Paper 2025/347
Helix: Scalable Multi-Party Machine Learning Inference against Malicious Adversaries
Abstract
With the growing emphasis on data privacy, secure multi-party computation has garnered significant attention for its strong security guarantees in developing privacy-preserving machine learning (PPML) schemes. However, only a few works address scenarios with a large number of participants. The state of the art by Liu et al. (LXY24, USENIX Security'24) first achieves a practical PPML protocol for up to 63 parties but is constrained to semi-honest security. Although naive extensions to the malicious setting are feasible, they would introduce significant overhead in verifying the correctness of multiplications. In this paper, we propose Helix, a scalable framework for maliciously secure PPML in the honest majority setting, aiming to enhance both the scalability and practicality of maliciously secure protocols. In particular, we first report a privacy leakage issue in LXY24 during prefix OR operations and introduce a round-optimized alternative based on a single-round vectorized four-input multiplication protocol. To mitigate the verification burden, we propose a set of lightweight compression protocols by exploiting reusability properties within the computation process, and seamlessly integrate them into existing verification techniques. Building on these enhancements, we further construct a practically-efficient and general $n$-party computation protocol that serves as the cryptographic foundation for advanced PPML schemes. As a result, Helix achieves efficiency comparable to semi-honest frameworks. For instance, in 63-party neural network inference, Helix is only 1.9$\times$ (1.1$\times$) slower in the online phase and 1.2$\times$ (1.1$\times$) slower in preprocessing under LAN (WAN), compared to LXY24, in the best case.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Secure multi-party computationMalicious securityhonest majorityprivacy-preserving machine learning
- Contact author(s)
-
zhangyansong @ iie ac cn
chenxiaojun @ iie ac cn
zhangqinghui @ iie ac cn
chenxudong @ iie ac cn
dongye @ nus edu sg - History
- 2025-05-19: revised
- 2025-02-25: received
- See all versions
- Short URL
- https://ia.cr/2025/347
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2025/347,
author = {Yansong Zhang and Xiaojun Chen and Qinghui Zhang and Xudong Chen and Ye Dong},
title = {Helix: Scalable Multi-Party Machine Learning Inference against Malicious Adversaries},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/347},
year = {2025},
url = {https://eprint.iacr.org/2025/347}
}