arXiv:cs.LG· Guang Yang, Fengchen Liu·· 5 小时前AI 评分27
GenomeOcean Anywhere:面向基因组 MoE 的私有 WebGPU 推理
GenomeOcean Anywhere: Private WebGPU Inference for Genome MoEs
AI 导读
研究者构建了一套系统,让 150 亿参数的基因组 MoE 模型在志愿者浏览器中运行,由可信协调器负责 attention 与路由,浏览器 worker 通过手写 WebGPU kernel 执行专家前馈网络。
正文
This paper has been withdrawn by Guang Yang
No PDF available, click to view other formats
Abstract:Genome foundation models are most useful where sequences are generated, yet the largest models need datacenter accelerators and a place to send private DNA. We ask whether a 15-billion-parameter genome mixture-of-experts (MoE) model can instead run on volunteers' web browsers, with the experts spread across many untrusted devices, without changing its predictions and without revealing the sequence to any single device. We build a system in which a trusted coordinator runs attention and routing while browser workers run every expert feed-forward network through hand-written WebGPU kernels, and we protect the expert inputs with real-valued Lagrange coded computing: each worker receives only a Gaussian-padded share, computes the expert's linear maps, and the coordinator decodes from any two of three workers. On GenomeOcean-MoE (8 experts, top-2 routing, 24 layers), the browser path matches native this http URL at every quantization level, the distributed path stays at the BF16 numerical noise floor (KL 0.0036 nats per token), and an unfitted latency model predicts decode time within 0.74% (median) under emulated wide-area links. We first show that plaintext expert inputs are not private: a probe recovers the token from a single vector at every depth, and one worker can identify the source genome from 300 unordered tokens with 92% accuracy. With coded experts, an adaptive attacker trained on shares falls to the most-frequent-token baseline, one worker's information about each token is bounded below one bit per forward pass, and the fidelity cost stays below the BF16 noise floor; in Chrome, coded decoding runs at 220 to 376 ms per token, depending on how much of the routing is hidden, and continues without replicas when a worker fails.
| Comments: | Withdrawn by the authors pending an institutional intellectual property review |
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG); Genomics (q-bio.GN) |
| Cite as: | arXiv:2609.35882 [cs.CR] |
| (or arXiv:2609.35882v2 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2609.35882 arXiv-issued DOI via DataCite |
Submission history
From: Guang Yang [view email]
[v1]
Sun, 27 Sep 2026 00:21:26 UTC (186 KB)
[v2]
Thu, 1 Oct 2026 22:14:29 UTC (1 KB) (withdrawn)
来源:arXiv:cs.LG · arxiv.org