Back
Google unveils HEIR, an open-source compiler for AI inference on encrypted data
SiTech AI Team3 წთ. საკითხავი

Google unveils HEIR, an open-source compiler for AI inference on encrypted data

HEIR converts pre-trained models so they can run on encrypted inputs, letting servers compute without seeing user data. Google also published four compiled demos.

Google has added HEIR to its Private Computing Toolkit — an open-source compiler that, the company says, makes cryptographically secure private AI inference practical. The project was presented on the Google Security Blog on 14 August 2026 by staff software engineer Jeremy Kun.

What homomorphic encryption changes

Homomorphic encryption allows computations to be performed directly on encrypted data: a server processes ciphertexts and returns an encrypted result without ever exposing the underlying information. Google's example is concrete — a cloud service can produce content recommendations without seeing the user's features. Standard end-to-end encryption, the company argues, forces a compromise: data is protected from breaches, but the provider can no longer offer features that depend on it, such as spam or virus detection. Healthcare and finance are especially wary, and regulations limit data sharing between institutions. Local processing is constrained by device capability and by the risk of leaking a proprietary model.

Homomorphic encryption carries a non-trivial cost overhead, but according to Google that simply turns the capability-versus-privacy trade-off into a question of cost — and that cost is falling quickly.

Why HEIR exists

The obstacle is that converting an existing program to use homomorphic encryption efficiently normally requires a team of cryptographers. HEIR — Homomorphic Encryption Intermediate Representation — addresses that by converting pre-trained AI models that operate on plaintext into models that accept encrypted inputs. The stated goal is a one-click route for non-experts to incorporate encrypted inference into production applications.

Four compiled demos

Google published four applications compiled with HEIR, with latency figures measured on a single-threaded CPU and source code in its fully-homomorphic-encryption GitHub repository: a deep learning recommendation model for private content recommendations built with Belfort Labs, LG and New York University; a credit card fraud detector compiled with Niobium and hardshell.ai; the Kitsune anomaly-detection system for encrypted network traffic, also with Niobium, which lets a provider spot anomalies without seeing the contents of packets; and a hotword detector with Belfort Labs, which would let an audio-triggered agent recognise a wake word while protecting the recording.

Since announcing its intentions in 2023, Google says it has partnered with hardware accelerator makers Belfort, Niobium, Cornami and Optalysys, and plans to demonstrate the latency benefits of those accelerators soon. HEIR has also become a research platform, used in work with Georgia Tech, Carnegie Mellon, UC Santa Barbara, Illinois Institute of Technology, Purdue, the University of Edinburgh and Tsinghua University. Four peer-reviewed publications have been built on it so far.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.