Pith. sign in

REVIEW 4 major objections 6 minor 204 references

Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Perspectives

T0 review · 4 major / 6 minor · reviewed 2026-08-06 · deepseek-v4-flash

Pith's one-line read The paper claims that privacy-preserving machine learning efficiency research can be organized by a three-level taxonomy—protocol, model, system—and that future gains require co-optimizing across all three levels.

desk verdict A useful three-level taxonomy and cross-level framing for PPML optimization, but Table 2's internal inconsistencies undercut the 'meticulous quantitative comparison' claim and need fixing before this can be fully trusted. read the letter →

arxiv 2507.14519 v1 pith:UONNL3CX submitted 2025-07-19 cs.CR cs.AI

classification cs.CRcs.AI
keywords privacy-preservingmachinelearningsecuretwo-partyinferencehomomorphicencryptionoblivioustransfermodel-leveloptimizationHEcompilersGPUaccelerationcross-levelco-optimization
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Privacy-preserving machine learning (PPML) is cryptographically strong but orders of magnitude slower than plaintext inference, and the paper's aim is to bring order to the scattered literature that tries to close that gap. It claims that every optimization belongs to one of three levels—cryptographic protocol, model architecture, or computing system—and that this three-level map is new: earlier surveys covered only some levels or blurred them together. If the map is right, researchers gain a reliable catalog of what has been tried, side-by-side complexity and latency comparisons of representative systems, and a concrete argument that the biggest remaining speedups will come from cross-level co-optimization rather than single-level tricks. A sympathetic reading takes the survey's contribution to be the taxonomy itself plus the roadmap it supports.

What carries the argument

The load-bearing object is the paper's three-level taxonomy (its Figure 2), which partitions PPML optimization into protocol-level work (OT- and HE-based linear layers, non-linear layers, graph-level techniques), model-level work (PPML-friendly linear layers, ReLU/GeLU/Softmax pruning-approximation, quantization), and system-level work (HE compilers, GPU acceleration, libraries). The taxonomy carries the survey's comparisons: Table 2 gives asymptotic complexity of HE encoding schemes for convolution and matrix multiplication, and Figure 9 gives GPU-accelerated latencies for representative workloads. Within the protocol level, a key analytic mechanism is the encoding comparison, where nested encoding leverages the identity that polynomial multiplication in coefficient encoding corresponds to element-wise multiplication in SIMD encoding under the discrete Fourier transform, allowing convolution to run with roughly $O(\sqrt{hwCK/n})$ rotations. This mechanism is what lets the paper claim that no single encoding wins everywhere and that protocol choice must be matched to the computation graph.

What would settle it

Recompute the asymptotic complexities in Table 2 from the original papers; any mismatch—for example, if a cited rotation bound is not $O(\sqrt{d_1 d_2 d_3 / n})$ as stated—would falsify the quantitative comparison. Alternatively, identify a substantial, well-cited body of PPML protocol, model, or system optimization that cannot be placed in any leaf of the Figure 2 taxonomy, which would falsify the comprehensiveness claim.

Watch

Extended reading notes

Core claim

The paper's central claim is that PPML efficiency research splits into protocol-level, model-level, and system-level optimization, and that the field has reached the point where these levels must be co-designed. At the protocol level it reviews OT-based and HE-based protocols for linear and non-linear layers, including three HE encoding families (SIMD, coefficient, and nested) with theoretical complexity comparisons. At the model level it reviews PPML-friendly architectures, pruning and approximation of ReLU, GeLU, and Softmax, and quantization designed for OT or HE. At the system level it reviews HE compilers, GPU acceleration, and open-source libraries. The paper positions itself as the first survey to integrate all three levels in one taxonomy, and it argues that cross-level co-optimization—protocol-aware quantization, protocol-aware compilers, model-aware protocols—is the main open direction.

Load-bearing premise

The survey's value depends on the assumption that its paper selection and classification are complete and faithful: if a significant line of PPML optimization is missing from the taxonomy, or if a cited result is mischaracterized—especially the complexity numbers in Table 2 and the GPU latencies in Figure 9—the comprehensiveness claim loses force.

Editorial extensions

If this is right

  • If the taxonomy is complete, a new PPML optimization can be located in the map and compared against the reported baselines at its level, making Table 2 and Figure 9 the natural starting points for evaluating claims of speedup.
  • If the three-level coupling argument holds, then model-only optimizations such as ReLU pruning or quantization are incomplete without protocol support, because bit-width extension, truncation, and re-quantization can erase the savings.
  • If the encoding analysis holds, then FHE pipeline designers should choose SIMD, coefficient, or nested encoding based on whether consecutive linear layers must be computed without re-encoding, not per-operation in isolation.
  • If the system-level review is right, then HE compilers should treat scale management and bootstrapping placement as one coupled problem, and GPU kernels should be designed with protocol primitives (NTT, key switching, bootstrapping) rather than general ML tensor ops in mind.
  • The paper's roadmap implies that the most promising research direction is integrated cross-level co-optimization, e.g., protocol-aware quantization, protocol-aware compiler passes, and model architectures chosen for the underlying cryptographic primitives.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the three-level map is accurate, one testable meta-prediction follows: as baselines improve, papers that report model-only or system-only optimizations will show shrinking measured gains, because the omitted levels become the bottleneck; a chronological meta-analysis of reported speedups could test this directly.
  • The paper's repeated separation of pre-processing (offline) cost from online cost implies that community-wide reporting of only online latency overstates progress; adopting a standard 'total cost including pre-processing communication' metric would make results comparable across frameworks.
  • The observation that convolution can be fused into bootstrapping's discrete Fourier transform suggests an architecture-level extension the paper only hints at: designing model layer shapes around bootstrapping boundaries so that expensive domain conversions are amortized rather than added.
  • For large language models, the paper's preference for training-free techniques implies that post-training quantization, KV-cache eviction, and sparsity-aware protocols should be prioritized over neural-architecture-search methods that require fine-tuning at LLM scale.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The manuscript is a survey of privacy-preserving machine learning (PPML) with focus on two-party computation (2PC) built from MPC and FHE. It organizes the literature into three levels of optimization: protocol level (linear layers, non-linear layers, computation-graph techniques), model level (PPML-friendly architecture, non-linear approximation, quantization), and system level (compilers, GPU acceleration, open-source libraries). The paper provides a taxonomy (Figure 2), complexity comparisons (Table 2), model-level comparison tables (Tables 3-6), a compiler roadmap, GPU benchmark summary (Figure 9), and a public GitHub repository. Its central claim is to be the first systematic review covering protocol, model, and system levels with a meticulous PPML taxonomy and quantitative comparisons.

Significance. If the taxonomy and quantitative tables are accurate, this would be a useful reference and roadmap for the PPML community. The paper is transparent about its scope (2PC, MPC/FHE), covers a broad corpus, and offers concrete takeaways (e.g., nested encoding for convolution, coefficient-encoding layout inconsistency, protocol-aware compiler design). The level-based organization is pedagogically helpful, and the public GitHub repository is a practical contribution. No equations are derived or fitted, so the risk of circular reasoning is minimal. However, the quantitative centerpiece of the paper (Table 2) contains internal contradictions with the prose, and several citations are misattributed. These issues are locally fixable but currently undermine the 'meticulous quantitative comparison' advertised in the abstract.

major comments (4)
  1. [Section 3.1.2 and Table 2] The Gazelle row in Table 2 reports MatMul complexity as PMults O(d1*d2*d3/n), rotations O(d1*(d2+d3)/n + d3), and ciphertexts O(d1*(d2+d3)/n), whereas Section 3.1.2 states that 'Gazelle requires O(d1*d2*d3/n) rotations and PMults for MatMul.' These two statements cannot both be correct. This discrepancy changes the asymptotic comparison of encoding schemes, which is the advertised contribution of Table 2, and it propagates into statements about subsequent works such as BOLT being state-of-the-art for ct-pt MatMul. Please align the prose and the table, and provide a derivation or a precise source for the formula used.
  2. [Table 2, Iron row] Section 3.1.2 says Iron 'reduces transmitted ciphertexts to sqrt(2*d1*d2*d3/n)', while Table 2 logs O(sqrt(d1*d2*d3/n)). The missing sqrt(2) factor is not asymptotically decisive, but it is a concrete transcription error that casts doubt on the table's precision. More generally, Table 2 provides no derivation or source column, so the reader cannot tell which expression is authoritative. The authors should add derivations or precise references for every entry.
  3. [Section 4.2.3, Table 5, and Table 1] CipherPrune is cited as [84] in Section 4.2.3 ('CihperPrune [84] proposes encrypted token pruning'), but reference [84] is CipherGPT, while Table 5 lists CipherPrune as [200]. Similarly, the Powerformer row in Table 1 cites [202], which is Power-Softmax, whereas the text cites PowerFormer as [149]. These misattributions affect the survey's reliability as a map of the literature and should be corrected systematically.
  4. [Sections 3-5 and Tables 2-6] The paper does not state a paper-selection methodology (search sources, time window, inclusion/exclusion criteria) or a procedure for deriving the complexity expressions in Table 2. Given the title's 'Systematic Review' claim and the abstract's 'meticulous PPML taxonomy', the absence of such methodology makes the comprehensiveness claim difficult to audit. Please add a short methodology subsection and, for each quantitative table entry, either a derivation or a precise pointer to the source result.
minor comments (6)
  1. [Section 2.2.4] 'BFV/GV' should be 'BFV/BGV'.
  2. [Section 3.2.1] 'LLAMA applies FFS-based protocol' should be 'FSS-based protocol'.
  3. [Sections 4.2.3 and 6.3] 'CihperPrune' is a typo for 'CipherPrune', and 'Complicate PPML-aware optimizations' should be 'Complicated PPML-aware optimizations'.
  4. [Table 1 footnote] 'Encoding is unconsistent' should be 'Encoding is inconsistent'.
  5. [Figure 9] The x-axis is labeled 'Latency (Log10)' but no units, numerical values, or per-point source annotations are provided; please include a data table or a link to the underlying measurements so the figure can be checked.
  6. [Section 2.4.1] 'W AN' has an extra space and should read 'WAN'.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper is a bibliographic survey whose claims are comparative and descriptive, not derived from fitted parameters or self-citation chains.

full rationale

This manuscript is a systematic literature review, not a derivation. Its central claim — being the first to systematically review PPML across protocol, model, and system levels with a meticulous taxonomy — is a bibliographic and organizational assertion, supported by comparisons to prior surveys [124, 33, 143] and by the paper's own classification structure. No equation is derived from an input, no parameter is fitted to data, and no quantitative result is 'predicted' from a model built in the paper. The complexity expressions in Table 2 are presented as a synthesis of cited works, and while the table appears internally inconsistent with the prose in Section 3.1.2 regarding Gazelle rotations (Table 2 lists O(d1(d2+d3)/n + d3) rotations while the text states O(d1 d2 d3 / n) rotations) and Iron ciphertexts (a missing sqrt(2) factor), those are correctness and consistency concerns, not circularity. The paper does cite many works by its own authors (e.g., PrivCirNet [186], PrivQuant [187], EQO [196], MPCache [193], FlexHE [191]), but these citations are used as surveyed objects and as pointers to externally checkable results, not as the justification for the survey's framework or for any derived conclusion. There is no self-citation chain that makes a claim true by construction, no ansatz smuggled in via citation, and no known result renamed as a new finding. The non-finding of circularity is therefore the honest and proportionate outcome.

Assumptions & free parameters 0 free parameters · 2 assumptions · 0 invented entities

No quantitative model is proposed; the survey rests on the completeness and accuracy of its literature coverage and on trusting reported results in cited papers.

assumptions (2)
  • domain assumption The selected papers represent the full space of PPML efficiency optimizations.
    No search protocol or inclusion/exclusion criteria are given (Section 1), so the comprehensiveness of the survey rests on this assumption.
  • domain assumption Quantitative values in the comparison tables and figures (e.g., Table 2, Figure 9) faithfully reflect the original papers.
    The survey does not re-run experiments; it transcribes reported costs, so correctness depends on the reliability of the cited sources and the authors' transcription.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Perspectives." pith.science (2026). https://pith.science/paper/UONNL3CX

@misc{pith2026250714519,
  author       = {Pith},
  title        = {Pith review of: Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Perspectives},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/UONNL3CX}},
  note         = {Machine review of arXiv:2507.14519}
}
read the original abstract

Privacy-preserving machine learning (PPML) based on cryptographic protocols has emerged as a promising paradigm to protect user data privacy in cloud-based machine learning services. While it achieves formal privacy protection, PPML often incurs significant efficiency and scalability costs due to orders of magnitude overhead compared to the plaintext counterpart. Therefore, there has been a considerable focus on mitigating the efficiency gap for PPML. In this survey, we provide a comprehensive and systematic review of recent PPML studies with a focus on cross-level optimizations. Specifically, we categorize existing papers into protocol level, model level, and system level, and review progress at each level. We also provide qualitative and quantitative comparisons of existing works with technical insights, based on which we discuss future research directions and highlight the necessity of integrating optimizations across protocol, model, and system levels. We hope this survey can provide an overarching understanding of existing approaches and potentially inspire future breakthroughs in the PPML field. As the field is evolving fast, we also provide a public GitHub repository to continuously track the developments, which is available at https://github.com/PKU-SEC-Lab/Awesome-PPML-Papers.

Figures

Figures reproduced from arXiv: 2507.14519 by the authors.

Figure 1
Figure 1. (a) Overall 2PC inference framework, involving a client and a server. (b) Interactive MPC inference with secret sharing. (c) [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Taxonomy of existing PPML studies, including protocol-level, model-level, and system-level optimizations. [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Basic protocol workflow of (a) OT-based linear layer computation, including a pre-processing stage and an online stage to [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figures from the paper (6 more)
Figure 4
Figure 4. Figure 4: Toy example of (a) MatMul protocol and (b) Conv protocol using SIMD encoding in Gazelle [ [PITH_FULL_IMAGE:figures/full_fig_p010_4.png]
Figure 5
Figure 5. Figure 5: Toy example of (a) MatMul protocol and (b) Conv protocol using coefficient encoding. [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: A timeline of existing model-level PPML optimizations for layer and non-linear layers. Model-level optimization heavily relies [PITH_FULL_IMAGE:figures/full_fig_p017_6.png]
Figure 7
Figure 7. Figure 7: Timeline of HE Compilers. PPML-specific compilers are positioned in the upper region (Classification is based on whether the [PITH_FULL_IMAGE:figures/full_fig_p024_7.png]
Figure 8
Figure 8. Figure 8: Roadmap of CKKS compilers focusing on scale management (SM) and bootstrapping placement (BP) optimizations. For each [PITH_FULL_IMAGE:figures/full_fig_p026_8.png]
Figure 9
Figure 9. Figure 9: Execution time of GPU-accelerated PPML workloads (as defined in Section [PITH_FULL_IMAGE:figures/full_fig_p029_9.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

204 extracted references · 49 canonical work pages

  1. [84]

    Xiaoyang Hou, Jian Liu, Jingyu Li, Yuhan Li, Wen-jie Lu, Cheng Hong, and Kui Ren. 2023. Ciphergpt: Secure two-party gpt inference. Cryptology ePrint Archive (2023)

  2. [200]

    Yancheng Zhang, Jiaqi Xue, Mengxin Zheng, Mimi Xie, Mingzhe Zhang, Lei Jiang, and Qian Lou. 2025. Cipherprune: Efficient and scalable private transformer inference. arXiv preprint arXiv:2502.16782 (2025)

  3. [60]

    Fabian Boemer et al. 2020. MP2ML: A mixed-protocol machine learning framework for private inference. In Proceedings of the 15th International Conference on A vailability, Reliability and Security. 1–10

  4. [202]

    Itamar Zimerman, Allon Adir, Ehud Aharoni, Matan Avitan, Moran Baruch, Nir Drucker, Jenny Lerner, Ramy Masalha, Reut Meiri, and Omri Soceanu. 2024. Power-Softmax: Towards Secure LLM Inference over Encrypted Data. arXiv preprint arXiv:2410.09457 (2024)

  5. [149]

    Dongjin Park, Eunsang Lee, and Joon-Woo Lee. 2025. Powerformer: Efficient privacy-preserving transformer with batch rectifier-power max function and optimized homomorphic attention. ACL (2025)

  6. [1]

    Lattigo v6

    2024. Lattigo v6. Online: https://github.com/tuneinsight/lattigo. EPFL-LDS, Tune Insight SA

  7. [2]

    Nitin Agrawal, Ali Shahin Shamsabadi, Matt J Kusner, and Adrià Gascón. 2019. QUOTIENT: Two-party secure neural network training and prediction. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 1231–1247

  8. [3]

    Ehud Aharoni, Allon Adir, Moran Baruch, Nir Drucker, Gilad Ezov, Ariel Farkash, Lev Greenberg, Ramy Masalha, Guy Moshkowich, Dov Murik, et al. 2020. Helayers: A tile tensors framework for large neural networks on encrypted data. arXiv preprint arXiv:2011.01805 (2020). 32 Wenxuan Zeng et al

Show all 204 references
  1. [4]

    Zama AI. 2024. TFHE-rs: A pure rust implementation of the TFHE scheme for boolean and integer arithmetics over encrypted data. Software available at https://github.com/zama-ai/tfhe-rs (2024)

  2. [5]

    Yoshimasa Akimoto, Kazuto Fukuchi, Youhei Akimoto, and Jun Sakuma. 2023. Privformer: Privacy-preserving transformer with mpc. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) . IEEE, 392–410

  3. [6]

    Ahmad Al Badawi, Jack Bates, Flavio Bergamaschi, David Bruce Cousins, Saroja Erabelli, Nicholas Genise, Shai Halevi, Hamish Hunt, Andrey Kim, Yongwoo Lee, Zeyu Liu, Daniele Micciancio, Ian Quah, Yuriy Polyakov, Saraswathy R.V., Kurt Rohloff, Jonathan Saylor, Dmitriy Suponitsky...

  4. [7]

    Amjad Almusaed, Ibrahim Yitmen, and Asaad Almssad. 2023. Enhancing smart home design with AI models: A case study of living spaces implementation review. Energies 16, 6 (2023), 2636

  5. [8]

    Anthropic. 2025. Claude 4. https://www.anthropic.com/news/claude-4

  6. [9]

    2024.{AutoFHE}: Automated Adaption of{CNNs} for Efficient Evaluation over{FHE}

    Wei Ao and Vishnu Naresh Boddeti. 2024.{AutoFHE}: Automated Adaption of{CNNs} for Efficient Evaluation over{FHE}. In 33rd USENIX Security Symposium (USENIX Security 24) . 2173–2190

  7. [10]

    Youngjin Bae, Jung Hee Cheon, Jaehyung Kim, and Damien Stehlé. 2024. Bootstrapping Bits with CKKS. In Annual International Conference on the Theory and Applications of Cryptographic Techniques . Springer, 94–123

  8. [11]

    Youngjin Bae, Jaehyung Kim, Damien Stehlé, and Elias Suvanto. 2025. Bootstrapping small integers with CKKS. In International Conference on the Theory and Application of Cryptology and Information Security . Springer, 330–360

  9. [12]

    Donald Beaver. 1995. Precomputing oblivious transfer. In Annual International Cryptology Conference. Springer, 97–109

  10. [13]

    Mihir Bellare, Viet Tung Hoang, Sriram Keelveedhi, and Phillip Rogaway. 2013. Efficient garbling from a fixed-key blockcipher. In 2013 IEEE Symposium on Security and Privacy . IEEE, 478–492

  11. [14]

    Adrien Benamira, Tristan Guérand, Thomas Peyrin, and Sayandeep Saha. 2023. TT-TFHE: a torus fully homomorphic encryption-friendly neural network architecture. arXiv preprint arXiv:2302.01584 (2023)

  12. [15]

    Yuchen Bian, Jiaji Huang, Xingyu Cai, Jiahong Yuan, and Kenneth Church. 2021. On attention redundancy: A comprehensive study. In Proceedings of the 2021 conference of the north american chapter of the association for computational linguistics: human language technologies . 930–945

  13. [16]

    Fabian Boemer, Anamaria Costache, Rosario Cammarota, and Casimir Wierzynski. 2019. nGraph-HE2: A high-throughput framework for neural network inference on encrypted data. In Proceedings of the 7th ACM workshop on encrypted computing & applied homomorphic cryptography . 45–56

  14. [17]

    Fabian Boemer, Yixing Lao, Rosario Cammarota, and Casimir Wierzynski. 2019. nGraph-HE: a graph compiler for deep learning on homomorphically encrypted data. In Proceedings of the 16th ACM international conference on computing frontiers . 3–13

  15. [18]

    Jean-Philippe Bossuat, Christian Mouchet, Juan Troncoso-Pastoriza, and Jean-Pierre Hubaux. 2021. Efficient bootstrapping for approximate homomorphic encryption with non-sparse keys. In Annual International Conference on the Theory and Applications of Cryptographic Techniques ....

  16. [19]

    Jean-Philippe Bossuat, Juan Troncoso-Pastoriza, and Jean-Pierre Hubaux. 2022. Bootstrapping for approximate homomorphic encryption with negligible failure-probability by using sparse-secret encapsulation. In International Conference on Applied Cryptography and Network Security...

  17. [20]

    Christina Boura, Nicolas Gama, and Mariya Georgieva. 2018. Chimera: a unified framework for B/FV, TFHE and HEAAN fully homomorphic encryption and predictions for deep learning. IACR Cryptol. ePrint Arch. 2018 (2018), 758

  18. [21]

    Christina Boura, Nicolas Gama, Mariya Georgieva, and Dimitar Jetchev. 2019. Simulating homomorphic evaluation of deep learning predictions. In International Symposium on Cyber Security Cryptography and Machine Learning . Springer, 212–230

  19. [22]

    Florian Bourse, Michele Minelli, Matthias Minihold, and Pascal Paillier. 2018. Fast homomorphic evaluation of deep discretized neural networks. In Advances in Cryptology–CRYPTO 2018: 38th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19–23, 2018, P...

  20. [23]

    Elette Boyle, Geoffroy Couteau, Niv Gilboa, and Yuval Ishai. 2018. Compressing vector OLE. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 896–912

  21. [24]

    Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. 2014. (Leveled) fully homomorphic encryption without bootstrapping.ACM Transactions on Computation Theory (TOCT) 6, 3 (2014), 1–36

  22. [25]

    Lennart Braun, Daniel Demmler, Thomas Schneider, and Oleksandr Tkachenko. 2020. MOTION - A Framework for Mixed-Protocol Multi-Party Computation. Cryptology ePrint Archive, Paper 2020/1137. doi:10.1145/3490390

  23. [26]

    Tom Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared D Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, et al. 2020. Language models are few-shot learners. Advances in neural information processing systems 33 (2020), 1877–1901

  24. [27]

    Megha Byali, Harsh Chaudhari, Arpita Patra, and Ajith Suresh. 2019. FLASH: Fast and robust framework for privacy-preserving machine learning. Cryptology ePrint Archive (2019)

  25. [28]

    Yifei Cai, Qiao Zhang, Rui Ning, Chunsheng Xin, and Hongyi Wu. 2022. Hunter: HE-Friendly Structured Pruning for Efficient Privacy-Preserving Deep Learning (ASIA CCS ’22). Association for Computing Machinery, New York, NY, USA, 931–945. doi:10.1145/3488932.3517401

  26. [29]

    Nishanth Chandran, Divya Gupta, Aseem Rastogi, Rahul Sharma, and Shardul Tripathi. 2019. EzPC: Programmable and efficient secure two-party computation for machine learning. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 496–511. Towards Efficient Pri...

  27. [30]

    Harsh Chaudhari, Rahul Rachuri, and Ajith Suresh. 2019. Trident: Efficient 4pc framework for privacy preserving machine learning. arXiv preprint arXiv:1912.02631 (2019)

  28. [31]

    Dake Chen, Yuke Zhang, Souvik Kundu, Chenghao Li, and Peter A Beerel. 2023. RNA-ViT: Reduced-Dimension Approximate Normalized Attention Vision Transformers for Latency Efficient Private Inference. In 2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD) . IEEE, 1–9

  29. [32]

    Huili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni, and Farinaz Koushanfar. 2020. Ahec: End-to-end compiler framework for privacy-preserving machine learning acceleration. In 2020 57th ACM/IEEE Design Automation Conference (DAC) . IEEE, 1–6

  30. [33]

    Qiguang Chen, Libo Qin, Jinhao Liu, Dengyun Peng, Jiannan Guan, Peng Wang, Mengkang Hu, Yuhang Zhou, Te Gao, and Wanxiang Che. 2025. Towards reasoning era: A survey of long chain-of-thought for reasoning large language models. arXiv preprint arXiv:2503.09567 (2025)

  31. [34]

    Tianyu Chen, Hangbo Bao, Shaohan Huang, Li Dong, Binxing Jiao, Daxin Jiang, Haoyi Zhou, Jianxin Li, and Furu Wei. 2022. The-x: Privacy- preserving transformer inference with homomorphic encryption. arXiv preprint arXiv:2206.00216 (2022)

  32. [35]

    Ke Cheng, Ning Xi, Ximeng Liu, Xinghui Zhu, Haichang Gao, Zhiwei Zhang, and Yulong Shen. 2023. Private Inference for Deep Neural Networks: A Secure, Adaptive, and Efficient Realization. IEEE Trans. Comput. 72, 12 (2023), 3519–3531. doi:10.1109/TC.2023.3305754

  33. [36]

    Jung Hee Cheon, Kyoohyung Han, Andrey Kim, Miran Kim, and Yongsoo Song. 2018. Bootstrapping for approximate homomorphic encryption. In Advances in Cryptology–EUROCRYPT 2018: 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel A ...

  34. [37]

    Jung Hee Cheon, Kyoohyung Han, Andrey Kim, Miran Kim, and Yongsoo Song. 2018. A full RNS variant of approximate homomorphic encryption. In International Conference on Selected Areas in Cryptography . Springer, 347–368

  35. [38]

    Jung Hee Cheon, Andrey Kim, Miran Kim, and Yongsoo Song. 2017. Homomorphic encryption for arithmetic of approximate numbers. InAdvances in Cryptology–ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong,...

  36. [39]

    2024.{DaCapo}: Automatic Bootstrapping Management for Efficient Fully Homomorphic Encryption

    Seonyoung Cheon, Yongwoo Lee, Dongkwan Kim, Ju Min Lee, Sunchul Jung, Taekyung Kim, Dongyoon Lee, and Hanjun Kim. 2024.{DaCapo}: Automatic Bootstrapping Management for Efficient Fully Homomorphic Encryption. In 33rd USENIX Security Symposium (USENIX Security 24) . 6993–7010

  37. [40]

    Seonyoung Cheon, Yongwoo Lee, Hoyun Youm, Dongkwan Kim, Sungwoo Yun, Kunmo Jeong, Dongyoon Lee, and Hanjun Kim. 2025. HALO: Loop- aware Bootstrapping Management for Fully Homomorphic Encryption. In Proceedings of the 30th ACM International Conference on Architectural Support f...

  38. [41]

    Diego Chialva and Ann Dooms. 2018. Conditionals in homomorphic encryption and machine learning applications. arXiv preprint arXiv:1810.12380 (2018)

  39. [42]

    Ilaria Chillotti, Nicolas Gama, Mariya Georgieva, and Malika Izabachène. 2020. TFHE: fast fully homomorphic encryption over the torus. Journal of Cryptology 33, 1 (2020), 34–91

  40. [43]

    Ilaria Chillotti, Marc Joye, and Pascal Paillier. 2021. Programmable bootstrapping enables efficient homomorphic inference of deep neural networks. In Cyber Security Cryptography and Machine Learning: 5th International Symposium, CSCML 2021, Be’er Sheva, Israel, July 8–9, 2021...

  41. [44]

    Minsu Cho, Zahra Ghodsi, Brandon Reagen, Siddharth Garg, and Chinmay Hegde. 2022. Sphynx: A Deep Neural Network Design for Private Inference. IEEE Security & Privacy 20, 5 (Sept. 2022), 22–34. doi:10.1109/msec.2022.3165475

  42. [45]

    Minsu Cho, Ameya Joshi, Brandon Reagen, Siddharth Garg, and Chinmay Hegde. 2022. Selective network linearization for efficient private inference. In International Conference on Machine Learning . PMLR, 3947–3961

  43. [46]

    Geoffroy Couteau and Clément Ducros. 2023. Pseudorandom correlation functions from variable-density LPN, revisited. In IACR International Conference on Public-Key Cryptography . Springer, 221–250

  44. [47]

    Meghan Cowan, Deeksha Dangwal, Armin Alaghi, Caroline Trippel, Vincent T Lee, and Brandon Reagen. 2021. Porcupine: A synthesizing compiler for vectorized homomorphic encryption. In Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and ...

  45. [48]

    CSIRO’s Data61. 2013. Python Paillier Library. https://github.com/data61/python-paillier

  46. [49]

    Roshan Dathathri, Blagovesta Kostova, Olli Saarikivi, Wei Dai, Kim Laine, and Madan Musuvathi. 2020. EVA: An encrypted vector arithmetic language and compiler for efficient homomorphic computation. In Proceedings of the 41st ACM SIGPLAN conference on programming language desig...

  47. [50]

    Roshan Dathathri, Olli Saarikivi, Hao Chen, Kim Laine, Kristin Lauter, Saeed Maleki, Madanlal Musuvathi, and Todd Mytkowicz. 2019. CHET: an optimizing compiler for fully-homomorphic neural-network inferencing. In Proceedings of the 40th ACM SIGPLAN conference on programming la...

  48. [51]

    Leo de Castro, Daniel Escudero, Adya Agrawal, Antigoni Polychroniadou, and Manuela Veloso. [n. d.]. EncryptedLLM: Privacy-Preserving Large Language Model Inference via GPU-Accelerated Fully Homomorphic Encryption. In Forty-second International Conference on Machine Learning

  49. [52]

    Leo de Castro, Antigoni Polychroniadou, and Daniel Escudero. 2024. Privacy-Preserving Large Language Model Inference via GPU-Accelerated Fully Homomorphic Encryption. In Neurips Safe Generative AI Workshop 2024

  50. [53]

    Daniel Demmler, Thomas Schneider, and Michael Zohner. 2015. ABY-A framework for efficient mixed-protocol secure two-party computation.. In NDSS. 34 Wenxuan Zeng et al

  51. [54]

    Naren Dhyani, Jianqiao Mo, Minsu Cho, Ameya Joshi, Siddharth Garg, Brandon Reagen, and Chinmay Hegde. 2023. PriViT: Vision Transformers for Fast Private Inference. arXiv preprint arXiv:2310.04604 (2023)

  52. [55]

    Abdulrahman Diaa, Lucas Fenaux, Thomas Humphries, Marian Dietz, Faezeh Ebrahimianghazani, Bailey Kacsmar, Xinda Li, Nils Lukas, Ra- soul Akhavan Mahdavi, Simon Oya, et al. 2024. Fast and private inference of deep neural networks by co-designing activation functions. In 33rd US...

  53. [56]

    Ye Dong, Wen-jie Lu, Yancheng Zheng, Haoqi Wu, Derun Zhao, Jin Tan, Zhicong Huang, Cheng Hong, Tao Wei, and Wenguang Chen. 2023. Puma: Secure inference of llama-7b in five minutes. arXiv preprint arXiv:2307.12533 (2023)

  54. [57]

    Zhen Dong, Zhewei Yao, Amir Gholami, Michael W Mahoney, and Kurt Keutzer. 2019. Hawq: Hessian aware quantization of neural networks with mixed-precision. In Proceedings of the IEEE/CVF international conference on computer vision . 293–302

  55. [58]

    Alexey Dosovitskiy. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)

  56. [59]

    Austin Ebel, Karthik Garimella, and Brandon Reagen. 2023. Orion: A Fully Homomorphic Encryption Compiler for Private Deep Neural Network Inference. arXiv preprint arXiv:2311.03470 (2023)

  57. [61]

    Guang Fan, Mingzhe Zhang, Fangyu Zheng, Shengyu Fan, Tian Zhou, Xianglong Deng, Wenxu Tang, Liang Kong, Yixuan Song, and Shoumeng Yan. 2025. WarpDrive: GPU-Based Fully Homomorphic Encryption Acceleration Leveraging Tensor and CUDA Cores. In 2025 IEEE International Symposium on...

  58. [62]

    Guang Fan, Fangyu Zheng, Lipeng Wan, Lili Gao, Yuan Zhao, Jiankuo Dong, Yixuan Song, Yuewu Wang, and Jingqiang Lin. 2023. Towards faster fully homomorphic encryption implementation with integer and floating-point computing power of GPUs. In 2023 IEEE International Parallel and...

  59. [63]

    Junfeng Fan and Frederik Vercauteren. 2012. Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive (2012)

  60. [64]

    Shengyu Fan, Zhiwei Wang, Weizhi Xu, Rui Hou, Dan Meng, and Mingzhe Zhang. 2023. Tensorfhe: Achieving practical computation on encrypted data using gpgpu. In 2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA) . IEEE, 922–934

  61. [65]

    Lars Folkerts, Charles Gouert, and Nektarios Georgios Tsoutsos. 2021. REDsec: Running encrypted discretized neural networks in seconds. Cryptology ePrint Archive (2021)

  62. [66]

    Jordan Frery, Andrei Stoian, Roman Bredehoft, Luis Montero, Celia Kherfallah, Benoit Chevallier-Mames, and Arthur Meyre. 2023. Privacy- preserving tree-based inference with fully homomorphic encryption. Cryptology ePrint Archive (2023)

  63. [67]

    Vinod Ganesan, Anwesh Bhattacharya, Pratyush Kumar, Divya Gupta, Rahul Sharma, and Nishanth Chandran. 2022. Efficient ml models for practical secure inference. arXiv preprint arXiv:2209.00411 (2022)

  64. [68]

    Xian Gao, Peixiong He, Yi Zhou, and Xiao Qin. 2024. Artificial Intelligence Applications in Smart Healthcare: A Survey. Future Internet 16, 9 (2024), 308

  65. [69]

    Juan Garay, Berry Schoenmakers, and José Villegas. 2007. Practical and secure solutions for integer comparison. In Public Key Cryptography–PKC 2007: 10th International Conference on Practice and Theory in Public-Key Cryptography Beijing, China, April 16-20, 2007. Proceedings 1...

  66. [70]

    Zahra Ghodsi, Nandan Kumar Jha, Brandon Reagen, and Siddharth Garg. 2021. Circa: Stochastic relus for private deep learning. Advances in Neural Information Processing Systems 34 (2021), 2241–2252

  67. [71]

    Zahra Ghodsi, Akshaj Kumar Veldanda, Brandon Reagen, and Siddharth Garg. 2020. Cryptonas: Private inference on a relu budget. Advances in Neural Information Processing Systems 33 (2020), 16961–16971

  68. [72]

    Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In International conference on machine learning . PMLR, 201–210

  69. [73]

    Yakir Gorski, Amir Jevnisek, and Shai Avidan. 2023. Securing Neural Networks with Knapsack Optimization. arXiv preprint arXiv:2304.10442 (2023)

  70. [74]

    Daya Guo, Dejian Yang, Haowei Zhang, Junxiao Song, Ruoyu Zhang, Runxin Xu, Qihao Zhu, Shirong Ma, Peiyi Wang, Xiao Bi, et al . 2025. Deepseek-r1: Incentivizing reasoning capability in llms via reinforcement learning. arXiv preprint arXiv:2501.12948 (2025)

  71. [75]

    Meng-Hao Guo, Zheng-Ning Liu, Tai-Jiang Mu, and Shi-Min Hu. 2022. Beyond self-attention: External attention using two linear layers for visual tasks. IEEE Transactions on Pattern Analysis and Machine Intelligence 45, 5 (2022), 5436–5447

  72. [76]

    Kanav Gupta, Neha Jawalkar, Ananta Mukherjee, Nishanth Chandran, Divya Gupta, Ashish Panwar, and Rahul Sharma. 2023. Sigma: Secure gpt inference with function secret sharing. Cryptology ePrint Archive (2023)

  73. [77]

    Kanav Gupta, Deepak Kumaraswamy, Nishanth Chandran, and Divya Gupta. 2022. Llama: A low latency math library for secure inference. Cryptology ePrint Archive (2022)

  74. [78]

    Shai Halevi and Victor Shoup. 2020. Design and implementation of HElib: a homomorphic encryption library. Cryptology ePrint Archive, Paper 2020/1481. https://eprint.iacr.org/2020/1481

  75. [79]

    Kyoohyung Han, Seungwan Hong, Jung Hee Cheon, and Daejun Park. 2019. Logistic regression on homomorphic encrypted data at scale. In Proceedings of the AAAI conference on artificial intelligence , Vol. 33. 9466–9471

  76. [80]

    Kyoohyung Han and Dohyeong Ki. 2020. Better bootstrapping for approximate homomorphic encryption. In Cryptographers’ Track at the RSA Conference. Springer, 364–390. Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Pers...

  77. [81]

    Meng Hao, Hongwei Li, Hanxiao Chen, Pengzhi Xing, Guowen Xu, and Tianwei Zhang. 2022. Iron: Private inference on transformers. Advances in neural information processing systems 35 (2022), 15718–15731

  78. [82]

    Jiaxing He, Kang Yang, Guofeng Tang, Zhangjie Huang, Li Lin, Changzheng Wei, Ying Yan, and Wei Wang. 2024. Rhombus: Fast Homomorphic Matrix-Vector Multiplication for Secure Two-Party Inference. InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications S...

  79. [83]

    Ming-Chien Ho, Yu-Te Ku, Yu Xiao, Feng-Hao Liu, Chih-Fan Hsu, Ming-Ching Chang, Shih-Hao Hung, and Wei-Chao Chen. 2024. Efficient Design of FHEW/TFHE Bootstrapping Implementation with Scalable Parameters. In Proceedings of the 43rd IEEE/ACM International Conference on Computer...

  80. [85]

    Jie Huang and Kevin Chen-Chuan Chang. 2022. Towards reasoning in large language models: A survey. arXiv preprint arXiv:2212.10403 (2022)

  81. [86]

    Zhicong Huang, Wen-jie Lu, Cheng Hong, and Jiansheng Ding. 2022. Cheetah: Lean and fast secure{Two-Party} deep neural network inference. In 31st USENIX Security Symposium (USENIX Security 22) . 809–826

  82. [87]

    Siam Umar Hussain, Mojan Javaheripi, Mohammad Samragh, and Farinaz Koushanfar. 2021. Coinn: Crypto/ml codesign for oblivious inference via neural networks. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 3266–3281

  83. [88]

    Alberto Ibarrondo and Alexander Viand. 2021. Pyfhel: Python for homomorphic encryption libraries. In Proceedings of the 9th on Workshop on Encrypted Computing & Applied Homomorphic Cryptography . 11–16

  84. [89]

    Yuval Ishai, Joe Kilian, Kobbi Nissim, and Erez Petrank. 2003. Extending oblivious transfers efficiently. InAnnual International Cryptology Conference. Springer, 145–161

  85. [90]

    Neha Jawalkar, Kanav Gupta, Arkaprava Basu, Nishanth Chandran, Divya Gupta, and Rahul Sharma. 2024. Orca: Fss-based secure training and inference with gpus. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE, 597–616

  86. [91]

    Nandan Kumar Jha, Zahra Ghodsi, Siddharth Garg, and Brandon Reagen. 2021. Deepreduce: Relu reduction for fast private inference. InInternational Conference on Machine Learning . PMLR, 4839–4849

  87. [92]

    Nandan Kumar Jha and Brandon Reagen. 2024. AERO: Softmax-Only LLMs for Efficient Private Inference. arXiv preprint arXiv:2410.13060 (2024)

  88. [93]

    Nandan Kumar Jha and Brandon Reagen. 2024. DeepReShape: Redesigning Neural Networks for Efficient Private Inference. arXiv:2304.10593 [cs.CR] https://arxiv.org/abs/2304.10593

  89. [94]

    Xiaoqian Jiang, Miran Kim, Kristin Lauter, and Yongsoo Song. 2018. Secure outsourced matrix computation and application to neural networks. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security . 1209–1222

  90. [95]

    Dian Jiao, Xianglong Deng, Zhiwei Wang, Shengyu Fan, Yi Chen, Dan Meng, Rui Hou, and Mingzhe Zhang. 2025. Neo: Towards Efficient Fully Homomorphic Encryption Acceleration using Tensor Core. In Proceedings of the 52nd ACM/IEEE International Symposium on Computer Architecture (I...

  91. [96]

    Jae Hyung Ju, Jaiyoung Park, Jongmin Kim, Minsik Kang, Donghwan Kim, Jung Hee Cheon, and Jung Ho Ahn. 2024. NeuJeans: Private Neural Network Inference with Joint Optimization of Convolution and FHE Bootstrapping. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer ...

  92. [97]

    Wonkyung Jung, Sangpyo Kim, Jung Ho Ahn, Jung Hee Cheon, and Younho Lee. 2021. Over 100x faster bootstrapping in fully homomorphic encryption through memory-centric optimization with GPUs. IACR Transactions on Cryptographic Hardware and Embedded Systems (2021), 114–148

  93. [98]

    2018.{GAZELLE}: A low latency framework for secure neural network inference

    Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018.{GAZELLE}: A low latency framework for secure neural network inference. In 27th USENIX security symposium (USENIX security 18) . 1651–1669

  94. [99]

    Marcel Keller. 2020. MP-SPDZ: A Versatile Framework for Multi-Party Computation. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security . doi:10.1145/3372297.3417872

  95. [100]

    Marcel Keller and Ke Sun. 2022. Secure quantized training for deep learning. In International Conference on Machine Learning . PMLR, 10912–10938

  96. [101]

    Andrey Kim, Antonis Papadimitriou, and Yuriy Polyakov. 2022. Approximate homomorphic encryption with reduced approximation error. In Cryptographers’ Track at the RSA Conference . Springer, 120–144

  97. [102]

    Dongwoo Kim and Cyril Guyot. 2023. Optimized privacy-preserving cnn inference with fully homomorphic encryption. IEEE Transactions on Information Forensics and Security 18 (2023), 2175–2187

  98. [103]

    Jongmin Kim, Wonseok Choi, and Jung Ho Ahn. 2024. Cheddar: A swift fully homomorphic encryption library for cuda gpus. arXiv preprint arXiv:2407.13055 (2024)

  99. [104]

    Jongmin Kim, Sungmin Yun, Hyesung Ji, Wonseok Choi, Sangpyo Kim, and Jung Ho Ahn. 2025. Anaheim: Architecture and Algorithms for Processing Fully Homomorphic Encryption in Memory. In 2025 IEEE International Symposium on High Performance Computer Architecture (HPCA) . IEEE, 1158–1173

  100. [105]

    Miran Kim, Xiaoqian Jiang, Kristin Lauter, Elkhan Ismayilzada, and Shayan Shams. 2022. Secure human action recognition by encrypted neural network inference. Nature communications 13, 1 (2022), 4799

  101. [106]

    Miran Kim, Dongwon Lee, Jinyeong Seo, and Yongsoo Song. 2023. Accelerating HE operations from key decomposition technique. In Annual International Cryptology Conference. Springer, 70–92. 36 Wenxuan Zeng et al

  102. [107]

    Brian Knott, Shobha Venkataraman, Awni Hannun, Shubho Sengupta, Mark Ibrahim, and Laurens van der Maaten. 2021. Crypten: Secure multi-party computation meets machine learning. Advances in Neural Information Processing Systems 34 (2021), 4961–4973

  103. [108]

    2021.{SWIFT}: Super-fast and robust{Privacy-Preserving} machine learning

    Nishat Koti, Mahak Pancholi, Arpita Patra, and Ajith Suresh. 2021.{SWIFT}: Super-fast and robust{Privacy-Preserving} machine learning. In 30th USENIX Security Symposium (USENIX Security 21) . 2651–2668

  104. [109]

    Nishat Koti, Arpita Patra, Rahul Rachuri, and Ajith Suresh. 2021. Tetrad: Actively secure 4pc for secure training and inference. arXiv preprint arXiv:2106.02850 (2021)

  105. [110]

    Aleksandar Krastev, Nikola Samardzic, Simon Langowski, Srinivas Devadas, and Daniel Sanchez. 2024. A tensor compiler with automatic data packing for simple and efficient fully homomorphic encryption. Proceedings of the ACM on Programming Languages 8, PLDI (2024), 126–150

  106. [111]

    Souvik Kundu, Shunlin Lu, Yuke Zhang, Jacqueline Liu, and Peter A Beerel. 2023. Learning to linearize deep neural networks for secure and efficient private inference. arXiv preprint arXiv:2301.09254 (2023)

  107. [112]

    Eunsang Lee, Joon-Woo Lee, Young-Sik Kim, and Jong-Seon No. 2022. Optimization of homomorphic comparison algorithm on rns-ckks scheme. IEEE Access 10 (2022), 26163–26176

  108. [113]

    Eunsang Lee, Joon-Woo Lee, Junghyun Lee, Young-Sik Kim, Yongjune Kim, Jong-Seon No, and Woosuk Choi. 2022. Low-complexity deep convolutional neural networks on fully homomorphic encryption using multiplexed parallel convolutions. In International Conference on Machine Learning...

  109. [114]

    Eunsang Lee, Joon-Woo Lee, Jong-Seon No, and Young-Sik Kim. 2021. Minimax approximation of sign function by composite polynomial for homomorphic comparison. IEEE Transactions on Dependable and Secure Computing 19, 6 (2021), 3711–3727

  110. [115]

    Junghyun Lee, Eunsang Lee, Young-Sik Kim, Yongwoo Lee, Joon-Woo Lee, Yongjune Kim, and Jong-Seon No. 2023. Optimizing layerwise polynomial approximation for efficient private inference on fully homomorphic encryption: a dynamic programming approach. arXiv preprint arXiv:2310.1...

  111. [116]

    Joon-Woo Lee, HyungChul Kang, Yongwoo Lee, Woosuk Choi, Jieun Eom, Maxim Deryabin, Eunsang Lee, Junghyun Lee, Donghoon Yoo, Young-Sik Kim, et al. 2022. Privacy-preserving machine learning with fully homomorphic encryption for deep neural network. iEEE Access 10 (2022), 30039–30054

  112. [117]

    2023.{ELASM}:{Error-Latency-Aware} Scale Management for Fully Homomorphic Encryption

    Yongwoo Lee, Seonyoung Cheon, Dongkwan Kim, Dongyoon Lee, and Hanjun Kim. 2023.{ELASM}:{Error-Latency-Aware} Scale Management for Fully Homomorphic Encryption. In 32nd USENIX Security Symposium (USENIX Security 23) . 4697–4714

  113. [118]

    Yongwoo Lee, Seonyeong Heo, Seonyoung Cheon, Shinnung Jeong, Changsu Kim, Eunkyung Kim, Dongyoon Lee, and Hanjun Kim. 2022. HECATE: Performance-aware scale optimization for homomorphic encryption compiler. In 2022 IEEE/ACM International Symposium on Code Generation and Optimiz...

  114. [119]

    Bo-hu Li, Bao-cun Hou, Wen-tao Yu, Xiao-bing Lu, and Chun-wei Yang. 2017. Applications of artificial intelligence in intelligent manufacturing: a review. Frontiers of Information Technology & Electronic Engineering 18, 1 (2017), 86–96

  115. [120]

    Dacheng Li, Rulin Shao, Hongyi Wang, Han Guo, Eric P Xing, and Hao Zhang. 2022. Mpcformer: fast, performant and private transformer inference with mpc. arXiv preprint arXiv:2211.01452 (2022)

  116. [121]

    Fabing Li, Yuanhao Zhai, Shuangyu Cai, and Mingyu Gao. [n. d.]. Seesaw: Compensating for Nonlinear Reduction with Linear Computations for Private Inference. In Forty-first International Conference on Machine Learning

  117. [122]

    Long Li, Jianxin Lai, Peng Yuan, Tianxiang Sui, Yan Liu, Qing Zhu, Xiaojing Zhang, Linjie Xiao, Wenguang Chen, and Jingling Xue. 2025. ANT-ACE: An FHE Compiler Framework for Automating Neural Network Inference. In Proceedings of the 23rd ACM/IEEE International Symposium on Cod...

  118. [123]

    Qirui Li and Rui Zong. 2025. CAT: A GPU-Accelerated FHE Framework with Its Application to High-Precision Private Dataset Query. arXiv preprint arXiv:2503.22227 (2025)

  119. [124]

    Yang Li, Xinyu Zhou, Yitong Wang, Liangxin Qian, and Jun Zhao. 2024. A Survey on Private Transformer Inference.arXiv preprint arXiv:2412.08145 (2024)

  120. [125]

    Chenqi Lin, Tianshi Xu, Zebin Yang, Runsheng Wang, Ru Huang, and Meng Li. 2024. FastQuery: Communication-efficient Embedding Table Query for Private LLMs inference. In Proceedings of the 61st ACM/IEEE Design Automation Conference . 1–6

  121. [126]

    Aixin Liu, Bei Feng, Bing Xue, Bingxuan Wang, Bochao Wu, Chengda Lu, Chenggang Zhao, Chengqi Deng, Chenyu Zhang, Chong Ruan, et al

  122. [127]

    Jian Liu, Mika Juuti, Yao Lu, and Nadarajah Asokan. 2017. Oblivious neural network predictions via minionn transformations. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security . 619–631

  123. [128]

    Siqi Liu, Zhusen Liu, Donglong Chen, Wangchen Dai, Lu Zhou, Zhe Liu, Ray CC Cheung, and Çetin Kaya Koç. 2025. MLFormer: a high performance MPC linear inference framework for transformers. Journal of Cryptographic Engineering 15, 1 (2025), 2

  124. [129]

    Xuanqi Liu and Zhuotao Liu. 2023. Llms can understand encrypted prompt: Towards privacy-computing friendly transformers. arXiv preprint arXiv:2305.18396 (2023)

  125. [130]

    Yan Liu, Jianxin Lai, Long Li, Tianxiang Sui, Linjie Xiao, Peng Yuan, Xiaojing Zhang, Qing Zhu, Wenguang Chen, and Jingling Xue. 2025. ReSBM: Region-based Scale and Minimal-Level Bootstrapping Management for FHE via Min-Cut. In Proceedings of the 30th ACM International Confere...

  126. [131]

    Yanxin Liu and Qianqian Su. 2024. PPTIF: Privacy-Preserving Transformer Inference Framework for Language Translation. IEEE Access (2024). Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and System Perspectives 37

  127. [132]

    Zeyu Liu and Yunhao Wang. 2023. Amortized functional bootstrapping in less than 7 ms, with O˜(1) polynomial multiplications. In International Conference on the Theory and Application of Cryptology and Information Security . Springer, 101–132

  128. [133]

    Zeyu Liu and Yunhao Wang. 2025. Relaxed functional bootstrapping: A new perspective on BGV/BFV bootstrapping. In International Conference on the Theory and Application of Cryptology and Information Security . Springer, 208–240

  129. [134]

    Qian Lou, Yilin Shen, Hongxia Jin, and Lei Jiang. 2021. Safenet: A secure, accurate and fast neural network inference. In International Conference on Learning Representations

  130. [135]

    Wen-jie Lu, Zhicong Huang, Zhen Gu, Jingyu Li, Jian Liu, Cheng Hong, Kui Ren, Tao Wei, and WenGuang Chen. 2023. Bumblebee: Secure two-party inference framework for large transformers. Cryptology ePrint Archive (2023)

  131. [136]

    Jinglong Luo, Yehong Zhang, Zhuo Zhang, Jiaqi Zhang, Xin Mu, Hui Wang, Yue Yu, and Zenglin Xu. 2024. SecFormer: Fast and Accurate Privacy- Preserving Inference for Transformer Models via SMPC. In Findings of the Association for Computational Linguistics ACL 2024 . 13333–13348

  132. [137]

    Yukui Luo, Nuo Xu, Hongwu Peng, Chenghong Wang, Shijin Duan, Kaleel Mahmood, Wujie Wen, Caiwen Ding, and Xiaolin Xu. 2023. Aq2pnn: Enabling two-party privacy-preserving deep neural network inference with adaptive quantization. In Proceedings of the 56th Annual IEEE/ACM Interna...

  133. [138]

    Junming Ma, Yancheng Zheng, Jun Feng, Derun Zhao, Haoqi Wu, Wenjing Fang, Jin Tan, Chaofan Yu, Benyu Zhang, and Lei Wang. 2023. {SecretFlow-SPU}: A Performant and{User-Friendly} Framework for{Privacy-Preserving} Machine Learning. In 2023 USENIX Annual Technical Conference (USE...

  134. [139]

    Raghav Malik, Kabir Sheth, and Milind Kulkarni. 2023. Coyote: A compiler for vectorizing encrypted arithmetic circuits. In Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 3 . 118–133

  135. [140]

    Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca Ada Popa. 2020. Delphi: A cryptographic inference system for neural networks. In Proceedings of the 2020 Workshop on Privacy-Preserving Machine Learning in Practice . 27–30

  136. [141]

    Payman Mohassel and Peter Rindal. 2018. ABY3: A mixed protocol framework for machine learning. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security . 35–52

  137. [142]

    Payman Mohassel and Yupeng Zhang. 2017. Secureml: A system for scalable privacy-preserving machine learning. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 19–38

  138. [143]

    Lucien KL Ng and Sherman SM Chow. 2023. Sok: Cryptographic neural-network computation. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE, 497–514

  139. [144]

    Isaac Kofi Nti, Adebayo Felix Adekoya, Benjamin Asubam Weyori, and Owusu Nyarko-Boateng. 2022. Applications of artificial intelligence in engineering and manufacturing: a systematic review. Journal of Intelligent Manufacturing 33, 6 (2022), 1581–1601

  140. [145]

    OpenAI. 2022. ChatGPT. https://openai.com/blog/chatgpt

  141. [146]

    Ali Şah Özcan, Can Ayduman, Enes Recep Türkoğlu, and Erkay Savaş. 2023. Homomorphic encryption on GPU.IEEE Access 11 (2023), 84168–84186

  142. [147]

    Marie Paindavoine and Bastien Vialla. 2015. Minimizing the number of bootstrappings in fully homomorphic encryption. InInternational Conference on Selected Areas in Cryptography . Springer, 25–43

  143. [148]

    Qi Pang, Jinhao Zhu, Helen Möllering, Wenting Zheng, and Thomas Schneider. 2024. Bolt: Privacy-preserving, accurate and efficient inference for transformers. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE, 4753–4771

  144. [150]

    Jaiyoung Park, Donghwan Kim, Jongmin Kim, Sangpyo Kim, Wonkyung Jung, Jung Hee Cheon, and Jung Ho Ahn. 2023. Toward practical privacy-preserving convolutional neural networks exploiting fully homomorphic encryption. arXiv preprint arXiv:2310.16530 (2023)

  145. [151]

    Jaiyoung Park, Michael Jaemin Kim, Wonkyung Jung, and Jung Ho Ahn. 2022. AESPA: Accuracy preserving low-degree polynomial activation for fast private inference. arXiv preprint arXiv:2201.06699 (2022)

  146. [152]

    Hongwu Peng, Shaoyi Huang, Tong Zhou, Yukui Luo, Chenghong Wang, Zigeng Wang, Jiahui Zhao, Xi Xie, Ang Li, Tony Geng, et al . 2023. Autorep: Automatic relu replacement for fast private network inference. In Proceedings of the IEEE/CVF International Conference on Computer Visio...

  147. [153]

    Hongwu Peng, Shanglin Zhou, Yukui Luo, Nuo Xu, Shijin Duan, Ran Ran, Jiahui Zhao, Shaoyi Huang, Xi Xie, Chenghong Wang, Tong Geng, Wujie Wen, Xiaolin Xu, and Caiwen Ding. 2023. RRNet: Towards ReLU-Reduced Neural Network for Two-party Computation Based Private Inference. arXiv:...

  148. [154]

    Hongwu Peng, Shanglin Zhou, Yukui Luo, Nuo Xu, Shijin Duan, Ran Ran, Jiahui Zhao, Chenghong Wang, Tong Geng, Wujie Wen, et al. 2023. PASNet: polynomial architecture search framework for two-party computation-based secure neural network deployment. In 2023 60th ACM/IEEE Design ...

  149. [155]

    Robert Podschwadt and Daniel Takabi. 2020. Classification of Encrypted Word Embeddings using Recurrent Neural Networks.. In PrivateNLP@ WSDM. 27–31

  150. [156]

    Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al. 2019. Language models are unsupervised multitask learners. OpenAI blog 1, 8 (2019), 9

  151. [157]

    Deevashwer Rathee, Anwesh Bhattacharya, Rahul Sharma, Divya Gupta, Nishanth Chandran, and Aseem Rastogi. 2022. Secfloat: Accurate floating-point meets secure 2-party computation. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 576–595. 38 Wenxuan Zeng et al

  152. [158]

    Deevashwer Rathee, Dacheng Li, Ion Stoica, Hao Zhang, and Raluca Popa. 2024. MPC-Minimized Secure LLM Inference. arXiv preprint arXiv:2408.03561 (2024)

  153. [159]

    Deevashwer Rathee, Mayank Rathee, Rahul Kranti Kiran Goli, Divya Gupta, Rahul Sharma, Nishanth Chandran, and Aseem Rastogi. 2021. Sirnn: A math library for secure rnn inference. In 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 1003–1020

  154. [160]

    Deevashwer Rathee, Mayank Rathee, Nishant Kumar, Nishanth Chandran, Divya Gupta, Aseem Rastogi, and Rahul Sharma. 2020. Cryptflow2: Practical 2-party secure inference. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security . 325–342

  155. [161]

    2019.{XONN}:{XNOR-based} oblivious deep neural network inference

    M Sadegh Riazi, Mohammad Samragh, Hao Chen, Kim Laine, Kristin Lauter, and Farinaz Koushanfar. 2019.{XONN}:{XNOR-based} oblivious deep neural network inference. In 28th USENIX Security Symposium (USENIX Security 19) . 1501–1518

  156. [162]

    Lorenzo Rovida and Alberto Leporati. 2024. Encrypted image classification with low memory footprint using fully homomorphic encryption. Cryptology ePrint Archive (2024)

  157. [163]

    Microsoft SEAL (release 4.1)

    SEAL 2023. Microsoft SEAL (release 4.1). https://github.com/Microsoft/SEAL. Microsoft Research, Redmond, WA

  158. [164]

    Ebrahimzadeh, Felix Hui, and Lu Aye

    Samad Sepasgozar, Reyhaneh Karimi, Leila Farahzadi, Farimah Moezzi, Sara Shirowzhan, Sanee M. Ebrahimzadeh, Felix Hui, and Lu Aye. 2020. A systematic content review of artificial intelligence and the internet of things applications in smart home. Applied Sciences 10, 9 (2020), 3074

  159. [165]

    Liyan Shen, Ye Dong, Binxing Fang, Jinqiao Shi, Xuebin Wang, Shengli Pan, and Ruisheng Shi. 2022. ABNN2: secure two-party arbitrary-bitwidth quantized neural network predictions. In Proceedings of the 59th ACM/IEEE Design Automation Conference . 361–366

  160. [166]

    Shiyu Shen, Hao Yang, Yu Liu, Zhe Liu, and Yunlei Zhao. 2022. CARM: CUDA-accelerated RNS multiplication in word-wise homomorphic encryption schemes for internet of things. IEEE Trans. Comput. 72, 7 (2022), 1999–2010

  161. [167]

    Shiyu Shen, Hao Yang, Zhe Liu, Ying Liu, Xianhui Lu, Wangchen Dai, Lu Zhou, Yunlei Zhao, and Ray CC Cheung. 2025. VeloFHE: GPU Acceleration for FHEW and TFHE Bootstrapping. IACR Transactions on Cryptographic Hardware and Embedded Systems 2025, 3 (2025), 81–114

  162. [168]

    Kaustubh Shivdikar, Yuhui Bao, Rashmi Agrawal, Michael Shen, Gilbert Jonatan, Evelio Mora, Alexander Ingare, Neal Livesay, José L Abellán, John Kim, et al. 2023. Gme: Gpu-based microarchitectural extensions to accelerate homomorphic encryption. In Proceedings of the 56th Annua...

  163. [169]

    Andrei Stoian, Jordan Frery, Roman Bredehoft, Luis Montero, Celia Kherfallah, and Benoit Chevallier-Mames. 2023. Deep neural networks for encrypted inference with tfhe. In International Symposium on Cyber Security, Cryptology, and Machine Learning . Springer, 493–500

  164. [170]

    AVLN Sujith, Guna Sekhar Sajja, V Mahalakshmi, Shibili Nuhmani, and Balaji Prasanalakshmi. 2022. Systematic review of smart health monitoring using deep learning and Artificial intelligence. Neuroscience Informatics 2, 3 (2022), 100028

  165. [171]

    Hugo Touvron, Louis Martin, Kevin Stone, Peter Albert, Amjad Almahairi, Yasmine Babaei, Nikolay Bashlykov, Soumya Batra, Prajjwal Bhargava, Shruti Bhosale, et al. 2023. Llama 2: Open foundation and fine-tuned chat models. arXiv preprint arXiv:2307.09288 (2023)

  166. [172]

    A Vaswani. 2017. Attention is all you need. Advances in Neural Information Processing Systems (2017)

  167. [173]

    Vertex.AI and Intel AI Lab. 2024. PlaidML: PlaidML - a framework for making deep learning work everywhere. https://github.com/plaidml/plaidml. Accessed: 2025-06-04

  168. [174]

    2023.{HECO}: Fully homomorphic encryption compiler

    Alexander Viand, Patrick Jattke, Miro Haller, and Anwar Hithnawi. 2023.{HECO}: Fully homomorphic encryption compiler. In 32nd USENIX Security Symposium (USENIX Security 23) . 4715–4732

  169. [175]

    Sameer Wagh. 2022. Pika: Secure computation using function secret sharing over rings. Proceedings on Privacy Enhancing Technologies (2022)

  170. [176]

    Sameer Wagh, Shruti Tople, Fabrice Benhamouda, Eyal Kushilevitz, Prateek Mittal, and Tal Rabin. 2020. Falcon: Honest-majority maliciously secure framework for private deep learning. arXiv preprint arXiv:2004.02229 (2020)

  171. [177]

    Malozemoff, and Jonathan Katz

    Xiao Wang, Alex J. Malozemoff, and Jonathan Katz. 2016. EMP-toolkit: Efficient MultiParty computation toolkit. https://github.com/emp-toolkit

  172. [178]

    Yongqin Wang, G Edward Suh, Wenjie Xiong, Benjamin Lefaudeux, Brian Knott, Murali Annavaram, and Hsien-Hsin S Lee. 2022. Characterization of mpc-based private inference for transformer-based models. In 2022 IEEE International Symposium on Performance Analysis of Systems and So...

  173. [179]

    Zhiwei Wang, Peinan Li, Rui Hou, Zhihao Li, Jiangfeng Cao, XiaoFeng Wang, and Dan Meng. 2023. He-booster: An efficient polynomial arithmetic acceleration on gpus for fully homomorphic encryption. IEEE Transactions on Parallel and Distributed Systems 34, 4 (2023), 1067–1081

  174. [180]

    Jason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma, Fei Xia, Ed Chi, Quoc V Le, Denny Zhou, et al. 2022. Chain-of-thought prompting elicits reasoning in large language models. Advances in neural information processing systems 35 (2022), 24824–24837

  175. [181]

    Haoqi Wu, Wenjing Fang, Yancheng Zheng, Junming Ma, Jin Tan, Yinggui Wang, and Lei Wang. 2024. Ditto: Quantization-aware Secure Inference of Transformers upon MPC. arXiv preprint arXiv:2405.05525 (2024)

  176. [182]

    Yu Xiao, Feng-Hao Liu, Yu-Te Ku, Ming-Chien Ho, Chih-Fan Hsu, Ming-Ching Chang, Shih-Hao Hung, and Wei-Chao Chen. 2025. GPU Acceleration for FHEW/TFHE Bootstrapping. IACR Transactions on Cryptographic Hardware and Embedded Systems 2025, 1 (2025), 314–339

  177. [183]

    Tianshi Xu, Meng Li, and Runsheng Wang. 2024. HEQuant: Marrying Homomorphic Encryption and Quantization for Communication-Efficient Private Inference. arXiv preprint arXiv:2401.15970 (2024)

  178. [184]

    Tianshi Xu, Meng Li, Runsheng Wang, and Ru Huang. 2023. Falcon: Accelerating homomorphically encrypted convolutions for efficient private mobile network inference. In 2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD) . IEEE, 1–9

  179. [185]

    Tianshi Xu, Wen-jie Lu, Jiangrui Yu, Yi Chen, Chenqi Lin, Runsheng Wang, and Meng Li. 2025. Breaking the Layer Barrier: Remodeling Private Transformer Inference with Hybrid CKKS and MPC. USENIX Security Symposium (2025)

  180. [186]

    Tianshi Xu, Lemeng Wu, Runsheng Wang, and Meng Li. 2024. PrivCirNet: Efficient Private Inference via Block Circulant Transformation. arXiv preprint arXiv:2405.14569 (2024). Towards Efficient Privacy-Preserving Machine Learning: A Systematic Review from Protocol, Model, and Sys...

  181. [187]

    Tianshi Xu, Shuzhang Zhong, Wenxuan Zeng, Runsheng Wang, and Meng Li. 2024. PrivQuant: Communication-Efficient Private Inference with Quantized Network/Protocol Co-Optimization. arXiv preprint arXiv:2410.09531 (2024)

  182. [188]

    Guang Yan, Yuhui Zhang, Zimu Guo, Lutan Zhao, Xiaojun Chen, Chen Wang, Wenhao Wang, Dan Meng, and Rui Hou. 2025. Comet: Accelerating Private Inference for Large Language Model by Predicting Activation Sparsity. In 2025 IEEE Symposium on Security and Privacy (SP) . IEEE, 2827–2845

  183. [189]

    Hao Yang, Shiyu Shen, Wangchen Dai, Lu Zhou, Zhe Liu, and Yunlei Zhao. 2024. Phantom: A cuda-accelerated word-wise homomorphic encryption library. IEEE Transactions on Dependable and Secure Computing 21, 5 (2024), 4895–4906

  184. [190]

    AC Yao. [n. d.]. How to generate and exchange secrets (extended abstract). FOCS

  185. [191]

    Jiangrui Yu, Wenxuan Zeng, Tianshi Xu, Renze Chen, Yun Liang, Runsheng Wang, Ru Huang, and Meng Li. 2024. FlexHE: A flexible Kernel Generation Framework for Homomorphic Encryption-Based Private Inference. In Proceedings of the 43rd IEEE/ACM International Conference on Computer...

  186. [192]

    Ardhi Wiratama Baskara Yudha, Jiaqi Xue, Qian Lou, Huiyang Zhou, and Yan Solihin. 2024. BoostCom: Towards Efficient Universal Fully Homomorphic Encryption by Boosting the Word-wise Comparisons. In Proceedings of the 2024 International Conference on Parallel Architectures and C...

  187. [193]

    Wenxuan Zeng, Ye Dong, Jinjin Zhou, Junming Ma, Jin Tan, Runsheng Wang, and Meng Li. 2025. MPCache: MPC-Friendly KV Cache Eviction for Efficient Private Large Language Model Inference. arXiv preprint arXiv:2501.06807 (2025)

  188. [194]

    Wenxuan Zeng, Meng Li, Wenjie Xiong, Tong Tong, Wen-jie Lu, Jin Tan, Runsheng Wang, and Ru Huang. 2023. Mpcvit: Searching for accurate and efficient mpc-friendly vision transformer with heterogeneous attention. In Proceedings of the IEEE/CVF International Conference on Compute...

  189. [195]

    Wenxuan Zeng, Meng Li, Haichuan Yang, Wen-jie Lu, Runsheng Wang, and Ru Huang. 2023. CoPriv: network/protocol co-optimization for communication-efficient private inference. Advances in Neural Information Processing Systems 36 (2023), 78906–78925

  190. [196]

    Wenxuan Zeng, Tianshi Xu, Meng Li, and Runsheng Wang. 2024. EQO: Exploring Ultra-Efficient Private Inference with Winograd-Based Protocol and Quantization Co-Optimization. arXiv preprint arXiv:2404.09404 (2024)

  191. [197]

    Jiawen Zhang, Xinpeng Yang, Lipeng He, Kejia Chen, Wen-jie Lu, Yinghao Wang, Xiaoyang Hou, Jian Liu, Kui Ren, and Xiaohu Yang. 2024. Secure transformer inference made non-interactive. Cryptology ePrint Archive (2024)

  192. [198]

    Xinqiao Zhang, Mohammad Samragh, Siam Hussain, Ke Huang, and Farinaz Koushanfar. 2024. Scalable Binary Neural Network applications in Oblivious Inference. ACM Transactions on Embedded Computing Systems 23, 3 (2024), 1–18

  193. [199]

    Yuke Zhang, Dake Chen, Souvik Kundu, Chenghao Li, and Peter A Beerel. 2023. Sal-vit: Towards latency efficient private inference on vit using selective attention search with a learnable softmax approximation. In Proceedings of the IEEE/CVF International Conference on Computer ...

  194. [201]

    Yancheng Zhang, Mengxin Zheng, Yuzhang Shang, Xun Chen, and Qian Lou. [n. d.]. HEPrune: Fast Private Training of Deep Neural Networks With Encrypted Data Pruning. In The Thirty-eighth Annual Conference on Neural Information Processing Systems

  195. [203]

    Itamar Zimerman, Moran Baruch, Nir Drucker, Gilad Ezov, Omri Soceanu, and Lior Wolf. 2023. Converting transformers to polynomial form for secure inference over homomorphic encryption. arXiv preprint arXiv:2311.08610 (2023)

  196. [2024]

    arXiv preprint arXiv:2412.19437 (2024)

    Deepseek-v3 technical report. arXiv preprint arXiv:2412.19437 (2024)

Pith tools

Reviewed August 6, 2026 · model on record in the stance chip above.