Lukas Böhm, Arjhun Swaminathan, Anika Hannemann, Erik Buchmann
8 min
Abstract
Quantum Federated Learning (QFL) enables distributed training of Quantum Machine Learning (QML) models by sharing model gradients instead of raw data. However, these gradients can still expose sensitive user information. To enhance privacy, homomorphic encryption of parameters has been proposed as a solution in QFL and related frameworks. In this work, we evaluate the overhead introduced by Fully Homomorphic Encryption (FHE) in QFL setups and assess its feasibility for real-world applications. We implemented various QML models including a Quantum Convolutional Neural Network (QCNN) trained in a federated environment with parameters encrypted using the CKKS scheme. This work marks the first QCNN trained in a federated setting with CKKS-encrypted parameters. Models of varying architectures were trained to predict brain tumors from MRI scans. The experiments reveal that memory and communication overhead remain substantial, making FHE challenging to deploy. Minimizing overhead requires reducing the number of model parameters, which, however, leads to a decline in classification performance, introducing a trade-off between privacy and model complexity.
Alex: With 20 clients each training on bits of the brain tumor MRI dataset, how does the central server combine their encrypted updates without peeking?
Sam: Each client trains locally on their share—about 250 images resized and normalized—computing changes to the model's dials, or gradients. They encrypt those gradients and send them sealed. The server adds up the encrypted values using a standard averaging method called FedAvg, without unlocking anything, then sends the combined result back for clients to decrypt and apply. This blocks attacks where a bad server might reconstruct patient images from raw gradients.
Alex: Right, so the server's just doing math on locked boxes. But the paper's tests show this encryption balloons communication—from 9 kilobytes to 258 megabytes per round?
Sam: Yes, and central memory jumps around 50 times higher too. They ran models like CNN-QCNN hybrids on the MRI dataset for tumor classes—glioma, meningioma, pituitary, no tumor—with accuracy holding steady but at huge resource cost. Shrinking tunable parameters helps feasibility, yet it trades off some classification precision, as smaller models miss subtle tumor patterns.
Alex: Sam, those broad costs are one thing, but what does the paper drill down into—like, where exactly does most of the slowdown hit during training?
Sam: The study breaks it out clearly: encryption and decryption on the client side take just one or two seconds each, which is quick. But the central server's job of averaging those sealed updates—basically adding up the locked math from all 20 clients—jumps from under a second to around a minute per round. That's because doing arithmetic on encrypted data is computationally heavy, mostly on the central side, pushing total training time up by about 10 to 17 percent across models.
Alex: Huh—so clients barely notice, but the server grinds during those aggregation steps?
Sam: Exactly. Client round times stay similar or even dip slightly, while central times climb noticeably. On memory, clients see about a fourfold jump to around 4 gigabytes, but the central server takes the real hit—over 50 times more, often past 50 gigabytes.
Alex: And communication—that surge makes cross-device setups impractical right now?
Sam: For a typical model, unencrypted updates are about 9 kilobytes per client per round—tiny, like a short text. Encrypted, each balloons to around 259 megabytes, so with 20 clients, the server handles over 13 gigabytes incoming each time.
Alex: Right, so privacy locks everything down tight, but floods the network. Does squeezing the model smaller to cut that overhead hurt the tumor detection?
Sam: Yes—the paper shows reducing tunable parts to around 2,000 helps manage costs, but accuracy drops because simpler models miss finer details in MRI patterns, like subtle tumor edges. It's a direct trade-off: stronger privacy means leaner models and weaker performance on tasks like distinguishing glioma from meningioma.
Alex: Huh—ResNet holds up under encryption, but adding quantum tanks it? Why the drop there?
Sam: The paper cautions it's likely from simulating quantum parts on regular computers, which adds hidden slowdowns not seen on real quantum hardware. Also, deeper models like ResNet with quantum layers struggled to settle into good predictions on this MRI data, which varies between hospitals—think non-uniform lighting or scan angles causing "data heterogeneity." Reducing complexity for encryption amplified that.
Alex: Right, so even without quantum, bigger models crash on memory during encryption. The study flags untuned encryption settings too?
Sam: Exactly—using library defaults for encryption parameters meant more ciphertexts and higher costs than possible with tweaks. They encrypted every layer separately, inflating communication further.
Alex: So those limitations like untuned settings and shared computers paint a realistic picture. But pulling it all together, what's the main takeaway on balancing privacy with usable performance here?
Sam: The core insight is a clear trade-off: to tame the encryption's huge memory and communication demands, teams must slim down the model's adjustable parts, but that weakens its ability to spot subtle differences in brain tumors. Pre-trained setups like ResNet hold up well under encryption alone, delivering solid results on metrics that balance correct hits and avoiding false alarms. Yet adding quantum layers struggles, likely because MRI scans vary between hospitals in ways the simpler models can't handle. This first full test shows secure collaboration works in principle, but real clinics need fixes to make it practical—like encrypting only sensitive parts or fine-tuning settings.
Alex: Well said, Sam. This gives a clear sense of the challenges and next moves in secure quantum AI for medicine. Thanks for breaking it down. Thanks for listening to ResearchPod.