When and Where Faults Matter: A Study of Transient Errors in CKKS Multiplication
Vattana Chan, Matías Mazzanti, Karthik Swaminathan, Augusto Vega, Esteban Mocskos, Radha Venkatagiri
University of Buenos Aires · IBM T. J. Watson Research Center · Georgetown University
cs.AR, cs.CR
Submitted: 2026-08-11
Updated: 2026-08-12
Comments: 3 pages, 2 figures
Code: https://github.com/Microsoft/SEAL
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 75/100
The gist: This paper presents an in-depth analysis of the resilience of homomorphic multiplication in the CKKS (Cheon–Kim–Kim–Song) fully homomorphic encryption (FHE) scheme in the presence of
Terminology
Summary
This paper presents an in-depth analysis of the resilience of homomorphic multiplication in the CKKS (Cheon–Kim–Kim–Song) fully homomorphic encryption (FHE) scheme in the presence of hardware-induced transient single-bit flip errors. The study focuses on server-side homomorphic multiplication in the unoptimized CKKS scheme, examining how both the timing and the location of errors in the ciphertext components c0 and c1 impact the correctness of the final FHE output.
The authors demonstrate three key findings: "1). homomorphic multiplication is highly susceptible to faults, 2). errors affecting ciphertext polynomials c0 and c1 follow distinct fault-propagation paths, and 3). the timing at which c0 and c1 encounter faults significantly influences the final decrypted output."
The methodology involves using a custom CKKS implementation (C-CKKS) in C++ combined with the error injection tool LLTFI. Single-bit transient errors are injected into different ciphertext polynomials during ciphertext-ciphertext multiplication, and the full homomorphic encryption pipeline is run to evaluate the decoded output using Maximum Relative Error Percentage (MREP). The study focuses on homomorphic multiplication without optimizations such as NTT and RNS.
The paper explains that transient errors can lead to three distinctive outcomes: "(i) the homomorphic operation fails and the error is detected, (ii) the operation completes successfully and the output is masked, (iii) the operation completes successfully, but the error propagated and corrupts the final output, which is called Silent Data Corruption (SDC)."
A key theoretical contribution is the analytical modeling of injected faults. The authors model a fault as an error polynomial ei,j ∈ Z[X] whose only non-zero coefficient is the i-th one, corresponding to a bit flip at position j of coefficient i. They highlight the difference between corrupting c0 in both d0 and d1 versus corrupting it only in d1. When a fault is injected in c0 affecting both uses (in d0 and d1), the resulting expression forms a valid ciphertext: the decrypted value can be interpreted as the intended product plus the scheme-inherent approximation error, and an additional low-magnitude term. In contrast, when the fault affects only d1, the cancellation does not occur, leaving residual randomness terms after decryption and producing a significantly larger error.
The paper also notes that "both c0 and c1 from each ciphertext are each used twice in the computation of the final result: c0 contributes to the formation of d0 and d1, while c1 contributes to d1 and d2. This inherent reuse induces a symmetric algebraic structure across the partial products." When a bit-flip affects only one of these uses, this symmetry is broken, leading to silent data corruption. However, when the same bit-flip is consistently injected into both uses of c0 (or both uses of c1), the algebraic symmetry is preserved and masking patterns remain intact.
The authors conclude that homomorphic multiplication in CKKS is highly susceptible to faults, with the timing and location of bit-level faults leading to remarkably different outcomes, including unexpected behaviors such as the absence of the scaling factor ∆, the lack of a gap, or no N/2 coefficient resilience.
Improvements for AI systems
Improvements to AI Systems:
- Fault-Aware Error Propagation Modeling for FHE Pipelines
-
Enhance AI systems that orchestrate or execute CKKS-based homomorphic encryption by integrating a predictive model of fault propagation paths for
c0vs.c1polynomials. -
The improved system can pre-emptively classify potential bit-flip outcomes (detected error, masked output, or silent data corruption) based on the timing and location of injected faults, enabling runtime fault-risk assessment before execution.
- Adaptive Redundancy and Checkpointing in Homomorphic Computation
-
Use the paper’s finding that symmetric reuse of
c0andc1preserves algebraic structure, while asymmetric faults break it, to design an AI-driven scheduler that decides when to duplicate specific ciphertext components or insert verification steps. -
The improved system can dynamically adjust redundancy levels (e.g., recompute only
d1ord0when a fault is detected in a single use) to minimize overhead while preventing silent data corruption.
- Fault-Injection Simulation for Robustness Testing of AI Models on Encrypted Data
-
Incorporate the analytical error polynomial model (single-bit flip at coefficient
i, bit positionj) into AI-based testing frameworks that simulate hardware faults during training or inference on encrypted data. -
The improved system can generate targeted fault scenarios (e.g., faults in
d0vs.d1at different pipeline stages) to stress-test the robustness of neural networks or other AI models that rely on CKKS, identifying which layers or operations are most vulnerable.
- Error-Aware Loss Function and Post-Decryption Correction
-
Leverage the paper’s distinction between low-magnitude errors (when both uses of
c0are corrupted) and large residual randomness (when only one use is affected) to train an AI-based post-processor that detects and corrects corrupted outputs. -
The improved system can estimate the expected error magnitude from the fault’s algebraic signature and apply a learned correction model, reducing the impact of silent data corruption on downstream AI tasks (e.g., classification or regression).
- Timing-Sensitive Fault Tolerance in Real-Time Encrypted AI Inference
-
Use the finding that the timing of faults (during which partial product formation) drastically changes the output to build an AI-based runtime monitor that predicts the criticality of each computation stage.
-
The improved system can prioritize fault mitigation (e.g., rollback or recomputation) for stages where errors are more likely to cause SDC, while allowing masked errors to proceed without intervention, improving throughput and reliability.
- Hardware-Aware Compilation for FHE-Enabled AI
-
Integrate the paper’s insights on
c0/c1reuse and the absence of scaling factor∆under certain faults into an AI-guided compiler that optimizes CKKS multiplication for fault resilience. -
The improved system can automatically reorder or transform homomorphic multiplication operations to reduce the probability of asymmetric faults (e.g., by aligning bit-flip patterns) or to make the output more robust to single-bit errors, without sacrificing performance.
Sources
- Silent Data Corruptions at Scale
- Characterizing the Sensitivity to Individual Bit Flips in Client-Side Operations of the CKKS Scheme
Related papers
- WitCert: Sound Runtime Risk Observability and Gating for KV-Cache Quantization
- Golden Ruler: A Numeric Format Catalog with Bit-Exact Conformance Vectors for FP8, BF16, MXFP4, and Microscaling Formats
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERI
- Provisioning to Runtime Optimization of a 100 MW-Scale AI Cluster
- Bit-Accurate Modeling of GPU Matrix Multiply-Accumulate Units: Demystifying Numerical Discrepancy and Accuracy
- Optimizing Polynomial Multiplication and Fixed-Weight Sampling for HQC on ARM Cortex-M4