LIVE · cybersecurity feed
Live wire
ai

Google’s open-source HEIR lets AI work with data it can’t see

Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencrypted data into models that process encrypted inputs. The platform helps application developers, compiler engineers, hardw

zeroday.news ·

Google has released the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source toolchain and development platform designed to enable artificial intelligence models to process encrypted data. This initiative, first announced in 2023, allows pre-trained AI models that typically operate on unencrypted information to be converted into versions capable of handling encrypted inputs.

The HEIR platform is intended to support various stakeholders, including application developers, compiler engineers, hardware designers, and cryptography researchers, in creating privacy-focused software systems. Its core function is to simplify the development, optimization, and deployment of fully homomorphic encryption (FHE), a technology that permits computations on data while it remains encrypted, thereby safeguarding sensitive information.

While homomorphic encryption traditionally incurs substantial computational overhead, Google states that these costs are diminishing, making the technology increasingly viable for privacy-preserving data processing in sectors like healthcare and finance. The HEIR project aims to further reduce these costs and improve efficiency.

According to a staff software engineer at Google, HEIR provides cryptographers with a robust infrastructure for testing, benchmarking, and comparing optimizations, allowing them to concentrate on specific performance enhancements. The platform supports multiple FHE schemes, libraries, and front-end programming languages. Future goals for the project include generating code for hardware accelerators such such as GPUs, TPUs, FPGAs, and custom ASICs.

HEIR has also fostered collaborations between Google and academic researchers, with four peer-reviewed publications already built upon the project's foundation and more in development.

Practical applications demonstrated by HEIR include private recommendation systems, credit card fraud detection, network intrusion detection, and hotword recognition. These examples illustrate how the technology can enable systems to analyze sensitive data without exposing its content during processing. Developers can write programs in Python, designate sensitive data, and use HEIR to compile these programs into implementations that operate on encrypted data. Hardware designers can integrate accelerators at various stages of FHE computation, and cryptography researchers can leverage HEIR's compiler infrastructure to build, test, benchmark, and compare cryptographic optimizations.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introdu

breach

OpenAI tightens defenses after AI agents breach research environment

Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online. OpenAI President Greg Brockman said

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

security

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume

security

Microsoft tests faster Windows File Explorer, new context menu

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]

phishing

Heights Finance data breach: What customers need to know

Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.