[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124323-en":3,"doc-seo-124323-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124323,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Towards Efficient Privacy-Preserving Machine Learning - A Systematic Review from Protocol, Model, and System Perspectives - Survey overview","Privacy-preserving machine learning (PPML) protects sensitive user data in cloud-based ML services through cryptographic techniques, yet it often suffers major efficiency and scalability overhead compared with plaintext computation. This systematic survey consolidates recent PPML research and organizes it into protocol, model, and system perspectives, emphasizing cross-level optimizations. It compares existing methods qualitatively and quantitatively, extracts technical insights, and outlines future research directions to motivate integrated improvements across layers. A public GitHub repository tracks ongoing developments.","Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Perspectives  \nWENXUAN ZENG∗ , TIANSHI XU∗ , YI CHEN∗ , and YIFAN ZHOU, Peking University, China  \nMINGZHE ZHANG, JIN TAN, CHENG HONG, Ant Group, China MENG LI†, Peking University, China  \nPrivacy-preserving machine learning (PPML) based on cryptographic protocols has emerged as a promising paradigm to protect user data privacy in cloud-based machine learning services. While it achieves formal privacy protection, PPML often incurs significant efficiency and scalability costs due to orders of magnitude overhead compared to the plaintext counterpart. Therefore, there has been a considerable focus on mitigating the efficiency gap for PPML. In this survey, we provide a comprehensive and systematic review of recent PPML studies with a focus on cross-level optimizations. Specifically, we categorize existing papers into protocol level, model level, and system level, and review progress at each level. We also provide qualitative and quantitative comparisons of existing works with technical insights, based on which we discuss future research directions and highlight the necessity of integrating optimizations across protocol, model, and system levels. We hope this survey can provide an overarching understanding of existing approaches and potentially inspire future breakthroughs in the PPML field. As the field is evolving fast, we also provide a public GitHub repository to continuously track the developments, which is available at [https://github.com/PKU-SEC-Lab/Awesome-PPML-Papers](https://github.com/PKU-SEC-Lab/Awesome-PPML-Papers).  \nCCS Concepts: • General and reference → Surveys and overviews; • Security and privacy → Privacy-preserving protocols; • Computing methodologies → Artificial intelligence.  \n1 Introduction  \nWith the advent of machine learning (ML), artificial intelligence (AI) has ushered in an unprecedented era, profoundly benefiting diverse aspects of society such as smart homes [7, 164], intelligent manufacturing [119, 144], and smart healthcare [68, 170]. In recent years, Transformer-based models [172], especially large language models (LLMs), have emerged as a game-changing revolution in the AI field, such as ChatGPT [145], DeepSeek [74, 126], and Claude [8] . These models demonstrate advanced capabilities in multimodal understanding and complex reasoning [33, 85, 180] .  \nWhile the models demonstrate exceptional performance, ML as a service (MLaaS) on the cloud has raised serious privacy issues [86, 140, 159, 160] . The clients are required to upload their input prompts to the cloud, which may contain sensitive personal information. Meanwhile, the service provider (i.e., server) like OpenAI is unwilling to offload the trained model to the user in order to protect the proprietary model weights. Hence, despite the convenience and computational power offered by MLaaS, privacy issues remain a critical obstacle to the broader deployment of AI in real-world settings.  \nTo address the issue, privacy-preserving machine learning (PPML) has become a promising and prevalent paradigm for cryptographically strong data privacy protection, fulfilling both parties’ requirements1 : the server learns nothing about the user’s input, and the user learns nothing about the server’s weights, apart from the final inference results as shown in Figure 1(a). PPML includes many research areas such as multi-party computation (MPC), fully homomorphic encryption (FHE), differential privacy (DP), trusted execution environment (TEE), federated learning (FL), etc. In this  \n∗ Authors contributed equally.  \n†Corresponding author ([meng.li@pku.edu.cn](meng.li@pku.edu.cn)) .  \n1This paper primarily focuses on two-party computation (2PC) while computation involving three or more parties will only be briefly discussed.  \nAuthors’ Contact Information: Wenxuan Zeng; Tianshi Xu; Yi Chen; Yifan Zhou, Peking University, China; Mingzhe Zhang, Jin Tan, Ch","cbCaim1rEZxW1oKO","https://ap.wps.com/l/cbCaim1rEZxW1oKO","pdf",10128144,1,39,"English","en",105,"# Introduction\n## PPML paradigm and privacy-efficiency trade-off\n## Survey scope: protocol, model, system perspectives\n## PPML building blocks: MPC and FHE\n## Cross-level optimization opportunities","[{\"question\":\"What problem does privacy-preserving machine learning (PPML) address in cloud ML services?\",\"answer\":\"PPML protects sensitive user prompts and restricts knowledge leakage so the server learns nothing about user inputs and the user learns nothing about server model weights beyond inference results.\"},{\"question\":\"Why does PPML face adoption challenges despite providing formal privacy protection?\",\"answer\":\"PPML typically incurs orders-of-magnitude efficiency and scalability overhead compared with plaintext computation, creating a practical performance gap.\"},{\"question\":\"How does the survey structure PPML research and optimizations?\",\"answer\":\"It categorizes existing studies into protocol level, model level, and system level, then reviews progress at each level with emphasis on integrating cross-level optimizations.\"}]","Towards Efficient Privacy-Preserving Machine Learning - A Systematic Review from Protocol, Model, and System Perspectives - Survey overview | PDF",1785821599,98,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"towards-efficient-privacy-preserving-machine-learning-a-systematic-review-from-protocol-model-and-system-perspectives-survey-overview","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/towards-efficient-privacy-preserving-machine-learning-a-systematic-review-from-protocol-model-and-system-perspectives-survey-overview/124323/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does privacy-preserving machine learning (PPML) address in cloud ML services?","Question",{"text":75,"@type":76},"PPML protects sensitive user prompts and restricts knowledge leakage so the server learns nothing about user inputs and the user learns nothing about server model weights beyond inference results.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why does PPML face adoption challenges despite providing formal privacy protection?",{"text":80,"@type":76},"PPML typically incurs orders-of-magnitude efficiency and scalability overhead compared with plaintext computation, creating a practical performance gap.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the survey structure PPML research and optimizations?",{"text":84,"@type":76},"It categorizes existing studies into protocol level, model level, and system level, then reviews progress at each level with emphasis on integrating cross-level optimizations.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]