Skip to main content

Documentation Index

Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt

Use this file to discover all available pages before exploring further.

This page presents detailed benchmark results comparing PVAC-HFHE against production-optimized FHE schemes from OpenFHE.

Schemes compared

SchemeTypeImplementationSecurity
BFVRLWE, exact integerOpenFHE 1.2128-bit
BGVRLWE, exact integerOpenFHE 1.2128-bit
CKKSRLWE, approximateOpenFHE 1.2128-bit
TFHEBit-levelOpenFHE 1.2128-bit
FHEWBit-level, GINXOpenFHE 1.2128-bit
PVAC-HFHELPN, exact uint64PoC/research128-bit (est)
All schemes are configured for 128-bit security. PVAC-HFHE security is based on the Learning Parity with Noise (LPN) problem, which is less studied than RLWE but undergoes active cryptanalytic evaluation.

Scalar multiplication (ct × ct)

SchemeModeTime (ms)vs PVAC
PVAC-HFHEscalar2.471.0x
BFVshallow (d=1)7.232.9x slower
BFVleveled (d=5)18.287.4x slower
BGVleveled17.617.1x slower
CKKSleveled35.2314.3x slower

BFV plaintext modulus comparison

BFV performance varies with plaintext modulus selection:
ModulusBitsRing dimMul time (ms)CT size
655371781928.81384 KB
7864332081928.12384 KB
2013265921311638419.751024 KB
BFV requires NTT-friendly primes (p-1 must be divisible by 2×ring_dim). PVAC-HFHE has no such constraint and works with arbitrary uint64 values.

Scalar addition (ct + ct)

Homomorphic addition performance:
SchemeTime (ms)vs PVAC
PVAC-HFHE0.0121.0x
BFV0.12410x slower
BGV0.55246x slower
CKKS1.05087x slower
PVAC-HFHE’s addition operation is extremely fast, ranging from 10x to 87x faster than RLWE schemes.

Ciphertext size

Fresh ciphertext comparison

SchemeModeSizevs PVAC
PVAC-HFHEscalar42 KB1.0x
BFVshallow256 KB6x larger
BFVleveled1024 KB24x larger
BGVleveled1792 KB43x larger
CKKSleveled3584 KB85x larger
PVAC-HFHE ciphertexts are dramatically smaller, ranging from 6x to 85x smaller than RLWE schemes for fresh encryptions.

PVAC-HFHE ciphertext growth with depth

PVAC-HFHE ciphertext size grows exponentially with circuit depth in the current PoC implementation.
DepthTime (ms)SizeGrowth factor
d0 (fresh)-42 KB1.0x
d12.6834 KB0.8x
d210.34136 KB3.2x
d331.46441 KB10.5x
d497.111359 KB32x
d5285.834112 KB98x
PVAC-HFHE ciphertext size exceeds BFV leveled at depth 4.

Circuit depth performance

Performance comparison across different multiplicative depths:
DepthPVAC-HFHEBFVBGVCKKSFastest
d12.68 ms19.54 ms17.40 ms35.85 msPVAC 7.3x
d210.34 ms14.38 ms15.11 ms31.22 msPVAC 1.4x
d331.46 ms13.98 ms14.39 ms30.71 msBFV 2.3x
d497.11 ms13.84 ms11.10 ms21.83 msBGV 8.7x
d5285.83 ms11.37 ms9.50 ms18.93 msBGV 30x
PVAC-HFHE (PoC) exhibits exponential performance degradation with depth, while RLWE schemes maintain near-constant performance through modulus switching and other optimizations.

Dot product (scalar vectors)

Vector dot product performance for various vector sizes:
Size (n)PVAC-HFHEBFVBGVCKKSSpeedup
49.61 ms73.24 ms74.55 ms156.53 ms7.6x
819.08 ms149.68 ms152.55 ms308.24 ms7.8x
1638.49 ms297.02 ms294.65 ms605.52 ms7.7x
3280.27 ms598.94 ms626.17 ms1218.69 ms7.5x
PVAC-HFHE maintains a consistent 7.5-7.8x speedup across all vector sizes.

Polynomial evaluation

Evaluating f(x) = 3x³ + 2x² + 5x + 7 (requires depth 3):
SchemeTime (ms)vs PVAC
PVAC-HFHE62.881.0x
BFV71.721.1x slower
BGV92.791.5x slower
CKKS182.352.9x slower
For degree-3 polynomials, PVAC-HFHE maintains competitive performance despite depth limitations.

Bit-level FHE comparison

NAND gate performance

Single NAND gate evaluation:
SchemeModeKeygen (ms)NAND (ms)
FHEWGINX37479.30
TFHEstd12844081.71
binfhe_apAP785102.56

Derived 64-bit multiplication

These estimates are derived by multiplying NAND gate latency by the number of gates required for 64-bit schoolbook multiplication (24,576 gates) without optimizations. This comparison is primarily academic, as bit-level FHE and scalar FHE solve different problems.
Scheme64-bit mul timevs PVAC
PVAC-HFHE2.47 ms1.0x
FHEW32.48 min789,000x slower
TFHE33.47 min813,000x slower
binfhe_ap42.01 min1,020,000x slower

TFHE-rs GPU comparison

Comparison with TFHE-rs on both CPU and GPU for 64-bit integer operations:
OperationPVAC-HFHE (PoC)TFHE-rs CPUTFHE-rs GPUvs CPUvs GPU
Addition0.012 ms109 ms8.97 ms9,083x747x
Subtraction0.012 ms109 ms8.97 ms9,083x747x
Multiplication2.47 ms402 ms31.9 ms163x13x
Source: TFHE-rs official benchmarks

SIMD and batch throughput

RLWE SIMD performance

RLWE schemes support native SIMD operations:
SchemeSlotsMul time (ms)Per-slot (μs)
BFV819217.852.18
CKKS409635.498.66

PVAC-HFHE parallel throughput

PVAC-HFHE parallel multiplication performance (8 threads):
OperationsSequential (ms)Parallel (ms)SpeedupThroughput
51213911897.4x2711 ops/s
204849637956.2x2575 ops/s
81921990426087.6x3141 ops/s

Throughput comparison

RLWE schemes achieve significantly higher throughput through native SIMD support, while PVAC-HFHE relies on multi-threading.
ModeOps/secondRelative
BFV SIMD (8192 slots)~459,000146x faster
PVAC-HFHE parallel (8 threads)~3,1411.0x

Key generation and encryption

Setup and encryption operation performance:
SchemeKeygen (ms)Encrypt (ms)Decrypt (ms)
BFV38.4310.912.54
BGV62.0312.703.48
CKKS143.6123.3410.37
PVAC-HFHE858.9584.1113.38
PVAC-HFHE key generation is 22x slower and encryption is 8x slower than BFV. This is acceptable for a proof of concept and is primarily due to unoptimized initialization. However, key generation typically only needs to be performed once.

Key sizes

Public key and ciphertext size comparison:
SchemePublic key sizeCT size
PVAC-HFHE8 MB42 KB
BFV-1024 KB
BGV-1792 KB
CKKS-3584 KB
PVAC-HFHE has a larger public key (8 MB) but much smaller ciphertexts for fresh encryptions.

Performance summary

Where PVAC-HFHE excels

  • Scalar multiplication (2.9-14.3x faster)
  • Scalar addition (10-87x faster)
  • Dot products (7.5-7.8x faster)
  • Fresh ciphertext size (6-85x smaller)
  • Shallow circuits (depth 1-2)

Where RLWE schemes excel

  • Deep circuits (depth ≥ 3)
  • SIMD batch processing (146x higher throughput)
  • Ciphertext size at depth ≥ 4
  • Key generation and encryption speed
Choose PVAC-HFHE for applications requiring fast scalar arithmetic at shallow depths with minimal ciphertext size. Choose RLWE schemes for deep circuits or batch processing workloads.

Build docs developers (and LLMs) love