Skip to content

Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference

Sep 2026 · IACR Cryptology ePrint Archive · Vol 2026, pp. 1527 · 0 citations · 30 references
Computer Science

TL;DR

It is shown that input DP is orthogonal to model confidentiality and that the local-DP premise required for shuffle amplification cannot hold under correctness-bounded noise, and that the leaked spectra enable fingerprinting, lineage attribution, and improved logit-based extraction, while suppressing them destroys inference utility.

Abstract

Hybrid fully homomorphic encryption~(FHE) inference improves the practicality of private inference by letting the server evaluate linear layers homomorphically while the client decrypts and applies nonlinearities. Recent schemes attempt to protect model confidentiality by returning noisy, output-permuted responses and appealing to shuffle-model differential privacy~(DP). We show that this protection fails in the correctness regime required by hybrid FHE systems. For a $d$-input linear layer, $d+1$ admissible queries suffice for exact recovery of a permutation-invariant layer summary, hence for perfect model distinguishability. We further show that input DP is orthogonal to model confidentiality and that the local-DP premise required for shuffle amplification cannot hold under correctness-bounded noise. We recover all linear layers of a \safhire{}-style ResNet-20 end-to-end from TFHE transcripts with zero error, using $d+1$ queries per layer for a total of $5{,}712$ direct queries. Under the same query model, we also confirm exact per-layer recovery on pretrained ImageNet-scale CNNs and ViT-B/16. The leaked spectra enable fingerprinting, lineage attribution, and improved logit-based extraction, while suppressing them destroys inference utility.

View source

Similar papers

Preprint Sep 2026

An Open-Source End-to-End FHE Implementation for Privacy-Preserving Llama 3 8B Inference

Odin is the first open-source end-to-end GPU CKKS implementation of Llama-3, an FHE inference system that co-designs ciphertext packing and model execution for Llama and uses a feature-major cross-layer layout to unify residual connections and layer interfaces.

Yu-Hang Fan, Yu-Si Chen, Kan-Yu Ye et al. · 0 citations
Preprint Aug 2026

Revisiting Continuous Noise Sampling for Multi-Party Differential Privacy

This paper revisits the continuous noise sampling protocols and makes several improvements in both security and efficiency and turns to discrete sampling at the granularity of individual biased bits to address the security and efficiency issues together.

Yu-Cheng Fu, Tianhao Wang · 1 citation
Preprint Aug 2026

Beyond Explicit Generators: Distribution-Free Linear-Decomposition Attacks on Public-Key Encryption

Linear-decomposition attacks can break public-key schemes without recovering the secret algebraic action: when a target public state lies in a known linear span, its decomposition coefficients transfer through the unknown action to reveal the shared value. We study a setting in which the adversary uses only the public...

Zi-Yan Chen, Ding-Xuan Zhou · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.