Paper 2026/2349

Output Policies for Anomaly Detection with Homomorphic Encryption: Threshold Resolution, Decision Preservation, and Numerical Stability

Subeen Cho, Hansung University
Jiwon Bang, Hansung University
Minseo Kim, Hansung University
Seungwon Lee, Hansung University
Hwajeong Seo, Hansung University
Abstract

Homomorphic encryption computes anomaly scores without exposing inputs, but released scores and decisions can reveal a private threshold. We evaluate whether output policies limit numerical threshold information while preserving existing decisions, and whether this limitation also impedes decision prediction on other inputs. Policies distinguish internal-score and released-score decisions and share decision-loss and score-distortion constraints. Thresholds were estimated in all 45 plaintext experiments combining three intrusion-detection datasets, three scoring models, and five seeds. All 45 CKKS experiments combining the same datasets, five autoencoder seeds, and three independent keys yielded threshold-containing intervals after revalidating supplied starting intervals. A 16-query cap stopped every plaintext baseline search but served only 16 of 512 separate usage requests, reducing availability. Under random splitting, released-score quantization preserved 99.864% of decisions on average while limiting numerical threshold precision. Surrogates trained on 128 decision-only responses achieved mean balanced accuracy 0.817. With training-only preprocessing and a CIC-IDS2017 weekday split, model-wise balanced accuracies were 0.816–0.911. Separating time and Flow IDs across five resampled evaluations reduced model-wise means to approximately 0.5, showing that prediction transfer depends on data splitting. Threshold-dependent reselection of quantization width changed responses that matched under fixed widths. Selected CKKS boundary tests yielded one released-decision mismatch in 57 queries. Numerical threshold information and service decision prediction therefore require separate protection goals. Output policies must assess decision preservation and response rate alongside policy selection, data splitting, and numerical boundary conditions.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Homomorphic encryptionAnomaly detectionOutput policyThreshold leakageDecision preservation
Contact author(s)
chosubin1208 @ gmail com
bgjiwon754 @ gmail com
msq000212 @ gmail com
dkajdfhd1 @ gmail com
hwajeong84 @ gmail com
History
2026-10-07: approved
2026-10-05: received
See all versions
Short URL
https://ia.cr/2026/2349
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/2349,
      author = {Subeen Cho and Jiwon Bang and Minseo Kim and Seungwon Lee and Hwajeong Seo},
      title = {Output Policies for Anomaly Detection with Homomorphic Encryption: Threshold Resolution, Decision Preservation, and Numerical Stability},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2349},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2349}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.