Testing and Understanding Deviation Behaviors in FHE-Hardened Machine Learning Models
Yiteng Peng, Daoyuan Wu, Zhibo Liu, Dongwei Xiao, Zhenlan Ji, Juergen Rahmel, Shuai Wang
Abstract
Fully homomorphic encryption (FHE) is a promising cryptographic primitive that enables secure computation over encrypted data. A primary use of FHE is to support privacypreserving machine learning (ML) on public cloud infrastructures. Despite the rapid development of FHE-based ML (or HE-ML), the community lacks a systematic understanding of their robustness.
In this paper, we aim to systematically test and understand the deviation behaviors of HE-ML models, where the same input causes deviant outputs between FHE-hardened models and their plaintext versions, leading to completely incorrect model predictions. To effectively uncover deviation-triggering inputs under the constraints of expensive FHE computations, we design a novel differential testing tool called HEDIFF, which leverages the margin metric on the plaintext model as guidance to drive targeted testing on FHE models. For the identified deviation inputs, we further analyze them to determine whether they exhibit general noise patterns that are transferable. We evaluate HEDIFF using three popular HE-ML frameworks, covering 12 different combinations of models and datasets. HEDIFF successfully detected hundreds of deviation inputs across almost every tested FHE framework and model. We also quantitatively show that the identified deviation inputs are (visually) meaningful in comparison to regular inputs. Further schematic analysis reveals the root cause of these deviant inputs and allows us to generalize their noise patterns for more directed testing. Our work sheds light on enabling robust HE-ML for real-world usage.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 943bf0f9-1d4e-4c82-aeae-593bcab983a0Cited by top-tier papers2
- Eidolon: Perform Noise-Aware Fuzzing on FHE Libraries via Equivalence Expression TransformationZhensheng Xian, Zhen Yan, Yuanliang Chen, Xuelian Cao et al.FSE 2026
- The Phantom Menace in Crypto-Based PET-Hardened Deep Learning Models: Invisible Configuration-Induced AttacksYiteng Peng, Dongwei Xiao, Zhibo Liu, Zhenlan Ji et al.CCS 2025
Builds on19
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Detecting Violations of Differential PrivacyZeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang et al.CCS 2018 · 156 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
- A comprehensive study of deep learning compiler bugsQingchao Shen, Haoyang Ma, Junjie Chen, Yongqiang Tian et al.FSE 2021 · 123 citations
Related papers
- MPCDiff: Testing and Repairing MPC-Hardened Deep Learning ModelsQi Pang, Yuanyuan Yuan, Shuai WangNDSS 2024
- FxHENN: FPGA-based acceleration framework for homomorphic encrypted CNN inferenceYilan Zhu, Xinyao Wang, Lei Ju, Shanqing GuoHPCA 2023 · 39 citations
- SoK: Fully Homomorphic Encryption CompilersAlexander Viand, Patrick Jattke, Anwar HithnawiS&P 2021 · 117 citations
- AHEC: End-to-end Compiler Framework for Privacy-preserving Machine Learning AccelerationHuili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni et al.DAC 2020 · 10 citations
- GlitchFHE: Attacking Fully Homomorphic Encryption Using Fault InjectionLakshmi Likhitha Mankali, Mohammed Nabeel, Faiq Raees, Michail Maniatakos et al.USENIX Security 2025
