一种用于CPU上CKKS计算的高效容错方案
An Efficient Fault-Tolerance Scheme for CKKS Computation on CPUs
浏览论文内容
中文总结 AI 辅助
针对FHE中CPU易受瞬态硬件故障影响的问题,提出用于CPU上CKKS计算的高效容错方案,通过三个层面降低保护开销,实现高检测率,运行时开销低,相比直接校验和保护大幅降低平均保护开销。
中文摘要 AI 辅助
全同态加密(FHE)允许对加密数据进行计算,但其长密文数据流和高维模运算易受瞬态硬件故障导致的静默数据损坏影响。现有保护方法要么针对专用加速器,要么给CPU带来大量执行、模运算和内存访问开销。本文提出一种用于基于CPU的CKKS计算的高效容错方案,在三个层面降低保护开销的同时检查多项式算子的输入输出一致性。一是利用CPU宽累加器减少昂贵的模约简;二是将校验和累积嵌入算子数据流;三是消除相邻算子间冗余校验和计算。通过在OpenFHE中实现该方案并在随机单比特瞬态故障下评估,在150,000个未崩溃的损坏结果案例中实现了100%的经验检测率,运行时开销仅6.0%至8.4%,平均6.8%,与基于直接校验和的保护相比,平均保护开销降低4.9倍。
英文摘要
Fully homomorphic encryption (FHE) enables computation on encrypted data, but its long ciphertext dataflow and high-dimensional modular arithmetic make it vulnerable to silent data corruption caused by transient hardware faults. Existing protection methods either target dedicated accelerators or impose substantial execution, modular-arithmetic, and memory-access overheads on CPUs. This work presents an efficient fault-tolerance scheme for CPU-based CKKS computation. It checks the input-output consistency of polynomial operators while reducing protection overhead at three levels. First, modulus-aware bucket checksum exploits wide CPU accumulators to reduce expensive modular reductions. Second, dataflow-fused in-operator checking embeds checksum accumulation into operator dataflows, avoiding separate scans of long ciphertext polynomials. Third, cross-operator check fusion eliminates redundant checksum computations between adjacent operators while preserving end-to-end checking invariants. We implement the scheme in OpenFHE and evaluate it on representative encrypted applications and ciphertext primitives under random single-bit transient faults. It achieves a 100 percent empirical detection rate across 150,000 non-crashing corrupted-result cases and maintains application accuracy close to the fault-free baseline over a wide range of fault rates. The scheme incurs only 6.0 percent to 8.4 percent runtime overhead, averaging 6.8 percent, and reduces average protection overhead by 4.9 times compared with direct checksum-based protection.