ULD-Net: Enabling Ultra-Low-Degree Fully Polynomial Networks for Homomorphically Encrypted Inference
Xi Xie, Ran Ran, Jiahui Zhao, Bin Lei, Zhijie Shi, Wujie Wen, Caiwen Ding
Abstract
Fully polynomial neural networks-models whose computations comprise only additions and multiplications-are attractive for privacy-preserving inference under homomorphic encryption (HE). Yet most prior systems obtain such models by post-hoc replacement of nonlinearities with high-degree or cascaded polynomials, which inflates HE cost and makes training numerically fragile and hard to scale. We introduce ULD-Net, a training methodology that enables ultra-low-degree (multiplicative depth ≤ 3 for each operator) fully polynomial networks to be trained from scratch at ImageNet and transformer scale while maintaining high accuracy. The key is a polynomial-only normalization, PolyNorm, coupled with a principled choice of normalization axis that keeps activations in a wellconditioned range across deep stacks of polynomial layers. Together with a special set of polynomial-aware operator replacements, such as polynomial activation functions and linear attention, ULD-Net delivers stable optimization without resorting to high-degree approximations. Experimental results demonstrate that ULD-Net enables stable training of lowdegree fully polynomial networks on large-scale model architectures and datasets. Applying ULD-Net to ViT-Small and ViT-Base achieves 76.70% and 75.20% top-1 accuracy on ImageNet, respectively, which are comparable to the original models and represent the first fully polynomial models successfully scaled to the ViT/ImageNet level. Additionally, ULD-Net outperforms several state-of-the-art open-source fully and partially polynomial approaches across diverse model architectures and datasets in both accuracy and HE inference latency. The code is available at GitHub † .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b3bd2511-a0ee-4c16-8eb8-3bb0c3eae657Builds on12
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Rethinking Spatial Dimensions of Vision TransformersByeongho Heo, Sangdoo Yun, Dongyoon Han, Sanghyuk Chun et al.ICCV 2021 · 733 citations
- VanillaNet: the Power of Minimalism in Deep LearningHanting Chen, Yunhe Wang, Jianyuan Guo, Dacheng TaoNeurIPS 2023 · 228 citations
- SAFENet: A Secure, Accurate and Fast Neural Network InferenceQian Lou, Yilin Shen, Hongxia Jin, Lei JiangICLR 2021 · 65 citations
- LinGCN: Structural Linearized Graph Convolutional Network for Homomorphically Encrypted InferenceHongwu Peng, Ran Ran, Yukui Luo, Jiahui Zhao et al.NeurIPS 2023 · 57 citations
Related papers
- Converting Transformers to Polynomial Form for Secure Inference Over Homomorphic EncryptionItamar Zimerman, Moran Baruch, Nir Drucker, Gilad Ezov et al.ICML 2024 · 26 citations
- PAPER: Privacy-Preserving Convolutional Neural Networks using Low-Degree Polynomial Approximations and Structural Optimizations on Leveled FHEEduardo Chielle, Manaar Alam, Jinting Liu, Jovan Kascelan et al.CCS 2026
- Low-Rank Adaptation in Multilinear Operator Networks for Security-Preserving Incremental LearningHuu Binh Ta, Duc Nguyen, Quyen Tran, Toan Tran et al.CVPR 2025
- Multilinear Operator NetworksYixin Cheng, Grigorios Chrysos, Markos Georgopoulos, Volkan CevherICLR 2024
- An Enhanced Data Packing Method for General Matrix Multiplication in Brakerski/Fan-Vercauteren SchemeXiangchen Meng, Yan Tan, Zijun Jiang, Yangdi LyuDAC 2025
