{"id":"https://openalex.org/W7127130474","doi":"https://doi.org/10.1109/trustcom66490.2025.00028","title":"Hamster: Private Transformer Inference via Fully Homomorphic Encryption","display_name":"Hamster: Private Transformer Inference via Fully Homomorphic Encryption","publication_year":2025,"publication_date":"2025-11-14","ids":{"openalex":"https://openalex.org/W7127130474","doi":"https://doi.org/10.1109/trustcom66490.2025.00028"},"language":null,"primary_location":{"id":"doi:10.1109/trustcom66490.2025.00028","is_oa":false,"landing_page_url":"https://doi.org/10.1109/trustcom66490.2025.00028","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048562423","display_name":"Huizhuo Wang","orcid":"https://orcid.org/0009-0002-7799-6654"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huizhuo Wang","raw_affiliation_strings":["Quan Cheng Laboratory,Jinan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Quan Cheng Laboratory,Jinan,China","institution_ids":["https://openalex.org/I4210136793"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124861840","display_name":"Zhiyong Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhiyong Zhang","raw_affiliation_strings":["Quan Cheng Laboratory,Jinan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Quan Cheng Laboratory,Jinan,China","institution_ids":["https://openalex.org/I4210136793"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5124787949","display_name":"Lei Ju","orcid":null},"institutions":[{"id":"https://openalex.org/I154099455","display_name":"Shandong University","ror":"https://ror.org/0207yh398","country_code":"CN","type":"education","lineage":["https://openalex.org/I154099455"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lei Ju","raw_affiliation_strings":["Shandong University,Quan Cheng Laboratory,Jinan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shandong University,Quan Cheng Laboratory,Jinan,China","institution_ids":["https://openalex.org/I154099455"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.80831589,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"184","last_page":"191"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9320999979972839,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9320999979972839,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.05790000036358833,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.001500000013038516,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/homomorphic-encryption","display_name":"Homomorphic encryption","score":0.6837999820709229},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6621999740600586},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.611299991607666},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.5273000001907349},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.4068000018596649},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.35499998927116394},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.34700000286102295},{"id":"https://openalex.org/keywords/public-key-cryptography","display_name":"Public-key cryptography","score":0.3411000072956085}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7038999795913696},{"id":"https://openalex.org/C158338273","wikidata":"https://www.wikidata.org/wiki/Q2154943","display_name":"Homomorphic encryption","level":3,"score":0.6837999820709229},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6621999740600586},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.611299991607666},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.5273000001907349},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.4068000018596649},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.35499998927116394},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.34700000286102295},{"id":"https://openalex.org/C203062551","wikidata":"https://www.wikidata.org/wiki/Q201339","display_name":"Public-key cryptography","level":3,"score":0.3411000072956085},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.33809998631477356},{"id":"https://openalex.org/C158622935","wikidata":"https://www.wikidata.org/wiki/Q660848","display_name":"Nonlinear system","level":2,"score":0.33640000224113464},{"id":"https://openalex.org/C6295992","wikidata":"https://www.wikidata.org/wiki/Q976521","display_name":"Cryptosystem","level":3,"score":0.33469998836517334},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.32919999957084656},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3098999857902527},{"id":"https://openalex.org/C206729178","wikidata":"https://www.wikidata.org/wiki/Q2271896","display_name":"Scheduling (production processes)","level":2,"score":0.30469998717308044},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.2971000075340271},{"id":"https://openalex.org/C2777168461","wikidata":"https://www.wikidata.org/wiki/Q42196253","display_name":"Set operations","level":3,"score":0.2946000099182129},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.2867000102996826},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2800999879837036},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.27889999747276306},{"id":"https://openalex.org/C3087436","wikidata":"https://www.wikidata.org/wiki/Q1386603","display_name":"Secret sharing","level":3,"score":0.27790001034736633},{"id":"https://openalex.org/C92757383","wikidata":"https://www.wikidata.org/wiki/Q382497","display_name":"Affine transformation","level":2,"score":0.2711000144481659},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.2703000009059906},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.2660999894142151},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.25220000743865967}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/trustcom66490.2025.00028","is_oa":false,"landing_page_url":"https://doi.org/10.1109/trustcom66490.2025.00028","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320313895","display_name":"Department of Science and Technology of Shandong Province","ror":"https://ror.org/01b9fvd84"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W1491861813","https://openalex.org/W2006453614","https://openalex.org/W2031533839","https://openalex.org/W2098290658","https://openalex.org/W2152926062","https://openalex.org/W2226167778","https://openalex.org/W2768174108","https://openalex.org/W2768505000","https://openalex.org/W2899140612","https://openalex.org/W2923014074","https://openalex.org/W2979826702","https://openalex.org/W2990280959","https://openalex.org/W3006531732","https://openalex.org/W3083485178","https://openalex.org/W4205350912","https://openalex.org/W4281806276","https://openalex.org/W4320495408","https://openalex.org/W4321499901","https://openalex.org/W4385412524","https://openalex.org/W4387776339","https://openalex.org/W4400382079","https://openalex.org/W4402263660","https://openalex.org/W4408750063","https://openalex.org/W4408750076","https://openalex.org/W4415259023"],"related_works":[],"abstract_inverted_index":{"Large":[0],"transformer-based":[1],"models":[2],"have":[3],"achieved":[4],"remarkable":[5],"performance":[6,75,126,178],"in":[7,120,174],"natural":[8,30],"language":[9],"processing":[10],"and":[11,49,69,77,98,185,194],"related":[12],"fields,":[13],"yet":[14],"they":[15],"pose":[16],"significant":[17],"privacy":[18],"risks":[19],"when":[20],"handling":[21],"sensitive":[22],"data.":[23],"Fully":[24],"homomorphic":[25,129],"encryption":[26],"(FHE)":[27],"offers":[28],"a":[29,108,139,147],"solution":[31],"for":[32,115,152],"private":[33,90,153],"transformer":[34,91,121,154],"inference:":[35],"the":[36,39,42,50,57,116,125,192],"client":[37,97],"encrypts":[38],"input":[40],"data,":[41],"server":[43,99],"performs":[44],"inference":[45,71,92,163],"directly":[46],"on":[47],"ciphertexts,":[48],"results":[51],"remain":[52],"encrypted":[53,70],"until":[54],"decrypted":[55],"by":[56,183,189],"key":[58],"holder.":[59],"However,":[60],"FHE":[61],"struggles":[62],"to":[63],"efficiently":[64],"support":[65,138],"non-linear":[66],"activation":[67],"functions,":[68],"often":[72],"incurs":[73],"substantial":[74],"overhead":[76,127],"degrades":[78],"model":[79,175],"accuracy.":[80,176],"To":[81],"address":[82],"these":[83],"challenges,":[84],"we":[85],"propose":[86],"Hamster,":[87],"an":[88,161],"FHE-based":[89],"system":[93],"that":[94,136],"protects":[95],"both":[96],"privacy.":[100],"Our":[101],"contributions":[102],"are":[103],"twofold.":[104],"First,":[105],"Hamster":[106,145,159],"introduces":[107],"comprehensive":[109],"set":[110,141],"of":[111,128,142,165,196],"more":[112],"efficient":[113],"approximations":[114],"costly":[117],"nonlinear":[118,143],"functions":[119],"models,":[122],"significantly":[123],"reducing":[124],"evaluation.":[130],"Second,":[131],"unlike":[132],"some":[133],"existing":[134],"works":[135],"only":[137],"limited":[140],"components,":[144],"implements":[146],"complete":[148],"end-to-end":[149],"evaluation":[150],"pipeline":[151],"inference.":[155],"Extensive":[156],"experiments":[157],"demonstrate":[158],"achieves":[160],"average":[162],"time":[164],"approximately":[166],"12":[167],"minutes":[168],"per":[169],"token,":[170],"with":[171],"minimal":[172],"loss":[173],"This":[177],"outperforms":[179],"BumbleBee":[180],"(NDSS":[181,187],"2025)":[182,188],"2.2\u00d7":[184],"NEXUS":[186],"1.2\u00d7,":[190],"highlighting":[191],"effectiveness":[193],"practicality":[195],"our":[197],"system.":[198]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-02-03T00:00:00"}
