[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-127965-en":3,"doc-seo-127965-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},127965,687207024643,"Oliver","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",8,"Research & Report","Helix - Scalable Multi-Party Machine Learning Inference against Malicious Adversaries","Helix proposes a scalable maliciously secure framework for privacy-preserving machine learning under the honest majority setting. The work targets gaps in prior semi-honest PPML approaches scaled to up to 63 parties, highlighting a privacy leakage issue in LXY24’s prefix OR operations and replacing it with a round-optimized vectorized single-round three-layer multiplication alternative. It further introduces lightweight compression protocols for efficient multiplication verification and a batch check to reduce the complexity of revealing operations. For 63-party neural network inference, Helix shows only modest slowdown compared with semi-honest baselines in online and preprocessing phases.","Helix: Scalable Multi-Party Machine Learning Inference against Malicious Adversaries (Full  \nVersion)  \nYansong Zhang 1 ,2 ,3 , Xiaojun Chen 1 ,2 ,3 , Qinghui Zhang 1 ,2 ,3 , Ye Dong4 , and  \nXudong Chen 1 ,2  \n1 Institute of Information Engineering, Chinese Academy of Sciences, China  \n2 State Key Laboratory of Cyberspace Security Defense, China  \n3 School of Cyber Security, University of Chinese Academy of Sciences, China {zhangyansong,chenxiaojun,zhangqinghui,[chenxudong}@iie.ac.cn](chenxudong}@iie.ac.cn)  \n4 National University of Singapore, Singapore  \n[dongye@nus.edu.sg](dongye@nus.edu.sg)  \nAbstract. With the growing emphasis on data privacy, secure multiparty computation has garnered significant attention for its strong security guarantees in developing privacy-preserving machine learning (PPML) schemes. However, only a few works address scenarios with a large number of participants. The state of the art by Liu et al. ( LXY24, USENIX Security’24) first achieves a practical PPML protocol for up to 63 parties but is constrained to semi-honest security. Although naive extensions to the malicious setting are possible, they would introduce significant overhead.  \nIn this paper, we propose Helix, a scalable framework for maliciously secure PPML in the honest majority setting, aiming to enhance both thescalability and practicality of maliciously secure protocols. In particular, we report a privacy leakage issue in LXY24 during prefix OR operations and introduce a round-optimized alternative based on a single-round vectorized three-layer multiplication protocol. Additionally, by exploiting reusability properties within the computation process, we propose lightweight compression protocols that substantially improve the efficiency of multiplication verification. We also develop a batch check protocol to reduce the computational complexity of revealing operations in the malicious setting. For 63-party neural network inference, compared to the semi-honest LXY24 , Helix is only 1.9 × (1.1×) slower in the online phase and 1.2 × (1.1×) slower in preprocessing under LAN (WAN) in the best case.  \nKeywords: secure multi-party computation · malicious security · honest majority · privacy-preserving machine learning.  \n1 Introduction  \nMachine learning (ML) is increasingly applied across diverse domains, including medicine, finance, and recommendation systems. However, this widespread success has raised significant privacy concerns regarding both models and personal  \n2 Y. Zhang et al.  \ndata. As such, privacy-preserving techniques should be employed to ensure the privacy of the data used in machine-learning-as-a-service.  \nSecure multi-party computation (MPC) [38] is a notable approach for enabling privacy-preserving machine learning (PPML) . MPC allows n parties to collaboratively compute a function over their private inputs while ensuring input privacy and output correctness. Nowadays, MPC-based PPML has made significant progress, particularly under the semi-honest setting [15,29,37], where adversaries honestly follow the protocol but try to learn secret values. Nevertheless, in real-world scenarios involving large numbers of participants, such as federated learning, expecting that all individual parties are semi-honest is overly strong and impractical. Therefore, there is an urgent need for scalable protocols that support efficient PPML with many parties in the malicious setting, where adversaries can arbitrarily deviate from the protocol.  \nHowever, existing malicious PPML protocols primally focus on 2-4 parties [10, 19, 21, 28, 32, 39], where one party is corrupt. In the most recent work, Liu et al. [24] utilize Shamir secret sharing [35] to design scalable PPML protocols under the semi-honest secure honest majority model. Their approach enables efficient PPML inference with up to 63 parties. For ease of reference, we denote this work [24] as “ LXY24”. Trivially, the protocols in LXY24 can be adapted to malicious security using stand","cbCaimCc12mi2Nv7","https://ap.wps.com/l/cbCaimCc12mi2Nv7","pdf",647066,3,1,25,"English","en",105,"# Introduction\n## Privacy leakage in prefix OR comparison\n## Performance limitations in multiplication verification and revealing","[{\"question\":\"What problem does Helix address in scalable malicious PPML?\",\"answer\":\"Helix addresses the inefficiency and security gaps of extending semi-honest scalable PPML to the malicious setting, especially verification of multiplication and revealing operations at large party counts.\"},{\"question\":\"How does Helix improve the prefix OR operation compared with LXY24?\",\"answer\":\"Helix reports a privacy leakage issue in LXY24’s prefix OR and proposes a round-optimized alternative based on a single-round vectorized three-layer multiplication protocol.\"},{\"question\":\"What techniques does Helix use to improve multiplication verification efficiency?\",\"answer\":\"Helix exploits reusability in the computation process to design lightweight compression protocols that substantially reduce the efficiency cost of multiplication verification, and it uses a batch check to lower revealing complexity.\"}]","Helix - Scalable Multi-Party Machine Learning Inference against Malicious Adversaries | PDF",1785943369,63,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"helix-scalable-multi-party-machine-learning-inference-against-malicious-adversaries","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":20},"https://docshare.wps.com/document/research-report/",{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/helix-scalable-multi-party-machine-learning-inference-against-malicious-adversaries/127965/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-27","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does Helix address in scalable malicious PPML?","Question",{"text":76,"@type":77},"Helix addresses the inefficiency and security gaps of extending semi-honest scalable PPML to the malicious setting, especially verification of multiplication and revealing operations at large party counts.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does Helix improve the prefix OR operation compared with LXY24?",{"text":81,"@type":77},"Helix reports a privacy leakage issue in LXY24’s prefix OR and proposes a round-optimized alternative based on a single-round vectorized three-layer multiplication protocol.",{"name":83,"@type":74,"acceptedAnswer":84},"What techniques does Helix use to improve multiplication verification efficiency?",{"text":85,"@type":77},"Helix exploits reusability in the computation process to design lightweight compression protocols that substantially reduce the efficiency cost of multiplication verification, and it uses a batch check to lower revealing complexity.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]