diff --git a/README.md b/README.md index 85a6848..84b4737 100644 --- a/README.md +++ b/README.md @@ -32,6 +32,8 @@ Each workload represents a real-world use case with clear specifications, refere - [**BERT**](./BERT/index.html). Privacy-preserving BERT inference on encrypted inputs. Currently supports [BERT-Base (110M)](https://huggingface.co/google-bert/bert-base-cased-finetuned-mrpc) inference on the MRPC task in the [GLUE benchmark](https://gluebenchmark.com/). +- [**Face Recognition**](./face-recognition/index.html). End-to-end privacy-preserving face verification with encrypted feature extraction and matching, including single-pair and batched benchmark results. + *Additional workloads are under development. Check back for updates.* ## Suite Structure @@ -84,6 +86,16 @@ For questions or to get involved: Visit the Homomorphic Encryption Standardization community: [homomorphicencryption.org](https://homomorphicencryption.org) +Additional tutorials and research: + +- [Computer Vision over Homomorphically Encrypted Data — CVPR 2025 Tutorial](https://fhe4cv.github.io/) +- [SecureRAG: End-to-End Secure Retrieval-Augmented Generation](https://openreview.net/pdf?id=5uXACIHz6K) — *NeurIPS GenAI4Health Workshop, 2025*. +- [Homomorphically Encrypted Biometric Template Fusion and Matching](https://doi.org/10.1109/TBIOM.2025.3595438) — *IEEE Transactions on Biometrics, Behavior, and Identity Science, 2025*. +- [AutoFHE: Automated Adaptation of CNNs for Efficient Evaluation over FHE](https://arxiv.org/abs/2310.08012) — *33rd USENIX Security Symposium, 2024*. +- [HERS: Homomorphically Encrypted Representation Search](https://arxiv.org/abs/2003.12197) — *IEEE Transactions on Biometrics, Behavior, and Identity Science, 2022*. +- [HEFT: Homomorphically Encrypted Fusion of Biometric Templates](https://arxiv.org/abs/2208.07241) — *IEEE International Joint Conference on Biometrics, 2022*. +- [Secure Face Matching Using Fully Homomorphic Encryption](https://arxiv.org/abs/1805.00577) — *IEEE International Conference on Biometrics: Theory, Applications, and Systems, 2018*. + ### Organizers Andreea Alexandru, Flavio Bergamaschi, Shruthi Gorantala, Shai Halevi @@ -98,4 +110,4 @@ Andreea Alexandru, Flavio Bergamaschi, Shruthi Gorantala, Shai Halevi --- -[Code of Conduct](./CODE_OF_CONDUCT.html) | © 2026 [HomomorphicEncryption.org](https://homomorphicencryption.org) | Last updated 2026-02-19 +[Code of Conduct](./CODE_OF_CONDUCT.html) | © 2026 [HomomorphicEncryption.org](https://homomorphicencryption.org) | Last updated 2026-08-06 diff --git a/face-recognition/Large.html b/face-recognition/Large.html new file mode 100644 index 0000000..ccd449f --- /dev/null +++ b/face-recognition/Large.html @@ -0,0 +1,169 @@ + + + + + + + FHE Benchmarking Results - Face Recognition (Large Batch - 1,024) + + + + + + + + + +

FHE Benchmarking Results - Face Recognition (Large Batch - 1,024)

+

Timing and batched quality values are averages across 3 measurement run(s). Single-pair scores and labels are listed per run. Durations are wall time unless labeled as worker time.

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SubmitterBandwidthQualityTiming (harness)Timing (server)
NameDateCPURAMOrionSlotsChunkR/LRunsKeysModelInputResultFHE EERFHE TAR@1%FHE TAR@0.1%ArcFace EERArcFace TAR@1%ArcFace TAR@0.1%EER gapTAR@1% gapTAR@0.1% gapMax EER gapResultTotalOffline setupOnline evaluationDatasetKeygenModel prepInput genInput prepInput encComputeDecryptPostprocessArcFaceQualityTotal (wall)Process lifetimeSetup (wall)Model I/ORuntime compileInput I/O (worker)Transport (worker)Inference (worker)Compute (wall)Backbones (worker)Normalize (worker)Inner product (worker)Mean / pair
CryptoFace2026-08-06 11:57:25AMD EPYC 7502 32-Core Processor1007.7 GiB7e27281354f91050L328.8G114.1G128.1G1.0G0.07230.84770.82030.06050.93550.93160.0117-0.0879-0.11130.1500PASS12.507h17.689m12.213h325.8ms8.320m9.364m19.437s22.180m46.576m10.688h3.428m47.4ms18.950m11.7ms10.644h10.677h22.475m13.842m8.478m51.956m9.143m663.424h10.270h662.592h42.366m7.560m36.105s
+
+ + + diff --git a/face-recognition/Medium.html b/face-recognition/Medium.html new file mode 100644 index 0000000..bd613a1 --- /dev/null +++ b/face-recognition/Medium.html @@ -0,0 +1,169 @@ + + + + + + + FHE Benchmarking Results - Face Recognition (Medium Batch - 256) + + + + + + + + + +

FHE Benchmarking Results - Face Recognition (Medium Batch - 256)

+

Timing and batched quality values are averages across 3 measurement run(s). Single-pair scores and labels are listed per run. Durations are wall time unless labeled as worker time.

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SubmitterBandwidthQualityTiming (harness)Timing (server)
NameDateCPURAMOrionSlotsChunkR/LRunsKeysModelInputResultFHE EERFHE TAR@1%FHE TAR@0.1%ArcFace EERArcFace TAR@1%ArcFace TAR@0.1%EER gapTAR@1% gapTAR@0.1% gapMax EER gapResultTotalOffline setupOnline evaluationDatasetKeygenModel prepInput genInput prepInput encComputeDecryptPostprocessArcFaceQualityTotal (wall)Process lifetimeSetup (wall)Model I/ORuntime compileInput I/O (worker)Transport (worker)Inference (worker)Compute (wall)Backbones (worker)Normalize (worker)Inner product (worker)Mean / pair
CryptoFace2026-08-05 19:34:36AMD EPYC 7502 32-Core Processor1007.7 GiB7e27281354f91050L328.8G114.1G32.0G258.6M0.08680.83950.82080.07210.92560.92090.0146-0.0861-0.10010.1500PASS3.418h21.038m3.067h415.5ms8.578m12.453m5.577s4.611m12.660m2.670h1.675m25.4ms4.779m64.8ms2.633h2.664h20.390m12.060m8.221m8.295m1.903m143.533h2.294h143.339h9.848m1.763m32.254s
+
+ + + diff --git a/face-recognition/Single.html b/face-recognition/Single.html new file mode 100644 index 0000000..abd1f4f --- /dev/null +++ b/face-recognition/Single.html @@ -0,0 +1,151 @@ + + + + + + + FHE Benchmarking Results - Face Recognition (Single - 1) + + + + + + + + + +

FHE Benchmarking Results - Face Recognition (Single - 1)

+

Timing and batched quality values are averages across 1 measurement run(s). Single-pair scores and labels are listed per run. Durations are wall time unless labeled as worker time.

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SubmitterBandwidthQualityTiming (harness)Timing (server)
NameDateCPURAMOrionSlotsChunkR/LRunsKeysModelInputResultScore(s)Label(s)TotalOffline setupOnline evaluationDatasetKeygenModel prepInput genInput prepInput encComputeDecryptPostprocessArcFaceQualityTotal (wall)Process lifetimeSetup (wall)Model I/ORuntime compileInput I/O (worker)Transport (worker)Inference (worker)Compute (wall)Backbones (worker)Normalize (worker)Inner product (worker)Mean / pair
CryptoFace2026-08-05 19:34:36AMD EPYC 7502 32-Core Processor1007.7 GiB7e27281354f91050L128.8G114.1G128.1M1.0M0.588810147.710m19.391m28.319m306.0ms8.837m10.548m588.6ms8.774s2.307m24.623m1.233m28.0ms-3.6ms23.892m24.272m19.709m11.547m8.059m1.834s347.5ms19.623m4.183m19.583m2.077s376.2ms4.183m
+
+ + + diff --git a/face-recognition/Small.html b/face-recognition/Small.html new file mode 100644 index 0000000..0663c14 --- /dev/null +++ b/face-recognition/Small.html @@ -0,0 +1,169 @@ + + + + + + + FHE Benchmarking Results - Face Recognition (Small Batch - 128) + + + + + + + + + +

FHE Benchmarking Results - Face Recognition (Small Batch - 128)

+

Timing and batched quality values are averages across 3 measurement run(s). Single-pair scores and labels are listed per run. Durations are wall time unless labeled as worker time.

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
SubmitterBandwidthQualityTiming (harness)Timing (server)
NameDateCPURAMOrionSlotsChunkR/LRunsKeysModelInputResultFHE EERFHE TAR@1%FHE TAR@0.1%ArcFace EERArcFace TAR@1%ArcFace TAR@0.1%EER gapTAR@1% gapTAR@0.1% gapMax EER gapResultTotalOffline setupOnline evaluationDatasetKeygenModel prepInput genInput prepInput encComputeDecryptPostprocessArcFaceQualityTotal (wall)Process lifetimeSetup (wall)Model I/ORuntime compileInput I/O (worker)Transport (worker)Inference (worker)Compute (wall)Backbones (worker)Normalize (worker)Inner product (worker)Mean / pair
CryptoFace2026-08-05 19:34:36AMD EPYC 7502 32-Core Processor1007.7 GiB7e27281354f91050L328.8G114.1G16.0G129.3M0.07450.83990.83990.06310.93690.93690.0114-0.0970-0.09700.1500PASS2.240h19.243m1.919h291.4ms8.375m10.863m1.649s2.560m8.395m1.656h1.632m25.2ms3.149m4.6ms1.614h1.647h22.159m13.494m8.556m9.351m1.239m77.353h1.245h77.251h5.171m56.208s35.014s
+
+ + + diff --git a/face-recognition/index.html b/face-recognition/index.html new file mode 100644 index 0000000..cd97e2a --- /dev/null +++ b/face-recognition/index.html @@ -0,0 +1,256 @@ + + + + + + +FHE Benchmarking: Face Recognition Workload + + + + + + + +

FHE Benchmarking: Face Recognition Workload

+ +

Results - CelebA face verification

+ + +

Specification

+

The face recognition workload implements an encrypted face verification functionality. +The input is a pair of in-the-wild face images drawn from the CelebA dataset. +The goal is a binary decision: determine whether the two images depict the same person (a genuine pair) or two different people (an impostor pair). +For each pair the model computes, under homomorphic encryption, a similarity score between the two faces; only that score is decrypted. A genuine/impostor decision corresponds to thresholding this score, and the harness evaluates quality by sweeping thresholds to compute the Equal Error Rate and TAR@FAR (see below). +

+ +

The workload includes two interfaces for benchmark submitters to implement:

+ + + + + + + + + + + + + + + + + + + + + + + + +
SizePairs (N)
Small128
Medium256
Large1,024
+ +

Each variant samples N pairs from a fixed master set of 1,024 screened CelebA pairs (512 genuine, 512 impostor); the Large variant uses the full set. +Hence, there are a total of four variants of this workload: single inference and batch inference for each one of the three sizes. +Submitters need not implement all four, instead each submitter can implement and report the results of any subset.

+ +

Submission to the benchmarking suite must set the implementation parameters so as to achieve security level of at least 128 bits (against a semi-honest server). +Submitters must document their choice of parameters and explain why they believe that it meets the 128-bit security mandate. +The reference CryptoFace submission uses RNS-CKKS with ring dimension N = 216 and a sparse ternary secret (Hamming weight 192); its parameter selection and security analysis are described in [AB25].

+ +

Submissions are also required to meet a quality bar defined relative to a plaintext ArcFace [DGX+19] baseline that the harness evaluates on the same sampled pairs. +For batched inference, the encrypted model's Equal Error Rate (EER) must be no more than 0.15 above the ArcFace baseline EER on the same pairs. +EER is used because it is threshold-free and stable across batch sizes; the harness additionally reports the True Accept Rate at fixed False Accept Rates (TAR@FAR = 1% and 0.1%). +For single inference, the harness reports the encrypted similarity score for the pair. +

+ +

The face-recognition harness contains a script that can be called to run the implementation of submitters, that script accepts command-line arguments to specify which interface of what instance size to run. +The harness currently supports verification on CelebA pairs with a reference CryptoFace [AB25] submission (a patch-wise CNN with polynomial activations, evaluated under RNS-CKKS). In the future, this workload may be updated to support more models and more datasets.

+ +
+

+$ uv run python harness/run_submission.py -h
+usage: run_submission.py [-h] [--num_runs NUM_RUNS] [--seed SEED]
+                         [--clrtxt CLRTXT]
+                         {0,1,2,3}
+
+Run Face Verification FHE benchmark.
+
+positional arguments:
+  {0,1,2,3}            Instance size (0-single/1-small/2-medium/3-large)
+
+options:
+  -h, --help           show this help message and exit
+  --num_runs NUM_RUNS  Number of times to run stages 4-10 (default: 1)
+  --seed SEED          Random seed for reproducible pair sampling (default: 42).
+                       Fixed by default so all submissions sample identical pairs.
+  --clrtxt CLRTXT      Set to 1 to force rerun of the cleartext reference
+
+
+ +

Because the harness generates the evaluation pairs (submission-agnostic) before invoking any submission, and the seed defaults to a fixed value, every submission run with the default configuration is evaluated on the same pairs and is therefore directly comparable.

+ +You can find more details on the face-recognition Github repository. + + +
+

Bibliography

+
+

[AB25] +CryptoFace: End-to-End Encrypted Face Recognition. +Wei Ao and Vishnu Naresh Boddeti. +IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2025. +

+
+
+

[DGX+19] +ArcFace: Additive Angular Margin Loss for Deep Face Recognition. +Jiankang Deng, Jia Guo, Niannan Xue, and Stefanos Zafeiriou. +IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2019. +

+
+ +

Resources

+ + + diff --git a/index.html b/index.html index 63b33b7..ac83f12 100644 --- a/index.html +++ b/index.html @@ -3,6 +3,7 @@ + FHE Benchmarking Suite -
+
+

FHE Benchmarking Suite

+

Local website preview. Use the links below to open the newly added face-recognition pages.

+ +

Face Recognition

+

End-to-end privacy-preserving face verification with encrypted feature extraction and matching.

+ + +

Additional Tutorials and Research

+ +