<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CKKS scheme &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/ckks-scheme/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Tue, 22 Sep 2026 16:07:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>CKKS scheme &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>New survey maps how compilers make encrypted computing usable</title>
		<link>https://scienmag.com/new-survey-maps-how-compilers-make-encrypted-computing-usable/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 16:07:57 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[advancements in homomorphic encryption compiler technology]]></category>
		<category><![CDATA[bootstrapping]]></category>
		<category><![CDATA[challenges in encrypted program development]]></category>
		<category><![CDATA[CKKS scheme]]></category>
		<category><![CDATA[cloud computing privacy]]></category>
		<category><![CDATA[compilers]]></category>
		<category><![CDATA[cryptographic techniques for data privacy]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[encrypted data processing in cloud computing]]></category>
		<category><![CDATA[end-to-end encrypted data analysis]]></category>
		<category><![CDATA[fully homomorphic encryption]]></category>
		<category><![CDATA[fully homomorphic encryption software tools]]></category>
		<category><![CDATA[homomorphic encryption compilers]]></category>
		<category><![CDATA[homomorphic encryption libraries]]></category>
		<category><![CDATA[homomorphic encryption scheme implementations]]></category>
		<category><![CDATA[improving efficiency of encrypted computations]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[parameter selection]]></category>
		<category><![CDATA[program synthesis]]></category>
		<category><![CDATA[scale management]]></category>
		<category><![CDATA[secure data outsourcing in healthcare and finance]]></category>
		<category><![CDATA[SIMD vectorization]]></category>
		<category><![CDATA[software mapping of homomorphic encryption schemes]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=206595</guid>

					<description><![CDATA[A new survey systematically examines the compilers that translate ordinary programs into fully homomorphic encryption code, a technology that enables computing on encrypted data but remains up to 100,000 times slower than plaintext computation.]]></description>
										<content:encoded><![CDATA[<p>Fully homomorphic encryption has long been billed as the holy grail of data privacy: a cryptographic technique that lets a cloud server compute on encrypted data without ever seeing a single plaintext value. Yet for all its promise, actually writing a homomorphic encryption program has remained a punishingly specialized art. A new open-access survey in the journal Cybersecurity, led by Zhuoyu Tian of the Institute of Information Engineering at the Chinese Academy of Sciences together with colleagues from the University of Chinese Academy of Sciences and Ant Research, offers the most detailed map yet of the software tools, known as fully homomorphic encryption compilers, that are trying to change that.</p>
<p>The stakes are enormous. Fully homomorphic encryption enables end-to-end encrypted data processing in untrusted environments, meaning a hospital could outsource genome analysis or a bank could delegate fraud detection to a cloud provider without exposing any sensitive records. Schemes such as BGV, BFV, GSW, CKKS, and TFHE have matured steadily over the past decade, and libraries like HElib, SEAL, HEAAN, Lattigo, OpenFHE, and PALISADE now implement their underlying arithmetic. But even with these libraries, the survey reports, encrypted computations on CPUs run four to five orders of magnitude slower than their plaintext equivalents. Well-optimized programs can be hundreds of times faster than naive ones, which makes efficient programming not a nicety but a necessity.</p>
<p>The difficulty begins with the extremely restricted set of primitive operations. Homomorphic programs can only perform vector element-wise addition, element-wise multiplication, and rotation shifts over long ciphertext vectors containing thousands to tens of thousands of slots. Operations that are trivial on a CPU, such as accessing a single array element or shuffling a vector, can require dozens or even hundreds of rotations and consume precious computational budget. Sophisticated tricks, like the single-input single-output convolution scheme that needs only kernel-squared rotations instead of a naive avalanche of masks and shifts, can improve efficiency by orders of magnitude, but designing such non-intuitive implementations demands years of cryptographic and numerical expertise.</p>
<p>A second layer of complexity comes from ciphertext maintenance. In the CKKS scheme, which the survey focuses on because of its dominance in machine learning workloads, every multiplication roughly squares a ciphertext&#8217;s scaling factor, and Rescale operations must be strategically inserted to keep scales and noise from growing exponentially. Binary operations also impose strict constraints: their operands must sit at the same level and, for additions, share the same scaling factor. Even seemingly obvious strategies backfire. The survey&#8217;s authors walk through a simple computation of x squared plus x to show that the always-rescale approach wastes a level, and a ResNet-style example demonstrates that naively bootstrapping ciphertexts the moment they run out of levels can nullify most of bootstrapping&#8217;s benefit, an operation that alone can consume over 80 percent of total runtime in deep inference workloads.</p>
<p>Parameter selection forms a third minefield. The polynomial degree N, the initial level budget L, and the small-prime bit width B interact in complicated ways that determine correctness, security, and speed simultaneously. The approximate nature of CKKS makes this worse: unlike exact schemes such as BFV and BGV, CKKS decryption always carries error, and bootstrapping merely restores multiplication capacity without cleaning the noise. The survey cites a striking case where a ResNet-20 inference program achieves 89.53 percent accuracy with a prime width of 33 bits but collapses to 10.87 percent, essentially random guessing, when that width drops to 31 bits.</p>
<p>Fully homomorphic encryption compilers attack these problems by translating ordinary programs, whether tensor code resembling PyTorch or plain scalar programs with loops, into optimized ciphertext programs. The survey describes a typical workflow: parse the input into an internal graph representation, optionally rewrite primitive operations, insert scale management and bootstrapping operations, choose evaluation keys and cryptographic parameters, and finally emit source code targeting a backend library or a standalone executable. Crucially, these compilers are device-agnostic, introducing minimal overhead compared with dedicated hardware accelerators, and they often generate code that outperforms expert hand-tuned implementations.</p>
<p>The heart of the survey is a systematic dissection of scale-management techniques. EVA, the first compiler to prioritize this problem, introduced watermark-based rescaling and eager level matching, delivering a 2.3-times average speedup over earlier approaches. Hecate extended that framework with a new Downscale operation and a search procedure driven by a cost model, gaining a further 27.85 percent on average but at the price of compilation times that can stretch to hundreds of seconds. ELASM added a scale-to-noise-ratio concept with noise-aware waterlines, letting users trade accuracy against latency, cutting output error by tens to hundreds of times at equal latency. The newest entrant, Reserve, replaces search with a backward static analysis that nearly matches Hecate&#8217;s performance while compiling in seconds rather than minutes.</p>
<p>Bootstrapping insertion has undergone a parallel revolution. DaCapo uses liveness analysis, bypass edge detection, and dynamic programming to find cost-minimizing insertion points, achieving a 1.21-times speedup over manual implementations on networks up to ResNet-40 and MobileNet. Fhelipe streamlines the same idea with depth boundaries and shortcut edges, and additionally supports hundreds of tensor data layouts, producing an 18.5-times speedup over the earlier layout compiler CHET. HALO specializes in dynamic loops whose trip counts depend on encrypted values, packing loop-carried variables into a single bootstrapped ciphertext and reducing code size by up to 11 times compared with DaCapo. Orion, tailored to private neural inference, models bootstrapping placement as a shortest-path problem on a level digraph, reducing ResNet-20 compilation to under two seconds, an 8.14-times speedup over DaCapo, and trimming inserted bootstraps by 36.2 percent relative to Fhelipe.</p>
<p>For general scalar programs, the survey contrasts synthesis-based and heuristic-based vectorization. Porcupine uses counter-example-guided program synthesis to discover optimal homomorphic kernels, matching or beating expert code with up to 52 percent improvements, but it can only handle roughly a dozen instructions and needed over 609 seconds for a small image filter. Coyote, building on superword-level parallelism, shows why naive vectorization fails when rotations are expensive, yet its own gains remain modest at 0.74 times expert performance. HECO, by contrast, applies a heuristic batching pipeline that transforms imperative code into efficient vectorized form in under a second, delivering three to four orders of magnitude improvement over naive element-by-element translation while scaling to large programs.</p>
<p>The survey closes with a candid assessment of what remains broken. Most compilers still target only the SEAL library, which lacks bootstrapping support and therefore caps program depth; documentation and user experience lag far behind mainstream compiler infrastructure; and parameter selection often relies on crude fixed defaults rather than precise cost models. The authors call for compilers that integrate state-of-the-art homomorphic algorithms, support general-purpose control flow, span multiple schemes from CKKS to TFHE, and even compile across schemes within a single application, an area where only the HEIR project has made an early start. Their conclusion is unambiguous: just as compilers absorbed the manual optimizations of early CPU programming, fully homomorphic encryption compilers are poised to become the primary gateway through which ordinary programmers, not cryptographers, will unlock computation on encrypted data.</p>
<p><strong>Subject of Research:</strong> Compilers for fully homomorphic encryption, the tools that automatically convert ordinary programs into optimized code for computing on encrypted data.</p>
<p><strong>Article Title:</strong> A survey on fully homomorphic encryption compilers</p>
<p><strong>Article References:</strong> Tian, Z., Fan, S., Deng, X., Hou, R., Meng, D., &amp; Zhang, M. (2026). A survey on fully homomorphic encryption compilers. <em>Cybersecurity, 9</em>(1), Article 218. <a href="https://doi.org/10.1186/s42400-026-00641-z" rel="noopener noreferrer">https://doi.org/10.1186/s42400-026-00641-z</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s42400-026-00641-z" rel="noopener noreferrer">10.1186/s42400-026-00641-z</a></p>
<p><strong>Keywords:</strong> fully homomorphic encryption, compilers, CKKS scheme, cryptography, cloud computing privacy, bootstrapping, scale management, SIMD vectorization, machine learning, program synthesis, parameter selection, data privacy</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">206595</post-id>	</item>
		<item>
		<title>Privacy-First AI Detects Fainting Condition Without Exposing Patient Data</title>
		<link>https://scienmag.com/privacy-first-ai-detects-fainting-condition-without-exposing-patient-data/</link>
		
		<dc:creator><![CDATA[Ophelia Keating]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 16:18:51 +0000</pubDate>
				<category><![CDATA[Medicine]]></category>
		<category><![CDATA[AI interpretability in medicine]]></category>
		<category><![CDATA[biomedical engineering]]></category>
		<category><![CDATA[CKKS scheme]]></category>
		<category><![CDATA[differential privacy]]></category>
		<category><![CDATA[differential privacy in healthcare]]></category>
		<category><![CDATA[DP-SGD]]></category>
		<category><![CDATA[electrocardiogram]]></category>
		<category><![CDATA[encrypted medical data analysis]]></category>
		<category><![CDATA[ethical AI in cardiovascular diagnostics]]></category>
		<category><![CDATA[explainable AI]]></category>
		<category><![CDATA[fainting diagnosis using machine learning]]></category>
		<category><![CDATA[head-up tilt test]]></category>
		<category><![CDATA[head-up tilt test analysis with AI]]></category>
		<category><![CDATA[homomorphic encryption]]></category>
		<category><![CDATA[LIME]]></category>
		<category><![CDATA[machine learning pipeline for fainting condition]]></category>
		<category><![CDATA[privacy-first healthcare technology]]></category>
		<category><![CDATA[privacy-preserving AI]]></category>
		<category><![CDATA[secure inference]]></category>
		<category><![CDATA[secure patient data processing]]></category>
		<category><![CDATA[SHAP]]></category>
		<category><![CDATA[transparent AI models for clinical diagnosis]]></category>
		<category><![CDATA[vasovagal syncope]]></category>
		<category><![CDATA[vasovagal syncope detection]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=196251</guid>

					<description><![CDATA[A proof-of-concept study shows that differentially private, explainable AI can detect vasovagal syncope from tilt-test data with minimal accuracy loss, while fully homomorphic encryption for secure inference remains limited by approximation error.]]></description>
										<content:encoded><![CDATA[<p>Vasovagal syncope, the sudden and temporary loss of consciousness caused by a drop in blood pressure and heart rate, affects a large share of the population and often leaves patients waiting years for a clear diagnosis. The gold-standard diagnostic procedure, the head-up tilt test, requires patients to be tilted upright on a table while clinicians monitor how their cardiovascular system responds. Although the test is widely used, its diagnostic sensitivity has remained limited, and hospitals have been slow to embrace artificial intelligence tools that could sharpen interpretation. A new proof-of-concept study suggests a way forward that addresses two of the biggest obstacles to clinical AI at once: protecting patient privacy and making the model&#8217;s reasoning transparent to doctors.</p>
<p>Researchers led by Mahbuba Ferdowsi, Ban-Hoe Kwan, Maw Pin Tan and Choon-Hian Goh, working across Universiti Tunku Abdul Rahman in Malaysia, the University of New South Wales in Australia, Universiti Malaya and Sunway University, have built a machine learning pipeline that trains on sensitive physiological data using differential privacy, produces explanations clinicians can inspect, and even runs its predictions on encrypted data. The work, published in BioMedical Engineering OnLine, analysed records from 137 participants who underwent head-up tilt testing, of whom 54 were classified as vasovagal syncope positive and 83 as negative. From electrocardiogram and blood pressure signals recorded during the tilt protocol, the team extracted 54 features capturing the haemodynamic and autonomic signatures of each patient&#8217;s response.</p>
<p>The privacy guarantee at the heart of the training process comes from differentially private stochastic gradient descent, or DP-SGD. In conventional training, a neural model&#8217;s gradients are computed from each patient example and used to update the model weights, which creates a risk that memorised details of individual patients could be extracted from the finished model. DP-SGD interrupts this leakage path in two ways. First, it clips the gradient computed from every individual example so that no single patient can exert an outsized influence on the weights. Second, it injects calibrated Gaussian noise into the clipped gradients before they are aggregated, obscuring the contribution of any one record. The strength of this protection is formally quantified by a privacy budget, expressed as epsilon and delta. In this study, the model was trained under a privacy budget of approximately epsilon equal to 16.5 with delta set to 10 to the power of minus 5, a setting that provides a mathematically provable bound on how much any single participant&#8217;s information can leak into the model or its outputs.</p>
<p>Crucially, this formal privacy came at a surprisingly modest cost in accuracy. The DP-SGD trained logistic regression model, combined with a feature importance selection step that retained the most informative variables, achieved a cross-validated accuracy of 0.833 plus or minus 0.035 and an area under the receiver operating characteristic curve of 0.888 plus or minus 0.019. The evaluation used a stratified five-fold cross-validation framework in which all pre-processing steps were performed strictly within each training fold, a design choice that prevents subtle data leakage from inflating performance estimates. For comparison, the researchers also trained baseline models including a standard logistic regression, random forest classifiers and artificial neural networks, providing a benchmark for how much predictive power was preserved once the privacy machinery was switched on.</p>
<p>The second, more ambitious layer of the pipeline attempted to hide patient data even at the moment of prediction, using fully homomorphic encryption. This cryptographic technique allows computation directly on encrypted values, meaning a hospital could send an encrypted feature vector to an untrusted server and receive an encrypted diagnosis without the server ever seeing the underlying physiological measurements. The team implemented the Cheon-Kim-Kim-Song scheme, often abbreviated CKKS, using the TenSEAL library, which is designed for arithmetic on approximate real numbers and is well suited to encrypting continuous biomedical features. Because homomorphic encryption supports only addition and multiplication, non-linear activation functions must be approximated by polynomials, and the researchers used a degree-3 polynomial approximation of the sigmoid function to perform encrypted classification.</p>
<p>Here the study delivered an honest and instructive negative result. While the differentially private model performed well, inference carried out entirely under encryption degraded sharply, with the area under the curve falling to roughly 0.53, barely better than a coin flip. The culprit was approximation error: the polynomial surrogate for the sigmoid, combined with the noise inherent in CKKS arithmetic, distorted the decision boundary enough to destroy much of the model&#8217;s discriminative power. The authors are careful to frame this as a feasibility assessment rather than a failure, noting that the encrypted pipeline was applied only at the prediction stage and that optimised homomorphic architectures are a clear direction for future work. The finding matters for the field because it quantifies, in a real clinical setting, the gap between privacy-preserving training and fully secure inference, showing that the former is nearly free in utility terms while the latter remains a genuine engineering challenge.</p>
<p>Interpretability, the third pillar of the framework, was assessed with two widely used explanation techniques, LIME and SHAP, which attribute a model&#8217;s predictions back to individual input features. Both methods converged on the same picture of what the model had learned. Tilt-phase haemodynamic measurements, specifically systolic and diastolic blood pressure recorded during the tilt (SBP_T and DBP_T), together with autonomic balance indices derived from heart rate variability and blood pressure variability in the low-frequency to high-frequency bands (LFHF_RRI_T and LFHF_SBP_T), emerged as the key predictors of a positive vasovagal syncope diagnosis. This alignment is clinically reassuring, because these features correspond to the physiological mechanisms physicians already associate with tilt-induced fainting: an exaggerated drop in vascular tone and a shift in autonomic control when the body is tilted upright.</p>
<p>The study&#8217;s authors are explicit about the limits of what their results demonstrate. All reported performance figures are internal, cross-validated estimates derived from a single-centre dataset of 137 participants, and the team cautions that they should not be read as evidence of generalizable clinical performance. The relatively modest sample size also meant that subgroup analyses were omitted, a decision consistent with the data minimisation principle that underpins the privacy framework itself. External validation on multi-centre cohorts, and independent confirmation that the identified haemodynamic and autonomic features hold across different populations and tilt-test protocols, remain essential next steps before any deployment in a clinical environment.</p>
<p>Even so, the work arrives at a moment when healthcare systems worldwide are wrestling with how to exploit the predictive power of machine learning without breaching patient trust or privacy law. Differential privacy, homomorphic encryption and explainable AI are usually studied in isolation; this study is notable for assembling all three around a concrete diagnostic problem and reporting exactly where each succeeds and where each breaks down. The demonstration that a formally private model can match conventional baselines with minimal utility loss offers a template for other biomedical prediction tasks, from arrhythmia detection to sepsis early warning, where training data are scarce, sensitive and ethically charged.</p>
<p>The research was funded by the UTAR Research Fund from Universiti Tunku Abdul Rahman and received ethics approval from both the UTAR Scientific and Ethical Review Committee and the UMMC Medical Research Ethics Committee, with written informed consent obtained from all participants. As hospitals move toward federated learning and cloud-based clinical AI, studies of this kind provide the empirical grounding needed to decide which privacy technologies are ready for the clinic today and which still require the next generation of cryptographic engineering. For patients whose fainting spells have defied easy diagnosis, the promise is an AI assistant that reads their tilt test accurately, explains its reasoning, and never exposes their data in the process.</p>
<p><strong>Subject of Research:</strong> Privacy-preserving and explainable machine learning for vasovagal syncope detection from head-up tilt test signals</p>
<p><strong>Article Title:</strong> Differentially private and explainable machine learning for vasovagal syncope detection: a feasibility study of homomorphic encryption for secure inference</p>
<p><strong>Article References:</strong> Ferdowsi, M., Kwan, B.-H., Tan, M. P., &amp; Goh, C.-H. (2026). Differentially private and explainable machine learning for vasovagal syncope detection: a feasibility study of homomorphic encryption for secure inference. <em>BioMedical Engineering OnLine</em>. <a href="https://doi.org/10.1186/s12938-026-01626-2" rel="noopener noreferrer">https://doi.org/10.1186/s12938-026-01626-2</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s12938-026-01626-2" rel="noopener noreferrer">10.1186/s12938-026-01626-2</a></p>
<p><strong>Keywords:</strong> vasovagal syncope, head-up tilt test, differential privacy, DP-SGD, homomorphic encryption, CKKS scheme, explainable AI, LIME, SHAP, secure inference, biomedical engineering, electrocardiogram</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">196251</post-id>	</item>
	</channel>
</rss>
