On the Security of Homomorphic Encryption on Approximate Numbers
Baiyu Li, Daniele Micciancio
Abstract
We present passive attacks against CKKS, the homomorphic encryption scheme for arithmetic on approximate numbers presented at Asiacrypt 2017. The attack is both theoretically efficient (running in expected polynomial time) and very practical, leading to complete key recovery with high probability and very modest running times. We implemented and tested the attack against major open source homomorphic encryption libraries, including HEAAN, SEAL, HElib and PALISADE, and when computing several functions that often arise in applications of the CKKS scheme to machine learning on encrypted data, like mean and variance computations, and approximation of logistic and exponential functions using their Maclaurin series.
The attack shows that the traditional formulation of IND-CPA security (or indistinguishability against chosen plaintext attacks) achieved by CKKS does not adequately capture security against passive adversaries when applied to approximate encryption schemes, and that a different, stronger definition is required to evaluate the security of such schemes.
We provide a solid theoretical basis for the security evaluation of homomorphic encryption on approximate numbers (against passive attacks) by proposing new definitions, that naturally extend the traditional notion of INDCPA security to the approximate computation setting. We propose both indistinguishability-based and simulation-based variants, as well as restricted versions of the definitions that limit the order and number of adversarial queries (as may be enforced by some applications). We prove implications and separations among different definitional variants, and discuss possible modifications to CKKS that may serve as a countermeasure to our attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 92c0efe3-2e67-4dd9-a68c-9ef7a0658a8eCited by top-tier papers21
- PEGASUS: Bridging Polynomial and Non-polynomial Evaluations in Homomorphic EncryptionWen-jie Lu, Zhicong Huang, Cheng Hong, Yiping Ma et al.S&P 2021 · 139 citations
- SoK: Fully Homomorphic Encryption CompilersAlexander Viand, Patrick Jattke, Anwar HithnawiS&P 2021 · 117 citations
- Securing Approximate Homomorphic Encryption Using Differential PrivacyBaiyu Li, Daniele Micciancio, Mark Schultz, Jessica SorrellCRYPTO 2022 · 55 citations
- On the Practical CPAD Security of "exact" and Threshold FHE Schemes and LibrariesMarina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul BultelCRYPTO 2024 · 31 citations
- Key Recovery Attacks on Approximate Homomorphic Encryption with Non-Worst-Case Noise Flooding CountermeasuresQian Guo, Denis Nabokov, Elias Suvanto, Thomas JohanssonUSENIX Security 2024 · 29 citations
Related papers
- Attacks Against the IND-CPAD Security of Exact FHE SchemesJung Hee Cheon, Hyeongmin Choe, Alain Passelègue, Damien Stehlé et al.CCS 2024 · 23 citations
- Efficient Multi-Key Homomorphic Encryption with Packed Ciphertexts with Application to Oblivious Neural Network InferenceHao Chen, Wei Dai, Miran Kim, Yongsoo SongCCS 2019 · 235 citations
- Verifiable Computation for Approximate Homomorphic Encryption SchemesIgnacio Cascudo, Anamaria Costache, Daniele Cozzo, Dario Fiore et al.CRYPTO 2025 · 11 citations
- IND-CPA-D of Relaxed Functional Bootstrapping: A New Attack, A General Fix, and A Stronger ModelZeyu Liu, Yunhao Wang, Ben FischCCS 2025
- Asymptotically Faster Multi-Key Homomorphic Encryption from Homomorphic Gadget DecompositionTaechan Kim, Hyesun Kwak, Dongwon Lee, Jinyeong Seo et al.CCS 2023 · 30 citations
