Paper 2025/347

Helix: Scalable Multi-Party Machine Learning Inference against Malicious Adversaries

Yansong Zhang, Institute of Information Engineering
Xiaojun Chen, Institute of Information Engineering
Qinghui Zhang, Institute of Information Engineering
Xudong Chen, Institute of Information Engineering
Ye Dong, Singapore University of Technology and Design
Abstract

With the growing emphasis on data privacy, secure multi-party computation has garnered significant attention for its strong security guarantees in developing privacy-preserving machine learning (PPML) schemes. However, only a few works address scenarios with a large number of participants. The state of the art by Liu et al. (LXY24, USENIX Security'24) first achieves a practical PPML protocol for up to 63 parties but is constrained to semi-honest security. Although naive extensions to the malicious setting are feasible, they would introduce significant overhead in verifying the correctness of multiplications. In this paper, we propose Helix, a scalable framework for maliciously secure PPML in the honest majority setting, aiming to enhance both the scalability and practicality of maliciously secure protocols. In particular, we first report a privacy leakage issue in LXY24 during prefix OR operations and introduce a round-optimized alternative based on a single-round vectorized four-input multiplication protocol. To mitigate the verification burden, we propose a set of lightweight compression protocols by exploiting reusability properties within the computation process, and seamlessly integrate them into existing verification techniques. Building on these enhancements, we further construct a practically-efficient and general $n$-party computation protocol that serves as the cryptographic foundation for advanced PPML schemes. As a result, Helix achieves efficiency comparable to semi-honest frameworks. For instance, in 63-party neural network inference, Helix is only 1.9$\times$ (1.1$\times$) slower in the online phase and 1.2$\times$ (1.1$\times$) slower in preprocessing under LAN (WAN), compared to LXY24, in the best case.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Secure multi-party computationMalicious securityhonest majorityprivacy-preserving machine learning
Contact author(s)
zhangyansong @ iie ac cn
chenxiaojun @ iie ac cn
zhangqinghui @ iie ac cn
chenxudong @ iie ac cn
dongye @ nus edu sg
History
2025-05-19: revised
2025-02-25: received
See all versions
Short URL
https://ia.cr/2025/347
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2025/347,
      author = {Yansong Zhang and Xiaojun Chen and Qinghui Zhang and Xudong Chen and Ye Dong},
      title = {Helix: Scalable Multi-Party Machine Learning Inference against Malicious Adversaries},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/347},
      year = {2025},
      url = {https://eprint.iacr.org/2025/347}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.