The iO circuit would need the FHE decryption key and the hidden output. If there were exactly one FHE ciphertext for any plaintext (which can't work, otherwise you could distinguish FHE values and break it), then you could simply implement this by supplying <target FHE ciphertext> XOR <obfuscated secret>.
Is there a scheme where iO could do this, or is it impossible because any obfuscation would necessarily require both the FHE decryption key and the obfuscated secret?
In simple terms, why is FHE different from iO? I’ve read your reply a few times, but I don’t understand the concrete distinction. What is the “best possible result” of input + 42 obfuscatabiliry?
Note that I am using + 42 as a trivial example; please mentally substitute with “for example, a bunch of matrix operations to compute a super secret formula result.”
[1] https://juliacomputing.com/blog/2019/11/encrypted-machine-le...
Here's what iO means: given two different circuits C_0 and C_1 that both compute a function f, the obfuscations iO(C_0) and iO(C_1) are indistinguishable (to a polytime adversary). In the email example, you could have a circuit C that computes isSpam over encrypted emails, but with a decrypted result. That is, C(Enc(email)) = isSpam(email). But note that this leaks information to Google, and the security definition of iO does NOT guarantee that Google does not learn anything about your secret key (the obfuscation might not hide the secret key at all).
Definitionally, they're very, very different things and have very different security guarantees. The weird thing about iO is that the security definition doesn't immediately appear to actually secure much, so it doesn't seem very useful. However, it turns out that iO is an incredibly powerful primitive because it can be combined with other things like pseudorandom generators to build up a lot of other primitives. For example, you can combine secret-key encryption and iO to get public-key encryption in a very elegant way.