Paper 2025/1532
Breaking the Layer Barrier: Remodeling Private Transformer Inference with Hybrid CKKS and MPC
Abstract
This paper presents an efficient framework for private Transformer inference that combines Homomorphic Encryption (HE) and Secure Multi-party Computation (MPC) to protect data privacy. Existing methods often leverage HE for linear layers (e.g., matrix multiplications) and MPC for non-linear layers (e.g., Softmax activation functions), but the conversion between HE and MPC introduces significant communication costs. The proposed framework, dubbed BLB, overcomes this by breaking down layers into fine-grained operators and further fusing adjacent linear operators, reducing the need for HE/MPC conversions. To manage the increased ciphertext bit width from the fused linear operators, BLB proposes the first secure conversion protocol between CKKS and MPC and enables CKKS-based computation of the fused operators. Additionally, BLB proposes an efficient matrix multiplication protocol for fused computation in Transformers. Extensive evaluations on BERT-base, BERT-large, and GPT2-base show that BLB achieves a $21\times$ reduction in communication overhead compared to BOLT (S&P'24) and a $2\times$ reduction compared to Bumblebee (NDSS'25), along with latency reductions of $13\times$ and $1.8\times$, respectively, when leveraging GPU acceleration.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Published elsewhere. USENIX Security 2025
- Keywords
- Privacy-Preserving Transformer InferenceHECKKSSecure Two-Party Computation
- Contact author(s)
-
tianshixu @ stu pku edu cn
luwenjie @ tiktok com
jiangrui yu @ stu pku edu cn
chenyi22 @ hust edu cn
linchenqi1018 @ gmail com
ruhuang @ pku edu cn
meng li @ pku edu cn - History
- 2025-09-01: revised
- 2025-08-27: received
- See all versions
- Short URL
- https://ia.cr/2025/1532
- License
-
CC BY-NC-ND
BibTeX
@misc{cryptoeprint:2025/1532,
author = {Tianshi Xu and Wen-jie Lu and Jiangrui Yu and Yi Chen and Chenqi Lin and Runsheng Wang and Meng Li},
title = {Breaking the Layer Barrier: Remodeling Private Transformer Inference with Hybrid {CKKS} and {MPC}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1532},
year = {2025},
url = {https://eprint.iacr.org/2025/1532}
}