arXiv:cs.LG· Guang Yang, Fengchen Liu·· 5 小时前AI 评分26
CipherGenome:面向基因组 MoE 模型的同态推理协议
CipherGenome: Homomorphic Inference for Genomic Mixture-of-Experts
AI 导读
CipherGenome 让 15.1B 参数的基因组 MoE 模型在可信瘦客户端保留嵌入、注意力和路由器,将占 95.8% 参数的专家投影以 module-LWE 加密外包给不可信 GPU 服务器。
正文
This paper has been withdrawn by Guang Yang
No PDF available, click to view other formats
Abstract:Genome foundation models are growing into sparse mixture-of-experts (MoE) networks whose expert weights no longer fit on the machines that hold the sequences, yet sending a private genome to rented accelerators exposes it: we show that a single server hosting one expert recovers the input nucleotides with 99.8% top-1 accuracy. We present CipherGenome, a protocol that keeps the embedding, attention and router of a 15.1B-parameter MoE genome model on a trusted thin client and outsources every expert projection, 95.8% of the parameters, to untrusted and possibly colluding GPU servers under module-LWE encryption. The design exploits three structural facts: expert layers are linear between two SwiGLU gates, expert weights are public, and GPU integer tensor cores can evaluate a ciphertext-weight product exactly modulo $2^{48}$ in a single GEMM. The client evaluates the nonlinearity exactly and re-encrypts with fresh secrets, so no polynomial approximation or bootstrapping is ever needed. On 72 windows from 12 bacterial genomes, encryption adds $2.54 \times 10^{-4}$ nats per token of KL divergence (95% CI upper bound $3.95 \times 10^{-4}$), below a pre-registered non-inferiority margin and indistinguishable from bf16 inference, while the same inversion attack falls to chance level. A reusable public hint cuts end-to-end latency by 3.54 times, wire compression reduces traffic 6.8 times, per-layer padding reduces routing leakage from 54.9% to 8.9% accuracy, and HE-compatible int4 experts remain non-inferior to their plaintext counterparts. Per expert and token, the server-side cost is more than six orders of magnitude below a CKKS baseline.
| Comments: | Withdrawn by the authors pending an institutional intellectual property review |
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG); Genomics (q-bio.GN) |
| Cite as: | arXiv:2609.35883 [cs.CR] |
| (or arXiv:2609.35883v2 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2609.35883 arXiv-issued DOI via DataCite |
Submission history
From: Guang Yang [view email]
[v1]
Sun, 27 Sep 2026 00:26:27 UTC (232 KB)
[v2]
Thu, 1 Oct 2026 22:15:00 UTC (1 KB) (withdrawn)
来源:arXiv:cs.LG · arxiv.org