Send the Brain, Keep the Body: Hybrid Private Transformer Inference with Minimal Secret Control
Abstract
Hybrid private inference combines the computational strengths of homomorphic encryption (HE) and secure multiparty computation (MPC), but repeatedly converting intermediate states between them incurs substantial communication. Prior work optimizes operator partitioning and evaluation, but still organizes HE–MPC execution around transfers of intermediate states. We observe that the secret decisions involved in nonlinear evaluation can be separated from the high-dimensional numerical state. Based on this observation, we introduce SHRINK, a hybrid Transformer inference architecture with decoupled data and control paths. SHRINK sends MPC only decision-critical information, while HE continues the main computation on retained ciphertexts. MPC generates secret controls that HE applies to existing ciphertexts, enabling continued HE evaluation across nonlinear boundaries. We exploit Transformer structure to design compact control protocols for GELU, attention, and LayerNorm. We further tailor ciphertext representations and feedback to the HE operations that use these controls, and reuse control computations across data blocks, reducing communication and redundant homomorphic computation. On BERT-base and BERT-large, SHRINK reduces communication by 8.4–1048.6 compared with hybrid inference baselines, while maintaining accuracy close to that of plaintext inference without retraining.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.