Skip to main navigation Skip to search Skip to main content

East: Efficient and Accurate Secure Inference Framework for Transformer

  • Yuanchao Ding
  • , Hua Guo*
  • , Yewei Guan
  • , Weixin Liu
  • , Jiarong Huo
  • , Zhenyu Guan
  • , Xiyong Zhang
  • *Corresponding author for this work
  • Beihang University
  • Key Laboratory of Precision Opto-Mechatronics Technology (Ministry of Education)
  • Beijing Institute of Satellite Information Engineering

Research output: Contribution to journalArticlepeer-review

Abstract

Transformer has been successfully used in practical applications due to its powerful advantages. However, users’ input is leaked to the model provider during the service. With people’s attention to privacy, privacy-preserving Transformer inference is on the demand of such services. Secure protocols for non-linear functions are crucial in privacy-preserving Transformer inference, which are not well studied. Thus, designing practical secure protocols for non-linear functions is hard but significant to model performance. In this work, we propose a framework East to enable efficient and accurate secure Transformer inference. First, we propose a new oblivious piecewise polynomial evaluation algorithm and apply it to the activation functions, which reduces the runtime and communication of GELU by over 1.5× and 2.5×, compared to prior arts. Second, the secure protocols for softmax and layer normalization are carefully designed to faithfully maintain the desired functionality. Third, several optimizations are conducted in detail to enhance the overall efficiency. We applied East to BERT and the results show that the inference accuracy remains consistent with the plaintext inference without fine-tuning. Compared to Iron, we achieve about 1.8× lower communication within 1.2× lower runtime.

Original languageEnglish
Pages (from-to)2038-2046
Number of pages9
JournalIEEE Transactions on Services Computing
Volume18
Issue number4
DOIs
StatePublished - 2025

Keywords

  • Privacy-preserving inference
  • homomorphic encryption
  • secure multi-party computation
  • transformer

Fingerprint

Dive into the research topics of 'East: Efficient and Accurate Secure Inference Framework for Transformer'. Together they form a unique fingerprint.

Cite this