Skip to main content
This page presents detailed benchmark results comparing PVAC-HFHE against production-optimized FHE schemes from OpenFHE.

Schemes compared

All schemes are configured for 128-bit security. PVAC-HFHE security is based on the Learning Parity with Noise (LPN) problem, which is less studied than RLWE but undergoes active cryptanalytic evaluation.

Scalar multiplication (ct × ct)

BFV plaintext modulus comparison

BFV performance varies with plaintext modulus selection:
BFV requires NTT-friendly primes (p-1 must be divisible by 2×ring_dim). PVAC-HFHE has no such constraint and works with arbitrary uint64 values.

Scalar addition (ct + ct)

Homomorphic addition performance: PVAC-HFHE’s addition operation is extremely fast, ranging from 10x to 87x faster than RLWE schemes.

Ciphertext size

Fresh ciphertext comparison

PVAC-HFHE ciphertexts are dramatically smaller, ranging from 6x to 85x smaller than RLWE schemes for fresh encryptions.

PVAC-HFHE ciphertext growth with depth

PVAC-HFHE ciphertext size grows exponentially with circuit depth in the current PoC implementation.
PVAC-HFHE ciphertext size exceeds BFV leveled at depth 4.

Circuit depth performance

Performance comparison across different multiplicative depths:
PVAC-HFHE (PoC) exhibits exponential performance degradation with depth, while RLWE schemes maintain near-constant performance through modulus switching and other optimizations.

Dot product (scalar vectors)

Vector dot product performance for various vector sizes: PVAC-HFHE maintains a consistent 7.5-7.8x speedup across all vector sizes.

Polynomial evaluation

Evaluating f(x) = 3x³ + 2x² + 5x + 7 (requires depth 3): For degree-3 polynomials, PVAC-HFHE maintains competitive performance despite depth limitations.

Bit-level FHE comparison

NAND gate performance

Single NAND gate evaluation:

Derived 64-bit multiplication

These estimates are derived by multiplying NAND gate latency by the number of gates required for 64-bit schoolbook multiplication (24,576 gates) without optimizations. This comparison is primarily academic, as bit-level FHE and scalar FHE solve different problems.

TFHE-rs GPU comparison

Comparison with TFHE-rs on both CPU and GPU for 64-bit integer operations: Source: TFHE-rs official benchmarks

SIMD and batch throughput

RLWE SIMD performance

RLWE schemes support native SIMD operations:

PVAC-HFHE parallel throughput

PVAC-HFHE parallel multiplication performance (8 threads):

Throughput comparison

RLWE schemes achieve significantly higher throughput through native SIMD support, while PVAC-HFHE relies on multi-threading.

Key generation and encryption

Setup and encryption operation performance:
PVAC-HFHE key generation is 22x slower and encryption is 8x slower than BFV. This is acceptable for a proof of concept and is primarily due to unoptimized initialization. However, key generation typically only needs to be performed once.

Key sizes

Public key and ciphertext size comparison: PVAC-HFHE has a larger public key (8 MB) but much smaller ciphertexts for fresh encryptions.

Performance summary

Where PVAC-HFHE excels

  • Scalar multiplication (2.9-14.3x faster)
  • Scalar addition (10-87x faster)
  • Dot products (7.5-7.8x faster)
  • Fresh ciphertext size (6-85x smaller)
  • Shallow circuits (depth 1-2)

Where RLWE schemes excel

  • Deep circuits (depth ≥ 3)
  • SIMD batch processing (146x higher throughput)
  • Ciphertext size at depth ≥ 4
  • Key generation and encryption speed
Choose PVAC-HFHE for applications requiring fast scalar arithmetic at shallow depths with minimal ciphertext size. Choose RLWE schemes for deep circuits or batch processing workloads.