Paper 2026/2349
Output Policies for Anomaly Detection with Homomorphic Encryption: Threshold Resolution, Decision Preservation, and Numerical Stability
Abstract
Homomorphic encryption computes anomaly scores without exposing inputs, but released scores and decisions can reveal a private threshold. We evaluate whether output policies limit numerical threshold information while preserving existing decisions, and whether this limitation also impedes decision prediction on other inputs. Policies distinguish internal-score and released-score decisions and share decision-loss and score-distortion constraints. Thresholds were estimated in all 45 plaintext experiments combining three intrusion-detection datasets, three scoring models, and five seeds. All 45 CKKS experiments combining the same datasets, five autoencoder seeds, and three independent keys yielded threshold-containing intervals after revalidating supplied starting intervals. A 16-query cap stopped every plaintext baseline search but served only 16 of 512 separate usage requests, reducing availability. Under random splitting, released-score quantization preserved 99.864% of decisions on average while limiting numerical threshold precision. Surrogates trained on 128 decision-only responses achieved mean balanced accuracy 0.817. With training-only preprocessing and a CIC-IDS2017 weekday split, model-wise balanced accuracies were 0.816–0.911. Separating time and Flow IDs across five resampled evaluations reduced model-wise means to approximately 0.5, showing that prediction transfer depends on data splitting. Threshold-dependent reselection of quantization width changed responses that matched under fixed widths. Selected CKKS boundary tests yielded one released-decision mismatch in 57 queries. Numerical threshold information and service decision prediction therefore require separate protection goals. Output policies must assess decision preservation and response rate alongside policy selection, data splitting, and numerical boundary conditions.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Homomorphic encryptionAnomaly detectionOutput policyThreshold leakageDecision preservation
- Contact author(s)
-
chosubin1208 @ gmail com
bgjiwon754 @ gmail com
msq000212 @ gmail com
dkajdfhd1 @ gmail com
hwajeong84 @ gmail com - History
- 2026-10-07: approved
- 2026-10-05: received
- See all versions
- Short URL
- https://ia.cr/2026/2349
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/2349,
author = {Subeen Cho and Jiwon Bang and Minseo Kim and Seungwon Lee and Hwajeong Seo},
title = {Output Policies for Anomaly Detection with Homomorphic Encryption: Threshold Resolution, Decision Preservation, and Numerical Stability},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2349},
year = {2026},
url = {https://eprint.iacr.org/2026/2349}
}