mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Next we'll be talking about the paper "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption".
Jane: The paper was written by Tanvir Ahmed, Yixuan Gao, Adnan Armouti and Rajalakshmi Nandakumar from Cornell Tech.
Tom: Stay tuned as we take you through the paper and discuss its implications.
Summary: Tom: So, Jane, building on our talk about the title and initial implications, the paper's summary really dives into how they structure this end-to-end system using mmFHE.
Jane: Right, Tom; what struck me was how they manage to keep the entire sensing workflow—from raw data acquisition right through to feature extraction—encrypted throughout. That’s a massive hurdle in real-world deployments.
Lu: They're essentially building a cryptographic cage around the entire signal processing chain, which is incredible because it means no single party, not even the cloud server running the inference, ever sees the plaintext raw data.
Meng: But when they talk about processing steps like those matrix multiplications or polynomial evaluations—are these operations designed to remain efficient *within* the FHE framework? Because that's where most of my concerns lie about latency.
Lalam: The implication here, beyond just security, is enabling truly decentralized sensing; organizations can share highly sensitive environmental data without ever giving up control over the decryption keys or revealing source information.
Tom: Exactly, Meng brings up the core difficulty there; it's not just adding FHE on top—it has to be *efficient* FHE for this to move past the lab bench.
Jane: And they achieve this by carefully mapping every step of the traditional signal processing pipeline into corresponding homomorphic operations, which is a huge intellectual feat.
Lu: I found their methodology description fascinating because they aren't just applying generic FHE; they are adapting specific circuit designs, like those matrix multiplications or squarings mentioned in the equations, to be inherently friendly to the polynomial ring used by FHE.
Meng: When you look at the details of implementing those circuits, specifically how they handle things like differential phase extraction or FIR filtering under encryption—that's where we need concrete proof of feasibility, not just theoretical possibility.
Lalam: Thinking about the impact, this means that sensitive industrial applications, like monitoring infrastructure integrity or analyzing crowd density in private spaces, can happen while maintaining absolute privacy guarantees for all involved parties.
Improvements: Tom: We've established the groundwork of "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption," and now we're looking at the specific improvements or architectural suggestions the authors propose to make this work even better.
Jane: It seems like their main focus is optimizing the overhead, acknowledging that pure FHE is computationally demanding for real-time use cases. They are suggesting ways to make the process more practical.
Lu: One area I was really paying attention to was how they handle the initial data processing steps; rather than encrypting everything from scratch, they propose optimizing certain components—like maybe pre-processing or specific feature extractions—to minimize the number of costly operations.
Meng: From an implementation standpoint, are these proposed improvements focused on hardware acceleration? Because if we're talking about real-time sensing, I'm not interested in a software patch; I need to know if this can run efficiently on specialized hardware like FPGAs or custom ASICs.
Lalam: The biggest implication of these suggested improvements is the democratization of high-security AI; it means smaller organizations or niche markets that currently couldn't afford dedicated, highly secure infrastructure might suddenly be able to leverage mmWave sensing.
Tom: Meng is right to push on the hardware side; efficiency is everything when you’re dealing with encrypted computations.
Jane: It seems like they are suggesting tailored circuit designs, optimizing specific operations—like those involved in calculating the phase difference or performing filtering—to reduce the polynomial degree and overall computational load within the FHE scheme.
Lu: That optimization of circuit depth is key; every single multiplication or squaring operation adds noise and cost in FHE, so minimizing that depth through clever architectural choices is a massive breakthrough for practical deployment.
Meng: And if we look at the specific components, they are suggesting ways to handle the non-linear parts of sensing, which are usually the hardest to map efficiently into polynomial arithmetic required by FHE.
Lalam: These improvements collectively suggest a roadmap toward making privacy-preserving sensing a standard capability rather than an academic curiosity, fundamentally changing how we trust data shared between parties.
Conclusion: Tom: Wow, what a deep dive; we've covered the security foundation, the operational summary, and even the suggested optimizations for "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption."
Jane: It really paints a picture of a future where sensitive data can be analyzed without ever being exposed in plaintext, which is such a powerful concept for privacy.
Lu: Ultimately, this work moves FHE from being just a theoretical construct to an actively applied tool for physical sensing—it's bridging two huge research domains that were previously separate.
Meng: I still think the biggest hurdle remains the sheer computational cost across all these complex steps; I’m hopeful that these proposed improvements will lead to tangible, accelerated hardware solutions soon.
Lalam: Considering everything we've discussed, the overarching impact is establishing a new paradigm for data trust in physical environments, allowing innovation to happen securely across competitive or sensitive domains.
Tom: We've got time for one last thought from our team members before wrapping up this discussion on "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption."
Jane: Before we sign off, I just want to reiterate how vital this blend of technologies is for building the next generation of trustworthy AI applications.
Lu: I'm incredibly excited about how this opens up possibilities for secure biometrics and personalized health monitoring that respects patient privacy above all else.
Meng: From an engineering standpoint, if they can demonstrate a clear path to real-time throughput, this changes everything for remote industrial monitoring and quality control inspections.
Lalam: I believe the societal benefit of this research lies in its ability to foster trust; trust in automated systems, trust between competing entities sharing data, that's where the cultural shift happens.
Tom: Thank you so much to all of you for breaking down "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption" with us today.
Jane: It's been a fascinating discussion, and we can't wait to talk about what comes next
Conclusion: Tom: So, summing up our discussion, it really boils down to making advanced sensing techniques usable when privacy is non-negotiable; that’s a huge leap forward for secure data exchange.
Jane: Exactly, Tom; it means we can finally build systems where the raw environmental data stays encrypted all the way through the processing pipeline, which is a massive hurdle overcome.
Lu: What I keep thinking about, though, is how this unlocks entirely new domains of interaction; imagine critical infrastructure monitoring where you can detect anomalies without ever knowing *who* caused them or *what* the precise details are.
Meng: But Lu, even with the perfect math working out, the real engineering challenge will be deploying this across varied hardware; we need to know how robustly this whole mmFHE framework scales outside of controlled lab environments.
Lalam: I think Meng's point touches on something deeper; if we can guarantee data sovereignty at the physical sensing layer, it fundamentally shifts trust back to the individual, improving our collective sense of digital safety.
Tom: It’s wild how much this changes the calculus for things like autonomous vehicles or remote medical diagnostics, Jane. We’re moving from "trust us" models to cryptographically verifiable ones.
Jane: Right? It feels like we're getting closer to that ideal of intelligence that works without requiring total visibility into the user's life, which is such a major cultural shift.
Lu: Considering the breadth of applications, this whole approach suggests a future where physical monitoring and digital privacy aren’t seen as opposing forces anymore; they’re integrated components.
Meng: From an implementation standpoint, I agree with that integration idea; if we can make the overhead manageable, it makes these solutions truly viable for commercial deployment right away.
Lalam: Ultimately, advancing techniques like those presented in "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption" helps build a digital culture based on verifiable trust rather than mere compliance.
Tom: That’s a perfect note to end on, Jane; it really paints a picture of where this technology is taking us.
Jane: Absolutely, team; we have so much excitement about this one that we can barely wait for the next paper to dive into.
Cornell Tech
cs.CR, cs.LG, eess.SP
Submitted: 2026-03-23
Updated: 2026-09-10
Comments: Accepted to the 32nd Annual International Conference on Mobile Computing and Networking (MobiCom '26)
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 82/100
The gist: The paper "mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption" presents a novel framework for performing complex radar signal processing entirely within an encrypted environment.
Key concepts
- Fully Homomorphic Encryption (FHE)
- A cryptographic method that allows complex computations (like matrix multiplications) to be performed directly on encrypted data. This ensures that no party, including the cloud server, ever sees the plaintext raw data.
- mmWave Sensing
- A sensing technique utilizing millimeter wave signals for gathering environmental data. The paper applies this technology within an FHE framework to analyze sensitive physical environments while maintaining user privacy.
- End-to-End Encryption
- The process of keeping data encrypted throughout the entire signal processing chain, from the moment raw data is acquired until feature extraction is complete. This prevents any single party from viewing unencrypted information.
- Decentralized Sensing
- The ability for multiple organizations to share highly sensitive environmental data without centralizing it or giving up control over their decryption keys or revealing source information.
Terminology
Summary
The paper mmFHE: mmWave Sensing with End-to-End Fully Homomorphic Encryption
presents a novel framework for performing complex radar signal processing entirely within an encrypted environment. This work is critical because it addresses the challenge of protecting sensitive biometric and positional data—such as micro-displacements (e.g., breathing and heartbeat)—while still enabling advanced sensing tasks like target detection and gesture recognition, thereby breaking the traditional inseparability barrier.
The Coherent Signal Representation
The radar input is modeled as a range-Doppler-antenna tensor Z[t] in C A times R times D over F frames. Each element z a,c[r, t] carries two distinct physical channels:
-
Magnitude z: This channel
tracks macro-movement (target presence, range).
-
Phase z: This channel
encodes micro-movement (sub-wavelength displacements such as breathing and heartbeat).
The utility of the phase information is derived from the fact that the mapping between bin k and phase shifts (phi k[t]) is linear and invertible,
allowing an adversary to recover the micro-displacement signal d k[t] from any disclosed phase sequence. The system achieves Nyquist sufficiency by collecting F samples of d k[t] at a rate f s at least 2f mu over a duration F/f s at least T, which is sufficient to reconstruct the continuous-time micro-displacement signal.
Security and Inseparability Guarantees
The security of the system is rooted in two core properties: inseparability and data obliviousness. The paper proves that any protocol granting a semi-honest server plaintext access for energy-based target detection necessarily leaks information regarding the phase. This is shown by the Algebraic inseparability
argument: since energy detection requires computing E k[t] = z k[t] squared, the server must receive the complex samples z k[t], which unavoidably discloses the phase phi k[t]. Furthermore, by demonstrating that any adversary distinguishing encrypted streams must break IND-CPA with a negligible advantage (epsilon at most F times negl(lambda)), the authors prove that mmFHE breaks the inseparability barrier.
Homomorphic Processing Pipeline (Kernels)
The entire radar processing chain, which includes spectral transforms, non-linear detection, and filtering, is executed using a set of specialized kernels (K1 through K7) defined over CKKS ciphertexts. The design ensures that the circuit trace for each kernel is fixed by public parameters and independent of the encrypted input. These kernels include:
-
** K1: Energy Integration:** Implements one ct-ct squaring and one ct-ct addition per frame, repeated F times.
-
** K2: Soft Power Attention:** Involves 2 gamma sequential squarings and a public index vector multiply.
-
** K3: DFT via Block-Diagonal Matmul:** Uses the BSGS diagonal method on a fixed block-diagonal matrix.
-
** K4: Soft I/Q Extraction:** Computes (z 2) phi times z, processing all R bins identically.
-
** K5: FIR Filtering:** Uses a pt-ct multiply with public FIR coefficients.
-
** K6: Notch Mask:** Implements a single pt-ct multiply with a fixed binary mask.
-
** K7: Differential Phase Extraction:** Evaluates the fixed polynomial phi[t] about y[t] x[t] squared - 13 y[t] cubed.
Data Obliviousness and Composition Closure
The system guarantees input-independent trace
through a two-step proof. First, each kernel is verified to define a fixed arithmetic circuit whose trace depends only on public parameters. Second, the composition closure property is utilized: since sequential composition of data-oblivious circuits results in a trace where both components are independent of the input x, any pipeline composed from this set maintains an input-independent trace, ensuring that the cloud evaluates detection and processing without recovering any plaintext value.
Improvements for AI systems
Improved AI System Architecture and Capabilities
The paper describes a novel fusion of advanced radar signal processing (FMCW, range-Doppler analysis), biometric monitoring (HR/RR estimation), and highly secure computation using Fully Homomorphic Encryption (FHE). The primary architectural improvement is the creation of Privacy-Preserving Biomedical Sensing Systems that eliminate the trade-off between high data utility and absolute patient privacy.
Here are the specific improvements and capabilities:
Improvement: Integration of a specialized Homomorphic Encryption (HE) pipeline designed specifically to process the complex IQ samples (Z[t]) over multiple frames (F) without ever decrypting the raw data or intermediate features. This system must utilize the CKKS scheme for approximate arithmetic required by spectral processing.
Technical Mechanism:
-
Input Layer: Accepts encrypted radar streams Enc(z[r, t]).
-
Core Processing Unit (Homomorphic Radar Pipeline): Implements the entire pipeline—from range FFT to spectral estimation—using fixed, data-oblivious arithmetic circuits (K1 through K7).
-
Spectral Estimation: The system performs homomorphic calculation of the **Range-Doppler-Antenna Tensor Z[t] ** and subsequent bandpass filtering (0.1–0.5 Hz for respiration, 0.8–2.0 Hz for heart rate) directly on the ciphertexts, bypassing the need to extract magnitude z or phase z separately in plaintext space.
-
Feature Extraction: The system computes homomorphic representations of Heart Rate (HR) and Respiration Rate (RR) by running a deep learning classifier (e.g., a small MLP or CNN) where all weights and inputs are processed under HE (Enc(z[t])).
-
Output: The system outputs an encrypted, actionable biometric vector Enc(HR, RR, Target Presence).
Improved Capability:
-
Zero-Trust Monitoring: Enables continuous, real-time monitoring of vital signs (HR/RR) and target movement without the cloud or server ever possessing plaintext access to the raw micro-displacement signal (d k[t]).
-
Inseparability Enforcement: Guarantees that unauthorized attempts to track macro-movement (magnitude analysis) cannot leak sufficient information for spectral extraction (phase analysis), due to the cryptographic binding enforced by the HE computation.
Sources
- TenSEAL: A Library for Encrypted Tensor Operations Using Homomorphic Encryption
- PrivyWave: Privacy-Aware Wireless Sensing of Heartbeat
- Quantized Approximate Signal Processing (QASP): Towards Homomorphic Encryption for audio
- Danger of using fully homomorphic encryption: A look at Microsoft SEAL
- SoK: Secure Human-centered Wireless Sensing
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs