Homomorphic ReLU with Full-Domain Bootstrapping
Abstract
1. Introduction
1.1. Our Contribution
- Signed Decomposition Algorithm . We design three atomic operations—(a) to eliminate carrying interference; (b) to perform signed modular reduction preserving arithmetic consistency; (c) to remove low-bit noise—which together enable the algorithm. This algorithm seamlessly splits large integer ciphertexts into signed 6-bit chunks without cross-segment carry propagation.
- Optimized ReLU Framework with Precision-Consistent Bootstrapping. We integrate the algorithm with an optimized small-integer ReLU bootstrapping scheme [13], introducing two key optimizations: (1) strategic use of [15] to minimize bootstrapping operations for integers ≤10 bits, and (2) redefinition of test polynomial coefficients to ensure uniform slot allocation across segments of varying precision. These optimizations collectively enable correct and efficient ReLU evaluation over decomposed ciphertexts while preventing computational errors when the highest-order segment has less than 6 bits of precision.
- Comprehensive Performance Advantage. Through rigorous analysis and experimentation, we demonstrate that our approach significantly reduces the bootstrapping cost (by an average of ) compared to state-of-the-art approaches while maintaining accuracy.
1.2. Roadmap
2. Preliminaries
2.1. Notation
2.2. From TLWE to Torus-Based Encryption
2.2.1. The Hardness of the Torus Learning with Errors (TLWE) Problem
2.2.2. Torus-Based Encryption Schemes
- : On input a security parameter , output an LWE dimension and an error distribution .
- : On input n, output a secret key .
- : On input and a plaintext , samples , , compute , and return a ciphertext .
- : On input and , compute and return the plaintext .
- : On input , output a polynomial degree and an error distribution .
- : On input N, output a secret key .
- : On input and a plaintext polynomial , sample , an error vector , compute , and return a ciphertext .
- : On input and , compute and return .
- : On input , output parameters N, a matrix dimension l, a gadget matrix h, and an error distribution .
- : On input N, output a secret key .
- : On input and a plaintext , compute a TRLWE ciphertext of length , sample an error , and return a ciphertext . (Here, h is a gadget vector/matrix used for decomposition.)
- : On input and , computes , return the plaintext . (This requires knowledge of the structure of or the use of a specific gadget decomposition function .)
2.3. Torus-Based Fully Homomorphic Encryption
2.3.1. Bit-Wise Fully Homomorphic Encryption
- : On input the security parameter , return the parameter set .
- ←: On input the parameter set , return the secret key , the bootstrapping key , and the key-switching key .
- : On input the secret key and plaintext (representing a bit), return .
- : On input the secret key and TLWE ciphertext , obtain via , then decrypt to get the corresponding plaintext m by rounding up or down, i.e., , return plaintext m.
- (← ): Transforms a ciphertext under one key into a ciphertext under another key, preserving the encrypted message.
- ←: Input a TRLWE ciphertext , extract the constant term coefficient, obtain a TLWE ciphertext , return TLWE ciphertext .
- (← ): The core innovation of TFHE. Take a noisy ciphertext encrypting and a constant , and return a fresh low-noise ciphertext encrypting . This enables homomorphic evaluation of gates (e.g., NAND) while simultaneously reducing noise.
2.3.2. Integer-Wise Fully Homomorphic Encryption
- (): Encrypt an integer by encoding it as . The ciphertext is , where .
- (): Decrypt by computing and rounding. Correctness requires a stricter noise constraint: .
- ( ): A generalized bootstrapping procedure. Input a noisy ciphertext encrypting and a function . Output a fresh ciphertext encrypting . It outputs for and for .
2.3.3. Radix-Based Large Integer Decomposition
- The decomposed small integer ciphertexts lose their sign bits, resulting in unsigned numbers that cannot support cross-domain functions.
- The integer bootstrapping in [18] can only handle single-bit carries, while homomorphic modulo operations may generate multi-bit carries, leading to decomposition errors.
3. Signed Large Integer Ciphertext Decomposition Algorithm
3.1. Signed Large-Integer Decomposition for ReLU
| Algorithm 1 . |
| Require: Ciphertext , shift bits Ensure: Ciphertext where 1: for to n do 2: 3: end for 4: 5: return |
| Algorithm 2 . |
| Require: Ciphertext , modulus bits Ensure: Ciphertext where (signed with random sign bit) 1: 2: for to n do 3: 4: end for 5: 6: 7: return |
| Algorithm 3 . |
| Require: Ciphertext , sign ciphertext , precision , bootstrapping key , key-switching key Ensure: Ciphertext where 1: 2: for to do 3: 4: 5: 6: 7: end for 8: return |
| Algorithm 4 . |
| Require: Ciphertext (precision Q), bootstrapping keys , key-switching keys Ensure: Ciphertexts where , , 1: if then 2: 3: 4: else 5: PBSManyLUT() 6: end if 7: 8: 9: 10: 11: 12: for to do 13: 14: if then 15: 16: end if 17: 18: 19: end for 20: if then 21: 22: else 23: 24: end if 25: for to do 26: 27: end for 28: 29: return |
3.2. The Left-Shift and Homomorphic Modulo Algorithms
3.3. The Ciphertext Cleaning Algorithm
3.4. The Signed Large Integer Ciphertext Decomposition Algorithm
3.4.1. Sign Evaluation Functions
3.4.2. Algorithmic Workflow and Explanation
3.4.3. Parameter Adaptation Examples for Different Precisions
- Number of segments ;
- Dynamic shift amounts used in Algorithm 4: and ;
- The effective data bits (num) for each segment, which determine the precision parameter in the subsequent CipherClean operation.
| Q | n | Shift1 | Shift2 | Seg1 | Seg2 | Seg3 |
|---|---|---|---|---|---|---|
| (num) | (num) | (num) | ||||
| 7 | 2 | 4 | 1 | 5 | 1 | – |
| 8 | 2 | 3 | 0 | 5 | 2 | – |
| 9 | 2 | 2 | −1 | 5 | 3 | – |
| 10 | 2 | 1 | −2 | 5 | 4 | – |
| 11 | 3 | 5 | 2 | 5 | 5 | 0 |
3.4.4. Detailed Step-by-Step Example
- Line 7: Subtracting from a constant gives (0 or −1), the offset for 16-bit precision.
- Line 8: Left-shifting by bits produces , the offset for precisions 14–16 (0/−4, 0/−2, 0/−1 respectively).
- Line 9: Subtracting from a constant gives (0 or −8), the offset for 13-bit precision.
- Line 10: Left-shifting by bits yields , the offset for precisions 12–13 (0/−16, 0/−8).
- Line 11: Left-shifting by 2 bits produces (0 or −32), which serves as the large integer’s sign bit ciphertext.
4. The Full-Domain Large Integer ReLU
4.1. Overview of the Proposed Method
4.2. The Defect of Directly Applying Small-Integer ReLU
4.3. The Large Integer ReLU Algorithm
| Algorithm 5 (, , ). |
| Require: Large integer ciphertext (precision ), bootstrapping key , key-switching key Ensure: Ciphertexts where , 1: 2: for to n do 3: 4: end for 5: return |
4.4. Correctness Analysis
4.5. Formal Correctness Analysis
- Test samples: 10,000 randomly generated integers uniformly distributed over the full range of the 6-bit signed domain .
- Hardware/Software: Experiments were conducted on an Alibaba Cloud instance (Intel Xeon Platinum 8369HB @3.30 GHz, 128 GB RAM) using the TFHE library [6].
4.6. Security Analysis
Information-Leakage Analysis
5. Algorithm Performance Analysis
5.1. Benchmark Algorithm: Bit Decomposition for Comparison
| Algorithm 6 Bit Decomposition Algorithm (). |
| Require: Large integer ciphertext , large integer precision n, bootstrapping key , key-switching key , where is the ciphertext of x Ensure: Ciphertexts satisfying 1: for to n do 2: Compute 3: Compute 4: Compute {Subtract ciphertext of constant } 5: end for 6: return Ciphertexts |
5.2. Theoretical Complexity Analysis
5.3. Experimental Validation
Limitations and Future Work
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Gentry, C. Fully Homomorphic Encryption Using Ideal Lattices. In Proceedings of the 41st Annual ACM Symposium on Theory of Computing, Bethesda, MD, USA, 31 May–2 June 2009; pp. 169–178. [Google Scholar]
- Marcolla, C.; Sucasas, V.; Manzano, M.; Bassoli, R.; Fitzek, F.H.P.; Aaraj, N. Survey on Fully Homomorphic Encryption, Theory, and Applications. Proc. IEEE 2022, 110, 1572–1609. [Google Scholar] [CrossRef] [Scilit]
- Wang, N.; Zhou, W.; Wang, J.; Guo, Y.; Fu, J.; Liu, J. Secure and Efficient Similarity Retrieval in Cloud Computing Based on Homomorphic Encryption. IEEE Trans. Inf. Forensics Secur. 2024, 19, 2454–2469. [Google Scholar] [CrossRef] [Scilit]
- Fukuchi, Y.; Hashimoto, S.; Sakai, K.; Fukumoto, S.; Sun, M.; Ku, W. Secure kNN for Distributed Cloud Environment Using Fully Homomorphic Encryption. IEEE Trans. Cloud Comput. 2025, 13, 721–736. [Google Scholar] [CrossRef] [Scilit]
- Meftah, S.; Tan, B.H.M.; Mun, C.F.; Aung, K.M.M.; Veeravalli, B.; Chandrasekhar, V. DOReN: Toward Efficient Deep Convolutional Neural Networks with Fully Homomorphic Encryption. IEEE Trans. Inf. Forensics Secur. 2021, 16, 3740–3752. [Google Scholar] [CrossRef] [Scilit]
- Chillotti, I.; Gama, N.; Georgieva, M.; Izabachene, M. Faster Fully Homomorphic Encryption: Bootstrapping in Less Than 0.1 Seconds. In Proceedings of the 22nd International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam, 4–8 December 2016; Volume 10031, pp. 3–33. [Google Scholar]
- Lou, Q.; Jiang, L. SHE: A Fast and Accurate Deep Neural Network for Encrypted Data. In Proceedings of the 33rd Neural Information Processing Systems, Vancouver, BC, Canada, 8–14 December 2019; Volume 32, pp. 10035–10043. [Google Scholar]
- Bourse, F.; Minelli, M.; Minihold, M.; Paillier, P. Fast Homomorphic Evaluation of Deep Discretized Neural Networks. In Proceedings of the 38th Annual International Cryptology Conference, Santa Barbara, CA, USA, 19–23 August 2018; pp. 483–512. [Google Scholar]
- Okada, H.; Kiyomoto, S.; Cid, C. Integerwise Functional Bootstrapping on TFHE. In Proceedings of the 23rd International Conference on Information Security, Bali, Indonesia, 16–18 December 2020; pp. 107–125. [Google Scholar]
- Kluczniak, K.; Schild, L. FDFB: Full Domain Functional Bootstrapping Towards Practical Fully Homomorphic Encryption. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022, 2023, 501–537. [Google Scholar]
- Clet, P.E.; Zuber, M.; Boudguiga, A.; Sirdey, R.; Gouy-Pailler, C. Putting Up the Swiss Army Knife of Homomorphic Calculations by Means of TFHE Functional Bootstrapping. Cryptol. Eprint Arch. 2022, 2022/149. Available online: https://eprint.iacr.org/2022/149.pdf (accessed on 15 March 2026).
- Yang, Z.; Xie, X.; Shen, H.; Chen, S.; Zhou, J. TOTA: Fully Homomorphic Encryption with Smaller Parameters and Stronger Security. Cryptol. Eprint Arch. 2021, 2021/1347. Available online: https://eprint.iacr.org/2021/1347 (accessed on 15 March 2026).
- Huang, Y.; Wan, J.; Jiang, Z.L.; Zhou, J.; Fang, J.; Cao, Z. An Efficient Integer-Wise ReLU on TFHE. In Proceedings of the Information Security and Privacy—29th Australasian Conference, ACISP 2024, Sydney, NSW, Australia, 15–17 July 2024; Proceedings, Part I; Lecture Notes in Computer Science; Zhu, T., Li, Y., Eds.; Springer: Berlin/Heidelberg, Germany, 2024; Volume 14895, pp. 161–179. [Google Scholar]
- Bergerat, L.; Boudi, A.; Bourgerie, Q.; Chillotti, I.; Ligier, D.; Orfila, J.B.; Tap, S. Parameter Optimization and Larger Precision for (T) FHE. J. Cryptol. 2023, 36, 28–100. [Google Scholar] [CrossRef] [Scilit]
- Chillotti, I.; Ligier, D.; Orfila, J.B.; Tap, S. Improved Programmable Bootstrapping with Larger Precision and Efficient Arithmetic Circuits for TFHE. In Proceedings of the 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, 6–10 December 2021; pp. 670–699. [Google Scholar]
- Regev, O. On Lattices, Learning with Errors, Random Linear Codes, and Cryptography. J. ACM 2009, 56, 1–40. [Google Scholar] [CrossRef] [Scilit]
- Chillotti, I.; Gama, N.; Georgieva, M.; Izabachène, M. TFHE: Fast Fully Homomorphic Encryption over the Torus. J. Cryptol. 2020, 33, 34–91. [Google Scholar] [CrossRef] [Scilit]
- Liu, Z.; Micciancio, D.; Polyakov, Y. Large-Precision Homomorphic Sign Evaluation Using FHEW/TFHE Bootstrapping. In Proceedings of the 28th International Conference on the Theory and Application of Cryptology and Information Security, Taiwan, China, 5–9 December 2022; Volume 13792, pp. 130–160. [Google Scholar]





| Scheme | Data Type | Max Precision | Negative Integers | Bootstrapping Cost |
|---|---|---|---|---|
| Chillotti [6] | Bit | 1 bit | Limited | for n-bit operations |
| Okada [9] | Integer | 4 bits | No | for n-bit integer division |
| FDFB [10] | Integer | 6 bits | Yes | |
| Huang [13] | Integer | 6 bits | Yes | Precision-agnostic |
| Loris [14] | Integer | n bits | Yes | |
| Ours | Integer | n bits | Yes |
| Parameter | Symbol | Value |
|---|---|---|
| LWE dimension | n | 500 |
| TRLWE dimension | N | 1024 |
| TRGSW dimension | l | 2 |
| Gadget decomposition precision | 512 | |
| Gadget decomposition accuracy | ||
| BK noise std dev | ||
| Key-switching decomposition precision | t | 16 |
| KS noise std dev |
| Integer Precision | Integer Interval Parameter B | Standard Deviation | Algorithm Correctness Probability |
|---|---|---|---|
| 4 | 8 | 99.99% | |
| 5 | 16 | 99.99% | |
| 6 | 32 | 95.2% | |
| 7 | 64 | 66.3% |
| Algorithm | Data Type | Number of Boostrapping for n-Bit Precision |
|---|---|---|
| LargeBitReLU [7] | Bit | |
| Loris [14] | Integer | |
| LargeIntReLU (Ours) | Integer |
| Algorithm | Library | Data Type | Bootstrapping Time for n Bit-Precision | ||||
|---|---|---|---|---|---|---|---|
| = 7 | = 8 | = 9 | = 10 | = 11 | |||
| LargeBitReLU [7] | TFHE | Bit | 1.498 | 1.734 | 1.964 | 2.199 | 2.423 |
| LargeIntReLU (Ours) | TFHE | Integer | 1.160 | 1.273 | 1.393 | 1.506 | 1.621 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Lin, Y.; Huang, Y.; Tang, X.; Fan, J.; Xu, Q.; Jiang, Z.-L.; Zhang, X.; Fang, J. Homomorphic ReLU with Full-Domain Bootstrapping. Cryptography 2026, 10, 21. https://doi.org/10.3390/cryptography10020021
Lin Y, Huang Y, Tang X, Fan J, Xu Q, Jiang Z-L, Zhang X, Fang J. Homomorphic ReLU with Full-Domain Bootstrapping. Cryptography. 2026; 10(2):21. https://doi.org/10.3390/cryptography10020021
Chicago/Turabian StyleLin, Yuqun, Yi Huang, Xiaomeng Tang, Jingjing Fan, Qifei Xu, Zoe-Lin Jiang, Xiaosong Zhang, and Junbin Fang. 2026. "Homomorphic ReLU with Full-Domain Bootstrapping" Cryptography 10, no. 2: 21. https://doi.org/10.3390/cryptography10020021
APA StyleLin, Y., Huang, Y., Tang, X., Fan, J., Xu, Q., Jiang, Z.-L., Zhang, X., & Fang, J. (2026). Homomorphic ReLU with Full-Domain Bootstrapping. Cryptography, 10(2), 21. https://doi.org/10.3390/cryptography10020021

