SilentWood: Efficient Private Inference Over Gradient-Boosting Decision Forests
Gradient boosting decision forests, used by XGBoost or AdaBoost, offer higher accuracy and lower training times than decision trees on large datasets. Private inference protocols for decision trees can preserve both input and tree privacy. However, naively extending them to decision forests by replication leads to impractical running times. In this paper, we propose an efficient private decision inference protocol using homomorphic encryption. We present several optimizations that identify and remove (approximate) duplication between trees, significantly reducing communication and computation costs over the naive approach. We present the private inference protocol for highly scalable gradient boosting decision forests. Our protocol SilentWood is faster than parallel RCC-PDTE by up to 42.5x, Zama's Concrete ML XGBoost by up to 27.8x, and SoK-GGG's two-party garbled circuit protocol by 2.94x.