Google推出了HEIR(同态加密中间表示),这是一个开源编译器工具链,能够将预训练的AI模型转换为直接在加密数据上运行 [1]。通过同态加密技术,这套工具实现了密码学意义上的安全私密AI推理,使服务提供商可以在不暴露用户数据的前提下向用户提供AI功能 [1]。
Google在该项目的开发中与多家硬件企业和学术机构展开合作 [1]。硬件合作伙伴包括Belfort、Niobium、Cornami和Optalysys等公司,致力于开发同态加密硬件加速器;学术合作则涵盖Georgia Tech、Carnegie Mellon、UC Santa Barbara、Illinois Institute of Technology、Purdue、Edinburgh University和Tsinghua University等机构 [1]。项目已经产生了四篇同行评审论文,更多研究成果仍在准备中 [1]。
为验证HEIR的实用价值,Google展示了四个应用案例,分别涉及内容推荐、信用卡欺诈检测、网络入侵异常检测和热词检测 [1]。
Google has introduced HEIR, an open-source compiler toolchain designed to convert pre-trained artificial intelligence models into systems capable of running on encrypted data [1]. This development leverages homomorphic encryption—a cryptographic technique that enables computationally secure private AI inference—allowing service providers to deliver AI functionality without exposing user data [1].
The project, which Google initially announced its intention to pursue in 2023 [1], includes collaborations with multiple hardware companies including Belfort, Niobium, Cornami, and Optalysys to develop homomorphic encryption hardware accelerators [1]. Academic partnerships span institutions such as Georgia Tech, Carnegie Mellon, UC Santa Barbara, Illinois Institute of Technology, Purdue, Edinburgh University, and Tsinghua University [1]. The initiative has already produced four peer-reviewed papers, with additional research underway [1].
Google has demonstrated the practical application of this technology across four use cases: content recommendation using deep learning models, credit card fraud detection, network intrusion anomaly detection, and keyword detection [1]. These demonstrations illustrate how the HEIR compiler can translate unencrypted AI model operations into equivalent computations performed directly on encrypted inputs [1].