• Home
  • Search
  • SPRINT: Scalable Secure & Differentially Private Inference for Transformers
  • https://doi.org/10.56553/popets-2026-0008Copy DOI Icon

SPRINT: Scalable Secure & Differentially Private Inference for Transformers

Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

Machine learning as a service (MLaaS) enables scalable model deployment and inference on cloud servers. However, MLaaS exposes user queries and model parameters to servers. To guarantee confidentiality of queries and model parameters, multi-party computation (MPC) enables secure inference by distributing data and computations across multiple service providers. MPC eliminates single points of failure, mitigates provider breaches and ensures confidentiality beyond legal agreements. Beyond confidentiality of queries and parameters, the model itself can memorize and leak training data during inference. To mitigate privacy concerns, differential privacy (DP) provides a formal privacy guarantee for training data, which can be satisfied by injecting carefully calibrated noise into gradients during training. However, naive combinations of DP and MPC amplify accuracy loss due to DP noise and MPC approximations, and incur high computational and communication overhead due to cryptographic operations. We present SPRINT, the first scalable solution for efficient MPC inference on DP fine-tuned models with high accuracy. SPRINT fine-tunes public pre-trained models on private data using DP. It integrates DP-specific optimizations, e.g., parameter-efficient fine-tuning and noise-aware optimizers, with MPC optimizations, e.g., cleartext public parameters and efficient approximations of non-linear functions. We evaluate SPRINT on GLUE benchmark with RoBERTa, achieving up to 1.6x faster MPC inference than the state-of-the-art non-DP solution SHAFT, reducing communication by 1.6x. Notably, SPRINT maintains high accuracy during MPC inference, with <1 percentage point gap compared to cleartext accuracy.

Similar Papers
  • Single Report

Considerations for using Privacy Preserving Machine Learning Techniques for Safeguards

  • Dec 01, 2020
  • Nathan Martindale +3
  • Conference Article
  • Citations20

Privacy-Preserving Inductive Learning with Decision Trees

  • Jun 01, 2017
  • Stacey Truex +3
  • Book Chapter
  • Citations8

Machine Learning as a Service (MLaaS)—An Enterprise Perspective

  • Jan 01, 2023
  • Ioannis Grigoriadis +3
  • Conference Article
  • Citations4

Securely Sampling Discrete Gaussian Noise for Multi-Party Differential Privacy

  • Nov 15, 2023
  • Chengkun Wei +4
  • Conference Article
  • Citations50

Privacy Preserving Facial Recognition Against Model Inversion Attacks

  • Dec 01, 2020
  • Pavana Prakash +5
  • PDF
  • Research Article
  • Citations19

Individualized PATE: Differentially Private Machine Learning with Individual Privacy Guarantees

  • Jan 01, 2023
  • Proceedings on Privacy Enhancing Technologies
  • Franziska Boenisch +4
  • Research Article
  • Citations6

MedCo2: Privacy-Preserving Cohort Exploration and Analysis.

  • Jan 01, 2020
  • Studies in health technology and informatics
  • Froelicher David +4
  • Conference Article
  • Citations879

ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models

  • Jan 01, 2019
  • Ahmed Salem +5
  • Research Article
  • Citations52

SAQE

  • Jul 01, 2020
  • Proceedings of the VLDB Endowment
  • Johes Bater +4
  • Conference Article
  • Citations93

Composing Differential Privacy and Secure Computation

  • Oct 30, 2017
  • Xi He +3
  • Research Article
  • Citations4

B-LNN: Inference-time linear model for secure neural network inference

  • Apr 20, 2023
  • Information Sciences
  • Qizheng Wang +2
  • Research Article
  • Citations10

Privacy-Preserving Distributed Multi-Task Learning against Inference Attack in Cloud Computing

  • Oct 22, 2021
  • ACM Transactions on Internet Technology
  • Xindi Ma +5
  • Research Article

Securing AI Models: Cryptographic Approaches to Protect AI Algorithms and Data

  • Aug 31, 2024
  • Journal of Artificial Intelligence & Cloud Computing
  • Sreekanth Pasunuru +1
  • Dissertation

A systemic comparison comparison of concurrent multiparty secret sharing with SGD regression and classification

  • May 01, 2024
  • Ethan Wyatt Schutzenhofer
  • Conference Article
  • Citations8

A Novel Privacy-Preserving Neural Network Computing Approach for E-Health Information System

  • Jun 01, 2021
  • Yingying Yao +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.