Quantum Federated Learning (QFL) enables distributed training of Quantum Machine Learning (QML) models by sharing model gradients instead of raw data. However, these gradients can still expose sensitive user information. To enhance privacy, homomorphic encryption of parameters has been proposed as a solution in QFL and related frameworks. In this work, we evaluate the overhead introduced by Fully Homomorphic Encryption (FHE) in QFL setups and assess its feasibility for real-world applications. We implemented various QML models including a Quantum Convolutional Neural Network (QCNN) trained in a federated environment with parameters encrypted using the CKKS scheme. This work marks the first QCNN trained in a federated setting with CKKS-encrypted parameters. Models of varying architectures were trained to predict brain tumors from MRI scans. The experiments reveal that memory and communication overhead remain substantial, making FHE challenging to deploy. Minimizing overhead requires reducing the number of model parameters, which, however, leads to a decline in classification performance, introducing a trade-off between privacy and model complexity.
Alex: Welcome to another episode of ResearchPod. Sam, what are we looking at today?
Sam: This episode covers a study called "Understanding the Resource Cost of Fully Homomorphic Encryption in Quantum Federated Learning" by Lukas Böhm and colleagues. They built and tested the first quantum convolutional neural network trained across multiple computers using a special kind of encryption. The key finding is that this encryption boosts privacy but adds huge costs in memory and data transfer, creating a tough trade-off for real use.
Alex: So this paper is basically asking if hospitals can team up to train AI models on patient brain scans without sharing the actual images or risking leaks—while using quantum tech for a potential speed boost?
Sam: Yes, exactly. Imagine hospitals each holding private MRI scans of brain tumors—they want to build a shared model to spot tumors better, but can't send raw patient data due to privacy laws like GDPR. Regular federated learning lets them share just the model's learning updates, called gradients, instead. But even those can leak info through attacks, so the researchers encrypt them with fully homomorphic encryption before sending.
Alex: Right, so the core problem is that even without sharing data, those updates might reveal patient details to a sneaky central server?
Sam: Precisely. The study tests this in quantum federated learning, where part of the model runs on quantum computers for possible efficiency gains. They use CKKS encryption—first, you lock data so math like adding or averaging can happen while still sealed, like doing puzzles on envelopes without opening them. Decrypting gives the right answer, keeping secrets safe. Their tests on brain tumor prediction show communication jumps enormously—from kilobytes to megabytes—and memory use climbs over 50 times, making it hard for practical hospital setups.
Alex: Okay, that trade-off sounds significant. To cut costs, do they shrink the model somehow?
Sam: They do, by reducing parameters—the model's adjustable knobs. Fewer knobs mean less to encrypt, easing the burden. But that drops accuracy in spotting tumors, as the paper notes: privacy wins, but performance suffers. This is the first time anyone's run a full quantum convolutional network this way, trained on MRI data with classical feature extractors like CNNs feeding into quantum layers.
Alex: So using pre-trained networks like ResNet keeps the quantum part small and tunable. But how do they actually get classical MRI images into those quantum circuits without losing the key details?
Sam: They start by shrinking the image data down to a simple list of numbers that fits the limited number of qubits available—like summarizing a whole photo into a handful of key features your brain notices first. A classical network, such as a CNN or ResNet, pulls out those features automatically. Researchers call this setup variational quantum circuits, where the quantum part acts like adjustable dials on qubits that twist based on those features. The qubits then process the twisted states through layers that mimic filtering and pooling in regular image analysis, before measuring to get predictions like tumor type.
Alex: With 20 clients each training on bits of the brain tumor MRI dataset, how does the central server combine their encrypted updates without peeking?
Sam: Each client trains locally on their share—about 250 images resized and normalized—computing changes to the model's dials, or gradients. They encrypt those gradients and send them sealed. The server adds up the encrypted values using a standard averaging method called FedAvg, without unlocking anything, then sends the combined result back for clients to decrypt and apply. This blocks attacks where a bad server might reconstruct patient images from raw gradients.
Alex: Right, so the server's just doing math on locked boxes. But the paper's tests show this encryption balloons communication—from 9 kilobytes to 258 megabytes per round?
Sam: Yes, and central memory jumps around 50 times higher too. They ran models like CNN-QCNN hybrids on the MRI dataset for tumor classes—glioma, meningioma, pituitary, no tumor—with accuracy holding steady but at huge resource cost. Shrinking tunable parameters helps feasibility, yet it trades off some classification precision, as smaller models miss subtle tumor patterns.
Alex: Sam, those broad costs are one thing, but what does the paper drill down into—like, where exactly does most of the slowdown hit during training?
Sam: The study breaks it out clearly: encryption and decryption on the client side take just one or two seconds each, which is quick. But the central server's job of averaging those sealed updates—basically adding up the locked math from all 20 clients—jumps from under a second to around a minute per round. That's because doing arithmetic on encrypted data is computationally heavy, mostly on the central side, pushing total training time up by about 10 to 17 percent across models.
Alex: Huh—so clients barely notice, but the server grinds during those aggregation steps?
Sam: Exactly. Client round times stay similar or even dip slightly, while central times climb noticeably. On memory, clients see about a fourfold jump to around 4 gigabytes, but the central server takes the real hit—over 50 times more, often past 50 gigabytes.
Alex: And communication—that surge makes cross-device setups impractical right now?
Sam: For a typical model, unencrypted updates are about 9 kilobytes per client per round—tiny, like a short text. Encrypted, each balloons to around 259 megabytes, so with 20 clients, the server handles over 13 gigabytes incoming each time.
Alex: Right, so privacy locks everything down tight, but floods the network. Does squeezing the model smaller to cut that overhead hurt the tumor detection?
Sam: Yes—the paper shows reducing tunable parts to around 2,000 helps manage costs, but accuracy drops because simpler models miss finer details in MRI patterns, like subtle tumor edges. It's a direct trade-off: stronger privacy means leaner models and weaker performance on tasks like distinguishing glioma from meningioma.
Alex: Huh—ResNet holds up under encryption, but adding quantum tanks it? Why the drop there?
Sam: The paper cautions it's likely from simulating quantum parts on regular computers, which adds hidden slowdowns not seen on real quantum hardware. Also, deeper models like ResNet with quantum layers struggled to settle into good predictions on this MRI data, which varies between hospitals—think non-uniform lighting or scan angles causing "data heterogeneity." Reducing complexity for encryption amplified that.
Alex: Right, so even without quantum, bigger models crash on memory during encryption. The study flags untuned encryption settings too?
Sam: Exactly—using library defaults for encryption parameters meant more ciphertexts and higher costs than possible with tweaks. They encrypted every layer separately, inflating communication further.
Alex: So those limitations like untuned settings and shared computers paint a realistic picture. But pulling it all together, what's the main takeaway on balancing privacy with usable performance here?
Sam: The core insight is a clear trade-off: to tame the encryption's huge memory and communication demands, teams must slim down the model's adjustable parts, but that weakens its ability to spot subtle differences in brain tumors. Pre-trained setups like ResNet hold up well under encryption alone, delivering solid results on metrics that balance correct hits and avoiding false alarms. Yet adding quantum layers struggles, likely because MRI scans vary between hospitals in ways the simpler models can't handle. This first full test shows secure collaboration works in principle, but real clinics need fixes to make it practical—like encrypting only sensitive parts or fine-tuning settings.
Alex: Well said, Sam. This gives a clear sense of the challenges and next moves in secure quantum AI for medicine. Thanks for breaking it down. Thanks for listening to ResearchPod.