Open this publication in new window or tab >>2026 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]
The development of edge computing, Internet-of-Things (IoT), and AI-driven services involves increasing volumes of sensitive data at the network edge, including health records, industrial sensor readings, and personal information. Regulatory frameworks such as the GDPR, the European Health Data Space, and the EU AI Act impose strict requirements on such processing. However, privacy-enhancing technologies face trade-offs between privacy, utility, and computational cost that limit their practical uptake.
This thesis investigates how these trade-offs can be addressed through encrypted machine learning (ML) inference, architecture co-design for efficient encrypted computation, and privacy-preserving model training. The six appended papers address these trade-offs through controlled computational experiments and prototype-level studies, situated in different application domains and regulatory contexts.
First, fully homomorphic encryption (FHE) is applied to health-data processing and to remote monitoring and control of edge data center systems, to examine the feasibility of encrypted lightweight ML tasks. Two encryption schemes, CKKS and TFHE, are evaluated with the data remaining encrypted and the algorithm retained by the service provider. They prove complementary—TFHE suits non-polynomial operations, CKKS vectorized arithmetic—with execution times from milliseconds to tens of seconds.
Second, the computational bottleneck of neural network inference under FHE is addressed through architecture co-design. A novel mechanism is proposed—the Inhibitor—which replaces the variable-to-variable multiplications and softmax activations of conventional gated RNNs and Transformer attention with encryption-friendly addition and ReLU operations. Knowledge distillation produces a compact Inhibitor-based DistilBERT within 2.5 points of the conventional model on the GLUE average, and under TFHE the attention component shows a 3–6x speedup at short sequence lengths.
Third, two methods are developed to reduce privacy risk in distributed or sensitive-data training. A local conditioning approach for heterogeneous federated learning keeps client-specific statistics on the client, removing the peer-search of clustered methods—it therefore scales as standard federated averaging and sends nothing beyond the ordinary model updates. A complementary instance-targeted obfuscation method reduces measured membership-inference vulnerability by an order of magnitude at the evaluated operating point, without statistically significant loss of aggregate accuracy.
The contributions examine the trade-offs between privacy, utility, and computational cost, and propose methods that improve those trade-offs for the problems studied. Together they target the gap between what regulation demands and what technology can deliver, though validation in production deployments remains future work.
Place, publisher, year, edition, pages
Luleå: Luleå University of Technology, 2026
Series
Doctoral thesis / Luleå University of Technology, ISSN 1402-1544
Keywords
Privacy-preserving machine learning, Fully homomorphic encryption (FHE), Edge computing, Federated learning, Differential privacy, Neural architecture co-design, Membership inference, Privacy auditing, Privacy-enhancing technologies (PETs), Integritetsbevarande maskininlärning, Fullt homomorf kryptering (FHE), Kantberäkning, Federerad maskininlärning, Differentiell integritet, Dataskyddsreglering för AI, Integritetsstärkande tekniker (PET)
National Category
Computer Sciences Computer Systems
Research subject
Machine Learning
Identifiers
urn:nbn:se:ltu:diva-118353 (URN)978-91-8142-097-5 (ISBN)978-91-8142-098-2 (ISBN)
Public defence
2026-09-30, A117, Luleå University of Technology, Luleå, 09:00 (English)
Opponent
Supervisors
2026-06-162026-06-152026-09-09Bibliographically approved