FHERMA

Kernels

An operation on encrypted data, specified independently of the scheme or library that implements it.

/
Propose a kernel
33 KERNELS0 IMPLEMENTATIONS6 RUNNERS4 OPEN CHALLENGES33 AWAITING FIRST CODE
L3
Encrypted GELUencrypted-geluACTIVE

The Gaussian error linear unit evaluated on encrypted values. It is the activation transformer models use, so encrypted inference over modern language models depends on it being cheap.

SPEC v0.1.0NO IMPLFHENON-LINEARMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Lookupencrypted-lookupACTIVE

Reads element i of an array when both the array and the index are encrypted. Random access is the operation encrypted computation lacks, and everything from private databases to encrypted branching is built by faking it.

SPEC v0.1.0NO IMPLFHEDATA-ACCESS
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Matrix Inversionencrypted-matrix-inversionACTIVE

The inverse of an encrypted non-singular matrix. Solving a linear system without seeing it, which is what regression, calibration and least squares all reduce to.

SPEC v0.1.0NO IMPLFHELINEAR-ALGEBRA
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Matrix Multiplicationencrypted-matrix-multiplicationACTIVE

The product of two encrypted matrices. Almost every encrypted model is a chain of these, so the cost of one multiplication sets the cost of inference.

SPEC v0.1.0NO IMPLFHELINEAR-ALGEBRAMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Maximumencrypted-maxACTIVE

The largest value in an encrypted collection. A single comparison is already hard under encryption; the maximum needs a whole tournament of them, and how that tournament is arranged decides the depth it costs.

SPEC v0.1.0NO IMPLFHECOMPARISON
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Moduloencrypted-moduloACTIVE

The remainder a mod b where both operands are encrypted. Reduction is trivial when the modulus is public and hard when it is not, and the private-modulus case is what integer arithmetic over encrypted data keeps running into.

SPEC v0.1.0NO IMPLFHEARITHMETICNON-LINEAR
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Nearest Neighbour Searchencrypted-knnACTIVE

Finds the closest entries to an encrypted query vector. Retrieval, recommendation and similarity search all reduce to it, and doing it under encryption means ranking without seeing either the query or the ranking.

SPEC v0.1.0NO IMPLFHESEARCHMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Parityencrypted-parityACTIVE

The least significant bit of an encrypted integer. Extracting one bit is the hard step of extracting all of them, so this is the entry point to encrypted bit decomposition and everything built on it.

SPEC v0.1.0NO IMPLFHENON-LINEARBIT-EXTRACTION
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted ReLUencrypted-reluACTIVE

max(0, x) evaluated on encrypted values. The most common activation in neural networks, and the one that decides whether encrypted inference is practical, since a deep model applies it thousands of times.

SPEC v0.1.0NO IMPLFHENON-LINEARMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Set Membershipencrypted-set-membershipACTIVE

Answers whether an encrypted element belongs to a set, and nothing more than that. Sanctions screening and blocklist checks are exactly this question, asked about data neither side wants to hand over.

SPEC v0.1.0NO IMPLFHEPROTOCOLPRIVACY
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Sigmoidencrypted-sigmoidACTIVE

The logistic curve 1/(1+e⁻ˣ) evaluated on encrypted values. It is what turns an encrypted linear model into an encrypted classifier, which makes it the first non-linearity most private machine learning needs.

SPEC v0.1.0NO IMPLFHENON-LINEARMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Sign Functionencrypted-signACTIVE

The sign of an encrypted number, computed without decrypting it: +1 above zero, −1 below, 0 at zero. Encrypted comparison, maximum, sorting and ranking are all built on top of it.

SPEC v0.1.0NO IMPLFHENON-LINEARCOMPARISON
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Singular Value Decompositionencrypted-svdACTIVE

Factors an encrypted matrix into singular vectors and values. The general tool behind compression, denoising and dimensionality reduction, applied to data that stays encrypted throughout.

SPEC v0.1.0NO IMPLFHELINEAR-ALGEBRAMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Softmaxencrypted-softmaxACTIVE

Turns an encrypted vector of scores into an encrypted probability distribution. Every encrypted classifier ends with it, and unlike an activation it couples all elements together, which is what makes it hard.

SPEC v0.1.0NO IMPLFHENON-LINEARMACHINE-LEARNING
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Sortingencrypted-sortingACTIVE

Returns the values of an encrypted array in ascending order. Sorting is decision-making made of comparisons, and under encryption no decision can be made — so the order has to be computed rather than chosen.

SPEC v0.1.0NO IMPLFHECOMPARISONDATA-MANIPULATION
v0.1.0 · publishedNo implementationsNo dependencies
L3
Encrypted Substring Searchencrypted-substring-searchACTIVE

Finds occurrences of a pattern in a text without revealing the pattern. Searching a public corpus while keeping the query private is the case that motivates it — a patent database where the query would give away what someone is building.

SPEC v0.1.0NO IMPLFHESEARCHPROTOCOL
v0.1.0 · publishedNo implementationsNo dependencies
Kernels · FHERMA