← Latest papers
⚛️ quantum physics

Encryptability As a Coordinate Choice: Depth-One Homomorphic Federated Learning of Quantum Neural Networks

This paper demonstrates that by representing quantum neural network weights in a unit-quaternion coordinate system, the non-linear group operations required for encrypted federated learning become bilinear, thereby enabling efficient, non-interactive, depth-one homomorphic training of hybrid quantum-classical models with negligible accuracy loss and no need for bootstrapping.

Original authors: Marcel Mordarski, Nathan Mani, Arshad Patel, William Knottenbelt, Roberto Bondesan

Published 2026-09-28
📖 6 min read🧠 Deep dive

Original authors: Marcel Mordarski, Nathan Mani, Arshad Patel, William Knottenbelt, Roberto Bondesan

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the modern world of artificial intelligence, machines learn by finding patterns in vast amounts of data. Often, this data is sensitive, belonging to individuals who wish to keep it private, such as medical records or personal financial history. To solve this, scientists developed a method called federated learning, where the data stays on the user's device, and only the lessons learned from it are sent to a central server to improve a shared model. However, sending even these lessons carries a risk: a curious observer could potentially reverse-engineer the original data from the updates. To prevent this, researchers use a technique called encryption, which scrambles the information so that only the intended recipient can read it. The challenge arises when the learning model involves quantum computers, which operate on the strange rules of quantum physics. In these systems, the numbers used to train the model are not simple values but represent rotations in a complex, multi-dimensional space. For a long time, encrypting these specific types of rotations was thought to be prohibitively expensive, requiring so much computational power that it made the process impractical.

A team of researchers at Imperial College London has discovered that this difficulty was not a fundamental law of nature, but rather a consequence of how the numbers were being written down. They found that by changing the mathematical "language" used to describe these quantum rotations, the process of encrypting them becomes surprisingly simple and efficient. Instead of using a complex system that required thousands of steps for every single update, the researchers showed that using a specific coordinate system based on unit quaternions reduces the work to a single, straightforward calculation. This breakthrough allows quantum neural networks to be trained across many devices while keeping the data completely hidden, without the heavy computational penalty that previously made it impossible.

The core of the problem lay in how quantum computers describe their operations. The trainable parts of these machines are essentially rotations, similar to turning a dial. In the standard way of describing these turns, the math involved was so complex that encrypting the updates required a massive amount of processing, often needing thousands of separate operations for every single weight in the network. This made the idea of privacy-preserving quantum learning seem out of reach. The researchers realized that the complexity was an artifact of the coordinate system, much like how describing a circle using a jagged, step-by-step grid makes it look complicated, whereas describing it with a smooth curve makes it simple. By switching to a system based on unit quaternions, a mathematical tool that describes rotations in four dimensions, the relationship between the numbers became perfectly linear and simple. In this new language, combining two rotations is just a basic multiplication, a task that encryption systems can handle with ease.

This shift in perspective transformed the entire process. The researchers demonstrated that with this new coordinate choice, the server could combine the encrypted updates from many different clients without ever needing to decrypt them or perform the heavy, repetitive calculations that were previously required. The process became so efficient that it eliminated the need for a specific, time-consuming step known as bootstrapping, which was previously thought to be essential for keeping the encryption secure during complex calculations. The team built a working protocol that allowed clients to train their models locally, encrypt the results using this new method, and send them to a server. The server then combined these updates and sent the result back, all while the data remained scrambled. They tested this system on two different cryptographic backends to ensure the results were not just a fluke of one specific software, confirming that the efficiency gain was a fundamental property of the mathematics itself.

To verify that this new method did not sacrifice the quality of the learning, the team conducted rigorous experiments. They trained a hybrid model, which combines a small quantum circuit with a classical computer, on real-world datasets like housing prices and wine quality. They compared the performance of the encrypted system directly against an identical unencrypted system, running the tests multiple times with different starting conditions to ensure fairness. The results showed that the encryption added no measurable penalty to the learning process. The accuracy of the model remained exactly the same, proving that the privacy protection did not come at the cost of performance. Furthermore, they tested whether the noise introduced by encryption might accidentally help the model learn better, a phenomenon sometimes seen in other contexts. By running the system with different levels of precision, they found that adding more noise did not improve the results, confirming that the encryption was simply a transparent shield rather than a hidden helper.

The researchers also addressed the practical issue of how these models handle connections between different parts of the quantum circuit, known as entanglers. They proved mathematically that even with these complex connections, the new encryption method only added a constant, small amount of work, regardless of how deep or complex the circuit became. This means the efficiency of the method holds up even as the models grow larger and more sophisticated. To validate the findings in the real world, they ran the protocol on a physical quantum processor with 156 qubits. The system achieved a high level of fidelity, meaning the encrypted operations worked almost as perfectly as the unencrypted ones, with the tiny difference being attributable to the natural imperfections of the hardware rather than the encryption itself.

The study also highlighted the trade-offs involved in this approach. While the new method drastically reduced the number of communication rounds needed between the server and the clients—dropping from dozens of exchanges down to just one—it required sending larger amounts of data in each exchange. The researchers calculated that this trade-off is beneficial for most real-world scenarios, particularly those involving wide-area networks where the speed of the connection is the limiting factor. They noted that for very fast, local connections, the old interactive methods might still be slightly more efficient, but for the broader, cross-institutional networks where privacy is most critical, the new method offers a clear advantage. The work concludes that the barrier to encrypted quantum learning was never a lack of power, but a choice of perspective. By recognizing that the difficulty was a coordinate problem rather than a fundamental one, the researchers have opened the door to a future where quantum machines can learn collaboratively without ever compromising the privacy of the data they use.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →