Content
@
0 reply
0 recast
0 reaction
Yiğit
@yigitgurbulak
eprint.iacr.org/2024/639.pdf This study demonstrates that a MLaaS operator can provide consumers with cryptographic techniques ensuring computational integrity with minimal assumptions. - Consumers can be highly confident that the task is performed correctly
1 reply
0 recast
0 reaction
Yiğit
@yigitgurbulak
Packaged with a CUDA-compatible GPU computing backend, RISC-ZERO ZKVM significantly improves the computation time for DP-regression training. However, it comes at the cost of nearly exhausting the memory of the tested graphics unit (an 8GB NVIDIA GeForce RTX 4070 Laptop CPU).
1 reply
0 recast
0 reaction
Yiğit
@yigitgurbulak
They mitigate this by partitioning the dataset into 343 blocks and sequentially verifying each block with a single ZKVM. Thus, they verify approximately 55 minutes of DP-private regression training on 60,000 (x, y) examples with a single GPU.
1 reply
0 recast
0 reaction
Yiğit
@yigitgurbulak
After training on 60,000 examples, the difference in mean absolute error between both regressions is extremely low. Standard errors are measured for both regressions, with a very low delta of 0.00001.
1 reply
0 recast
0 reaction
Yiğit
@yigitgurbulak
This demonstrates that a privacy-preserving model can achieve nearly the same performance in predictions compared to a non-privacy-preserving model.
1 reply
0 recast
0 reaction