2607.05251v1 Jul 06, 2026 cs.CR

신경망의 프라이버시 보호 강건성 검증

Privacy-Preserving Robustness Verification for Neural Networks

Xiaokun Luan
Xiaokun Luan
Citations: 22
h-index: 3
Nianyun Song
Nianyun Song
Citations: 4
h-index: 1
Yu Guo
Yu Guo
Citations: 72
h-index: 6
Rongfang Bie
Rongfang Bie
Citations: 74
h-index: 6
Meng Sun
Meng Sun
Citations: 205
h-index: 8
Xiyue Zhang
Xiyue Zhang
Citations: 285
h-index: 9

신경망 검증과 데이터 프라이버시는 본질적으로 상충되는 관계에 있습니다. 검증은 모델 파라미터와 입력 데이터에 대한 완전한 접근을 요구하지만, 이러한 접근은 점점 더 프라이버시 규제 및 지적 재산권 제약으로 인해 제한되고 있습니다. 이러한 긴장은 프라이버시에 민감한 영역에서 강건성 검증을 비실용적으로 만듭니다. 본 연구에서는 SecureCROWN이라는 첫 번째 프라이버시 보호 신경망 강건성 검증 프레임워크를 통해 이러한 격차를 해소합니다. 안전한 2-파티 연산(2PC)을 기반으로 구축된 당사 프레임워크는 모델 소유자와 데이터 소유자가 함께 인증된 강건성 경계를 계산할 수 있도록 하며, 최종 결과만 공개하고 동시에 두 당사자의 개인 데이터를 반직접적 보안 모델 하에서 입증 가능하게 보호합니다. 주요 과제는 선형 바운드 전파에서 조건부 연산을 안전하게 계산하는 것입니다. 데이터에 의존적인 분기는 표준 안전 연산 프로토콜과 호환되지 않기 때문입니다. 우리는 분기를 없애기 위해 조건부 논리를 연속 산술 연산으로 표현했습니다. 또한, 수치적 안정성을 향상시키기 위한 뉴턴-랩슨 개선 방법을 도입했습니다. 광범위한 분석 및 실험 결과, SecureCROWN은 일반 검증 결과와 정확히 일치하며, 다양한 모델 크기와 통신 환경(LAN/WAN)에서 0.1초에서 200초 내에 완료되므로, 프라이버시 보호 신경망 검증의 실현 가능성을 입증합니다.

Original Abstract

Neural network verification and data privacy are inherently in tension: verification demands full access to model parameters and input data, yet both are increasingly restricted by privacy regulations and intellectual property constraints. This tension has left robustness verification impractical in privacy-sensitive domains. In this work, we address this gap with SecureCROWN, the first framework for privacy-preserving neural network robustness verification. Built upon secure two-party computation (2PC), our framework enables a model owner and a data owner to jointly compute certified robustness bounds -- revealing only the final result while provably protecting both parties' private data under the semi-honest security model. A key challenge is securely computing the conditional operations in Linear Bound Propagation, where the data-dependent branching is incompatible with standard secure computation protocols. We eliminate branching by formulating conditional logic as continuous arithmetic operations. Additionally, we introduce a Newton--Raphson refinement method to improve numerical stability. Extensive analysis and experiments show that SecureCROWN strictly matches plaintext verification results, while completing in 0.1--200s across varied model sizes and communication settings (LAN/WAN), demonstrating the feasibility of privacy-preserving neural network verification.

0 Citations
0 Influential
4.5 Altmetric
22.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!