Privacy-Preserving Machine Learning with Homomorphic Encryption: A Complete Benchmark for Medical Image Analysis
Resumo
Homomorphic encryption (HE) enables a remote server to perform Convolutional Neural Network (CNN) inference directly on encrypted medical images, but existing benchmarks often underreport deployment costs such as client-side cryptographic overhead and communication volume. This work presents an end-to-end benchmark of CKKS-encrypted CNN inference for binary pneumonia detection on PneumoniaMNIST, evaluated according to the seven-point reporting checklist proposed by Yanez and Yadav (2026). The evaluation covers plaintext-versus-encrypted classification quality, client-side key generation, encryption, and decryption on both a laptop and a Raspberry Pi 3 Model B+, server-side inference latency by operation, communication volume, edge-device energy consumption, and the assumed threat model under a CKKS parameter set providing at least 128 bits of classical security. The results show the main deployment barrier is not inference itself, but the one-time provisioning of evaluation keys, whose memory footprint exceeds the resources of typical edge devices and must therefore be delegated to a more capable host.Referências
Acar, A., Aksu, H., Uluagac, A. S., and Conti, M. (2018). A survey on homomorphic encryption schemes: Theory and implementation. ACM Computing Surveys, 51(4).
Aharoni, E., Adir, A., Baruch, M., Drucker, N., Ezov, G., Farkash, A., Greenberg, L., Masalha, R., Moshkowich, G., Murik, D., Shaul, H., and Soceanu, O. (2023). HeLayers: A Tile Tensors Framework for Large Neural Networks on Encrypted Data. Privacy Enhancing Technology Symposium (PETs) 2023.
Cheon, J. H., Kang, M., and Park, J. H. (2026). Towards Lightweight CKKS: On Client Cost Efficiency. In Proceedings of the ACM Asia Conference on Computer and Communications Security, ASIA CCS ’26, pages 1387–1398, New York, NY, USA. Association for Computing Machinery.
Choi, H., Kim, J., Kim, S., Park, S., Park, J., Choi, W., and Kim, H. (2024). UniHENN: Designing faster and more versatile homomorphic encryption-based CNNs without im2col. IEEE Access, 12:109323–109341.
Gentry, C. (2009). Fully homomorphic encryption using ideal lattices. In Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, STOC ’09, pages 169–178, New York, NY, USA. Association for Computing Machinery.
Gilad-Bachrach, R., Dowlin, N., Laine, K., Lauter, K., Naehrig, M., and Wernsing, J. (2016). CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy. In Balcan, M. F. and Weinberger, K. Q., editors, Proceedings of The 33rd International Conference on Machine Learning, volume 48 of Proceedings of Machine Learning Research, pages 201–210, New York, New York, USA. PMLR.
Gkoulalas-Divanis, A., Vatsalan, D., Karapiperis, D., and Kantarcioglu, M. (2021). Modern privacy-preserving record linkage techniques: An overview. IEEE Transactions on Information Forensics and Security, 16:4966–4987.
Hwang, I., Min, S., Seo, J., and Song, Y. (2025). On the security and privacy of CKKS-based homomorphic evaluation protocols. In International Conference on the Theory and Application of Cryptology and Information Security, pages 296–330. Springer.
Kim, D., Park, J., Kim, J., Kim, S., and Ahn, J. H. (2024). HyPHEN: A hybrid packing method and its optimizations for homomorphic encryption-based neural networks. IEEE Access, 12:3024–3038.
Kim, M., Jiang, X., Lauter, K., Ismayilzada, E., and Shams, S. (2022). Secure human action recognition by encrypted neural network inference. Nature Communications, 13(1):4799.
Krichen, M. (2023). Convolutional neural networks: A survey. Computers, 12(8):151.
Li, Z., Liu, F., Yang, W., Peng, S., and Zhou, J. (2022). A survey of convolutional neural networks: Analysis, applications, and prospects. IEEE Transactions on Neural Networks and Learning Systems, 33(12):6999–7019.
Litjens, G., Kooi, T., Bejnordi, B. E., Setio, A. A. A., Ciompi, F., Ghafoorian, M., Van Der Laak, J. A., Van Ginneken, B., and Sánchez, C. I. (2017). A survey on deep learning in medical image analysis. Medical Image Analysis, 42:60–88.
Liu, W., You, L., Shao, Y., Shen, X., Hu, G., Shi, J., and Gao, S. (2025). From accuracy to approximation: A survey on approximate homomorphic encryption and its applications. Computer Science Review, 55:100689.
Marcolla, C., Sucasas, V., Manzano, M., Bassoli, R., Fitzek, F. H. P., and Aaraj, N. (2022). Survey on fully homomorphic encryption, theory, and applications. Proceedings of the IEEE, 110(10):1572–1609.
Rovida, L. and Leporati, A. (2024). Encrypted image classification with low memory footprint using fully homomorphic encryption. International Journal of Neural Systems, 34(05):2450025.
Slama, M. F., Guerrouache, H., Challal, Y., Benatchba, K., and Baghdadi, R. (2025). Lightening encrypted convolutions: A GPU-optimized approach to private inference. In 2025 IEEE Conference on Communications and Network Security (CNS), pages 1–9.
Tanuwidjaja, H. C., Choi, R., Baek, S., and Kim, K. (2020). Privacy-preserving deep learning on machine learning as a service—a comprehensive survey. IEEE Access, 8:167425–167447.
Wang, T., Ye, Z., Huang, T., Wang, C., Ying, K., and Huang, K. (2026). PipFHE: Resource-efficient privacy-preserving deep CNN inference via padded batch packing and channel merging over FHE. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(1):1–25.
Xu, C. and Wang, Y. (2025). Optimization of CNN inference for multi-image with fully homomorphic encryption. Journal of King Saud University Computer and Information Sciences, 37(9):260.
Yamashita, R., Nishio, M., Do, R. K. G., and Togashi, K. (2018). Convolutional neural networks: an overview and application in radiology. Insights into Imaging, 9(4):611–629.
Yanez, P. and Yadav, N. (2026). Homomorphic encryption for secure healthcare artificial intelligence. Discover Artificial Intelligence, 6(1):200.
Yang, J., Shi, R., Wei, D., Liu, Z., Zhao, L., Ke, B., Pfister, H., and Ni, B. (2023). MedMNIST v2-A large-scale lightweight benchmark for 2D and 3D biomedical image classification. Scientific Data, 10(1):41.
Ye, Z., Wang, T., Huang, T., Li, Y., Wang, C., Cheung, R. C., and Huang, K. (2026). HTCNN: High-throughput batch CNN inference with homomorphic encryption. IEEE Transactions on Dependable and Secure Computing, 23(2):2400–2411.
Aharoni, E., Adir, A., Baruch, M., Drucker, N., Ezov, G., Farkash, A., Greenberg, L., Masalha, R., Moshkowich, G., Murik, D., Shaul, H., and Soceanu, O. (2023). HeLayers: A Tile Tensors Framework for Large Neural Networks on Encrypted Data. Privacy Enhancing Technology Symposium (PETs) 2023.
Cheon, J. H., Kang, M., and Park, J. H. (2026). Towards Lightweight CKKS: On Client Cost Efficiency. In Proceedings of the ACM Asia Conference on Computer and Communications Security, ASIA CCS ’26, pages 1387–1398, New York, NY, USA. Association for Computing Machinery.
Choi, H., Kim, J., Kim, S., Park, S., Park, J., Choi, W., and Kim, H. (2024). UniHENN: Designing faster and more versatile homomorphic encryption-based CNNs without im2col. IEEE Access, 12:109323–109341.
Gentry, C. (2009). Fully homomorphic encryption using ideal lattices. In Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, STOC ’09, pages 169–178, New York, NY, USA. Association for Computing Machinery.
Gilad-Bachrach, R., Dowlin, N., Laine, K., Lauter, K., Naehrig, M., and Wernsing, J. (2016). CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy. In Balcan, M. F. and Weinberger, K. Q., editors, Proceedings of The 33rd International Conference on Machine Learning, volume 48 of Proceedings of Machine Learning Research, pages 201–210, New York, New York, USA. PMLR.
Gkoulalas-Divanis, A., Vatsalan, D., Karapiperis, D., and Kantarcioglu, M. (2021). Modern privacy-preserving record linkage techniques: An overview. IEEE Transactions on Information Forensics and Security, 16:4966–4987.
Hwang, I., Min, S., Seo, J., and Song, Y. (2025). On the security and privacy of CKKS-based homomorphic evaluation protocols. In International Conference on the Theory and Application of Cryptology and Information Security, pages 296–330. Springer.
Kim, D., Park, J., Kim, J., Kim, S., and Ahn, J. H. (2024). HyPHEN: A hybrid packing method and its optimizations for homomorphic encryption-based neural networks. IEEE Access, 12:3024–3038.
Kim, M., Jiang, X., Lauter, K., Ismayilzada, E., and Shams, S. (2022). Secure human action recognition by encrypted neural network inference. Nature Communications, 13(1):4799.
Krichen, M. (2023). Convolutional neural networks: A survey. Computers, 12(8):151.
Li, Z., Liu, F., Yang, W., Peng, S., and Zhou, J. (2022). A survey of convolutional neural networks: Analysis, applications, and prospects. IEEE Transactions on Neural Networks and Learning Systems, 33(12):6999–7019.
Litjens, G., Kooi, T., Bejnordi, B. E., Setio, A. A. A., Ciompi, F., Ghafoorian, M., Van Der Laak, J. A., Van Ginneken, B., and Sánchez, C. I. (2017). A survey on deep learning in medical image analysis. Medical Image Analysis, 42:60–88.
Liu, W., You, L., Shao, Y., Shen, X., Hu, G., Shi, J., and Gao, S. (2025). From accuracy to approximation: A survey on approximate homomorphic encryption and its applications. Computer Science Review, 55:100689.
Marcolla, C., Sucasas, V., Manzano, M., Bassoli, R., Fitzek, F. H. P., and Aaraj, N. (2022). Survey on fully homomorphic encryption, theory, and applications. Proceedings of the IEEE, 110(10):1572–1609.
Rovida, L. and Leporati, A. (2024). Encrypted image classification with low memory footprint using fully homomorphic encryption. International Journal of Neural Systems, 34(05):2450025.
Slama, M. F., Guerrouache, H., Challal, Y., Benatchba, K., and Baghdadi, R. (2025). Lightening encrypted convolutions: A GPU-optimized approach to private inference. In 2025 IEEE Conference on Communications and Network Security (CNS), pages 1–9.
Tanuwidjaja, H. C., Choi, R., Baek, S., and Kim, K. (2020). Privacy-preserving deep learning on machine learning as a service—a comprehensive survey. IEEE Access, 8:167425–167447.
Wang, T., Ye, Z., Huang, T., Wang, C., Ying, K., and Huang, K. (2026). PipFHE: Resource-efficient privacy-preserving deep CNN inference via padded batch packing and channel merging over FHE. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(1):1–25.
Xu, C. and Wang, Y. (2025). Optimization of CNN inference for multi-image with fully homomorphic encryption. Journal of King Saud University Computer and Information Sciences, 37(9):260.
Yamashita, R., Nishio, M., Do, R. K. G., and Togashi, K. (2018). Convolutional neural networks: an overview and application in radiology. Insights into Imaging, 9(4):611–629.
Yanez, P. and Yadav, N. (2026). Homomorphic encryption for secure healthcare artificial intelligence. Discover Artificial Intelligence, 6(1):200.
Yang, J., Shi, R., Wei, D., Liu, Z., Zhao, L., Ke, B., Pfister, H., and Ni, B. (2023). MedMNIST v2-A large-scale lightweight benchmark for 2D and 3D biomedical image classification. Scientific Data, 10(1):41.
Ye, Z., Wang, T., Huang, T., Li, Y., Wang, C., Cheung, R. C., and Huang, K. (2026). HTCNN: High-throughput batch CNN inference with homomorphic encryption. IEEE Transactions on Dependable and Secure Computing, 23(2):2400–2411.
Publicado
01/09/2026
Como Citar
MACHADO, Lucas Castro Truppel; IDALINO, Thaís Bardini.
Privacy-Preserving Machine Learning with Homomorphic Encryption: A Complete Benchmark for Medical Image Analysis. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 961-976.
DOI: https://doi.org/10.5753/sbseg.2026.29325.
