Paper 2026/285

How (not) to Switch FHE Schemes: Framework and Attacks in the IND-CPA-D Model

Giacomo Santato, Helmholtz Center for Information Security, Saarland University
Riccardo Zanotto, Helmholtz Center for Information Security, Saarland University
Abstract

In this paper, we study the IND-CPA-D security of FHE schemes combined via scheme switching. We introduce a formal framework for capturing security in this setting and identify sufficient conditions under which such combined schemes achieve IND-CPA-D security. We then focus on the specific case of scheme switching from CKKS to exact FHE schemes. We show that the PEGASUS construction [LHHMQ21] does not achieve IND-CPA-D security, and provide a proof-of-concept implementation of a key-recovery attack against the CKKS-to-FHEW switching mechanism in the OpenFHE library.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
FHECKKSscheme switchingIND-CPA-D
Contact author(s)
giacomo santato @ cispa de
riccardo zanotto @ cispa de
History
2026-06-17: revised
2026-02-17: received
See all versions
Short URL
https://ia.cr/2026/285
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/285,
      author = {Giacomo Santato and Riccardo Zanotto},
      title = {How (not) to Switch {FHE} Schemes: Framework and Attacks in the {IND}-{CPA}-D Model},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/285},
      year = {2026},
      url = {https://eprint.iacr.org/2026/285}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.