[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120941-en":3,"doc-seo-120941-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120941,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","SHAPER: A General Architecture for Privacy-Preserving Primitives in Secure Machine Learning","Secure multi-party computation and homomorphic encryption are core privacy-preserving primitives in secure machine learning, but their adoption is constrained by computation and network communication overhead. SHAPER introduces a hybrid secret-sharing and homomorphic encryption architecture that protects sensitive data within encrypted or randomly shared domains without relying on a trusted third party. Algorithm–protocol–hardware co-design leverages plaintext SIMD and fine-grained scheduling to reduce end-to-end latency across network settings, supports secure domain computing acceleration, and enables conversion between common privacy-preserving primitives, achieving 94× FPGA acceleration over CPU clusters on large-scale logistic regression.","IACR Transactions on Cryptographic Hardware and Embedded Systems  \nISSN 2569-2925, Vol. 2024, No. 2, pp. 819–843. DOI:10.46586/tches.v2024.i2.819-843  \nSHAPER: A General Architecture for Privacy-Preserving Primitives in Secure Machine Learning  \nZiyuan Liang 1 , Qi’ao Jin 1 , Zhiyong Wang 1 , Zhaohui Chen2 ,3 ,4 , Zhen Gu3 ,4 ,5 ,  \nYanhheng Lu4 ,6 and Fan Zhang 1  \n1 Zhejiang University, Hangzhou, China,  \nliangziyuan,{jin_qi_ao,wangzhiyong, [fanzhang}@zju.edu.cn](fanzhang}@zju.edu.cn)  \n2 Peking University, Beijing, China  \n3 DAMO Academy, Alibaba group, Beijing, China,  \nchenzhaohui.czh,{[guzhen.gz}@alibaba-inc.com](guzhen.gz}@alibaba-inc.com)  \n4 Hupan Lab, Hangzhou, China  \n5 Tsinghua University, Beijing, China  \n6 Alibaba Group, Shanghai, China, [yanheng.lyh@alibaba-inc.com](yanheng.lyh@alibaba-inc.com)  \nAbstract. Secure multi-party computation and homomorphic encryption are two primary security primitives in privacy-preserving machine learning, whose wide adoption is, nevertheless, constrained by the computation and network communication overheads. This paper proposes a hybrid Secret-sharing and Homomorphic encryption Architecture for Privacy-pERsevering machine learning (SHAPER) . SHAPER protects sensitive data in encrypted or randomly shared domains instead of relying on a trusted third party. The proposed algorithm-protocol-hardware co-design methodology explores techniques such as plaintext Single Instruction Multiple Data (SIMD) and ﬁne-grained scheduling, to minimize end-to-end latency in various network settings. SHAPER also supports secure domain computing acceleration and the conversion between mainstream privacy-preserving primitives, making it ready for general and distinctive data characteristics. SHAPER is evaluated by FPGA prototyping with a comprehensive hyper-parameter exploration, demonstrating a 94 × speed-up over CPU clusters on large-scale logistic regression training tasks.  \nKeywords: Privacy-Preserving Machine Learning · Multi-Party Computation · Additive Homomorphic Encryption · Hardware Accelerator  \n1 Introduction  \nCross-agency data collaboration maximizes the accuracy of Machine learning (ML) models. Nonetheless, from the perspective of user privacy and business interests, concerns about data privacy and security arise [ARC19] . In practice, ML cannot be applied directly to health or ﬁnancial data for competitive and regulatory reasons. These sensitive data sets are isolated by diﬀerent parties, which is also known as the “isolated data island” problem. To solve this problem, privacy-preserving machine learning (PPML) [XBJ21] allows participants to collaborate on training and inference procedures by applying privacy-preserving computing techniques, e.g. multi-party computation (MPC) [Yao82], homomorphic encryption (HE) [FV12], and trusted execution environment (TEE) [CD16] . These security primitives prevent the raw data, model weights, and gradient values from being revealed to any other participants. Since the algorithms and protocols of PPML heavily depend  \nLicensed under Creative Commons License CC-BY 4 .0.   \nReceived: 2023-10-15 Accepted: 2023-12-15 Published: 2024-03-12  \n| Third-party\u003Cbr>Adversary\u003Cbr>Monitoring\u003Cbr> |\n| --- |\n|  |\n| PPML Protocols |\n\nTrust Barrier  \n| Sample ID | Features |\n| --- | --- |\n|  |  |\n|  |  |\n|  |  |\n\nFigure 1: PPML allows two parties to securely train ML models on sensitive data.  \non the data characteristics, scale, ownership, and security model, debates on technical roadmap never stop.  \nFig. 1 shows an example of PPML in a healthcare scenario. A hospital and a pharmaceutical company collaborate to develop a predictive model for personalized medicine while protecting patient data. The parties have access to diﬀerent sensitive patient records (labelsand features) . The parties use privacy-computing techniques to jointly train the model. The computational load is divided between the two parties, with each party performing local calculations and exchanging","cbCaiagmeHFdTyW9","https://ap.wps.com/l/cbCaiagmeHFdTyW9","pdf",1707107,1,25,"English","en",105,"# Introduction\n## Privacy-preserving machine learning (PPML) scenarios\n## Core primitives: MPC and HE\n## Gaps between research and real-world deployment","[{\"question\":\"What problem does SHAPER address in privacy-preserving machine learning?\",\"answer\":\"It targets the high computation and network communication overhead that limits practical adoption of privacy-preserving primitives like MPC and homomorphic encryption.\"},{\"question\":\"How does SHAPER protect sensitive data without a trusted third party?\",\"answer\":\"It uses a hybrid secret-sharing and homomorphic encryption architecture to keep data protected in encrypted or randomly shared domains rather than relying on trusted third-party key or protocol assistance.\"},{\"question\":\"What design techniques help SHAPER reduce end-to-end latency?\",\"answer\":\"It applies algorithm–protocol–hardware co-design, including plaintext SIMD and fine-grained scheduling, to minimize latency across different network environments.\"}]","SHAPER: A General Architecture for Privacy-Preserving Primitives in Secure Machine Learning | PDF",1785732916,63,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"shaper-a-general-architecture-for-privacy-preserving-primitives-in-secure-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/shaper-a-general-architecture-for-privacy-preserving-primitives-in-secure-machine-learning/120941/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does SHAPER address in privacy-preserving machine learning?","Question",{"text":75,"@type":76},"It targets the high computation and network communication overhead that limits practical adoption of privacy-preserving primitives like MPC and homomorphic encryption.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does SHAPER protect sensitive data without a trusted third party?",{"text":80,"@type":76},"It uses a hybrid secret-sharing and homomorphic encryption architecture to keep data protected in encrypted or randomly shared domains rather than relying on trusted third-party key or protocol assistance.",{"name":82,"@type":73,"acceptedAnswer":83},"What design techniques help SHAPER reduce end-to-end latency?",{"text":84,"@type":76},"It applies algorithm–protocol–hardware co-design, including plaintext SIMD and fine-grained scheduling, to minimize latency across different network environments.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]