HNHacker News
TopNewBestAskShowJobs

dowem

29 karma · joined June 6, 2020

submissionscomments
dowem··on IBM Fully Homomorphic Encryption Toolkit for Linux
Thanks for passing on that reference @onepointsixC. Yourself and the parent poster might be interested in a webinar we posted on YouTube which talks about those slides from one of the paper authors (Flavio) and yours truly. That slide is about halfway through the video, but the whole thing is worth a watch. https://www.youtube.com/watch?v=W9G1s1t_d80&list=PL0VD16H1q5...

We put up a cryptography playlist during the last week on youtube since it felt like people didn't have enough resources to refer to easily. We hope it helps! It includes the video walkthrough of how to get the toolkit running and run some demos.

dowem··on IBM Fully Homomorphic Encryption Toolkit for Linux
Thanks for helping the conversation along jlokier! I thought since you mentioned the database concepts in your response you might be interested in checking the database example in our toolkit. It is really not a literal database but rather an in-memory key value search as that is easier to code and demonstrate. One of the nuances of FHE programming is that a full table scan is needed for cases like our database search because fundamentally we cant test and branch to bail out early when we find something we want. Key comparison to an encrypted search key are obviously not literal matches. Each has its own polynomial representation with its own error added to keep terms from encrypting to the same value every time. There is no way to compare for short circuit evaluation for instance. So we end up doing an operation on each value and effectively summing up those partial solutions in a way that lets us determine if a match was found. If anyone is interested let us know on our public slack channel and someone can answer more tech details there.

You guys rock. Great questions and comments on this forum.

dowem··on IBM Fully Homomorphic Encryption Toolkit for Linux
(Reminder I am a maintainer of the toolkit and an IBMer, opinions are my own, etc. ) This is a pretty new field with people just starting to take it seriously for large problems. It seems from what I have seen in experiments, there can be big tradeoffs in latency against throughput and like most software, decomposing the problem and efficiently mapping it onto the underlying data structures gets the big performance wins. It is still very easy to do something naively with poor performance. Also while the performance overhead is "high" it is orders of magnitude better than it was years ago. The overhead in terms of resources is tractable. RAM is inexpensive and so is CPU time compared to the cost of a single data breach both financially and in terms of user impact. :)

My final comment on performance is that the way the code is generally structured it makes sense to do things in batches in parallel as opposed to doing individual atomic transactional data operations, but I think theres a lot of room to explore in the performance and optimization space.

I think better reference examples, and a common platform to run examples on will foster the healthy exchange ideas and will help advance the art a lot. One of my personal goals for the toolkit is to provide people with demos to run (and with community help or a massive outpouring of interest and or funds to my benevolent corporate overlord), and help explore these tradeoffs using demos which are better than trivial complexity. Some computer scientist, software engineer, or applied mathematician might get interested in this subject and get hacking because we tried to make it easier to experiment.

We know we COULD do a lot with this stuff (tons of applications or ways to use FHE), but few ARE doing things with this to solve real problems.

Oh and if anyone wants, of course IBM can be contacted if you have a business problem you want to discuss, or need corporate education and such on these things. For non corporate folks, this toolkit gives EVERYONE access to some baseline reference technology. Stepping away from the corporate perspective, speaking as an individual and an individual and maintainer of the repo, soon I hope some more baseline educational materials if the community help engage with us to understand questions and better explain things. Reactions to this toolkit and inquiry from potential clients will really help us accelerate this work.

Thanks for the continued interest in the hacker community and I wish we had time to respond to every interesting comment here!

dowem··on IBM Fully Homomorphic Encryption Toolkit for Linux
The toolkits are absolutely free to download and use and modify. When I say free I mean both gratis (no cost) and it is MIT licensed for the code IBM provided. We would love to see community contributions. Once downloaded you do not need network connectivity or anything to use the demos or play with the code!
dowem··on IBM Fully Homomorphic Encryption Toolkit for Linux
Hi Hackers! This is Eli (one of the authors of the toolkit). I wanted to make sure you all know you can check out the code. It is freely available on GitHub as linked by the OP. The press this weekend in places like Ars talks about trials, which we did and those were awesome, but the real story right now is the toolkits are out there for anyone to get access to the tech. I love that it was shared here. Several posts on Ycombiantor have come up as a result.

I just wanted to say that I think we packaged some cool demos in the toolkit. One is the privacy preserving search we debuted in the MacOS toolkit we put out a few weeks ago, and this one also has a fully encrypted neural network inference over credit card fraud data. If you like encryption, or like the idea of encrypted machine learning check it out! We built all the special dependencies for you, along with an integrated IDE setup to run the examples trivially. The encrypted ML example also uses a brand new, fresh out of the IBM research kitchen, encrypted machine learning library that makes it work.

This stuff is not fiction it is real and you can run it today if you want! Our toolkit is based on Docker and comes in Ubuntu, Fedora, and CentOS. You can even pull the docker images from Docker Hub. IF you want to see more of this effort show us some love on GitHub and Docker Hub by smashing that star button! Instructions are in the readme. Most people who know docker can get up to speed and running in less than 10 minutes. https://github.com/IBM/fhe-toolkit-linux/.

Monitoring the entirety of the internet for good questions and comments is not one of my superpowers. If anyone has questions get in touch with us on slack directly. The development team is here to help. Questions are great, we are trying to get together an FAQ. Hit us up on Slack here: https://app.slack.com/client/T0133ARBGBV#/. We want your feedback, questions, and ideas to help spread the word.

P.S. Thanks to user Darkstryder and throw0101a who commented below! You did some nice explanation for KaiserPros question, and shared some nice links for this community!

dowem··on IBM Releases Fully Homomorphic Encryption Toolkit for macOS and iOS
The library the toolkit is based on is called HElib and the developers (myself included) did not have the bandwidth to port anything to Windows. The core library and dependencies are Linux native. As it is, we are a bit behind on the Linux and android toolkits. With limited time and energy, we chose the most closely related platforms that all have Unix like underpinnings. Thanks for the question! If you have more feel free to join in the public slack conversation:

https://fhekit.slack.com/join/shared_invite/zt-e35rax8l-_ZbB...

dowem··on IBM Releases Fully Homomorphic Encryption Toolkit for macOS and iOS
Sure, tt is a first release integrating the HElib library, dependencies, and a working sample project that you just click the play button to get running that you can import directly from git into the platform IDE of choice. The intent is for more demo apps to be shipped along with other convenience utilities if people show interest. We could have left it behind closed doors until it was "perfect" but that is not really how we prefer to work. The response has been great, so I hope we double down and improve the toolkits accordingly with community help and input. It is an open-source project without a version number, so it may take some time but we will get there.
dowem··on IBM Releases Fully Homomorphic Encryption Toolkit for macOS and iOS
The latter is more like it. It is a case where you want something computed, like the sum of your paychecks over the last year, Or some credit card risk evaluation thing, or if you have markers for cancer in your genome data based on your personal information. Instead of sending these values to the server (perhaps encrypting in flight) where they are processed in plaintext (open to malicious intent on the server-side, or honest-but-curious folks who mine your sensitive personal information) the values, you upload remain encrypted so only you know what they mean. However the cloud side can sum them, perform threshold evaluations, search for things, determine fitness for a loan etc, without knowing anything, they go through the motions of the computation for you, but without being able to decipher anything about the computation result at any step along the way. Then when the server-side is done, it has computed whatever you asked it to do, but knows nothing. The server side reliably and deterministically manipulated symbols in a language it cant read. As it turns out, you can, so when the encrypted server-side results are sent back, you decrypt them and understand if you have been approved or have genetic markers for cancer or something.
dowem··on IBM Releases Fully Homomorphic Encryption Toolkit for macOS and iOS
In the algorithm implemented the search key is matched against all rows in the database. There is no short circuit evaluation and there cannot be... you cannot compare an encrypted value to a plaintext value and know they are equivalent without decrypting it first (which the server-side cannot do). This is true even for writing the code to do the search since you cannot do and if style comparison on encrypted values to break out of a loop. In the example, each value stored in the database is compared to the encrypted search term producing a partial result that is itself encrypted and meaningless to the server side. Once ALL value rows have been searched, the partial results (all those encrypted meaningless things) of all those comparisons are combined to yield a single encrypted result which is returned to the user that initiated the search. That result is then decrypted. There is no leakage because ALL code paths and all data must be evaluated for the program every time. However, from what I gather, the database can be shattered across multiple backend servers and each subset could be searched in parallel for a speedup for a practical deployment.
dowem··on IBM Releases Fully Homomorphic Encryption Toolkit for macOS and iOS
I am one of the developers, so I wanted to respond. Imagine you want to search for a coffee or restaurant nearby. You can now use an app which cares about your privacy by encrypting your location, and encrypting the intent of your food search (maybe you want to seek out only italian, chinese, mexican, or coffee shop places) and the app, sends that encrypted data to the cloud to retrieve an encrypted response back wherein the app, nor the backend service could mine anything about you or your preferences. It just satisfied your request. In such a scenario the app would likely be paid, but the service wouldn't use you as the product to grab all your information...