Paper 2026/2073

Revisiting ML Training under Fully Homomorphic Encryption: Convergence Guarantees, Differential Privacy, and Efficient Algorithms

Yvonne Zhou, University of Maryland, College Park
Mingyu Liang
Ivan Brugere
Danial Dervovic
Yue Guo
Antigoni Polychroniadou
Min Wu
Dana Dachman-Soled
Abstract

We present the first theoretical convergence analysis of machine learning training under fully homomorphic encryption (FHE), combined with a differentially private (DP) training algorithm tailored to encrypted computation. Our approach improves computational efficiency over standard differentially private gradient descent (DP-GD) while achieving comparable utility. In particular, we prove convergence of approximate gradient descent using polynomial approximations of activation and loss functions, which are required for FHE compatibility. To preserve privacy in downstream tasks, we integrate differential privacy without relying on costly per-sample gradient clipping, enabling scalable encrypted learning. We also provide data-independent hyperparameter selection and theoretically grounded strategies for polynomial approximation which can be of independent interest. Together, these contributions advance the feasibility of efficient, private, and secure machine learning on sensitive data.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. ICML2026
Keywords
fully homomorphic encryptiondifferential privacyprivacy-preserving machine learningencrypted machine learning
Contact author(s)
skyzhou @ umd edu
History
2026-09-19: approved
2026-09-17: received
See all versions
Short URL
https://ia.cr/2026/2073
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/2073,
      author = {Yvonne Zhou and Mingyu Liang and Ivan Brugere and Danial Dervovic and Yue Guo and Antigoni Polychroniadou and Min Wu and Dana Dachman-Soled},
      title = {Revisiting {ML} Training under Fully Homomorphic Encryption: Convergence Guarantees, Differential Privacy, and Efficient Algorithms},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2073},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2073}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.