Privacy-enhanced deep learning inference acceleration towards third-party cloud based on trusted execution environment
摘要
Deep Learning as a Service (DLaaS) has become a remarkable trend in modern data-driven online services. Both data providers and service providers are forced to put their faith in third-party cloud infrastructures. However, a breakdown in this trust can expose sensitive data and intellectual property to considerable risk of security and privacy violations. In response to these vulnerabilities, this paper introduces Branchy-TEE, a robust and efficient reasoning framework for collaborative cloud inference in potentially untrustworthy cloud environments. Branchy-TEE aims to protect the confidentiality and integrity of data and models belonging to multiple stakeholders throughout the inference process by leveraging the capabilities of the Trusted Execution Environment (TEE). Branchy-TEE innovatively employs an on-demand loading mechanism for the inference network based on an early-exit mechanism designed to avoid the performance limitations typically associated with TEE hardware. In addition, a novel joint training method for multi-exit networks based on knowledge distillation techniques is proposed. The method facilitates the transfer of “knowledge” from high-precision final exits to lower-precision early branching exits, thus optimizing the performance of the entire inference process. Finally, the effectiveness and efficiency of Branchy-TEE are verified through a large number of experiments in real environments while achieving the best balance between performance and hardware resources.