Skip to main content

tf-encrypted

Status License PyPI CircleCI Badge Documentation

tf-encrypted is a Python library built on top of TensorFlow for researchers and practitioners to experiment with privacy-preserving machine learning. It provides an interface similar to that of TensorFlow, and aims at making the technology readily available without first becoming an expert in machine learning, cryptography, distributed systems, and high performance computing.

In particular, the library focuses on:

  • Usability: The API and its underlying design philosophy make it easy to get started, use, and integrate privacy-preserving technology into pre-existing machine learning processes.
  • Extensibility: The architecture supports and encourages experimentation and benchmarking of new cryptographic protocols and machine learning algorithms.
  • Performance: Optimizing for tensor-based applications and relying on TensorFlow's backend means runtime performance comparable to that of specialized stand-alone frameworks.
  • Community: With a primary goal of pushing the technology forward the project encourages collaboration and open source over proprietary and closed solutions.
  • Security: Cryptographic protocols are evaluated against strong notions of security and known limitations are highlighted.

See below for more background material or visit the documentation to learn more about how to use the library.

The project has benefitted enormously from the efforts of several contributors following its original implementation, most notably Dropout Labs and members of the OpenMined community. See below for further details.

Installation & Usage

tf-encrypted is available as a package on PyPI supporting Python 3.5+ which can be installed using pip:

$ pip install tf-encrypted

The following is an example of simple matmul on encrypted data using tf-encrypted:

import tensorflow as tf
import tf_encrypted as tfe

def provide_input():
    # local TensorFlow operations can be run locally
    # as part of defining a private input, in this
    # case on the machine of the input provider
    return tf.ones(shape=(5, 10))

# define inputs
w = tfe.define_private_variable(tf.ones(shape=(10,10)))
x = tfe.define_private_input('input-provider', provide_input)

# define computation
y = tfe.matmul(x, w)

with tfe.Session() as sess:
    # initialize variables
    sess.run(tfe.global_variables_initializer())
    # reveal result
    result = sess.run(y.reveal())

For more information, check out our full getting started guide in the documentation.

Background & Further Reading

The following texts provide further in-depth presentations of the project:

Project Status

tf-encrypted is experimental software not currently intended for use in production environments. The focus is on building the underlying primitives and techniques, with some practical security issues post-poned for a later stage. However, care is taken to ensure that none of these represent fundamental issues that cannot be fixed as needed.

Known limitations

  • Elements of TensorFlow's networking subsystem does not appear to be sufficiently hardened against malicious users. Proxies or other means of access filtering may be sufficient to mitigate this.
  • The pseudo-random generators provided in TensorFlow are not cryptographically strong. Custom ops could easily be used to remedy this.

Contributions

Don't hesitate to send a pull request, open an issue, or ask for help!

Several individuals have already had an impact on the development of this library (in alphabetical order):

and several companies have invested significant resources:

  • Dropout Labs continues to sponsor a large amount of both research and engineering
  • OpenMined was the breeding ground for the initial idea and continues to support discussions and guidance

License

Licensed under Apache License, Version 2.0 (see LICENSE or http://www.apache.org/licenses/LICENSE-2.0). Copyright as specified in NOTICE.

Release files for tf-encrypt 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tf-encrypt 0.0.1
File Size Uploaded
tf-encrypt-0.0.1.tar.gz 59.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tf-encrypt 0.0.1
File Interpreter ABI Platform
tf_encrypt-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 950.0 kB

Release files / tf-encrypt-0.0.1.tar.gz

Download URL tf-encrypt-0.0.1.tar.gz
Size 59.1 kB
Tags Source
SHA-256 checksum
How to use checksums
6679c78a603d8be62425c72b6d2085c4e8c0fac22c6d7d75e22c03d4bf082f76
BLAKE2b-256 checksum
How to use checksums
7be24e13ea194adfeaa19b5ee5d62de32d3573eefe89b9e90809870d3946dc3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/39.1.0 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/3.5.6

Release files / tf_encrypt-0.0.1-py3-none-any.whl

Download URL tf_encrypt-0.0.1-py3-none-any.whl
Size 891.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
075fd91c8a26888add8072ef7f197575f4397346e57af00b72e12d40a7efeba6
BLAKE2b-256 checksum
How to use checksums
88cdca6b7c5b8a43dfd792561e1802e8523f97da6de1f294f63ddd3c72a57b44
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.20.1 setuptools/39.1.0 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/3.5.6

Release history Release notifications | RSS feed

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page