7
collaborators
2024–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
1 Talk
| Title | Conference | Type | Co-authors |
|---|---|---|---|
| Quantum-Secure Private Inference from Vacuum Fluctuations | QCRYPT 2026 | regular | Kfir Sulimany, Sri Krishna Vadlamani, Ryan Hamerly, Dirk Englund |
We show that the vacuum fluctuations of coherent light can serve as a cryptographic resource for private neural-network inference. A server encodes proprietary model weights into weak coherent states; a client computes the inference optically and returns a certificate state whose excess noise the server verifies. Weight-leakage bounds derived via the Holevo theorem hold against all IID attacks, including non-Gaussian ones. Data-leakage bounds derived via Cramér–Rao inequalities hold against individual attacks with arbitrary probes and collective attacks with Gaussian probes. On MNIST, the protocol achieves >95% accuracy with leakage below 0.1 bits per weight and per data element, an order of magnitude below the precision needed for functional inference. All components are standard CV-QKD hardware. Published in Physical Review X 15, 041056 (2025). |
|||
1 Poster
| Title | Conference | Co-authors |
|---|---|---|
| Quantum-secure multi-party deep learning | QCRYPT 2024 | Kfir Sulimany Solan, Sri Krishna Vadlamani, Cole Brabec, Leshem Choshen, Dirk Englund |
The necessity of multi-party computing has become increasingly evident due to the exploding demand for distributed machine learning. Offloading computationally intensive DNN inference to cloud servers introduces vulnerabilities that compromise user data security. To address this challenge, we introduce a coherent linear algebra engine for private multi-party computation of distributed machine learning tasks, leveraging conventional telecom components. We evaluate the fidelity of inner product computations, MNIST classification accuracy, and potential information leakage. Our analyses reveal a trade-off between classification accuracy and data privacy. This trade-off diminishes in significance for large-scale tasks, indicating the potential to achieve both classification accuracy and privacy simultaneously. |
||
Collaborators
| Co-author | Joint talks |
|---|---|
| Dirk Englund | 2 |
| Sri Krishna Vadlamani | 2 |
| Cole Brabec | 1 |
| Kfir Sulimany | 1 |
| Kfir Sulimany Solan | 1 |
| Leshem Choshen | 1 |
| Ryan Hamerly | 1 |