multiplication
effectively:
[] = lim
→∞
︂(
1 +
[] )︂ 

.
(2)
times</p>
        <p>[] ←
3:
5:  ←
7:  ←
9:
10:
11:
12:
13:
0
s
e
 ←
←
←
 ←
14: end for
15: return 
4: end parallel for</p>
        <p>(1, [], . . . , [‖‖− 1])
6: ◁ Iteratively exponentiating</p>
        <p>8: for  ∈ [0, ⌊ ‖‖ ⌋ − 1] do
 · ‖ ‖
( + 1) · ‖ ‖
 + : · 
[‖‖] · 
◁ Vectorized Beaver Multiplication
During each iteration, the -th power of the previous result
is calculated. With increasing iteration rounds , the answer
would become closer to the actual results.</p>
        <p>Logarithm. The calculation of logarithms relies on the
higher-order iterative methods for a better convergence, i.e.
Householder methods on  = ln :</p>
        <p>[ℎ] = 1 − []− []
[+1] = [] −
∑∞︁ 1</p>
        <p>=1
[ℎ]
Note that the implementation of logarithm is the
combination of exponentiation and univariate polynomials. The
degree of the polynomials determines the precision of the
output.</p>
        <p>Reciprocal. The reciprocal function  = 1 is calculated
using the Newton-Raphson method with an initial guess 0:
[+1] = [](2 − [][])</p>
        <p>= 2[] − [][][]
Trigonometry. Trigonometric functions could be treated
as the special case of exponentiation with  = 2. The sine
and cosine functions are calculated in the field of complex
numbers:
[sin ] = Im([])
[cos ] = Re([])</p>
        <p>Using the above-mentioned nonlinear functions, we can
calculate most of the existing loss functions in deep learning,
such as the sigmoid, tanh, and cross-entropy functions.
Various other common nonlinear functions, such as the
softmax function and kernel function, can also be
calculated using exponential and reciprocal functions.</p>
      </sec>
      <sec id="sec-4-4">
        <title>4.4. Communication Coalescing</title>
        <p>The key to achieving low-latency secret-sharing
computation is to reduce the total number of rounds of
communications among diferent parties. While we introduce a
latency-friendly implementation of basic math operations,
other kinds of communications, such as precision checking,
still require an additional but independent communication
round.</p>
        <p>In general, the communication involved in multiple math
operations could be abstracted as a communication graph,
or strictly, as a communication tree. Accordingly, we
observe some independent communications that do not afect
downstream results can be deferred and combined into one
single round of communication. This process is referred to
as communication coalescing, and it eliminates unnecessary
rounds of communication and improves the utilization of
network bandwidth.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Security Analysis</title>
      <p>The correctness of the multivariate multiplication is trivial
based on the observation in Equation 1 and 2. As univariate
polynomials are implemented using the same method as the
extended fast modulo algorithm, their efectiveness could
also be demonstrated by the correctness and security of
multivariate multiplication. Coalescing mechanisms only
alter the order of communication rounds without modifying
the payload, which is also reliable and secure.</p>
      <p>Multivariate computations are similarly secure as
traditional Beaver multiplications under semi-honest conditions.
It is intuitively obvious that since  is chosen at random
by TTP, the   =  −  value is indistinguishable from a
random number. Consequently, the disclosure of [ ] does
not reveal any critical information regarding . This
assumption holds even if multiple parties, except for the TTP,
collude.</p>
      <p>To clarify the security of multivariate multiplication
formally, we denote [] as the secret share of  for party
 ∈  . The global equations of the multivariate system are
as follows:
∑︁[] = 
∈
∑︁[] = 
∈
∑︁[ ] = 
∈</p>
      <p>
        . . . . . .
∑︁[1 . . . ] = 1 . . . 
∈
[] − [] = [ ]
(3)
with known [ ] for every  ∈  to each party. From each
party’s view, these 2 + 2 − 1 equations have Θ(2 ‖‖)
unknown variables. This indicates the dificulty in
determining the exact value of , as shown in [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
      </p>
      <p>A party’s view represents all the values it can obtain
during its execution. Then the following theorem holds:
Theorem 1. Let {′} and {′′} be random values. The
distribution of the view of each party is identical when  = ′
or  = ′′.</p>
      <p>This guarantees the security of multivariate multiplication
by ensuring the indistinguishability between the random
distribution and the view’s distribution.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Experiments</title>
      <sec id="sec-6-1">
        <title>6.1. Experimental Setup</title>
        <p>
          As part of our proposed methodology, we use CrypTen [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]
as the basic MPC deep learning framework, which has
already provided naïve implementations of
secret-sharingbased computations. In most of our experiments, we use
3-party MPC on CPUs. Additionally, we allow a maximum
of 4-ary multiplication as stated in Section 4.1, and we set
 = 3 for exponentiation and  = 8 for logarithm as
described in Section 4.3.
        </p>
        <p>
          To measure the performance, we perform several
experiments with deep learning models with diferent sizes:
(a) Linear Support Vector Classification (LinearSVC) with
L2 penalty; (b) LeNet [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ] with shallow convolutional
and linear layers along with ReLU activation functions;
(c) ResNet-18 model [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ] with multiple convolutional,
linear, pooling, and activation layers; (d) Transformer Encoder
model [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] with a single multi-head attention layer and
BatchNorm [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ] in place of LayerNorm [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ]. We employ
several datasets for classification tasks with appropriate
adaption to specific models, including MNIST [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ],
CIFAR10 [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ], ImageNet[
          <xref ref-type="bibr" rid="ref25">25</xref>
          ], and Sentiment140 [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ] datasets.
        </p>
        <p>Each of our experiments is conducted in a simulated
multinode environment using Docker. TTP is conducted in an
independent environment separate from the normal parties.
To manually simulate diferent network environments
concerning bandwidth and latency, we utilize the docker-tc
tool to adjust the docker network settings accordingly.</p>
      </sec>
      <sec id="sec-6-2">
        <title>6.2. Metrics</title>
        <p>To provide a comprehensive evaluation of our proposed
method, we adopt metrics from a variety of perspectives.
• comp: The computational time cost for evaluating a
single data sample in one round.
• comm: The time cost of communication associated
with evaluating a single data sample in one round.
• Size of Transmission Data: The size of
transmitted network packets when evaluating a single data
sample in one round.
• Accuracy: The classification accuracy when
evaluated on a particular dataset.</p>
      </sec>
      <sec id="sec-6-3">
        <title>6.3. Latency &amp; Throughput</title>
        <p>To assess the eficiency of our proposed method, we
simulate networks with diferent network latencies: (a) network
low with 0.1ms latency, (b) network med with 5ms
latency, (c) and network high with 40ms latency. All of these
networks have a bandwidth of 1Gbps. Our simulated
multinode settings include 3 nodes with an additional TTP by
default.</p>
        <p>As shown in Table 1, the computation cost of each model
is negligible in medium and high latency network settings
in comparison to the communication cost. Therefore, we
will focus only on the communication costs associated with
our proposed method.</p>
        <p>Compared to the naïve method implemented by CrypTen,
our method illustrated in Section 4.1 remains close since
it does not introduce a substantial amount of additional
communication payload if the maximum number of input
variables is set appropriately. For instance, a 3-ary or 4-ary
multiplication would not produce a significant increase in
the total size of communications.</p>
        <p>It is noteworthy that our proposed method reduces the
communication cost in every network setting as compared
to the naïve implementation of MPC. Overall, we achieve
an improvement of 10 ∼ 20%, which shows significant
enhancement in the performance of high-latency
environments for practical purposes.</p>
        <p>Furthermore, we observe that our proposed method
behaves diferently with neural models with diferent
architectures. Figure 1 illustrates the communication occupation
percentage of ResNet basic blocks and Attention blocks.
As can be seen, the attention mechanism is constrained
by its communication bottleneck in Softmax operation,
while CNN is constrained by its communication via
convolutional operations. Considering that our method makes an
improved optimization for nonlinear functions,
attentionbased models show a significant improvement in latency,
with almost a 25% improvement. Additionally, this explains
the limited improvement of only 8 ∼ 15% in traditional
machine-learning models and CNN-based models.</p>
      </sec>
      <sec id="sec-6-4">
        <title>6.4. Evaluation</title>
        <p>In this section, we examine the side efects and factors
associated with the basic settings, such as the downstream tasks’
accuracy, the number of parties involved, and the trade-of
between network latency and bandwidth.</p>
        <p>To evaluate the drop in accuracy, we compare our method
with both the original baseline and the naïve
implementation without a low-latency design. Figure 2 shows that, in
relatively small scenarios, both the naïve implementation
and our methods are capable of achieving perfect
performance as the baselines. Nevertheless, both MPC-based
implementations obtain lower accuracy in complex scenarios
than the baseline, while our methods perform slightly worse
than the naïve implementation. We hypothesize that the
multivariate multiplication introduces additional precision
requirements, which in turn reduces accuracy.</p>
        <p>The throughput and latency of MPC-based methods are
Na¨ıve
Ours
4</p>
        <p>5
# Parties
(a) Size of Trans. Data w.r.t # Parties
4</p>
        <p>5
# Parties
(b) Latency w.r.t # Parties
also aefcted by the number of parties involved in the
computation. From Figure 2, it can be seen that the communication
data size of both methods increases linearly as the number
of parties involved increases. There is, however, a tendency
for the latency to be worse when there are more parties
involved.</p>
        <p>Moreover, Figure 3 illustrates how network bandwidth
afects communication costs. When suficient bandwidth is
available, our method can still optimize the network latency.
It is important to note, however, that when the bandwidth
becomes the bottleneck, our method would not be any more
efective in reducing the overall costs of communication.
This indicates that bandwidth remains an important factor
in a multi-node MPC setting, especially as the number of
nodes in use grows.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>7. Discussion</title>
      <p>Since the proposed multivariate multiplication is based on
a finite ring, it is likely to have precision issues that lead to
incorrect results. Fortunately, a loss in precision would not
significantly afect the overall performance of deep learning,
since the loss could be interpreted as random noise and
6
6
distortion in the input data.</p>
      <p>
        Moreover, our proposed method is only applicable to
functions that are based on linear MPC operation. To avoid
heavy communications, a modern MPC-based deep
learning framework would also involve other protocols, such as
Homomorphic Encryption [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ], Garbled Circuit [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ], and
Function Secret Sharing[
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]. Though these works may have
less communication, our approach could still be seamlessly
integrated with the current secret-sharing framework and
achieve a latency improvement of ~20% without adding
excessive computational workload.
      </p>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusion</title>
      <p>This study proposes a secret-sharing-based MPC method for
enhancing the linear computation required in deep learning
through increased communication utilization. By utilizing
the multivariate multiplication and communication
coalescing mechanisms, we can reduce the number of unnecessary
communication rounds during the execution of both linear
and nonlinear deep learning functions. In our experiments,
we demonstrate that our proposed methods achieve an
overall improvement in latency of 10 ∼ 20% when compared
to the naïve MPC implementation. Additionally, it indicates
that throughput and downstream task performance are
comparable to naïve implementations, which demonstrate the
method’s validity and eficiency. We hope that this work
will inspire future improvements in privacy-preserving deep
learning techniques and lead to more practical MPC
applications.</p>
    </sec>
    <sec id="sec-9">
      <title>Acknowledgments</title>
      <p>This work is supported by the National Key R&amp;D Program
of China under grant (No. 2022YFB2703001).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>I.</given-names>
            <surname>Damgård</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Pastro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Smart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Zakarias</surname>
          </string-name>
          ,
          <article-title>Multiparty computation from somewhat homomorphic encryption</article-title>
          , in: R.
          <string-name>
            <surname>Safavi-Naini</surname>
          </string-name>
          , R. Canetti (Eds.),
          <source>CRYPTO 2012</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2012</year>
          , pp.
          <fpage>643</fpage>
          -
          <lpage>662</lpage>
          . doi:
          <volume>10</volume>
          .1007/ 978-3-
          <fpage>642</fpage>
          -32009-5_
          <fpage>38</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Keller</surname>
          </string-name>
          , Mp-spdz:
          <article-title>A versatile framework for multiparty computation</article-title>
          ,
          <source>in: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security</source>
          , CCS '20,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2020</year>
          , p.
          <fpage>1575</fpage>
          -
          <lpage>1590</lpage>
          . doi:
          <volume>10</volume>
          .1145/3372297.3417872.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>X.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Xie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Xiong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Ying</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Vasilakos</surname>
          </string-name>
          ,
          <article-title>Privacy and security issues in deep learning: A survey</article-title>
          ,
          <source>IEEE Access 9</source>
          (
          <year>2021</year>
          )
          <fpage>4566</fpage>
          -
          <lpage>4593</lpage>
          . doi:
          <volume>10</volume>
          . 1109/ACCESS.
          <year>2020</year>
          .
          <volume>3045078</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>D.</given-names>
            <surname>Lu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Yu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kate</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Maji</surname>
          </string-name>
          , Polymath:
          <article-title>Low-latency mpc via secure polynomial evaluations and its applications</article-title>
          ,
          <source>Proceedings on Privacy Enhancing Technologies</source>
          <year>2022</year>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .2478/popets-2022-0020.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>B.</given-names>
            <surname>Knott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Venkataraman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hannun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sengupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ibrahim</surname>
          </string-name>
          ,
          <string-name>
            <surname>L. van der Maaten</surname>
          </string-name>
          ,
          <article-title>Crypten: Secure multiparty computation meets machine learning</article-title>
          ,
          <source>NIPS</source>
          <volume>34</volume>
          (
          <year>2021</year>
          )
          <fpage>4961</fpage>
          -
          <lpage>4973</lpage>
          . doi:
          <volume>10</volume>
          .48550/arXiv.2109. 00984.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Tan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Knott</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Tian</surname>
          </string-name>
          ,
          <string-name>
            <surname>D. J. Wu,</surname>
          </string-name>
          <article-title>CryptGPU: Fast privacy-preserving machine learning on the gpu</article-title>
          , in: IEEE S&amp;P,
          <year>2021</year>
          . doi:
          <volume>10</volume>
          .1109/SP40001.
          <year>2021</year>
          .
          <volume>00098</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Guo</surname>
          </string-name>
          , E. Xing,
          <string-name>
            <surname>H. Zhang,</surname>
          </string-name>
          <article-title>Mpcformer: fast, performant and private transformer inference with mpc</article-title>
          ,
          <source>in: The 11th International Conference on Learning Representations</source>
          ,
          <year>2023</year>
          . doi:
          <volume>10</volume>
          . 48550/arXiv.2211.01452.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Wagh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Tople</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Benhamouda</surname>
          </string-name>
          , E. Kushilevitz,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mittal</surname>
          </string-name>
          , T. Rabin, Falcon:
          <article-title>Honest-majority maliciously secure framework for private deep learning</article-title>
          ,
          <source>Proceedings on Privacy Enhancing Technologies</source>
          <year>2021</year>
          (
          <year>2020</year>
          )
          <fpage>188</fpage>
          -
          <lpage>208</lpage>
          . doi:
          <volume>10</volume>
          .2478/popets-2021-0011.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>T.</given-names>
            <surname>Krips</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Küsters</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Reisert</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Rivinius</surname>
          </string-name>
          ,
          <article-title>Arithmetic tuples for mpc</article-title>
          ,
          <source>Cryptology ePrint Archive</source>
          (
          <year>2022</year>
          ). URL: https://eprint.iacr.org/
          <year>2022</year>
          /667.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Shamir</surname>
          </string-name>
          ,
          <article-title>How to share a secret</article-title>
          ,
          <source>Commun. ACM</source>
          <volume>22</volume>
          (
          <year>1979</year>
          )
          <fpage>612</fpage>
          -
          <lpage>613</lpage>
          . doi:
          <volume>10</volume>
          .1145/359168.359176.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>D.</given-names>
            <surname>Beaver</surname>
          </string-name>
          ,
          <article-title>Eficient multiparty protocols using circuit randomization</article-title>
          , in: J.
          <string-name>
            <surname>Feigenbaum</surname>
          </string-name>
          (Ed.),
          <source>CRYPTO 1991</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>1992</year>
          , pp.
          <fpage>420</fpage>
          -
          <lpage>432</lpage>
          . doi:
          <volume>10</volume>
          .1007/3-540-46766-1_
          <fpage>34</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ishai</surname>
          </string-name>
          , E. Kushilevitz,
          <article-title>Randomizing polynomials: A new representation with applications to roundeficient secure computation</article-title>
          ,
          <source>in: Proceedings 41st Annual Symposium on Foundations of Computer Science</source>
          ,
          <year>2000</year>
          , pp.
          <fpage>294</fpage>
          -
          <lpage>304</lpage>
          . doi:
          <volume>10</volume>
          .1109/SFCS.
          <year>2000</year>
          .
          <volume>892118</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>P.</given-names>
            <surname>Mohassel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Franklin</surname>
          </string-name>
          ,
          <article-title>Eficient polynomial operations in the shared-coeficients setting</article-title>
          , in: M.
          <string-name>
            <surname>Yung</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Dodis</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Kiayias</surname>
          </string-name>
          , T. Malkin (Eds.),
          <source>PKC 2006</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2006</year>
          , pp.
          <fpage>44</fpage>
          -
          <lpage>57</lpage>
          . doi:
          <volume>10</volume>
          .1007/11745853_4.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>D.</given-names>
            <surname>Dachman-Soled</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Malkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Raykova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Yung</surname>
          </string-name>
          ,
          <article-title>Secure eficient multiparty computing of multivariate polynomials and applications</article-title>
          , in: J.
          <string-name>
            <surname>Lopez</surname>
          </string-name>
          , G. Tsudik (Eds.),
          <source>Applied Cryptography and Network Security</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2011</year>
          , pp.
          <fpage>130</fpage>
          -
          <lpage>146</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -21554-
          <issue>4</issue>
          _
          <fpage>8</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Wagh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Chandran</surname>
          </string-name>
          ,
          <article-title>Securenn: Eficient and private neural network training</article-title>
          ,
          <source>Cryptology ePrint Archive</source>
          (
          <year>2018</year>
          ). URL: https://eprint.iacr.org/
          <year>2018</year>
          /442.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>P.</given-names>
            <surname>Mohassel</surname>
          </string-name>
          , P. Rindal,
          <article-title>Aby3: A mixed protocol framework for machine learning</article-title>
          ,
          <source>in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security</source>
          , CCS '18,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2018</year>
          , p.
          <fpage>35</fpage>
          -
          <lpage>52</lpage>
          . doi:
          <volume>10</volume>
          .1145/3243734.3243760.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>I.</given-names>
            <surname>Damgård</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Fitzi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Kiltz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. B.</given-names>
            <surname>Nielsen</surname>
          </string-name>
          , T. Toft,
          <article-title>Unconditionally secure constant-rounds multi-party computation for equality, comparison, bits and exponentiation</article-title>
          , in: S. Halevi, T. Rabin (Eds.),
          <source>Theory of Cryptography</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2006</year>
          , pp.
          <fpage>285</fpage>
          -
          <lpage>304</lpage>
          . doi:
          <volume>10</volume>
          .1007/11681878_
          <fpage>15</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>G.</given-names>
            <surname>Couteau</surname>
          </string-name>
          ,
          <article-title>A note on the communication complexity of multiparty computation in the correlated randomness model</article-title>
          ,
          <source>in: EUROCRYPT 2019</source>
          , Springer-Verlag, Berlin, Heidelberg,
          <year>2019</year>
          , p.
          <fpage>473</fpage>
          -
          <lpage>503</lpage>
          . doi:
          <volume>10</volume>
          .1007/ 978-3-
          <fpage>030</fpage>
          -17656-3_
          <fpage>17</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Lecun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bottou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Bengio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Hafner</surname>
          </string-name>
          ,
          <article-title>Gradientbased learning applied to document recognition</article-title>
          ,
          <source>Proceedings of the IEEE</source>
          <volume>86</volume>
          (
          <year>1998</year>
          )
          <fpage>2278</fpage>
          -
          <lpage>2324</lpage>
          . doi:
          <volume>10</volume>
          . 1109/5.726791.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>K.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , S. Ren,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <article-title>Deep residual learning for image recognition</article-title>
          ,
          <source>in: CVPR</source>
          ,
          <year>2016</year>
          , pp.
          <fpage>770</fpage>
          -
          <lpage>778</lpage>
          . doi:
          <volume>10</volume>
          .1109/CVPR.
          <year>2016</year>
          .
          <volume>90</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>A.</given-names>
            <surname>Vaswani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Shazeer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Parmar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Uszkoreit</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Jones</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. N.</given-names>
            <surname>Gomez</surname>
          </string-name>
          , L. u. Kaiser,
          <string-name>
            <surname>I. Polosukhin</surname>
          </string-name>
          ,
          <article-title>Attention is all you need</article-title>
          , in: I. Guyon,
          <string-name>
            <given-names>U. V.</given-names>
            <surname>Luxburg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bengio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Wallach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Fergus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Vishwanathan</surname>
          </string-name>
          , R. Garnett (Eds.), NIPS, volume
          <volume>30</volume>
          ,
          <string-name>
            <surname>Curran</surname>
            <given-names>Associates</given-names>
          </string-name>
          , Inc.,
          <year>2017</year>
          . doi:
          <volume>10</volume>
          .5555/3295222.3295349.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>S.</given-names>
            <surname>Iofe</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Szegedy</surname>
          </string-name>
          ,
          <article-title>Batch normalization: accelerating deep network training by reducing internal covariate shift</article-title>
          ,
          <source>in: Proc. 32nd Int. Conf. Machine Learning - Volume 37, ICML'15</source>
          , JMLR.org,
          <year>2015</year>
          , p.
          <fpage>448</fpage>
          -
          <lpage>456</lpage>
          . doi:
          <volume>10</volume>
          .5555/3045118.3045167.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>J. L.</given-names>
            <surname>Ba</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. R.</given-names>
            <surname>Kiros</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. E.</given-names>
            <surname>Hinton</surname>
          </string-name>
          , Layer normalization,
          <year>2016</year>
          . arXiv:
          <volume>1607</volume>
          .
          <fpage>06450</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>A.</given-names>
            <surname>Krizhevsky</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Hinton</surname>
          </string-name>
          , et al.,
          <article-title>Learning multiple layers of features from tiny images (</article-title>
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>J.</given-names>
            <surname>Deng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Dong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Socher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.-J.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Fei-Fei</surname>
          </string-name>
          ,
          <article-title>Imagenet: A large-scale hierarchical image database</article-title>
          ,
          <source>in: CVPR</source>
          ,
          <year>2009</year>
          , pp.
          <fpage>248</fpage>
          -
          <lpage>255</lpage>
          . doi:
          <volume>10</volume>
          .1109/CVPR.
          <year>2009</year>
          .
          <volume>5206848</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>A.</given-names>
            <surname>Go</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Bhayani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Huang</surname>
          </string-name>
          ,
          <article-title>Twitter sentiment classification using distant supervision</article-title>
          ,
          <source>CS224N project report, Stanford</source>
          <volume>1</volume>
          (
          <year>2009</year>
          )
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>C.</given-names>
            <surname>Gentry</surname>
          </string-name>
          ,
          <article-title>Fully homomorphic encryption using ideal lattices</article-title>
          ,
          <source>in: Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing</source>
          , STOC '09,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2009</year>
          , p.
          <fpage>169</fpage>
          -
          <lpage>178</lpage>
          . doi:
          <volume>10</volume>
          .1145/1536414. 1536440.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>A. C.</given-names>
            <surname>Yao</surname>
          </string-name>
          ,
          <article-title>Protocols for secure computations</article-title>
          ,
          <source>in: 23rd Annual Symposium on Foundations of Computer Science</source>
          (sfcs
          <year>1982</year>
          ),
          <year>1982</year>
          , pp.
          <fpage>160</fpage>
          -
          <lpage>164</lpage>
          . doi:
          <volume>10</volume>
          .1109/ SFCS.
          <year>1982</year>
          .
          <volume>38</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>E.</given-names>
            <surname>Boyle</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Gilboa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ishai</surname>
          </string-name>
          ,
          <article-title>Function secret sharing</article-title>
          , in: E. Oswald, M. Fischlin (Eds.),
          <source>EUROCRYPT 2015</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2015</year>
          , pp.
          <fpage>337</fpage>
          -
          <lpage>367</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -46803-6_
          <fpage>12</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>