acceptodds
Under review as a conference paper at ICLR 2027

Scalable Multi-User Secure Transformer Inference with SSE-Enabled Threshold CKKS

Abstract

Homomorphic encryption (HE) enables privacy-preserving transformer inference on encrypted inputs, but existing systems largely assume a single cryptographic owner. Extending HE inference to independent users therefore requires reusable collective cryptographic infrastructure. For transformer inference, we further employ sparse-secret encapsulation (SSE) to make CKKS bootstrapping more level-efficient. However, SSE introduces a fixed-weight sparse secret in addition to the dense secret used for regular computation, making distributed setup substantially more challenging. We develop an SSE-enabled threshold-CKKS framework centered on a reusable two-server-assisted setup. It generates dense and sparse collective secrets while preserving their prescribed distributions and structures, realizes both first in the Boolean-sharing domain, and delays RNS conversion until distributed CKKS and SSE key generation. Built on this infrastructure, ciphertexts from multiple independent users are consolidated through interleaved packing for shared Transformer evaluation, followed by per-user extraction and synchronized threshold decryption. With 16 users, shared inference reduces service time by with only interface overhead, while maintaining task accuracy within percentage points of plaintext inference and producing identical predictions to single-user encrypted inference.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.