Paper 2026/1527

Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference

Jiseung Kim, Jeonbuk National University
Hyung Tae Lee, Chung-Ang University
Abstract

Hybrid fully homomorphic encryption (FHE) inference improves the practicality of private inference by letting the server evaluate linear layers homomorphically while the client decrypts and applies nonlinearities. Recent schemes attempt to protect model confidentiality by returning noisy, output-permuted responses and appealing to shuffle-model differential privacy (DP). We show that this protection fails in the correctness regime required by hybrid FHE systems. For a $d$-input linear layer, $d+1$ admissible queries suffice for exact recovery of a permutation-invariant layer summary, hence for perfect model distinguishability. We further show that input DP is orthogonal to model confidentiality and that the local-DP premise required for shuffle amplification cannot hold under correctness-bounded noise. We recover all linear layers of a SAFHIRE-style ResNet-20 end-to-end from TFHE transcripts with zero error, using $d+1$ queries per layer for a total of $5{,}712$ direct queries. Under the same query model, we also confirm exact per-layer recovery on pretrained ImageNet-scale CNNs and ViT-B/16. The leaked spectra enable fingerprinting, lineage attribution, and improved logit-based extraction, while suppressing them destroys inference utility.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. ESORICS 2026
Keywords
Homomorphic encryptionPrivate inferenceModel confidentialityStructural cryptanalysisDifferential privacy
Contact author(s)
jiseungkim @ jbnu ac kr
hyungtaelee @ cau ac kr
History
2026-07-30: approved
2026-07-25: received
See all versions
Short URL
https://ia.cr/2026/1527
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1527,
      author = {Jiseung Kim and Hyung Tae Lee},
      title = {Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid {FHE} Inference},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1527},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1527}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.