[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122113-en":3,"doc-seo-122113-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122113,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Fully Encrypted Machine Learning Protocol using Functional Encryption","Privacy concerns have accelerated research in privacy-preserving machine learning (PPML), where sensitive data must remain hidden during model evaluation. Fully homomorphic encryption (FHE) and secure multi-party computation (MPC) are common building blocks, but FHE/MPC protocols typically require interaction and can expose more than inference results. This work introduces a fully encrypted PPML protocol based on functional encryption (FE) that evaluates arbitrary functions over encrypted data without information leakage. The paper constructs a vector FE scheme for quadratic polynomials and combines it with inner product encryption to support repeated compositions, proving security in the malicious model and demonstrating a fully encrypted 2-layer neural network with quadratic activations, along with experimental results.","Fully Encrypted Machine Learning Protocol using Functional Encryption  \nSeungwan Hong 1 , Jiseung Kim2 , Changmin Lee3 , and Minhye Seo4  \n1 Columbia University / New York Genome Center  \n[shong@nygenome.org](shong@nygenome.org)  \n2 Jeonbuk National University  \n[jiseungkim@jbnu.ac.kr](jiseungkim@jbnu.ac.kr)  \n3 Korea Institute for Advanced Study  \n[changminlee@kias.re.kr](changminlee@kias.re.kr)  \n4 Duksung Women’s University  \n[mhseo@duksung.ac.kr](mhseo@duksung.ac.kr)  \nAbstract. As privacy concerns have arisen in machine learning, privacy-preserving machine learning (PPML) has received signi􀀌cant attention. Fully homomorphic encryption (FHE)  \nand secure multi-party computation (MPC) are representative building blocks for PPML.  \nHowever, in PPML protocols based on FHE and MPC, interaction between the client (who provides encrypted input data) and the evaluator (who performs the computation) is essential to obtain the 􀀌nal result in plaintext. Functional encryption (FE) is a promising candidate to remove this constraint, but existing FE-based PPML protocols are restricted to evaluating only simple ML models, such as one-layer neural networks, or they support partially encrypted PPML, which makes them vulnerable to information leakage beyond the inference results.  \nIn this paper, we propose a fully encrypted FE-based PPML protocol, which supports the evaluation of arbitrary functions over encrypted data with no information leakage during computation, for the 􀀌rst time. To achieve this, we newly construct a vector functional encryption scheme for quadratic polynomials and combine it with an inner product encryption scheme. This enables multiple compositions of quadratic polynomials to compute arbitrary complex functions in an encrypted manner.  \nOur FE-based PPML protocol is secure in the malicious model, which means that an adversary cannot obtain any information about the input data even though they intentionally deviate from the protocol. We then show how to use our protocol to build a fully encrypted 2-layer neural network model with quadratic activation functions and present experimental results.  \n1 Introduction  \nMachine Learning (ML) has become a vital technology for companies across various industries, as it enables them to provide services that enhance people’s quality of life. In traditional machine learning, the data is generally centralized and available to the machine learning algorithm in its raw form. However, when dealing with sensitive data, it is crucial to safeguard the privacy of individuals represented in the data. For example, in the healthcare industry, machine learning models are used to analyze medical data for diagnosis, treatment, and drug discovery. However, medical data is highly sensitive, containing personal information about patients [33, 38] . Similarly, in 􀀌nance, machine learning models are utilized for fraud detection, risk assessment, and other applications, which often contain sensitive information about individuals’ income and spending habits [9, 36] . Additionally, online advertising, which employs machine learning models to personalize ads for individual users, requires the protection of sensitive information such as browsing habits and interests [8, 26] . As ML increasingly permeates various businesses and organizations, privacy issues concerning the underlying data have become more prominent. Privacy-preserving machine learning (PPML) techniques and approaches have been developed to enable machine learning models to provide a useful service while maintaining the data’s privacy. In line with this, research on PPML has begun to draw signi􀀌cant attention [17, 18 , 28 , 45] .  \nThe typical approaches to PPML are based on fully homomorphic encryption (FHE) and secure multi-party computation (MPC) . However, FHE-based and MPC-based PPML protocols have their  \nown limitations: MPC-based PPML protocols [28, 31 , 35 , 40] require computations to be performed in the online phase, necessitat","cbCaibd2dPKIP0ul","https://ap.wps.com/l/cbCaibd2dPKIP0ul","pdf",986697,1,36,"English","en",105,"# Introduction\n## Privacy-preserving machine learning (PPML) and its motivations\n## Limitations of FHE- and MPC-based PPML protocols\n## Functional encryption (FE) as an alternative for non-interactive computation","[{\"question\":\"Why do FHE- and MPC-based PPML protocols have limitations?\",\"answer\":\"MPC-based PPML typically requires online client participation during computation, while FHE-based PPML often needs interaction after encrypted computation to obtain plaintext results. These constraints hinder deployment in scenarios needing non-interactive inference.\"},{\"question\":\"What does the proposed fully encrypted FE-based PPML protocol achieve?\",\"answer\":\"It enables evaluation of arbitrary functions over encrypted data while preventing information leakage beyond the inference output during computation.\"},{\"question\":\"How is the protocol constructed to support complex encrypted functions?\",\"answer\":\"The approach builds a vector functional encryption scheme for quadratic polynomials and combines it with an inner product encryption scheme, allowing multiple compositions of quadratic polynomials to compute arbitrary functions securely.\"}]","Fully Encrypted Machine Learning Protocol using Functional Encryption | PDF",1785808882,91,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"fully-encrypted-machine-learning-protocol-using-functional-encryption","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/fully-encrypted-machine-learning-protocol-using-functional-encryption/122113/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do FHE- and MPC-based PPML protocols have limitations?","Question",{"text":75,"@type":76},"MPC-based PPML typically requires online client participation during computation, while FHE-based PPML often needs interaction after encrypted computation to obtain plaintext results. These constraints hinder deployment in scenarios needing non-interactive inference.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does the proposed fully encrypted FE-based PPML protocol achieve?",{"text":80,"@type":76},"It enables evaluation of arbitrary functions over encrypted data while preventing information leakage beyond the inference output during computation.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the protocol constructed to support complex encrypted functions?",{"text":84,"@type":76},"The approach builds a vector functional encryption scheme for quadratic polynomials and combines it with an inner product encryption scheme, allowing multiple compositions of quadratic polynomials to compute arbitrary functions securely.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]