<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="EN">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Cardiovasc. Med.</journal-id>
<journal-title>Frontiers in Cardiovascular Medicine</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Cardiovasc. Med.</abbrev-journal-title>
<issn pub-type="epub">2297-055X</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/fcvm.2023.1117360</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Cardiovascular Medicine</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Towards realistic privacy-preserving deep learning over encrypted medical data</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes"><name><surname>Cabrero-Holgueras</surname><given-names>Jos&#x00E9;</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<xref ref-type="corresp" rid="cor1">&#x002A;</xref><uri xlink:href="https://loop.frontiersin.org/people/2040631/overview"/></contrib>
<contrib contrib-type="author"><name><surname>Pastrana</surname><given-names>Sergio</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref></contrib>
</contrib-group>
<aff id="aff1"><label><sup>1</sup></label><institution>Innovation, IT Department, CERN</institution>, <addr-line>Geneva</addr-line>, <country>Switzerland</country></aff>
<aff id="aff2"><label><sup>2</sup></label><addr-line>Computer Science Department</addr-line>, <institution>Universidad Carlos III de Madrid</institution>, <addr-line>Madrid</addr-line>, <country>Spain</country></aff>
<author-notes>
<fn fn-type="edited-by"><p><bold>Edited by:</bold> Arrigo Francesco Giuseppe Cicero, University of Bologna, Italy</p></fn>
<fn fn-type="edited-by"><p><bold>Reviewed by:</bold> Leonard Johard, Innopolis University, Russia, Chinmay Chakraborty, Birla Institute of Technology, India</p></fn>
<corresp id="cor1"><label>&#x002A;</label><bold>Correspondence:</bold> Jos&#x00E9; Cabrero-Holgueras <email>jose.cabrero@alumnos.uc3m.es</email></corresp>
<fn fn-type="other" id="fn001"><p><bold>Specialty Section:</bold> This article was submitted to General Cardiovascular Medicine, a section of the journal Frontiers in Cardiovascular Medicine</p></fn>
</author-notes>
<pub-date pub-type="epub"><day>28</day><month>04</month><year>2023</year></pub-date>
<pub-date pub-type="collection"><year>2023</year></pub-date>
<volume>10</volume><elocation-id>1117360</elocation-id>
<history>
<date date-type="received"><day>06</day><month>12</month><year>2022</year></date>
<date date-type="accepted"><day>31</day><month>03</month><year>2023</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Cabrero-Holgueras and Pastrana.</copyright-statement>
<copyright-year>2023</copyright-year><copyright-holder>Cabrero-Holgueras and Pastrana</copyright-holder><license license-type="open-access" xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the <ext-link ext-link-type="uri" xlink:href="http://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution License (CC BY)</ext-link>. The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p></license>
</permissions>
<abstract>
<p>Cardiovascular disease supposes a substantial fraction of healthcare systems. The invisible nature of these pathologies demands solutions that enable remote monitoring and tracking. Deep Learning (DL) has arisen as a solution in many fields, and in healthcare, multiple successful applications exist for image enhancement and health outside hospitals. However, the computational requirements and the need for large-scale datasets limit DL. Thus, we often offload computation onto server infrastructure, and various Machine-Learning-as-a-Service (MLaaS) platforms emerged from this need. These enable the conduction of heavy computations in a cloud infrastructure, usually equipped with high-performance computing servers. Unfortunately, the technical barriers persist in healthcare ecosystems since sending sensitive data (e.g., medical records or personally identifiable information) to third-party servers involves privacy and security concerns with legal and ethical implications. In the scope of Deep Learning for Healthcare to improve cardiovascular health, Homomorphic Encryption (HE) is a promising tool to enable secure, private, and legal health outside hospitals. Homomorphic Encryption allows for privacy-preserving computations over encrypted data, thus preserving the privacy of the processed information. Efficient HE requires structural optimizations to perform the complex computation of the internal layers. One such optimization is Packed Homomorphic Encryption (PHE), which encodes multiple elements on a single ciphertext, allowing for efficient Single Instruction over Multiple Data (SIMD) operations. However, using PHE in DL circuits is not straightforward, and it demands new algorithms and data encoding, which existing literature has not adequately addressed. To fill this gap, in this work, we elaborate on novel algorithms to adapt the linear algebra operations of DL layers to PHE. Concretely, we focus on Convolutional Neural Networks. We provide detailed descriptions and insights into the different algorithms and efficient inter-layer data format conversion mechanisms. We formally analyze the complexity of the algorithms in terms of performance metrics and provide guidelines and recommendations for adapting architectures that deal with private data. Furthermore, we confirm the theoretical analysis with practical experimentation. Among other conclusions, we prove that our new algorithms speed up the processing of convolutional layers compared to the existing proposals.</p>
</abstract>
<kwd-group>
<kwd>privacy-preserving</kwd>
<kwd>deep learning</kwd>
<kwd>healthcare</kwd>
<kwd>homomorphic encryption</kwd>
<kwd>SIMD</kwd>
<kwd>linear algebra</kwd>
<kwd>algorithms</kwd>
</kwd-group><contract-num rid="cn002">PID2019-111429RB-C21, PID2019-111429RB</contract-num><contract-num rid="cn003">P2018/TCS-4566</contract-num><contract-sponsor id="cn001">CERN<named-content content-type="fundref-id">10.13039/100012470</named-content></contract-sponsor><contract-sponsor id="cn002">Spanish<named-content content-type="fundref-id">10.13039/501100004837</named-content></contract-sponsor><contract-sponsor id="cn003">Region of Madrid<named-content content-type="fundref-id">10.13039/100012818</named-content></contract-sponsor><counts>
<fig-count count="9"/>
<table-count count="18"/><equation-count count="697"/><ref-count count="52"/><page-count count="0"/><word-count count="0"/></counts>
</article-meta>
</front>
<body><sec id="s1" sec-type="intro"><label>1.</label><title>Introduction</title>
<p>Cardiovascular diseases produce substantial costs to health systems (<xref ref-type="bibr" rid="B1">1</xref>). The invisible nature of these pathologies makes them deadlier and more challenging to track and detect (<xref ref-type="bibr" rid="B2">2</xref>). The growing efforts to prevent cardiovascular disease go through continuous and more effective monitoring. However, monitoring and healthcare outside hospitals introduce often-neglected challenges in various domains. First, remote monitoring requires introducing automatic systems that monitor and perform data analytics on patients&#x2019; data. Second, due to the sensitive nature of that data, sharing and transmission involve legal, privacy, and security issues.</p>
<p>Deep Learning (DL) has stood as a driver of a new revolution carrying improvements and automation into many fields. In healthcare, multiple examples exist of successful applications of DL (<xref ref-type="bibr" rid="B3">3</xref>&#x2013;<xref ref-type="bibr" rid="B5">5</xref>); specifically, these models have succeeded in enhancing medical imaging and health outside hospitals. Deep Learning can help bridge these needs for automatic analysis outside healthcare centers, yet, the sensitive nature of data presents legal and ethical requirements for this data to be shared and adds to existing challenges due to model training and inference and computational capacity (<xref ref-type="bibr" rid="B6">6</xref>).</p>
<p>With the recent growth of cloud computing, DL has benefited from significant performance optimizations and flexible environments for its deployment. Concretely, Machine Learning as a Service (MLaaS) allows offloading computations to specialized third-party servers that benefit model owners. This paradigm has two main benefits. First, it relieves the client endpoint from heavy workloads since the processing burden is outsourced to high-performance computing servers (<xref ref-type="bibr" rid="B7">7</xref>, <xref ref-type="bibr" rid="B8">8</xref>). Second, it eases the integration of different stakeholders to work in a collaborative environment, where they could contribute with their data to train a common model (<xref ref-type="bibr" rid="B9">9</xref>&#x2013;<xref ref-type="bibr" rid="B11">11</xref>). However, scientific applications where sensitive data needs to be exchanged (e.g., healthcare or finances) have not sufficiently profited from the advantages of MLaaS due to ethical and legal restrictions when sharing the data (<xref ref-type="bibr" rid="B12">12</xref>, <xref ref-type="bibr" rid="B13">13</xref>).</p>
<p>During the last decade, multiple innovations have enabled secure data exchanges and private computation using Privacy-Preserving Computation Techniques (PPCT), e.g., Homomorphic Encryption (HE) and Secure Multiparty Computation (SMPC) (<xref ref-type="bibr" rid="B14">14</xref>). These techniques enhance the security and privacy of the cloud ecosystem by enabling users to safely and privately share data for its computation on external servers, either as a standalone procedure or in a collaborative environment.</p>
<p>In particular, HE schemes enable performing operations over the encrypted <italic>ciphertext</italic> without disclosing information about the <italic>cleartext</italic> data. A key milestone was the discovery of bootstrapping by Gentry in 2009, which allows (theoretically) to perform unlimited computation, i.e., HE was proven Fully Homomorphic (<xref ref-type="bibr" rid="B15">15</xref>). Since then, multiple improvements have made HE more efficient and practical (<xref ref-type="bibr" rid="B16">16</xref>). One such fundamental improvement is <italic>Ciphertext Packing</italic>, which allows the encoding of various entries of plaintext data (encoded as a vector) within a single ciphertext (<xref ref-type="bibr" rid="B17">17</xref>). Packing improves efficiency through Single Instruction Multiple Data (SIMD) since the individual operations to the ciphertext affect all the individual entries of the underlying plaintext vector. <xref ref-type="fig" rid="F1">Figure&#x00A0;1</xref> shows how HE packing works for a 2D Matrix. First, we transform the matrix into a vector using a Row-Column format. Then, we encode (packed) and encrypt it. Then, we can operate the ciphertext can using SIMD, where we modify all the elements of the encrypted vector (matrix)with each instruction.</p>
<fig id="F1" position="float"><label>Figure 1</label>
<caption><p>Encryption procedure for Homomorphic Encryption Schemes based on Learning with Errors (LWE).</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g001.tif"/>
</fig>
<sec id="s1a"><label>1.1.</label><title>Motivation</title>
<p>Over the last few years, there has been significant progress on the cryptographic protocols and theories related to ciphertext packing, which promises substantial improvements in the application of HE in complex, distributed applications such as Deep Learning for healthcare remote analysis and monitoring. However, adapting existing operations for SIMD over ciphertext packing is non-trivial.</p>
<p>Unfortunately, the application of ciphertext packing in DL is not straightforward. Indeed, the linear algebra operations used in the internal structures highly affect the performance (<xref ref-type="bibr" rid="B18">18</xref>). Understanding the impact of the ordering and election of internal operations on global performance is critical for designing efficient algorithms. However, this complex task requires a proper understanding of cryptographic protocols.</p>
<p>Existing works have attempted to automatically transform linear algebra algorithms so they can be applied using SIMD over packed ciphertexts (<xref ref-type="bibr" rid="B18">18</xref>&#x2013;<xref ref-type="bibr" rid="B20">20</xref>) (see <xref ref-type="sec" rid="s6">Section 6</xref>). However, these works provide simplistic views of the required algorithms, which limit their reproducibility and implementation in real-world architectures. Moreover, the algorithms are described and tested for isolated computations, far from the complex workflow and interconnections from the internal layers of Deep Learning. Since the input and output encoding of ciphertext packing differs from regular operations, it is necessary to account for the different formats of the inputs and outputs in each layer of the DL architecture and how these affect the overall performance. For example, when using SIMD operations, it is required to transform the output of a Convolutional Layer to be a valid input for subsequent Dense Layer. These transformations have not been described or accounted for the overall overhead in previous works. Also, depending on specific details of the DL layer, e.g., the use of stride or padding, this transformation requires different adaptions (we provide background on CNNs in <xref ref-type="sec" rid="s2c">Section 2.3</xref>). Furthermore, in rotations with packed ciphertexts, the last entries overflow to the first positions. Our work shows how some algorithms profit from this overflow to perform computation.</p>
<p>Overall, existing proposals either leave the adaptation to HE on the user (<xref ref-type="bibr" rid="B19">19</xref>) or provide algorithms that are not general for inputs of any size (<xref ref-type="bibr" rid="B18">18</xref>). Accordingly, we formulate the following research question:</p><disp-quote>
<p><italic>How can we adapt linear algebra operations used internally in DL architectures to operate with packed ciphertexts, so they can benefit from the improvements of <monospace>SIMD</monospace> operations for Homomorphic Encryption, and thus enable the analysis of privacy-sensitive medical images by untrusted parties?</italic></p></disp-quote>
</sec>
<sec id="s1b"><label>1.2.</label><title>Contribution</title>
<p>To tackle the question mentioned above, in this paper we describe a set of algorithms to efficiently transform the operations of Convolutional Neural Networks for their use on packed vectors. A key aspect in the design of the algorithms for cardiovascular diseases is that they work on arbitrary-sized input matrices and vectors, and thus they can adapt to medical images of any size. We provide a holistic view of the DL inference process by not only understanding the individual linear operations required by the algorithms but also the collective relationship of the different layers. For the first time, we show that the transformations required to interconnect the layers pose a significant overhead, which should be considered in the design of the DL architecture.</p>
<p>In summary, the main contributions proposed in this research are the following:
<list list-type="simple">
<list-item><label>1.</label>
<p>We describe algorithms for executing each layer of a Convolutional Neural Network (CNN) using SIMD HE over packed ciphertexts (<xref ref-type="sec" rid="s3">Section 3</xref>). We include algorithms to adapt the input and output encodings to meet the format required on each layer. As a fundamental contribution, we illustrate these algorithms to consider as inputs arbitrary size matrices, allowing their application to different existing architectures. Among these, we provide a streamlined version of the convolution algorithm that significantly improves the efficiency of the previously considered algorithms.</p></list-item>
<list-item><label>2.</label>
<p>We present a formal analysis of the different algorithms and their application to HE (<xref ref-type="sec" rid="s4">Section 4</xref>). We first define a set of metrics to compare the algorithms regarding HE constraints. Then, we analyze the impact of these metrics on the performance of all the algorithms. Finally, using the results of this analysis, we provide a set of recommendations and takeaways for applying the algorithms to DL inference. These conclusions allow us to understand the constraints and challenges of applying SIMD operations inside DL architectures.</p></list-item>
<list-item><label>3.</label>
<p>We empirically test the impact of the proposed algorithms in different use cases to practically verify the takeaways extracted (<xref ref-type="sec" rid="s5">Section 5</xref>). We measure the performance impact of the different stages of the algorithms. We observe how our conclusions match the obtained results. Also, it helps validate our claims that format transformations involve complex processing that we should not take out of the equation for Packed Homomorphic Encryption.</p></list-item>
</list>Overall, this paper shows off an existing problem arising from adapting DL architectures&#x2019; complex and interrelated operations for their efficient usage with ciphertext Packing and SIMD operations. The proposed algorithms and guidelines will allow programmers to simplify the adaption of existing CNN architectures, thus optimizing the inference process over encrypted data. To assist in the implementation of these algorithms, we provide prototype implementations in our GitHub repository<xref ref-type="fn" rid="FN0001"><sup>1</sup></xref> .</p>
</sec>
<sec id="s1c"><label>1.3.</label><title>Paper structure</title>
<p>The rest of the paper is organized as follows. First, we provide background information and describe the adversarial model in <xref ref-type="sec" rid="s2">Section 2</xref>. Second, we describe the different algorithms in <xref ref-type="sec" rid="s3">Section 3</xref>. Third, we conduct a formal analysis for the efficiency and performance of the algorithms in <xref ref-type="sec" rid="s4">Section 4</xref>. Fourth, we empirically evaluate a working prototype in well-defined tests in <xref ref-type="sec" rid="s5">Section 5</xref>. Finally, we discuss conclusions and future work in <xref ref-type="sec" rid="s7">Section 7</xref>.</p>
</sec>
</sec>
<sec id="s2"><label>2.</label><title>Background</title>
<p>This section provides base knowledge for the concepts used in the remainder of the document. We first describe the adversarial model and the privacy requirements assumed. Then, we cover an introduction to Homomorphic Encryption, and finally, we describe the Deep Learning Structures considered in the proposed algorithms.</p>
<sec id="s2a"><label>2.1.</label><title>Adversarial model</title>
<p>In this work, we consider an Honest-but-Curious adversary (<xref ref-type="bibr" rid="B21">21</xref>&#x2013;<xref ref-type="bibr" rid="B23">23</xref>), a passive adversary that complies with the protocol and does not tamper with the data for malicious purposes. However, it tries to learn as much information from data exchanges. Homomorphic Encryption inherently guarantees input privacy (i.e., the privacy of the data sent to the cloud during the inference process is guaranteed). However, HE does not account for the output privacy of the model. Thus, in our work, we assume that the service provider either is proprietary or has access to the model.<xref ref-type="fn" rid="FN0002"><sup>2</sup></xref></p>
<p>Furthermore, for all of our use cases, we consider the set of parameters established for the Learning with Errors problem following the guidelines described in the Homomorphic Encryption Security Standard (<xref ref-type="bibr" rid="B24">24</xref>). Thus, these parameters provide a secure environment for the execution of the algorithms.</p>
</sec>
<sec id="s2b"><label>2.2.</label><title>Homomorphic encryption</title>
<p>Homomorphic Encryption (HE) is a property of an encryption scheme that permits operating with the ciphertext while translating those changes to the underlying plaintext. This work focuses on widely used HE schemes based on the Ring Learning with Errors (RLWE) problem (<xref ref-type="bibr" rid="B25">25</xref>).</p>
<p>Concretely, we focus on Levelled Homomorphic Encryption (LHE) Schemes (<xref ref-type="bibr" rid="B16">16</xref>). In these schemes, we represent the RLWE polynomial coefficient modulus <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM1"><mml:mi>Q</mml:mi></mml:math></inline-formula> with a Chinese Remainder Theorem (CRT) coefficient moduli chain <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM2"><mml:msub><mml:mi>q</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. The representation allows performing a rescaling operation after each multiplication, thus reducing the incurred noise. Also, it reduces the size of the numbers that schemes have to treat. We note that these techniques do not restrict their application to FHE Packed Schemes, but their application to LHE Schemes remains more constraining and thus relevant.</p>
<p>A key point of LHE is the cost of individual operations on the underlying ciphertext representation, as ciphertext are big polynomials (<xref ref-type="bibr" rid="B17">17</xref>). Ciphertext Packing arose as a solution by enabling the introduction of more than one plaintext element per ciphertext (<xref ref-type="bibr" rid="B17">17</xref>). It permits executing Single-Instructions-Multiple-Data (SIMD) operations (i.e., the execution of an HE operation on a ciphertext propagates to the underlying plaintext vector).</p>
<p>An essential aspect of LHE design is parameter selection. The parameter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM3"><mml:mi>N</mml:mi></mml:math></inline-formula>, or polynomial degree, affects the various matrix operations presented in this paper. This parameter establishes the degree of the polynomial. Also, packed schemes define the number of plaintext elements <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM4"><mml:mi>n</mml:mi></mml:math></inline-formula> that a ciphertext can accommodate, i.e., the maximum length of a vector that can be encoded (see <xref ref-type="fig" rid="F1">Figure&#x00A0;1</xref>). Schemes such as BFV (<xref ref-type="bibr" rid="B26">26</xref>) allow packing as many elements as the length of the polynomial (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM5"><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>). In the scheme CKKS (<xref ref-type="bibr" rid="B27">27</xref>), though, due to the complex number packing, it is only possible to pack half of the vector size (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM6"><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula>). This paper treats parameter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM7"><mml:mi>N</mml:mi></mml:math></inline-formula> independently of the scheme (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM8"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>). However, all the conclusions are valid to CKKS by substituting <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM9"><mml:mi>N</mml:mi></mml:math></inline-formula> by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM10"><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula>. In Section <xref ref-type="sec" rid="s4a">4.1</xref>, we analyze the implications of different parameter selections on the efficiency of the algorithms. Next, we describe the basic routines of an HE scheme:
<list list-type="simple">
<list-item><label><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM11"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></label>
<p>A <bold>key generation</bold> routine produces a public key <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM12"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> and its corresponding private key <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM13"><mml:msub><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, defined by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM14"><mml:mi>K</mml:mi><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>Q</mml:mi><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM15"><mml:mi>N</mml:mi></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM16"><mml:mi>Q</mml:mi></mml:math></inline-formula> are the homomorphic encryption parameters.</p></list-item>
<list-item><label><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM17"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></label>
<p>The <bold>encoding</bold> routine takes a plaintext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM18"><mml:mi>v</mml:mi></mml:math></inline-formula> and encodes it based on the HE parameter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM19"><mml:mi>N</mml:mi></mml:math></inline-formula> obtaining <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM20"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> such that <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM21"><mml:mi>E</mml:mi><mml:mi>N</mml:mi><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>v</mml:mi><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. There is an inverse <bold>decoding</bold> routine that takes the encoded vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM22"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and obtains the plaintext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM23"><mml:mi>v</mml:mi></mml:math></inline-formula> such that <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM24"><mml:mi>D</mml:mi><mml:mi>E</mml:mi><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>v</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item><label><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM25"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></label>
<p>The <bold>encryption</bold> routine takes a public key <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM26"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> and an encoded vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM27"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to generate a ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM28"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> such that <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM29"><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>. The inverse <bold>decryption</bold> routine takes a ciphertext <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM30"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> and uses the private key <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM31"><mml:msub><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> to obtain the encoded vector such that <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM32"><mml:mi>D</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM33"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></label>
<p>The different <bold>evaluation</bold> routines compute over the ciphertext <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM34"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> one of the following operations: Element-wise Sum (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM35"><mml:mo>&#x2295;</mml:mo></mml:math></inline-formula>) Element-wise Subtraction (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM36"><mml:mo>&#x2296;</mml:mo></mml:math></inline-formula>), Element-wise Multiplication (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM37"><mml:mo>&#x2299;</mml:mo></mml:math></inline-formula>), and left/right Rotation (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM38"><mml:mo>&#x226A;</mml:mo></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM39"><mml:mo>&#x226B;</mml:mo></mml:math></inline-formula> respectively). We depict the SIMD schemes operation behavior in <xref ref-type="fig" rid="F2">Figure&#x00A0;2</xref>.</p></list-item>
</list></p>
<fig id="F2" position="float"><label>Figure 2</label>
<caption><p>SIMD Operations allowed by CKKS Packed Homomorphic Encryption Scheme and operation scenarios for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM40"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>8</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM41"><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mn>16</mml:mn></mml:math></inline-formula>.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g002.tif"/>
</fig>
</sec>
<sec id="s2c"><label>2.3.</label><title>Convolutional deep neural networks inference</title>
<p>Deep Learning is a set of statistical algorithms based on Deep Artificial Neural Networks. These algorithms have shown proficiency when learning from large amounts of data (<xref ref-type="bibr" rid="B6">6</xref>). The basic building blocks of DL models are layers (i.e., the different arrangements of neurons in an architecture). Each layer operates with the data differently, depending on its type (e.g., convolution or dot-product). The basic building blocks of layers have been ported to hardware acceleration and multiple libraries (<xref ref-type="bibr" rid="B28">28</xref>&#x2013;<xref ref-type="bibr" rid="B30">30</xref>). This work focuses on Convolutional Deep Neural Networks (CNN). These are nowadays the most prominent networks to deal with images (<xref ref-type="bibr" rid="B3">3</xref>, <xref ref-type="bibr" rid="B31">31</xref>) (e.g., classification, object detection, or segmentation). Thus, the use of CNN with privacy-preserving techniques is of paramount importance. For further information on CNN, we refer the reader to the book by Goodfellow et al. (<xref ref-type="bibr" rid="B32">32</xref>). Next, we overview the basic structures that require adaptation to work with SIMD operations.</p>
<p><italic>Convolutional layers</italic> compute the correlation between a multidimensional input matrix and a kernel or filter. When dealing with 2D images, we consider it to be the relation between an input image of dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM42"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> and a set of kernels or filters <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM43"><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:math></inline-formula>. The convolution iterates through regions of size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM44"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and computes the convolution with each filter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM45"><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:math></inline-formula> (i.e., multiplication and sum). Usually, in combination with convolutional layers, padding, and stride mechanisms are paired. Considering a picture over which we place a filter, the stride defines the axial displacement of the filters (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM46"><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>). Padding a matrix consists of uniformly adding a value <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM47"><mml:mi>p</mml:mi></mml:math></inline-formula> times at the beginning and end of each dimension. In CNN, padding highlights potential features existing on the borders and corners of the image that otherwise would disappear.</p>
<p><italic>Pooling layers</italic> act as aggregation component. They reduce the size of previous layers and help keep the number of parameters low. They perform a similar operation to the convolution, taking (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM48"><mml:msub><mml:mi>p</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>) regions of the input 2D matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM49"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> and computing an operation over the region. The most common type of pooling layer is the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM50"><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:math></inline-formula> pooling layer. It involves computing the maximum pixel of the extracted region. Unfortunately, the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM51"><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:math></inline-formula> function is non-linear. With current LHE schemes, non-linear functions require polynomial approximations (e.g., Taylor or Chebyshev approximations (<xref ref-type="bibr" rid="B33">33</xref>)), incurring extra complexity. Thus, it is also possible to use another classical, yet-effective approach to the Average Pooling Layer, which applies the following operation:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM1"><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac></mml:mrow><mml:mo>&#x2217;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula><italic>Fully connected or dense layers</italic> link each input element to all output activations. Dense layers usually translate to matrix multiplication between weights matrix (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM52"><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>) and the input vector (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM53"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>) and adding a bias element (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM54"><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>) (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM55"><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mi>b</mml:mi></mml:math></inline-formula>). In the weights matrix, each entry represents the relation between the input element <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM56"><mml:mi>y</mml:mi></mml:math></inline-formula> and output element <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM57"><mml:mi>x</mml:mi></mml:math></inline-formula> (i.e., each row relates to an input element, and the specific column represents the relationship with the output element).</p>
<p><italic>Activation functions</italic> are often non-linear functions that involve introducing non-linear behaviors in the approximated functions. The rationale of these functions is to resemble synaptic signals transmitted by biological neurons (<xref ref-type="bibr" rid="B34">34</xref>). Thus, without these, Neural Networks would reduce to complex polynomials. In this work, we do not cover activation function algorithms, as they involve operating on all entries of the ciphertext (i.e., it is straightforward with SIMD). Regarding the existing approximations of non-linearities, we refer the reader to different works (<xref ref-type="bibr" rid="B35">35</xref>, <xref ref-type="bibr" rid="B36">36</xref>).</p>
</sec>
<sec id="s2d"><label>2.4.</label><title>Privacy-preserving deep learning inference</title>
<p>In this paper, we consider a use case where a client-server scenario, where a client needs to outsource the computation of DL inference to a not necessarily trusted server. For that, the client and server rely on public-key FHE. The client performs the key generation, encrypts the data with his public key, and sends the ciphertext to the server. The server receives the public and relinearization keys and the ciphertext. Through privacy-preserving processing, the server can operate on the data and return the result to the client. The client owns a private key which he never released, therefore is the only person able to decrypt the information. Also, we consider that the client performs no computation except light tasks before encrypting or after decryption. For example, the client can perform padding to reduce the load of convolutions since it is a light task. Also, after decrypting the information, the client can retrieve the relevant information entries instead of having the server post-process the result.</p>
</sec>
</sec>
<sec id="s3"><label>3.</label><title>SIMD algorithms for deep learning</title>
<p>Most Deep Learning building blocks rely on standard linear algebra operations (e.g., matrix or vector multiplication). Some of these operations are not available in the encrypted domain (e.g., accessing an arbitrary entry of an array). Furthermore, existing optimizations for running classical linear algebra on computers, such as tiling memory accesses in matrix multiplications (<xref ref-type="bibr" rid="B37">37</xref>), are not possible when the smallest unit considered is a packed HE ciphertext (i.e., a polynomial in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM58"><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula>). Thus, it is necessary to develop focused algorithmic optimizations for these ciphertexts.</p>
<p>In this section, we provide general algorithms to adapt linear algebra operations so they can exploit the potential of SIMD operations in Deep Learning while working on HE ciphertexts. Concretely, we propose descriptions of algorithms that work on arbitrary matrices <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM59"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> (i.e., of height <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM60"><mml:mi>h</mml:mi></mml:math></inline-formula> and width <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM61"><mml:mi>w</mml:mi></mml:math></inline-formula>).</p>
<p>Additionally, since DL architectures consist of connected layers of different natures, the representations between these layers need to be compatible. This compatibility means that the output of SIMD operations resulting from a given layer needs to be formatted according to the input of the following layer. While previous works have proposed SIMD operations for these layers, they have only provided partial examples, not giving a holistic view of the DL pipeline and not considering the interconnections of the layers (<xref ref-type="bibr" rid="B18">18</xref>, <xref ref-type="bibr" rid="B19">19</xref>). Indeed, as we show in Section <xref ref-type="sec" rid="s5">5</xref>, the data transformations have a considerable overhead which the DL design phase should account for.</p>
<p>When dealing with Packed Homomorphic Encryption, the ciphertext encodes vectors of size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM62"><mml:mi>N</mml:mi></mml:math></inline-formula>. However, CNNs operate over matrices which require transforming matrices into vectors (see <xref ref-type="fig" rid="F1">Figure&#x00A0;1</xref>). We consider a standard representation that we refer to as Row-Column (RC) format, where the 2D matrix is flattened row by row (Equation <xref ref-type="disp-formula" rid="disp-formula1">1</xref>). This format allows the representation of information with the smallest <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM63"><mml:mi>N</mml:mi></mml:math></inline-formula>. Accordingly, in this work, we provide algorithms to transform the RC format to the appropriate Initial Representation for the algorithm and Result Transformation algorithms for returning to the RC format<disp-formula id="disp-formula1"><label>(1)</label><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="DM1"><mml:mi>R</mml:mi><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula>In a nutshell, the processing of each layer requires the following algorithms (executed before, during, and after the actual data processing):
<list list-type="simple">
<list-item><label>1.</label>
<p><bold>Initial Representation (IR)</bold> algorithms provide the corresponding layer with an appropriate representation of the data for executing the algorithm (i.e., according to the requirements of the layer).</p></list-item>
<list-item><label>2.</label>
<p><bold>Algorithm Execution (ALG)</bold> algorithms are the actual execution of the internal operations over the data. We next describe the convolution blocks (i.e., convolutional layer, pooling layer, and activation function) and dense blocks (i.e., dense layer and activation function).</p></list-item>
<list-item><label>3.</label>
<p><bold>Result Transformation (RT)</bold>. Due to the nature of SIMD operations, the algorithms usually introduce some extra, irrelevant data in the result (e.g., redundant or padded). Also, different SIMD operations produce different output formats. Thus, we elaborate dedicated algorithms to extract the relevant output information and turn it back into a format suitable for the next layer. We note that this process (RT) can sometimes be computed together with the Initial Representation (IR) of the following layer.</p></list-item>
</list></p><sec id="s3a"><label>3.1.</label><title>Notation</title>
<p>We use <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM64"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> to represent a matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM65"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:math></inline-formula> of dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM66"><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:math></inline-formula>. Also, we use <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM67"><mml:msub><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to refer to the entry on row <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM68"><mml:mi>i</mml:mi></mml:math></inline-formula> and column <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM69"><mml:mi>j</mml:mi></mml:math></inline-formula> of the matrix.</p>
<p>In <xref ref-type="sec" rid="s2b">Section 2.2</xref>, we described the encoding, encryption, decoding, and decryption routines. For simplicity, in the algorithms, we assume that a vector&#x2019;s encryption routine also comprises the previous encoding. Similarly, the decryption routine comprises the decoding after decryption. Thus, we denote <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM70"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, as the encryption of the encoded matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM71"><mml:mi>M</mml:mi></mml:math></inline-formula>, whose layout in the encrypted vector may be defined depending on the algorithm.</p>
<p>Many of the algorithms rely on binary bitmasks to obtain relevant information. These are composed of binary values. In the description of the algorithms, we assume bitmasks are initially filled with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM72"><mml:mn>0</mml:mn></mml:math></inline-formula>, and we express a condition to get the positions (indexes) where entries are set to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM73"><mml:mn>1</mml:mn></mml:math></inline-formula>. We use the parameter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM74"><mml:mi>t</mml:mi></mml:math></inline-formula> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM75"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>), which defines such indexes. For example, for a bitmask where even indexes are 1, we denote the mask as <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM76"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mspace width="thickmathspace" /><mml:mrow><mml:mi mathvariant="normal">mod</mml:mi></mml:mrow><mml:mspace width="thinmathspace" /><mml:mn>2</mml:mn><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>.</p>
<p>In HE, the ciphertext representation uses integer ring polynomial representation, unlike Deep Learning floating point representation. This problem has multiple approaches, such as fixed point representations or CKKS encoding (<xref ref-type="bibr" rid="B27">27</xref>). The algorithms provided here are represented generically without discussing the specific representation (i.e., the only requirement is the availability of the operations defined in <xref ref-type="sec" rid="s2b">Section 2.2</xref>).</p>
<p>In the following sections, we provide the general algorithms that allow the adaptation of common layers in CNNs, i.e., Convolutional and Dense blocks. Then, we provide a discussion on how to use activation functions (which are non-linear) in the context of Packed Homomorphic Encryption. <xref ref-type="fig" rid="F3">Figure&#x00A0;3</xref> provides a summary overview of the application of the different algorithms in a CNN pipeline.</p>
<fig id="F3" position="float"><label>Figure 3</label>
<caption><p>Overview of the different algorithms needed to perform a Convolutional Neural Network with Homomorphic Encryption.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g003.tif"/>
</fig>
</sec>
<sec id="s3b"><label>3.2.</label><title>SIMD convolutional layer</title>
<p>Computing a classical 2D Convolutional Layer involves a relationship between an input bi-dimensional matrix region and a bi-dimensional filter. As explained in <xref ref-type="sec" rid="s2c">2.3</xref>, the convolution can combine structures such as padding, stride, or pooling layers. Accordingly, the algorithms defined for LHE should also account for the use of these variants.</p>
<p>This section presents a new algorithm for convolution, dubbed the Streamlined Convolution Algorithm. It allows combining convolutional, pooling, and activation layers in subsequent blocks, neglecting the cost of initial representation and executing a single result transformation algorithm (i.e., we can use the output representation of the algorithm arbitrarily). We first describe the convolution algorithm with stride and the result transformation algorithm (<xref ref-type="sec" rid="s3b1">Section 3.2.1</xref>). Then, we provide its integration with padding (<xref ref-type="sec" rid="s3b2">Section 3.2.2</xref>). and Average Pooling Layers (<xref ref-type="sec" rid="s3b3">Section 3.2.3</xref>. For reference, <xref ref-type="app" rid="app1">Appendix A</xref> details the convolution algorithms that extend and generalizes previous work (<xref ref-type="bibr" rid="B18">18</xref>), which we use as a baseline comparison in <xref ref-type="sec" rid="s5">Section 5</xref>.</p>
<sec id="s3b1"><label>3.2.1.</label><title>Streamlined convolution algorithm</title>
<p>The convolution algorithm takes as input a plaintext filter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM77"><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula> of dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM78"><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula>. The filter is applied to a ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM79"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> that corresponds to an encrypted input matrix, i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM80"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM81"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> being the encryption key and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM82"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:math></inline-formula> the plaintext input matrix linearized. The algorithm leverages that the dimensions of filters are shorter than input matrices, and we have plaintext access to those. Thus, it computes the convolution between each filter pixel and the input matrix (i.e., represented by a ciphertext) and adds the partial results for each pixel. The algorithm is described in <xref ref-type="table" rid="A1">Algorithm 1</xref>.</p>
<table-wrap id="A1" position="float"><label>Algorithm 1</label>
<caption><p>Streamlined 2D Convolution</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM83"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM84"><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM85"><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>s</mml:mi><mml:mi>x</mml:mi><mml:mi>l</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>s</mml:mi><mml:mi>y</mml:mi><mml:mi>l</mml:mi></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM86"><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM87"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM88"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM89"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in SCBF format<break/>&#x2003;<bold>function</bold> C<sc>ONVOLUTION</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM90"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>,<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM91"><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM92"><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM93"><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM94"><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM95"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM96"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:mrow><mml:msubsup><mml:mi>s</mml:mi><mml:mi>x</mml:mi><mml:mi>l</mml:mi></mml:msubsup></mml:mfrac></mml:mrow><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM97"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:mrow><mml:msubsup><mml:mi>s</mml:mi><mml:mi>y</mml:mi><mml:mi>l</mml:mi></mml:msubsup></mml:mfrac></mml:mrow><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM98"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext>P</mml:mtext></mml:mrow><mml:mrow><mml:mstyle mathsize="0.85em"><mml:mrow><mml:mi mathvariant="normal">ADDING</mml:mi></mml:mrow></mml:mstyle></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM99"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM100"><mml:mi>j</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM101"><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x226A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM102"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM103"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We denote the linearized format of the matrix as Streamlined Backward Convolution Format (SCBF) since it depends on the information of previous layers. For multiple consecutive convolutions, the algorithm requires some information to determine the layout of the input vector. Concretely, in the execution of layer <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM104"><mml:mi>l</mml:mi></mml:math></inline-formula>, the algorithm receives as input the product of strides from previous layers, i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM105"><mml:msub><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:munderover><mml:msubsup><mml:mi>s</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM106"><mml:msub><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:munderover><mml:msubsup><mml:mi>s</mml:mi><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM107"><mml:msubsup><mml:mi>s</mml:mi><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>s</mml:mi><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> are the strides on <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM108"><mml:mi>x</mml:mi></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM109"><mml:mi>y</mml:mi></mml:math></inline-formula> axis of the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM110"><mml:mi>i</mml:mi></mml:math></inline-formula>th consecutive convolutional layer. Furthermore, the algorithm also requires the dimensions of the first encoded matrix, i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM111"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. These define the capacity of the algorithm to perform operations on the information. Whenever we execute a convolution, the result format depends on these values.</p>
<p>For the first layer, we use the Row-Column format, a subset of the SCBF format where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM112"><mml:msub><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM113"><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>.</p>
<p>Finally, if the convolution uses padding, the algorithm relies on the <monospace>PADDING</monospace> function, which we describe in the next section.</p>
</sec>
<sec id="s3b2"><label>3.2.2.</label><title>Streamlined padding algorithm</title>
<p>The insertion of padding is common in convolutional layers to ensure the preservation of details in the corners of matrices when using filters. In general, if the padding is added on the first layer of the CNN, we can apply it on the cleartext matrix (i.e., by the client) and encrypt afterward. However, if the padding is not present on the initial layer, it is the responsibility of the server to execute it. For that, we propose <xref ref-type="table" rid="A2">Algorithm 2</xref>, where based on the structure of the SCBF format, it performs padding with little computational effort, as opposed to the base algorithm described in <xref ref-type="app" rid="app1">Appendix A</xref>. The algorithm has two main tasks. First, it rotates the relevant information according to the padding needed for the first row. Then, using a bitmask, it introduces zeroes in the appropriate positions. Note that, for notation clarity, we perform an inversion of the bitmask (i.e., zeroes become ones and vice versa) denoted as <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM114"><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>.</p>
<table-wrap id="A2" position="float"><label>Algorithm 2</label>
<caption><p>Streamlined 2D Padding</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM115"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM116"><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM117"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM118"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM119"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, in SCBF format<break/>&#x2003;<bold>function</bold> P<sc>ADDING</sc> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM120"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM121"><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM122"><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM123"><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM124"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM125"><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM126"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>h</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM127"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>w</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM128"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x226B;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM129"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mi>t</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x2228;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2228;</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x2228;</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM130"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x25B7; Inverted bitmask<break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM131"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3b3"><label>3.2.3.</label><title>Streamlined average pooling layers</title>
<p>Similar to the usage of stride during the convolution operation, Pooling Layers allow for reducing the overall complexity required to process the information. Additionally, they highlight the most relevant features for the classification, extracting higher informative areas and discarding less informative ones. While Max Pooling is a popular choice for Deep Learning since it allows the extraction of pronounced and sharp changes (<xref ref-type="bibr" rid="B32">32</xref>) (e.g., edges in pictures for image segmentation), the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM132"><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:math></inline-formula> function is non-linear. Thus, its usage with current Homomorphic Encryption schemes remains complex and inefficient. In our work, we cover linear average pooling, which results less inefficient,<xref ref-type="fn" rid="FN0003"><sup>3</sup></xref> but extracts smoother changes from pictures (<xref ref-type="bibr" rid="B32">32</xref>).</p>
<p>The encrypted version takes an input ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM133"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, and a pool <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM134"><mml:mrow><mml:mi mathvariant="script">P</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>. The adaptation to SIMD HE can be obtained by using the convolution algorithm presented in <xref ref-type="sec" rid="s3b1">Section 3.2.1</xref>, but using a dedicated filter for the pooling, defined as:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM2"><mml:mrow><mml:mi mathvariant="script">P</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">P</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac></mml:mrow><mml:mo>&#x2223;</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:math></disp-formula>Similar to the convolution algorithm, the pooling layer also requires meta-information from previous layers.</p>
</sec>
<sec id="s3b4"><label>3.2.4.</label><title>Streamlined convolution result transformation</title>
<p>The previously presented algorithms can be arbitrarily combined between themselves and activation functions, incurring a minimal multiplication depth and the number of multiplications per layer. The only drawback is its combination with other types of layers (e.g., the dense layer). For that, we provide a function allowing the user to return to RC format to become compatible with other layers. The process depicted in <xref ref-type="table" rid="A3">Algorithm 3</xref> may not be the most efficient depending on the subsequent layer. If that is the case, the lines detailed as formatting in blue and with the formatting comment may swap for a more appropriate layout. This algorithm receives a ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM135"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, being the encrypted result of the convolutions of which we stored the output dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM136"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. Additionally, as in the previous examples, it is necessary to keep track of the product of strides in previous layers (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM137"><mml:msub><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>) and the initial dimensions (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM138"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>).</p>
<table-wrap id="A3" position="float"><label>Algorithm 3</label>
<caption><p>Streamlined Convolution Result Transformation</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM139"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in format, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM140"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM141"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM142"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM143"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> in RC format<break/>&#x2003;<bold>function</bold> RT-SCR-RC (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM144"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM145"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM146"><mml:mi>j</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM147"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">S</mml:mi></mml:mrow></mml:mrow><mml:mi>x</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM148"><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x2003;&#x25B7;Formatting<break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM149"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x226A;</mml:mo><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM150"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s3c"><label>3.3.</label><title>SIMD dense layer</title>
<p>The Dense or Fully-Connected Layer of a Neural Network performs a weighted connection of all the inputs to all outputs. It is a linear transformation that a matrix-vector multiplication can represent, where a weight matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM151"><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> is multiplied by the vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM152"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mi>n</mml:mi></mml:msup></mml:math></inline-formula>. The weights matrix contains parameters fine-tuned during the training. The input vector comprises all the outputs from the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM153"><mml:mi>n</mml:mi></mml:math></inline-formula> neurons in the previous layer.</p>
<p>This section proposes algorithms for efficiently applying SIMD operations over encrypted data on Dense Layers. These algorithms generalize two previously proposed algorithms for DL inference: a Diagonal Matrix-Vector multiplication (<xref ref-type="bibr" rid="B19">19</xref>) and a Matrix-Matrix multiplication (<xref ref-type="bibr" rid="B18">18</xref>). While these matrix multiplication algorithms report simplistic examples, in our work, we describe a generalization together with all the transformation algorithms required for the internal connections.</p>
<sec id="s3c1"><label>3.3.1.</label><title>Diagonal matrix-vector multiplication</title>
<p>This algorithm is based on the multiplication of a ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM154"><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> (i.e., data is encrypted, thus providing input-privacy) by a cleartext matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM155"><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> (i.e., the weights are not encrypted, thus not providing weight-secrecy). The algorithm decomposes the matrix in the extended diagonals (i.e., diagonal vectors of length <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM156"><mml:mi>h</mml:mi></mml:math></inline-formula>). Then the input vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM157"><mml:mi>x</mml:mi></mml:math></inline-formula> is rotated, multiplied by the diagonal matrix, and added. In this way, the algorithm ensures that each entry of the ciphertext vector multiplies each matrix value. Halevi and Shoup were the first to describe this approach in HElib (<xref ref-type="bibr" rid="B19">19</xref>). In their algorithm, authors do not cover the application to HE where the number of elements in the ciphertext <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM158"><mml:mi>n</mml:mi></mml:math></inline-formula> is fewer than the size of the ciphertext <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM159"><mml:mi>N</mml:mi></mml:math></inline-formula>. To solve this obstacle, we provide an explanation and an Initial Representation algorithm. We also introduce a generalization of the algorithm that enables its application to arbitrary size matrices in <xref ref-type="table" rid="A4">Algorithm 4</xref>. We discuss the practical implications of its application to HE and its relation to other layers in <xref ref-type="sec" rid="s4">Section 4</xref>.</p>
<table-wrap id="A4" position="float"><label>Algorithm 4</label>
<caption><p>Diagonal Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM160"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM161"><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM162"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi></mml:math></inline-formula><break/>&#x2003;<bold>function</bold> D<sc>IAGONAL</sc> M<sc>ATMUL</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM163"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow></mml:mrow></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM164"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM165"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM166"><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM167"><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>g</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mfrac><mml:mi>N</mml:mi><mml:mi>&#x03B1;</mml:mi></mml:mfrac></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM168"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mstyle mathsize="0.85em"><mml:mrow><mml:mi mathvariant="normal">WITCH</mml:mi></mml:mrow></mml:mstyle></mml:mrow><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mstyle mathsize="0.85em"><mml:mrow><mml:mi mathvariant="normal">PACING</mml:mi></mml:mrow></mml:mstyle></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM169"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM170"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>j</mml:mi><mml:mo>&lt;</mml:mo><mml:mi>h</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM171"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x226A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM172"><mml:msubsup><mml:mi>d</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mrow><mml:mstyle mathsize="0.85em"><mml:mrow><mml:mi mathvariant="normal">NC</mml:mi></mml:mrow></mml:mstyle></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM173"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>d</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM174"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The algorithm takes advantage of the overflow of the input vector during rotations, i.e., when the last values move to the first positions. In HE, the size of the underlying slots is determined by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM175"><mml:mi>N</mml:mi></mml:math></inline-formula>, which is a power of 2. Introducing a small plaintext vector within a larger ciphertext would prevent us from preserving the overflow behavior. Thus we propose a preprocessing step to keep the overflow happening.</p>
<p>The algorithm relies on two preprocessing steps for correctness. First, to enforce an overflow in longer vectors, the matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM176"><mml:mrow><mml:mi mathvariant="script">W</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> is extended to the closest power of 2 in both dimensions, resulting in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM177"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Second, based on these new dimensions, a spacing (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM178"><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:math></inline-formula>) is computed to move and split each entry of the plaintext vector uniformly within the ciphertext vector. This way, the shifts can be weighted by the spacing, and the overflow is kept. Concretely, the spacing is computed as follows: <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM179"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow></mml:math></inline-formula>. The denominator takes the maximum since a matrix multiplication either reduces or increases the size of the matrix. Note that since <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM180"><mml:mi>N</mml:mi></mml:math></inline-formula> is a power of 2, and so are <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM181"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM182"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, the result is an integer spacing value, also a power of 2. <xref ref-type="table" rid="A5">Algorithm 5</xref> shows the algorithm for these preprocessing steps. The algorithm is adapted to switch from a <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM183"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> spacing between vector elements to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM184"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub></mml:math></inline-formula> spacing. In this way, the algorithm can be used both as the Result Transformation of a Dense Layer and the Initial Representation of a subsequent Dense Layer.</p>
<table-wrap id="A5" position="float"><label>Algorithm 5</label>
<caption><p>Initial Representation and Result Transformation for Diagonal Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM185"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM186"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM187"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM188"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula><break/>&#x2003;<bold>function</bold> S<sc>WITCH</sc>S<sc>PACING</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM189"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM190"><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM191"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM192"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM193"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x226B;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM194"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3c2"><label>3.3.2.</label><title>Matrix-matrix multiplication</title>
<p>We propose an algorithm for a matrix-to-matrix multiplication, which takes as a starting point an example provided in CHET for matrices of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM195"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula> (<xref ref-type="bibr" rid="B18">18</xref>). Besides proposing a general description to apply this in arbitrary size matrices, we also provide the Initial Representation and Result Transformation algorithms so these matrix multiplications can be chained together in a DL architecture.</p>
<p>We assume that we want to multiply two matrices <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM196"><mml:mi>A</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM197"><mml:mi>B</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, which are encrypted and formatted in Row-Column format, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM198"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>A</mml:mi></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>A</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM199"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>B</mml:mi></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>B</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The key concept for the algorithm is the replication of the RC matrix representation. These special and alternative replications permit linear computation of all the necessary combinations. Thus, the main complexity of the algorithm resides in the Initial Representation algorithms. Once this is completed, the overall multiplication complexity is very low.</p>
<p>For matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM200"><mml:mi>A</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, its placement over the vector is repeated alternatively according to the formula <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM201"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. Thus, <italic>each element <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM202"><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> of matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM203"><mml:mi>A</mml:mi></mml:math></inline-formula> is consecutively repeated <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM204"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> times in the vector representation <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM205"><mml:msub><mml:mi>v</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></italic> (e.g., for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM206"><mml:mi>A</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM207"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>). <xref ref-type="table" rid="A6">Algorithm 6</xref>, shows the process to prepare the matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM208"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> from a Row Column representation of A denoted as <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM209"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>A</mml:mi></mml:msubsup></mml:math></inline-formula>.</p>
<table-wrap id="A6" position="float"><label>Algorithm 6</label>
<caption><p>Initial Representation for Matrix A in Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM210"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>A</mml:mi></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>A</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM211"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM212"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>function</bold> P<sc>REPARE</sc>M<sc>ATRIXA</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM213"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>A</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM214"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM215"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>i</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM216"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mi>A</mml:mi></mml:msubsup><mml:mo>=</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2299;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>A</mml:mi></mml:msubsup></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM217"><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mi>A</mml:mi></mml:msubsup><mml:mo>&#x226B;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM218"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM219"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mo>&#x226B;</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM220"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>For matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM221"><mml:mi>B</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>B</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x003C;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x003C;</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, its transformation involves repeating multiple times the vector according to the formula <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM222"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo></mml:math></inline-formula> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM223"><mml:msub><mml:mi>B</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>k</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msub><mml:mo>&#x2223;</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>k</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. Thus, <italic>the Row-Column representation of the matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM224"><mml:mi>B</mml:mi></mml:math></inline-formula> is repeated <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM225"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> times</italic> (e.g., for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM226"><mml:mi>B</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM227"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. <xref ref-type="table" rid="A7">Algorithm 7</xref> shows the algorithm to prepare the matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM228"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>.</p>
<table-wrap id="A7" position="float"><label>Algorithm 7</label>
<caption><p>Initial Representation for Matrix B in Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM229"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>B</mml:mi></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>B</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM230"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM231"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>function</bold> P<sc>REPARE</sc>M<sc>ATRIX</sc>B (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM232"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>B</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM233"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM234"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>B</mml:mi></mml:msubsup><mml:mo>&#x226B;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM235"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>t</mml:mi></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Once both matrices are transformed into the specified layout, the algorithm performs element-wise multiplications of the vectors, obtaining a result vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM236"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>C</mml:mi></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. Finally, it applies <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM237"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> rotations and sums to the resulting vector, obtaining the final result: <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM238"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>C</mml:mi></mml:msubsup><mml:mo>&#x226A;</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (see <xref ref-type="table" rid="A8">Algorithm 8</xref>).</p>
<table-wrap id="A8" position="float"><label>Algorithm 8</label>
<caption><p>Matrix-Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM239"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM240"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM241"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM242"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM243"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula><break/>&#x2003;<bold>function</bold> M<sc>ATRIX</sc>M<sc>ATRIX</sc>M<sc>UL</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM244"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM245"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>C</mml:mi></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>A</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>P</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM246"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM247"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>C</mml:mi></mml:msubsup><mml:mo>&#x226B;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM248"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>However, due to the nature of the algorithm, this result contains extra spacing that needs to be discarded. Concretely, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM249"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> relevant items in the vector (i.e., items from the actual result of the multiplication) are followed by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM250"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> non-relevant ones (i.e., irrelevant artifacts). These are discarded in a Result Extraction algorithm to finally get the Row-Column representation of the multiplication (see <xref ref-type="table" rid="A9">Algorithm 9</xref>, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM251"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:math></inline-formula> is the result with spacing that needs to be transformed, and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM252"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is the output of the transformation).</p>
<table-wrap id="A9" position="float"><label>Algorithm 9</label>
<caption><p>Result Extraction Matrix-Matrix Multiplication</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM253"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM254"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM255"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in RC format:<break/>&#x2003;<bold>function</bold> RE-M<sc>ATRIX</sc>M<sc>ATRIX</sc>M<sc>UL</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM256"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM257"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM258"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM259"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x226B;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM260"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>&#x226A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM261"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>B</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM262"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>B</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s3d"><label>3.4.</label><title>Activation functions</title>
<p>Neural Networks have excelled at classification and regression tasks because they can map non-linear distributions. Activation functions are a crucial component of such success, and their integration within FHE schemes is a hot research topic in the literature. Linear approximations of various kinds are among the most successful yet straightforward proposals to introduce activation functions in HE-based DL. Authors have proposed solutions ranging from alternative polynomials (<xref ref-type="bibr" rid="B35">35</xref>, <xref ref-type="bibr" rid="B38">38</xref>), Taylor and Chebyshev Polynomials (<xref ref-type="bibr" rid="B36">36</xref>) or simple linear regressions (<xref ref-type="bibr" rid="B39">39</xref>, <xref ref-type="bibr" rid="B40">40</xref>). The common goal of these works is to obtain a low-degree polynomial to approximate the non-linear behavior as accurately as possible. This paper assumes that the activation functions have somehow been approximated to polynomials using any of the existing proposals. Thus, computing an activation function to Packed Homomorphic Encryption does not require any particular format or construction as it applies the transformation to all the slots of the ciphertext. We can often insert the activation layers with other layers or building blocks of the layers (i.e., algorithm execution and result transformation) without changing the final result. In <xref ref-type="sec" rid="s4c">Section 4.3</xref>, we provide insights on where introducing activation functions for the convolutional and dense blocks would be more or less desirable.</p>
</sec>
</sec>
<sec id="s4"><label>4.</label><title>Efficiency analysis of algorithms</title>
<p>The previous section presented algorithms for SIMD execution of CNN inference. In this section, we formally analyze their efficiency and performance impact. Indeed, efficiency is one of the biggest challenges for applying Homomorphic Encryption for Deep Learning. We first define the metrics used to measure efficiency. Second, we provide some insights regarding applying rotations and large ciphertext vectors. Finally, we analyze all the algorithms in terms of the proposed metrics. That enables us to provide a series of guidelines for their application.</p>
<sec id="s4a"><label>4.1.</label><title>Efficiency metrics</title>
<p>Generally, HE operations are performance-wise heavy to execute over ciphertexts. Our analysis focuses on the transformations applied to ciphertexts. Plaintext operations have a negligible impact on the computation; thus, we do not account for them in the analysis. For evaluating these algorithms, we rely on four metrics that define the efficiency of a circuit <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM263"><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:math></inline-formula>:</p>
<p><italic>Multiplication depth (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM264"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>)</italic> defines the maximum number of consecutive products that an HE ciphertext needs to apply in a given circuit <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM265"><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:math></inline-formula>. The multiplication depth directly impacts the parametrization of HE schemes, specifically in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM266"><mml:mi>N</mml:mi></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM267"><mml:mi>Q</mml:mi></mml:math></inline-formula>. In terms of cleartext operations, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM268"><mml:mi>N</mml:mi></mml:math></inline-formula> defines the polynomial degree. Thus, a bigger <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM269"><mml:mi>N</mml:mi></mml:math></inline-formula> would involve operating over larger degree polynomials (i.e., more coefficients to compute per ciphertext operation). Also, working with bigger <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM270"><mml:mi>Q</mml:mi></mml:math></inline-formula> involves computing more remainders. In Levelled Homomorphic Encryption Schemes, each multiplication usually requires a rescaling operation to reduce the underlying noise. Therefore, we consider the need for one rescaling per <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM271"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> (i.e., per multiplication). In this case, we need <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM272"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> different moduli (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM273"><mml:msub><mml:mi>q</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>) in a polynomial coefficient modulus <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM274"><mml:mi>Q</mml:mi></mml:math></inline-formula>. In direct relation with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM275"><mml:mi>Q</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM276"><mml:mi>N</mml:mi></mml:math></inline-formula> often defines a maximum capacity for a <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM277"><mml:mi>Q</mml:mi></mml:math></inline-formula> (i.e., increasing the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM278"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> may not only involve increasing <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM279"><mml:mi>Q</mml:mi></mml:math></inline-formula> but also <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM280"><mml:mi>N</mml:mi></mml:math></inline-formula>). The optimization of these parameters is of paramount importance to obtain better runtimes. For all these reasons, keeping a minimal depth of the circuit is very important for achieving efficiency in the desired computation, which justifies why <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM281"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is one of the metrics analyzed for the efficiency of the algorithms.</p>
<p><italic>Operation cost</italic> differs across the different available computations in HE. Multiplication is the most costly since it not only requires multiplication but is paired with a relinearization phase (i.e., preventing the polynomial degree from growing) and a rescaling phase (i.e., reducing the noise scale). The next more costly operation is rotation, which involves generating different Galois Keys. In CKKS, if the encoding scale <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM282"><mml:mi>s</mml:mi></mml:math></inline-formula> is chosen the same as the smallest modulus prime <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM283"><mml:msub><mml:mi>q</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, we can neglect the noise and depth cost. Element-wise additions are the lowest cost operation and are considered linear in computation and noise growth. For the rest of the analysis, we denote the addition and subtraction complexity <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM284"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as the number of sums (and subtractions) required by a circuit. Likewise, we consider the multiplication complexity <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM285"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and rotation complexity <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM286"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as the number of multiplications and rotations in the circuit.</p>
<p><italic>Memory complexity (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM287"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>)</italic> accounts for the number of ciphertexts needed in memory to execute one of the algorithms. Given the large memory size of ciphertexts, minimizing the number of ciphertexts simultaneously residing in the main memory is essential.</p>
<p><italic>Memory constraints (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM288"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></italic>) determines the constraints that an algorithm imposes on the size of plaintext vectors <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM289"><mml:mi>n</mml:mi></mml:math></inline-formula> it operates with, so these can fit in ciphertext with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM290"><mml:mi>N</mml:mi></mml:math></inline-formula> slots (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM291"><mml:mi>n</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>). If the plaintext vectors do not fit in the ciphertext, the circuit would require an extended vector representation (i.e., the plaintext vectors are packed within multiple ciphertexts). In general, for most algorithms, we consider that for an input matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM292"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, we can compute the algorithm if <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM293"><mml:mi>h</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula> (i.e., if the full matrix size fits in a ciphertext vector slot). However, some specific algorithm representations of information may define harder or softer limits for the execution. As we detail in the following section, the memory constraints <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM294"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> directly impact the operation cost. In the following sections, we use <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM295"><mml:mi>r</mml:mi></mml:math></inline-formula> to define the number of ciphertext vectors of size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM296"><mml:mi>N</mml:mi></mml:math></inline-formula> needed to host a plaintext vector of size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM297"><mml:mi>n</mml:mi></mml:math></inline-formula>.</p>
</sec>
<sec id="s4b"><label>4.2.</label><title>Rotations on large ciphertexts</title>
<p>The effect of the &#x201C;Memory Constraints&#x201D; <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM298"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is important for the Rotation operation. In HE programming, most algebra circuits present memory constraints, given the difficulty of packing all the information within the same ciphertext. In parallelism with classical (non-HE) programming, we could consider when a program does not fit into the available memory and uses swap space. At that point, computation becomes a constraint and is more expensive. In HE circuits with packing, when we need multiple ciphertexts to represent the plaintext data, rotations have a worse impact on the efficiency of algorithms. Indeed, many algorithms rely on rotations to benefit from SIMD operations (e.g., to transform output layouts). Previous works assume rotations as &#x201C;cost-free&#x201D; operations and thus use them arbitrarily (<xref ref-type="bibr" rid="B18">18</xref>). We observe, however, that when an algorithm is generalized to work on arbitrary-size plaintext inputs (often large scale), the assumption does not hold anymore. Suppose the plaintext vector entries <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM299"><mml:mi>n</mml:mi></mml:math></inline-formula> extend over the available slots <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM300"><mml:mi>N</mml:mi></mml:math></inline-formula>. In that case, multiple ciphertexts are required, and the plaintext vectors and rotation cost are no longer neglectable since at least <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM301"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>n</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:math></inline-formula> ciphertext vectors are required.</p>
<p>To demonstrate this performance decrease, we depict in <xref ref-type="fig" rid="F4">Figure&#x00A0;4</xref> the rotation procedure for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM302"><mml:mi>n</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>, i.e., when more than one ciphertext is needed. In the example, we represent one input vector with two ciphertexts. Considering a 2-left rotation (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM303"><mml:mo>&#x226A;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula>), we observe that individual rotations of the vectors are partial. Thus, this involves further modifications, such as an additional multiplication of the vectors by a mask, which increases <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM304"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. <xref ref-type="table" rid="T1">Table&#x00A0;1</xref> shows the overall complexity of this process. We provide the details in <xref ref-type="table" rid="A10">Algorithm 10</xref>.</p>
<table-wrap id="A10" position="float"><label>Algorithm 10</label>
<caption><p>Rotation <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM305"><mml:mi>r</mml:mi></mml:math></inline-formula> times of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM306"><mml:mrow><mml:mrow><mml:mi mathvariant="script">V</mml:mi></mml:mrow></mml:mrow></mml:math></inline-formula> cleartext vector encoded in multiple ciphertexts <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM307"><mml:msub><mml:mi>v</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:math></inline-formula>.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>function</bold> R<sc>OTATE</sc> ({<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM308"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM309"><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:math></inline-formula>)<break/>&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM310"><mml:mi>q</mml:mi><mml:mo>,</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>r</mml:mi></mml:math></inline-formula><break/>&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM311"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>t</mml:mi><mml:mo>&lt;</mml:mo><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM312"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>r</mml:mi></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM313"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x226B;</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM314"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM315"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo>&#x2296;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end for</bold><break/>&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM316"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>r</mml:mi></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM317"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>q</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>0</mml:mn></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>q</mml:mi><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>1</mml:mn></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end for</bold><break/>&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM318"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/><bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<fig id="F4" position="float"><label>Figure 4</label>
<caption><p>Operations performed for privately rotating twice (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM319"><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x226A;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula>) a vector of dimension <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM320"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>16</mml:mn></mml:math></inline-formula> in with homomorphic encryption ciphertexts of size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM321"><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mn>8</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM322"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula>. The vector is encoded in two ciphertexts. The ciphertexts need to be rotated, masked and then reorganized to obtain the same result as in the plaintext rotation.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g004.tif"/>
</fig>
<table-wrap id="T1" position="float"><label>Table 1</label>
<caption><p>Efficiency analysis of Rotation of a big cleartext vector when it is packed over multiple ciphertexts (<xref ref-type="table" rid="A10">Algorithm 10</xref>).</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="left">Metric</th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM323"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM324"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM325"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM326"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM327"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM328"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Value</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM329"><mml:mn>1</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM330"><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM331"><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM332"><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM333"><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">&#x2013;</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4c"><label>4.3.</label><title>Analysis and takeaways for application to deep learning</title>
<p>In this section, we provide a detailed analysis of the algorithms presented in <xref ref-type="sec" rid="s3">Section 3</xref> concerning the efficiency metrics proposed. <xref ref-type="table" rid="T2">Table&#x00A0;2</xref> presents the performance formal complexity extracted from the different algorithms. Next, we give key insights extracted from the analysis and discuss future directions and best practices to apply the algorithms for Deep Learning Inference.</p>
<table-wrap id="T2" position="float"><label>Table 2</label>
<caption><p>Detailed analysis of the different metrics proposed in <xref ref-type="sec" rid="s4a">Section 4.1</xref> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM334"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM335"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM336"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM337"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM338"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM339"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>). Additionally, it shows the performance variation if Rotations are as in <xref ref-type="table" rid="A10">Algorithm 10</xref>.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="center" colspan="7">Formal analysis of algorithms</th>
</tr>
<tr>
<th valign="top" align="center">Algorithm</th>
<th valign="top" align="center" colspan="6">Metrics</th>
</tr>
<tr>
<th valign="top" align="center">Name</th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM340"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM341"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM342"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM343"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM344"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM345"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="center" rowspan="2">ALG (1) str. convolution</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM346"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM347"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM348"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM349"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM350"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM351"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM352"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM353"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM354"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM355"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">ALG (11) convolution</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM356"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM357"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM358"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM359"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM360"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM361"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM362"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM363"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM364"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM365"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">ALG (2) str. padding</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM366"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM367"><mml:mn>0</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM368"><mml:mn>1</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM369"><mml:mn>1</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM370"><mml:mn>2</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM371"><mml:msub><mml:mi>h</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM372"><mml:mn>2</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM373"><mml:mn>2</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM374"><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM375"><mml:mn>3</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">ALG (14) private padding</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM376"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM377"><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM378"><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM379"><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM380"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM381"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM382"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM383"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM384"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>h</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM385"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">RT (3) SCBF to RC</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM386"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM387"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM388"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM389"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM390"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM391"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM392"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM393"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM394"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM395"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">RT (12) CRF to RC</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM396"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM397"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM398"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM399"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM400"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM401"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM402"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM403"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM404"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM405"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">RT (13) SCRF to RC</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM406"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM407"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM408"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM409"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM410"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM411"><mml:mi>h</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM412"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM413"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM414"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM415"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">IR/RT (5) diag. mat. mult.</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM416"><mml:mi>n</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM417"><mml:mi>n</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM418"><mml:mi>n</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM419"><mml:mi>n</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM420"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM421"><mml:mi>n</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>f</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM422"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>n</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM423"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>n</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM424"><mml:mi>n</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>r</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM425"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">ALG (4) diag. mat. mult.</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM426"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM427"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM428"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM429"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM430"><mml:mn>4</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM431"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM432"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM433"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM434"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM435"><mml:mn>5</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">IR (6) prepare matrix A</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM436"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM437"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM438"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM439"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM440"><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM441"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">3</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM442"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM443"><mml:mi>r</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM444"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM445"><mml:mn>4</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">IR (7) prepare matrix B</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM446"><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM447"><mml:mn>0</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM448"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM449"><mml:mn>0</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM450"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM451"><mml:mn>2</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM452"><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM453"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM454"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM455"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM456"><mml:mn>3</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">ALG (8) mat-mat. mult.</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM457"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM458"><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM459"><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM460"><mml:mn>1</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM461"><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM462"><mml:mn>4</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM463"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM464"><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM465"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM466"><mml:mi>r</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM467"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM468"><mml:mn>5</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">RE (9) mat-mat. mult.</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM469"><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM470"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM471"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM472"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM473"><mml:mn>4</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM474"><mml:mi>n</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center">2</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM475"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM476"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM477"><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM478"><mml:mn>3</mml:mn><mml:mi>r</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s4c1"><label>4.3.1.</label><title>The streamlined convolutional blocks reduce the multiplication depth</title>
<p>The improved version of the algorithm we propose in <xref ref-type="sec" rid="s3b">Section 3.2</xref> introduces many efficiency improvements to the base algorithm. The streamlined version of the algorithms allows to insert <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM479"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> convolutions, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM480"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> strided convolutions, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM481"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> padding layers, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM482"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> average pooling layers or <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM483"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> activation functions (with cost <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM484"><mml:msubsup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>). This results in a depth cost of:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM3"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></disp-formula>The cost is one operation per layer and the Result Transformation algorithm. Also, it does not make any difference in using stridden or non-stridden convolutions. On the other hand, the base version proposed in previous work requires applying a result transformation function after each convolution, and the stride makes it more expensive in the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM485"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The overall cost of the base version is:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM4"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msubsup></mml:math></disp-formula>In summary, the base version heavily affects the depth because it requires result transformation algorithms.</p>
</sec>
<sec id="s4c2"><label>4.3.2.</label><title>The Streamlined Convolutional Blocks reduce the overall cost of auxiliary convolution routines</title>
<p>If we analyze the cost of operations, we can see how the overall cost of the streamlined convolution algorithm does not change concerning the base algorithm. However, looking at the rest of the streamlined routines (i.e., padding or stride), we can observe how the cost is highly reduced. Although the padding occupies the same multiplication depth slot, it reduces its cost to a single multiplication and rotation. Furthermore, the reduction in the cost of stride permits using it freely, allowing for faster training algorithms over higher dimensionality data. If we used the baseline algorithm, it would be preferable not to use padding and stride to 1 as much as possible to keep efficiency.</p>
</sec>
<sec id="s4c3"><label>4.3.3.</label><title>Prioritize IR prepare Matrix B over IR prepare Matrix A</title>
<p>Comparing both algorithms, we observe a clear advantage in the algorithm used to prepare Matrix B in the Matrix-Matrix multiplication. Indeed, both <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM486"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM487"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are smaller than in Prepare Matrix A. Furthermore, we consider the weights matrix to be provided in cleartext for Deep Learning Inference. In such a case, we recommend prioritizing IR Prepare Matrix A over the cleartext matrix (i.e., executing the heavy algorithm over the plaintext matrix); thus, the IR Prepare Matrix B algorithm on the ciphertext space. It allows for improving the overall performance of the multiplication routine while maintaining input privacy as a constraint.</p>
</sec>
<sec id="s4c4"><label>4.3.4.</label><title>Avoid using the Matrix-Matrix Algorithm for large input matrices</title>
<p>We observe that the Matrix-Matrix Algorithm (<xref ref-type="table" rid="A8">Algorithm 8</xref>) imposes significant limits on the size of matrices that can be multiplied (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM488"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>). For example, for a latent vector size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM489"><mml:mi>N</mml:mi></mml:math></inline-formula> of 1024, the maximum size of two square matrices <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM490"><mml:mi>A</mml:mi><mml:mo>,</mml:mo><mml:mi>B</mml:mi></mml:math></inline-formula> that we can privately multiply is around <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM491"><mml:mn>10</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>10</mml:mn></mml:math></inline-formula>. Introducing a larger size of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM492"><mml:mi>N</mml:mi></mml:math></inline-formula> (e.g., 16,384 or 32,768) would improve this factor slightly (e.g., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM493"><mml:mn>25</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>25</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM494"><mml:mn>32</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>32</mml:mn></mml:math></inline-formula>, respectively). This problem occurs due to the replication factor introduced by the algorithm, i.e., it requires the replication of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM495"><mml:mi>A</mml:mi></mml:math></inline-formula>&#x2019;s RC format <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM496"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula> times and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM497"><mml:mi>B</mml:mi></mml:math></inline-formula>&#x2019;s RC format <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM498"><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:math></inline-formula> times. In a real-world setting, Neural Networks often involve larger matrices. Encoding those input matrices often involves using multiple ciphertexts to represent the plaintext vector. The performance would be less in the encoding and execution time (as rotations demand). It also increases the memory requirements and the number of required operations (as described in <xref ref-type="table" rid="T2">Table&#x00A0;2</xref>).</p>
</sec>
<sec id="s4c5"><label>4.3.5.</label><title>The Matrix-Matrix multiplication Algorithm improves when <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM499"><mml:mi>B</mml:mi></mml:math></inline-formula> is a one-dimensional vector</title>
<p>This optimization partially overcomes certain of the previously presented weaknesses of this algorithm. Indeed, if we consider a real use case, often Dense Layers are flattened, representing information as a one-dimensional vector. If matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM500"><mml:mi>B</mml:mi></mml:math></inline-formula> is a vector (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM501"><mml:msub><mml:mi>w</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>), the constraint <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM502"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is reduced to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM503"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msubsup><mml:mi>h</mml:mi><mml:mi>B</mml:mi><mml:mn>2</mml:mn></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>. Furthermore, for reducing Dense layers, where the size of the output vector is smaller than the size of the input vector (i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM504"><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x2264;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>B</mml:mi></mml:msub></mml:math></inline-formula>), the constraint would be just on the shape of the underlying vector to the ciphertext. This constraint still imposes hard constraints for the underlying vector size (e.g., around 180 elements for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM505"><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mn>32</mml:mn><mml:mrow><mml:mo>,</mml:mo></mml:mrow><mml:mn>768</mml:mn></mml:math></inline-formula> or 128 for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM506"><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mn>16</mml:mn><mml:mrow><mml:mo>,</mml:mo></mml:mrow><mml:mn>384</mml:mn></mml:math></inline-formula>).</p>
</sec>
<sec id="s4c6"><label>4.3.6.</label><title>Choosing between Matrix-Matrix or diagonal matrix multiplication mostly depends on <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM507"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></title>
<p><xref ref-type="table" rid="T3">Table&#x00A0;3</xref> shows both algorithms&#x2019; overall cost of an arbitrary <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM508"><mml:mi>l</mml:mi></mml:math></inline-formula>-layer dense architecture. First, it is essential to consider the memory constraints of ciphertexts <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM509"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. In general, the Matrix-Matrix multiplication remains more efficient for small underlying plaintext vectors <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM510"><mml:mi>n</mml:mi></mml:math></inline-formula>. The improvement is due to having a lower <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM511"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and half the number of multiplications <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM512"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> than the Diagonal Matrix Multiplication. However, this only holds under the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM513"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> assumption, where we can represent the plaintext information under a single ciphertext. If not, the diagonal matrix multiplication becomes more efficient (i.e., the algorithm accepts larger matrix dimensions). At the same time, we must consider that increasing <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM514"><mml:mi>N</mml:mi></mml:math></inline-formula> to permit using more underlying plaintext elements <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM515"><mml:mi>n</mml:mi></mml:math></inline-formula> and working with the Matrix-Matrix multiplication may be counterproductive. This deficiency is due to the cleartext operations performed to execute a ciphertext operation. When we increase <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM516"><mml:mi>N</mml:mi></mml:math></inline-formula>, so does the number of cleartext operations to compute on each polynomial. Therefore, keeping a minimal <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM517"><mml:mi>N</mml:mi></mml:math></inline-formula> becomes likewise critical for efficiency. Before increasing <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM518"><mml:mi>N</mml:mi></mml:math></inline-formula>, using the Diagonal Matrix Multiplication would be better for performance. Finally, if the constraint <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM519"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> requires multiple vectors in both instances, it would be needed a trade-off between <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM520"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM521"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> based on the number of layers <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM522"><mml:mi>l</mml:mi></mml:math></inline-formula>. While the overall complexity remains similar for both algorithms, it is important to note two things. First, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM523"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> grows double as the number of layers <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM524"><mml:mi>l</mml:mi></mml:math></inline-formula> grows. Indeed, the Diagonal Matrix multiplication is less efficient for the same number of layers. Second, the increase of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM525"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM526"><mml:mi>l</mml:mi></mml:math></inline-formula> reduces in the Diagonal Matrix Multiplication with a comparison <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM527"><mml:mn>4</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mn>5</mml:mn><mml:mi>l</mml:mi></mml:math></inline-formula>. For neural network architectures with one dense layer <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM528"><mml:mi>l</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM529"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is better with the Matrix-Matrix multiplication algorithm. In the rest of the cases <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM530"><mml:mi>l</mml:mi><mml:mo>&#x003E;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, the overall <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM531"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> of the Diagonal Matrix is smaller.</p>
<table-wrap id="T3" position="float"><label>Table 3</label>
<caption><p>Detailed comparison of the different complete matrix multiplication algorithms described in the paper according to the different metrics proposed in <xref ref-type="sec" rid="s4a">Section 4.1</xref> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM532"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM533"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM534"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM535"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM536"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM537"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) for a generic <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM538"><mml:mi>l</mml:mi></mml:math></inline-formula>-layer Neural Network. Additionally, it shows the performance variation if Rotations are as in <xref ref-type="table" rid="A10">Algorithm 10</xref>. Note that, for Algorithms 4 and 5, we can consider <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM539"><mml:mi>&#x03B1;</mml:mi><mml:mo>=</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>. In Algorithms 7, 8, and 9, we consider the optimization of not using Preprocessing A and considering B is a one-dimensional vector.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="center" colspan="8">Matrix multiplication algorithm comparison on <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM540"><mml:mi>l</mml:mi></mml:math></inline-formula>-layer dense neural network</th>
</tr>
<tr>
<th valign="top" align="center" colspan="2">Algorithm</th>
<th valign="top" align="center" colspan="6">Metrics</th>
</tr>
<tr>
<th valign="top" align="center">Name</th>
<th valign="top" align="center">Alg.</th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM541"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM542"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="script">C</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM543"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>u</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM544"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM545"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM546"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="center" rowspan="2">Diagonal matrix multiplication</td>
<td valign="top" align="center" rowspan="2">5, 4</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM547"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM548"><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM549"><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM550"><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM551"><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM552"><mml:mn>4</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM553"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM554"><mml:mn>4</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM555"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM556"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM557"><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM558"><mml:mn>5</mml:mn><mml:mi>n</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center" rowspan="2">Matrix-matrix multiplication</td>
<td valign="top" align="center" rowspan="2">6, 7, 8, 9</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM559"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msubsup><mml:mi>h</mml:mi><mml:mi>B</mml:mi><mml:mn>2</mml:mn></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM560"><mml:mn>2</mml:mn><mml:mi>l</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM561"><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM562"><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM563"><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM564"><mml:mn>5</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM565"><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msubsup><mml:mi>h</mml:mi><mml:mi>B</mml:mi><mml:mn>2</mml:mn></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM566"><mml:mn>5</mml:mn><mml:mi>l</mml:mi></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM567"><mml:mn>3</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM568"><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM569"><mml:mi>l</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mi>r</mml:mi><mml:mrow><mml:mo>&#x22C5;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>h</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>A</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM570"><mml:mn>6</mml:mn><mml:mi>n</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="s5"><label>5.</label><title>Performance evaluation of guidelines</title>
<p>To study the impact of the algorithms in real-world inference and to corroborate the formal analysis and the critical findings from <xref ref-type="sec" rid="s4">Section 4</xref>, we conduct different experiments. These experiments implement variations from the base use case described in <xref ref-type="app" rid="app1">Appendix A</xref> (<xref ref-type="bibr" rid="B18">18</xref>). In each experiment, we conduct various tests varying the architectures and parameters to examine the performance impact of the different designed routines. All the experiments were run in a computer with processor MD Ryzen 3950X (16 cores at 3.5&#x2009;GHz), and 32GB of RAM memory.</p>
<p>The first experiment compares the baseline and streamlined convolution algorithms. The use case executes a set of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM571"><mml:mi>c</mml:mi></mml:math></inline-formula> convolutions in a row. All the convolutions have the same properties, with the parameter values described in <xref ref-type="table" rid="T4">Table&#x00A0;4</xref>. The results are depicted in <xref ref-type="fig" rid="F5">Figure&#x00A0;5</xref>. As expected by the formal analysis, the streamlined convolution algorithm does not impact the convolution operation since the execution times are similar. However, the algorithm produces an output format where the placement of the elements allows for efficient integration with the following layers. It impacts the execution time of the padding and the results transformation algorithms achieving a speedup of 8 times faster on average. Also, we can observe that in the baseline algorithm, the result transformation involves a substantial part of the computational effort, with a high impact on the overall performance.</p>
<fig id="F5" position="float"><label>Figure 5</label>
<caption><p>Convolution Performance Evaluation between Streamlined and Baseline approaches to algorithms.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g005.tif"/>
</fig>
<table-wrap id="T4" position="float"><label>Table 4</label>
<caption><p>Parametrization of the different tests performed for each of the four takeaways considered in <xref ref-type="sec" rid="s4c">Subsection 4.3</xref>.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="center" colspan="7">Convolution test case</td>
</tr>
<tr>
<td valign="top" align="center">Test</td>
<td valign="top" align="center">Num.</td>
<td valign="top" align="center">Initial shape</td>
<td valign="top" align="center">Kernel size</td>
<td valign="top" align="center">Stride</td>
<td valign="top" align="center">Padding</td>
<td valign="top" align="center">Speedup</td>
</tr>
<tr>
<td valign="top" align="center">0</td>
<td valign="top" align="center">10</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM572"><mml:mn>20</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>20</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM573"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM574"><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center">7.51</td>
</tr>
<tr>
<td valign="top" align="center">1</td>
<td valign="top" align="center">10</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM575"><mml:mn>30</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>30</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM576"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM577"><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center">8.37</td>
</tr>
<tr>
<td valign="top" align="center">2</td>
<td valign="top" align="center">10</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM578"><mml:mn>40</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>40</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM579"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM580"><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center">11.75</td>
</tr>
<tr>
<td valign="top" align="center">3</td>
<td valign="top" align="center">5</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM581"><mml:mn>30</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>30</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM582"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM583"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td valign="top" align="center">1</td>
<td valign="top" align="center">6.86</td>
</tr>
<tr>
<td valign="top" align="center" colspan="7">Matrix-Matrix multiplication test case</td>
</tr>
<tr>
<td valign="top" align="center">Test</td>
<td valign="top" align="center" colspan="3">Matrix shape</td>
<td valign="top" align="center" colspan="3">N</td>
</tr>
<tr>
<td valign="top" align="center">0</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM584"><mml:mn>2</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">16</td>
</tr>
<tr>
<td valign="top" align="center">1</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM585"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">32</td>
</tr>
<tr>
<td valign="top" align="center">2</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM586"><mml:mn>4</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center">3</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM587"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center">4</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM588"><mml:mn>20</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>20</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">8192</td>
</tr>
<tr>
<td valign="top" align="center" colspan="7">Diagonal dot multiplication test case</td>
</tr>
<tr>
<td valign="top" align="center">Test</td>
<td valign="top" align="center" colspan="3">Matrix shape</td>
<td valign="top" align="center" colspan="3">N</td>
</tr>
<tr>
<td valign="top" align="center">0</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM589"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">16</td>
</tr>
<tr>
<td valign="top" align="center">1</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM590"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>24</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">64</td>
</tr>
<tr>
<td valign="top" align="center">2</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM591"><mml:mn>24</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">64</td>
</tr>
<tr>
<td valign="top" align="center">3</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM592"><mml:mn>4</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center">4</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM593"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center">5</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM594"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">64</td>
</tr>
<tr>
<td valign="top" align="center">6</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM595"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">128</td>
</tr>
<tr>
<td valign="top" align="center">7</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM596"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>75</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center">8</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM597"><mml:mn>75</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>100</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">2048</td>
</tr>
<tr>
<td valign="top" align="center" colspan="7">Matrix-Matrix vs diagonal matrix multiplication test case</td>
</tr>
<tr>
<td valign="top" align="center">Test</td>
<td valign="top" align="center" colspan="3">Matrix shape</td>
<td valign="top" align="center" colspan="3">N</td>
</tr>
<tr>
<td valign="top" align="center">1</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM598"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">512</td>
</tr>
<tr>
<td valign="top" align="center">2</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM599"><mml:mn>10</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>10</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">1024</td>
</tr>
<tr>
<td valign="top" align="center">3</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM600"><mml:mn>20</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>20</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">8192</td>
</tr>
<tr>
<td valign="top" align="center">4</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM601"><mml:mn>40</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>40</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">65536</td>
</tr>
<tr>
<td valign="top" align="center">5</td>
<td valign="top" align="center" colspan="3"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM602"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula></td>
<td valign="top" align="center" colspan="3">65536</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In the second experiment, we evaluate the Matrix-Matrix Multiplication algorithm. We compute a sequence of Prepare Matrix Multiplications (for both A and B), the matrix multiplication algorithm, and the result transformation. We show the test cases evaluated in the second section of <xref ref-type="table" rid="T4">Table&#x00A0;4</xref> and the results in <xref ref-type="fig" rid="F6">Figure&#x00A0;6</xref>. As demonstrated in <xref ref-type="sec" rid="s4">Section 4</xref>, the IR Algorithm executed for Matrix A is highly inefficient. However, the IR for Matrix B is much more efficient, supposing a relatively minor difference. Therefore, if we consider one of the matrices to be cleartext (e.g., the weights of a Dense Layer are not private), we should always choose it to be matrix A. Another conclusion drawn from <xref ref-type="fig" rid="F6">Figure&#x00A0;6</xref> is the relevance of the Initial Representation and Result Transformation algorithms. Even in the most optimal use case, the matrix multiplication itself only supposes 40&#x0025; of the total amount of processing. Therefore, in other works that omit the Initial Representation or Result Transformation, the overall performance is only partially shown, as the transformations involve a significant portion of the overhead.</p>
<fig id="F6" position="float"><label>Figure 6</label>
<caption><p>Performance evaluation of <xref ref-type="table" rid="A8">Algorithm 8</xref>. The graph compares the preprocessing algorithms, Prepare A and Prepare B, in absolute terms, including other subroutines.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g006.tif"/>
</fig>
<p>The third experiment analyses the Diagonal Matrix Multiplication. For comparison purposes, we provide a detailed analysis of the diagonal matrix multiplication algorithm in <xref ref-type="fig" rid="F7">Figure&#x00A0;7</xref>. This algorithm generally shows the lesser <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM603"><mml:msub><mml:mrow><mml:mi mathvariant="script">O</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> requirements of the Diagonal Matrix multiplications. For bigger matrix sizes, the underlying ciphertext vector needs a smaller size of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM604"><mml:mi>N</mml:mi></mml:math></inline-formula> than the Matrix-Matrix Multiplication Algorithm. The tests executed on these algorithms can be found in the third subdivision of <xref ref-type="table" rid="T4">Table&#x00A0;4</xref>. As we can observe, the ordering of dimensions influences the preprocessing algorithm&#x2019;s time. In general, the maximum dimension of the matrices defines the dimension of the extended diagonal. Therefore, the test with matrices of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM605"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula> (test 4) obtains similar performance times to the test with matrices of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM606"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula> (tests 5 and 6). Also, given the small dimensions, the differences between the two tests with matrices of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM607"><mml:mn>50</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>50</mml:mn></mml:math></inline-formula> (tests 5 and 6) are negligible.</p>
<fig id="F7" position="float"><label>Figure 7</label>
<caption><p>Performance evaluation of the Diagonal Matrix Multiplication of two matrices. The graph shows the overall cost of the two main routines for Initial Representation/Result Transformation and the algorithm in absolute terms and relative to the execution time.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g007.tif"/>
</fig>
<p>The fourth experiment compares the different matrix multiplication algorithms. We perform the fourth experiment with the exact dimensions of the Matrix-Matrix and the Diagonal Dot multiplication algorithms. It enables us to compare the algorithms accurately. We provide the results in <xref ref-type="fig" rid="F8">Figure&#x00A0;8</xref> and the executed tests at the bottom of <xref ref-type="table" rid="T4">Table&#x00A0;4</xref>. Overall, we can observe how for smaller sizes of matrices, the lower execution time of the Matrix-Matrix Multiplication Algorithm imposes better runtimes. However, once the dimensions grow, the Diagonal Matrix Multiplication provides better runtimes. However, we note that the tests may give misleading information since, for the same <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM608"><mml:mi>N</mml:mi></mml:math></inline-formula>, the Diagonal Matrix Multiplication enables working with more significant matrices and generally involves less computation.</p>
<fig id="F8" position="float"><label>Figure 8</label>
<caption><p>Performance comparison of the Matrix-Matrix Multiplication Algorithm and the Diagonal Matrix Multiplication Algorithms.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g008.tif"/>
</fig>
<p>Finally, our fifth experiment combines the different algorithms in a Neural Network use case for cardiology and healthcare. This test analyzes the implications of putting together the algorithm in a real use case. For that, we develop a Convolutional Neural Network model based on the CheXpert dataset (<xref ref-type="bibr" rid="B41">41</xref>) with the typical Homomorphic Encryption-based architecture of Cryptonets (<xref ref-type="bibr" rid="B35">35</xref>). We perform inference on 250 samples and obtain the average runtime of the layers for the different proposed algorithms. The results of such tests are depicted in <xref ref-type="fig" rid="F9">Figure&#x00A0;9</xref>. First, we observe a noticeable difference between the first layers of the Neural Network and the last layers. As we showed in <xref ref-type="sec" rid="s4">Section 4</xref>, the complexity of the algorithms is often determined by the dimensionality of the treated matrices. The first layers deal with larger dimensions; thus, the computation is more affected by such dimensionality. This fact is especially noticeable with the Convolution and Average Pooling layers, where the Result Transformation is affected by such high dimensionality. Furthermore, when using Homomorphic Encryption, this behavior is emphasized with the existence of LHE, which introduces the concept of levels. Levels are treated with the Chinese Remainder Theorem and operate with more levels before dropping them with each rescaling. On the first layers, the efficiency is worse before rescaling, as HE operates on more remainders than in the latest layers, where most of the moduli have been dropped. Intermediate layers introduce a reduced delay due to being fundamentally a processing-based layer requiring no internal reorganization of the vectors. As a last factor, we analyze the algorithms&#x2019; precision compared to classic algorithms and obtain an equivalent absolute precision difference of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM609"><mml:mn>3.79</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>6</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, which we consider negligible for this application.</p>
<fig id="F9" position="float"><label>Figure 9</label>
<caption><p>Performance evaluation Cryptonets Neural Network based on the CheXpert dataset. Average runtime of the execution of 250 random samples of the dataset. The ordering of the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM610"><mml:mi>x</mml:mi></mml:math></inline-formula>-axis corresponds to the layer execution order (i.e., Conv. 0 is the first layer, and Act. 2 is the last layer).</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fcvm-10-1117360-g009.tif"/>
</fig>
</sec>
<sec id="s6"><label>6.</label><title>Related work</title>
<p>Various works have explored the use of packing within Homomorphic Encryption tasks. With the discovery of FHE by Gentry (<xref ref-type="bibr" rid="B15">15</xref>), research on ML tried to discover options for basic statistical models. Wu et al. (<xref ref-type="bibr" rid="B39">39</xref>) focus their research on linear regression, mean, and covariance with Somewhat Homomorphic Encryption. Due to the nature of SHE, their work tackles noise management to ensure the operations performed allow correct decryption of the result. The work of Duong et al. (<xref ref-type="bibr" rid="B42">42</xref>) goes one step beyond by implementing different embeddings applied when the encoding is performed and used to speed up matrix multiplications. Specifically, they cover two different embeddings, the binary and non-binary, whose placement varies in size and efficiency. These are similar to the replication factors covered in the Matrix-Matrix multiplication algorithm; however, they only cover <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM611"><mml:mi>m</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>m</mml:mi></mml:math></inline-formula> matrix multiplication, which could often result inefficient.</p>
<p>More recent works have focused on algorithms for Packed SIMD LHE. Halevi and Shoup (<xref ref-type="bibr" rid="B19">19</xref>) were the first to propose HE SIMD algorithms in their adaption to HELib (<xref ref-type="bibr" rid="B43">43</xref>). In their paper, they provide details on various algorithms, specifically those that allow using HE Packed vectors as usual operations. They cover various algorithms, from individual entry selection to replication and matrix multiplication. In contrast to our work, they provide more general algorithms that consider the minimization of the overload of HE parameters but do not strictly relate them to Deep Learning. Additionally, in our paper, we specifically cover the execution of algorithms for matrix multiplication on arbitrary matrix dimensions, while they only cover square matrices. In our paper, we consider a leveled approach to reduce the overall cost of the circuits in terms of efficiency.</p>
<p>Intel nGraph HE Transformer (<xref ref-type="bibr" rid="B44">44</xref>&#x2013;<xref ref-type="bibr" rid="B46">46</xref>) and MP2ML (<xref ref-type="bibr" rid="B47">47</xref>) are the first examples of privacy-preserving usability-oriented APIs for DL inference though users still need to incorporate the parametrization manually. Furthermore, the implementations of the different DL routines are opaque.</p>
<p>In CHET (<xref ref-type="bibr" rid="B18">18</xref>), the authors proposed a compiler for Deep Learning Inference which considers an analysis of the code to generate efficient HE code. EVA (<xref ref-type="bibr" rid="B48">48</xref>) improves CHET parameter selection and reduces it to a multiplication depth parameter. As mentioned before, for the algorithms for Convolution and Matrix Multiplication, we take as a basis the descriptions shown for CHET (<xref ref-type="bibr" rid="B18">18</xref>, <xref ref-type="bibr" rid="B48">48</xref>). However, what is shown in CHET is only valid for small matrices. We provide a deeper understanding of the dimensionality of matrices and efficiency guidelines together with the initial representation and result in transformation algorithms.</p>
<p>In GAZELLE (<xref ref-type="bibr" rid="B20">20</xref>), the authors propose a framework combining Packed Additively HE with Yao&#x2019;s Garbled Circuits (<xref ref-type="bibr" rid="B49">49</xref>) to speed up DL inference. As part of the packing, they introduce a new method of computing matrix multiplications based on computing halves of the matrix, but whose explanation makes it very difficult to replicate. In our work, we strive for replicability of the algorithms and provide source code for those.</p>
<p>HELayers (<xref ref-type="bibr" rid="B50">50</xref>) is a recent framework that aims to provide efficient abstraction layers that fully manage tiling (i.e., the packing of ciphertext vectors, enabling process applications such as DL). In HELayers, the basis for the automatization and interactions between different algorithms is explored.</p>
<p>Finally, Jiang et al. (<xref ref-type="bibr" rid="B51">51</xref>) propose a new method to compute matrix multiplication based on multiple iterations where they achieve better efficiency at the cost of a deeper circuit but only cover Matrix Multiplication and not other DL operations.</p>
<p>In comparison to other works, we provide a holistic analysis of the algorithms both individually as an algorithm and collectively within a Deep Neural Network. Furthermore, our analysis through metrics enables us to extract guidelines for use in DL inference. Future works also look in the line of automatic parametrization, combining SIMD algorithms with Homomorphic Encryption for Automated Parametrization (<xref ref-type="bibr" rid="B52">52</xref>)</p>
</sec>
<sec id="s7" sec-type="conclusions"><label>7.</label><title>Conclusions</title>
<p>Classically, healthcare has been limited to treatment in hospitals and health centers. Regulatory and privacy concerns limit the analysis of distributed medical data. It is crucial to allow for secure and efficient sharing and processing of sensitive data, such as health records and medical images, to adapt to the healthcare ecosystem and profit from computational improvements. Deep Learning and Cloud Computing arise as promising game-changing technologies in many fields. However, they still present privacy and security issues related to sensitive data. Homomorphic Encryption introduces a new way to preserve data privacy while performing computation. Not only does it enable secure data sharing and analytics, but it also guarantees privacy, security, and legal implications.</p>
<p>This work describes algorithms to adapt standard linear algebra routines to Packed Homomorphic Encryption (PHE). We focus on operations used in the inference process of Convolutional Neural Networks. In these settings, adapting classical to PHE operations poses additional challenges not covered in previous works. Concretely, our proposed algorithms consider the individual perspective (i.e., the algorithms working in a standalone scenario) and a holistic view (i.e., when different layers work connected in a neural network). A fundamental contribution is the generalization of the algorithms so we can apply them to theoretically arbitrary size inputs. Also, we propose routines such as the <italic>Initial Representation</italic> (IR) and the <italic>Result Transformation</italic> (RT) algorithms to deal with the data format inter-dependencies of the layers.</p>
<p>We elaborate on a set of metrics to represent the impact on the efficiency of PHE operations. The formal analysis of the algorithms shows that their application comes with a cost. Accordingly, we provide analysis for optimal application to DL to adapt existing architectures in the form of key findings. Our experimentation with different tests and use cases shows that the algorithms required to interconnect the layers (i.e., IR and RT) considerably impact the overall performance of the neural network. Thus, we propose optimizations to existing algorithms in the literature that streamline the layers so these additional transformations are optimized. We also provide key findings that can serve during the architectural design of the neural network to optimize its adaption to PHE.</p>
<p>This paper shows practical challenges arising from Packed Homomorphic Encryption with DL, providing a better understanding of the impact of the algorithms. It also provides guidelines for improving algorithms based on efficiency metrics. Also, with this work, we aim to reduce the inherent complexity of the area and understand the base factors upon which data scientists or security experts can design and implement efficient systems. Our experimentation with basic programs and neural networks shows that, in general, the modifications required to the base programs (so they can be used on top of the proposed algorithms) entail negligible computational overhead at no cost in terms of accuracy. This provides a step towards setting up practical, efficient, and private MLaaS services.</p>
<p>Further works should explore the automatic adaptation of algorithms from a classical setting to a vectorized SIMD setting for Homomorphic Encryption, exploiting the relations and the results present in algorithms when performing streamlined operations. Furthermore, establishing tiling frameworks should allow for providing standard representations for input and output, which standardizes the guidelines presented in this paper. Obtaining automatic parameters for Homomorphic Encryption is something that remains relevant as it is one of the more complex tasks in the procedure of Homomorphic Encryption code elaboration.</p>
</sec>
</body>
<back>
<sec id="s9" sec-type="data-availability"><title>Data availability statement</title>
<p>The original contributions presented in the study are included in the article/supplementary material, further inquiries can be directed to the corresponding author/s.</p>
</sec>
<sec id="s10" sec-type="author-contributions"><title>Author contributions</title>
<p>JCH: conceptualization, validation, methodology, software, validation, writing original draft, investigation. SP: conceptualization, investigation, resources, supervision, writing &#x2013; review &#x0026; editing. All authors contributed to the article and approved the submitted version.</p>
</sec>
<sec id="s11" sec-type="funding-information"><title>Funding</title>
<p>This work was partially supported by CERN openlab, the CERN Doctoral Student Programme, the Spanish grants ODIO (PID2019-111429RB-C21 and PID2019-111429RB), and the Region of Madrid grant CYNAMON-CM (P2018/TCS-4566), co-financed by European Structural Funds ESF and FEDER.</p>
</sec>
<ack><title>Acknowledgments</title>
<p>The opinions, findings, and conclusions or recommendations expressed are those of the authors and do not necessarily reflect those of any of the funders.</p>
</ack>
<sec id="s12" sec-type="COI-statement"><title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec id="s13" sec-type="disclaimer"><title>Publisher&#x0027;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<fn-group>
<fn id="FN0001"><p><sup>1</sup><ext-link ext-link-type="uri" xlink:href="https://github.com/anon-dlhe/DeepLearningLinearAlgebra.git">github.com/anon-dlhe/DeepLearningLinearAlgebra</ext-link></p></fn>
<fn id="FN0002"><p><sup>2</sup>Output privacy, e.g., preventing model inversion or membership inference attacks, requires mechanisms during training, such as Differential Privacy, which provides privacy protection against adversarial attacks. These are out of this paper&#x2019;s scope, which focuses on inference and assumes a pre-existing trained model.</p></fn>
<fn id="FN0003"><p><sup>3</sup>We note that so-called hybrid approaches, such as GAZELLE (<xref ref-type="bibr" rid="B20">20</xref>), are potential options for evaluating boolean non-linearities. However, they rely on other privacy-preserving computation techniques (e.g., Secure Multi-Party Computation) and, thus, are out of the scope of this paper.</p></fn>
</fn-group>
<ref-list><title>References</title>
<ref id="B1"><label>1.</label><citation citation-type="book"><person-group person-group-type="author"><name><surname>Roser</surname><given-names>M</given-names></name></person-group>. <source>Why is life expectancy in the US lower than in other rich countries?</source> <publisher-name>Our World in Data</publisher-name> (<year>2020</year>).</citation></ref>
<ref id="B2"><label>2.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Strodthoff</surname><given-names>N</given-names></name><name><surname>Strodthoff</surname><given-names>C</given-names></name></person-group>. <article-title>Detecting, interpreting myocardial infarction using fully convolutional neural networks</article-title>. <source>Physiol Meas</source>. (<year>2019</year>) <volume>40</volume>:<fpage>015001</fpage>. <pub-id pub-id-type="doi">10.1088/1361-6579/aaf34d</pub-id><pub-id pub-id-type="pmid">30523982</pub-id></citation></ref>
<ref id="B3"><label>3.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Topol</surname><given-names>EJ</given-names></name></person-group>. <article-title>High-performance medicine: the convergence of human, artificial intelligence</article-title>. <source>Nat Med</source>. (<year>2019</year>) <volume>25</volume>:<fpage>44</fpage>&#x2013;<lpage>56</lpage>. <pub-id pub-id-type="doi">10.1038/s41591-018-0300-7</pub-id><pub-id pub-id-type="pmid">30617339</pub-id></citation></ref>
<ref id="B4"><label>4.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Bhuyan</surname><given-names>HK</given-names></name><name><surname>Chakraborty</surname><given-names>C</given-names></name><name><surname>Shelke</surname><given-names>Y</given-names></name><name><surname>Pani</surname><given-names>SK</given-names></name></person-group>. <article-title>Covid-19 diagnosis system by deep learning approaches</article-title>. <source>Expert Syst</source>. (<year>2022</year>) <volume>39</volume>:<fpage>e12776</fpage>. <pub-id pub-id-type="doi">10.1111/exsy.12776</pub-id><pub-id pub-id-type="pmid">34511691</pub-id></citation></ref>
<ref id="B5"><label>5.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Muhammad</surname><given-names>L</given-names></name><name><surname>Algehyne</surname><given-names>EA</given-names></name><name><surname>Usman</surname><given-names>SS</given-names></name><name><surname>Ahmad</surname><given-names>A</given-names></name><name><surname>Chakraborty</surname><given-names>C</given-names></name><name><surname>Mohammed</surname><given-names>IA</given-names></name></person-group>. <article-title>Supervised machine learning models for prediction of COVID-19 infection using epidemiology dataset</article-title>. <source>SN Comput Sci</source>. (<year>2021</year>) <volume>2</volume>:<fpage>1</fpage>&#x2013;<lpage>13</lpage>. <pub-id pub-id-type="doi">10.1007/s42979-020-00394-7</pub-id></citation></ref>
<ref id="B6"><label>6.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Cs&#x00E1;ji</surname><given-names>BCetal.</given-names></name></person-group>. <comment>Approximation with artificial neural networks. Faculty of Sciences, E&#x00F6;tv&#x00F6;s Lor&#x00E1;nd University, Hungary, 24, 7 (2001)</comment>.</citation></ref>
<ref id="B7"><label>7.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Hunt</surname><given-names>T</given-names></name><name><surname>Song</surname><given-names>C</given-names></name><name><surname>Shokri</surname><given-names>R</given-names></name><name><surname>Shmatikov</surname><given-names>V</given-names></name><name><surname>Witchel</surname><given-names>E</given-names></name></person-group>. <comment>Chiron: privacy-preserving machine learning as a service [Preprint] (2018). Available at: arXiv:1803.05961</comment>.</citation></ref>
<ref id="B8"><label>8.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Qiang</surname><given-names>W</given-names></name><name><surname>Liu</surname><given-names>R</given-names></name><name><surname>Jin</surname><given-names>H</given-names></name></person-group>. <article-title>Defending CNN against privacy leakage in edge computing via binary neural networks</article-title>. <source>Future Gener Comput Syst</source>. (<year>2021</year>) <volume>125</volume>:<fpage>460</fpage>&#x2013;<lpage>70</lpage>. <pub-id pub-id-type="doi">10.1016/j.future.2021.06.037</pub-id></citation></ref>
<ref id="B9"><label>9.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Kairouz</surname><given-names>P</given-names></name><name><surname>McMahan</surname><given-names>HB</given-names></name><name><surname>Avent</surname><given-names>B</given-names></name><name><surname>Bellet</surname><given-names>A</given-names></name><name><surname>Bennis</surname><given-names>M</given-names></name><name><surname>Bhagoji</surname><given-names>AN</given-names></name></person-group>, et al. <comment>Advances, open problems in federated learning [Preprint] (2019). Available at: arXiv:1912.04977</comment>.</citation></ref>
<ref id="B10"><label>10.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Bonawitz</surname><given-names>K</given-names></name><name><surname>Eichner</surname><given-names>H</given-names></name><name><surname>Grieskamp</surname><given-names>W</given-names></name><name><surname>Huba</surname><given-names>D</given-names></name><name><surname>Ingerman</surname><given-names>A</given-names></name><name><surname>Ivanov</surname><given-names>V</given-names></name></person-group>, et al. <comment>Towards federated learning at scale: system design [Preprint] (2019). Available at: arXiv:1902.01046</comment>.</citation></ref>
<ref id="B11"><label>11.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Tonyali</surname><given-names>S</given-names></name><name><surname>Akkaya</surname><given-names>K</given-names></name><name><surname>Saputro</surname><given-names>N</given-names></name><name><surname>Uluagac</surname><given-names>AS</given-names></name><name><surname>Nojoumian</surname><given-names>M</given-names></name></person-group>. <article-title>Privacy-preserving protocols for secure, reliable data aggregation in IoT-enabled smart metering systems</article-title>. <source>Future Gener Comput Syst</source>. (<year>2018</year>) <volume>78</volume>:<fpage>547</fpage>&#x2013;<lpage>57</lpage>. <pub-id pub-id-type="doi">10.1016/j.future.2017.04.031</pub-id></citation></ref>
<ref id="B12"><label>12.</label><citation citation-type="book"><person-group person-group-type="author"><name><surname>Voigt</surname><given-names>P</given-names></name><name><surname>Bussche</surname><given-names>Av.d.</given-names></name></person-group>. <source>The EU general data protection regulation (GDPR): a practical guide</source>. <edition>1st ed</edition>. <publisher-loc>Incorporated</publisher-loc>: <publisher-name>Springer Publishing Company</publisher-name> (<year>2017</year>).</citation></ref>
<ref id="B13"><label>13.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Singh</surname><given-names>S</given-names></name><name><surname>Rathore</surname><given-names>S</given-names></name><name><surname>Alfarraj</surname><given-names>O</given-names></name><name><surname>Tolba</surname><given-names>A</given-names></name><name><surname>Yoon</surname><given-names>B</given-names></name></person-group>. <article-title>A framework for privacy-preservation of IoT healthcare data using federated learning and blockchain technology</article-title>. <source>Future Gener Comput Syst</source>. (<year>2022</year>) <volume>129</volume>:<fpage>380</fpage>&#x2013;<lpage>8</lpage>. <pub-id pub-id-type="doi">10.1016/j.future.2021.11.028</pub-id></citation></ref>
<ref id="B14"><label>14.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Cabrero-Holgueras</surname><given-names>J</given-names></name><name><surname>Pastrana</surname><given-names>S</given-names></name></person-group>. <article-title>SoK: privacy-preserving computation techniques for deep learning</article-title>. <source>Proc Priv Enh Technol</source>. (<year>2021</year>) <volume>2021</volume>:<fpage>139</fpage>&#x2013;<lpage>62</lpage>. <pub-id pub-id-type="doi">10.2478/popets-2021-0064</pub-id></citation></ref>
<ref id="B15"><label>15.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Gentry</surname><given-names>C</given-names></name></person-group>. <comment>A fully homomorphic encryption scheme. PhD thesis. Stanford University (2009). <ext-link ext-link-type="uri" xlink:href="crypto.stanford.edu/craig">crypto.stanford.edu/craig</ext-link></comment>.</citation></ref>
<ref id="B16"><label>16.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Brakerski</surname><given-names>Z</given-names></name><name><surname>Gentry</surname><given-names>C</given-names></name><name><surname>Vaikuntanathan</surname><given-names>V</given-names></name></person-group>. <article-title>(Leveled) fully homomorphic encryption without bootstrapping</article-title>. <source>ACM Trans Comput Theory</source>. (<year>2014</year>) <volume>6</volume>:<fpage>1</fpage>&#x2013;<lpage>36</lpage>. <pub-id pub-id-type="doi">10.1145/2633600</pub-id></citation></ref>
<ref id="B17"><label>17.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Brakerski</surname><given-names>Z</given-names></name><name><surname>Gentry</surname><given-names>C</given-names></name><name><surname>Halevi</surname><given-names>S</given-names></name></person-group>. <comment>Packed ciphertexts in LWE-based homomorphic encryption</comment>. <source>Public-Key Cryptography&#x2013;PKC 2013: 16th International Conference on Practice and Theory in Public-Key Cryptography Proceedings 16</source>; <comment>Feb 26&#x2013;Mar 1, 2013</comment>; <publisher-loc>Nara, Japan</publisher-loc>: <publisher-name>Springer</publisher-name> (<year>2013</year>). p. <fpage>1</fpage>&#x2013;<lpage>13</lpage>.</citation></ref>
<ref id="B18"><label>18.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Dathathri</surname><given-names>R</given-names></name><name><surname>Saarikivi</surname><given-names>O</given-names></name><name><surname>Chen</surname><given-names>H</given-names></name><name><surname>Laine</surname><given-names>K</given-names></name><name><surname>Lauter</surname><given-names>K</given-names></name><name><surname>Maleki</surname><given-names>S</given-names></name></person-group>, et al. <comment>CHET: an optimizing compiler for fully-homomorphic neural-network inferencing. In: <italic>Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation</italic> (2019). p. 142&#x2013;56</comment>.</citation></ref>
<ref id="B19"><label>19.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Halevi</surname><given-names>S</given-names></name><name><surname>Shoup</surname><given-names>V</given-names></name></person-group>. <comment>Algorithms in HElib. In: <italic>Annual Cryptology Conference</italic>. Springer (2014). p. 554&#x2013;71</comment>.</citation></ref>
<ref id="B20"><label>20.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Juvekar</surname><given-names>C</given-names></name><name><surname>Vaikuntanathan</surname><given-names>V</given-names></name><name><surname>Chandrakasan</surname><given-names>A</given-names></name></person-group>. <comment>GAZELLE: a low latency framework for secure neural network inference</comment>. In: <italic>27th USENIX Security Symposium (USENIX Security 18)</italic> <publisher-loc>Baltimore, MD</publisher-loc>: <publisher-name>USENIX Association</publisher-name> (<year>2018</year>). p. <fpage>1651</fpage>.</citation></ref>
<ref id="B21"><label>21.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Lindell</surname><given-names>Y</given-names></name></person-group>. <article-title>Secure multiparty computation</article-title>. <source>Commun. ACM</source>. (<year>2020</year>) <volume>64</volume>:<fpage>86</fpage>&#x2013;<lpage>96</lpage>. doi: <pub-id pub-id-type="doi">10.1145/3387108</pub-id></citation></ref>
<ref id="B22"><label>22.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Goldreich</surname><given-names>O</given-names></name><name><surname>Micali</surname><given-names>S</given-names></name><name><surname>Wigderson</surname><given-names>A</given-names></name></person-group>. <comment>How to play any mental game. In: <italic>Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing</italic>. New York, NY, USA: Association for Computing Machinery), STOC &#x2019;87 (1987). p. 218&#x2013;29. Available from: <ext-link ext-link-type="uri" xlink:href="https://doi.org:10.1145/28395.28420">https://doi.org:10.1145/28395.28420</ext-link></comment>.</citation></ref>
<ref id="B23"><label>23.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Goldreich</surname><given-names>O</given-names></name><name><surname>Micali</surname><given-names>S</given-names></name><name><surname>Wigderson</surname><given-names>A</given-names></name></person-group>. <comment>How to solve any protocol problem</comment>. <source>Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing STOC &#x2019;87</source>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>1987</year>). p. <fpage>218</fpage>&#x2013;<lpage>29</lpage>. <pub-id pub-id-type="doi">10.1145/28395.28420</pub-id></citation></ref>
<ref id="B24"><label>24.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Albrecht</surname><given-names>M</given-names></name><name><surname>Chase</surname><given-names>M</given-names></name><name><surname>Chen</surname><given-names>H</given-names></name><name><surname>Ding</surname><given-names>J</given-names></name><name><surname>Goldwasser</surname><given-names>S</given-names></name><name><surname>Gorbunov</surname><given-names>S</given-names></name></person-group>, et al. <comment><italic>Homomorphic encryption security standard</italic>. Toronto, Canada: HomomorphicEncryption.org (2018). Technical Report</comment>.</citation></ref>
<ref id="B25"><label>25.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Regev</surname><given-names>O</given-names></name></person-group>. <article-title>On lattices, learning with errors, random linear codes, and cryptography</article-title>. <source>J ACM (JACM)</source>. (<year>2009</year>) <volume>56</volume>:<fpage>1</fpage>&#x2013;<lpage>40</lpage>. <pub-id pub-id-type="doi">10.1145/1568318.1568324</pub-id></citation></ref>
<ref id="B26"><label>26.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Fan</surname><given-names>J</given-names></name><name><surname>Vercauteren</surname><given-names>F</given-names></name></person-group>. <article-title>Somewhat practical fully homomorphic encryption</article-title>. <source>IACR Cryptol ePrint Arch</source>. (<year>2012</year>) <volume>2012</volume>:<fpage>144</fpage>. Available at: <email>https://eprint.iacr.org/2012/144</email></citation></ref>
<ref id="B27"><label>27.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Cheon</surname><given-names>JH</given-names></name><name><surname>Kim</surname><given-names>A</given-names></name><name><surname>Kim</surname><given-names>M</given-names></name><name><surname>Song</surname><given-names>Y</given-names></name></person-group>, <comment>In: <italic>International Conference on the Theory and Application of Cryptology and Information Security</italic>. Springer (2017). p. 409&#x2013;37</comment>.</citation></ref>
<ref id="B28"><label>28.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Abadi</surname><given-names>M</given-names></name><name><surname>Agarwal</surname><given-names>A</given-names></name><name><surname>Barham</surname><given-names>P</given-names></name><name><surname>Brevdo</surname><given-names>E</given-names></name><name><surname>Chen</surname><given-names>Z</given-names></name><name><surname>Citro</surname><given-names>C</given-names></name></person-group>, et al. <comment>Tensorflow: large-scale machine learning on heterogeneous distributed systems [Preprint] (2016). Available at: arXiv:1603.04467</comment>.</citation></ref>
<ref id="B29"><label>29.</label><citation citation-type="other"><collab>[Dataset]</collab> <person-group person-group-type="author"><name><surname>Chollet</surname><given-names>F</given-names></name></person-group>, et al. <comment>Keras (2015). Available from: <ext-link ext-link-type="uri" xlink:href="https://github.com/fchollet/keras">https://github.com/fchollet/keras</ext-link></comment>.</citation></ref>
<ref id="B30"><label>30.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Paszke</surname><given-names>A</given-names></name><name><surname>Gross</surname><given-names>S</given-names></name><name><surname>Chintala</surname><given-names>S</given-names></name><name><surname>Chanan</surname><given-names>G</given-names></name><name><surname>Yang</surname><given-names>E</given-names></name><name><surname>DeVito</surname><given-names>Z</given-names></name></person-group>, et al. <comment>Automatic differentiation in PyTorch</comment>. <source>NIPS 2017 Workshop on Autodiff</source> (<year>2017</year>).</citation></ref>
<ref id="B31"><label>31.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>LeCun</surname><given-names>Y</given-names></name><name><surname>Bengio</surname><given-names>Y</given-names></name><name><surname>Hinton</surname><given-names>G</given-names></name></person-group>. <article-title>Deep learning</article-title>. <source>Nature</source>. (<year>2015</year>) <volume>521</volume>:<fpage>436</fpage>&#x2013;<lpage>44</lpage>. <pub-id pub-id-type="doi">10.1038/nature14539</pub-id><pub-id pub-id-type="pmid">26017442</pub-id></citation></ref>
<ref id="B32"><label>32.</label><citation citation-type="book"><person-group person-group-type="author"><name><surname>Goodfellow</surname><given-names>I</given-names></name><name><surname>Bengio</surname><given-names>Y</given-names></name><name><surname>Courville</surname><given-names>A</given-names></name><name><surname>Bengio</surname><given-names>Y</given-names></name></person-group>. <source>Deep learning</source>. Vol. <volume>1</volume>. <publisher-loc>Cambridge</publisher-loc>: <publisher-name>MIT Press</publisher-name> (<year>2016</year>).</citation></ref>
<ref id="B33"><label>33.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Karjanto</surname><given-names>N</given-names></name></person-group>. <comment>Properties of chebyshev polynomials [Preprint] (2020). Available at: arXiv:2002.01342</comment>.</citation></ref>
<ref id="B34"><label>34.</label><citation citation-type="book"><person-group person-group-type="author"><name><surname>Hassoun</surname><given-names>MHetal</given-names></name></person-group>. <source>Fundamentals of artificial neural networks</source>. <publisher-name>MIT Press</publisher-name> (<year>1995</year>).</citation></ref>
<ref id="B35"><label>35.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Gilad-Bachrach</surname><given-names>R</given-names></name><name><surname>Dowlin</surname><given-names>N</given-names></name><name><surname>Laine</surname><given-names>K</given-names></name><name><surname>Lauter</surname><given-names>K</given-names></name><name><surname>Naehrig</surname><given-names>M</given-names></name><name><surname>Wernsing</surname><given-names>J</given-names></name></person-group>. <comment>Cryptonets: applying neural networks to encrypted data with high throughput and accuracy. In: <italic>International Conference on Machine Learning</italic> (2016). p. 201&#x2013;10</comment>.</citation></ref>
<ref id="B36"><label>36.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Hesamifard</surname><given-names>E</given-names></name><name><surname>Takabi</surname><given-names>H</given-names></name><name><surname>Ghasemi</surname><given-names>M</given-names></name></person-group>. <comment>Cryptodl: deep neural networks over encrypted data [Preprint] (2017). Available at: arXiv:1711.05189</comment>.</citation></ref>
<ref id="B37"><label>37.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Valsalam</surname><given-names>V</given-names></name><name><surname>Skjellum</surname><given-names>A</given-names></name></person-group>. <article-title>A framework for high-performance matrix multiplication based on hierarchical abstractions, algorithms and optimized low-level kernels</article-title>. <source>Concurr Comput Pract Exp</source>. (<year>2002</year>) <volume>14</volume>:<fpage>805</fpage>&#x2013;<lpage>39</lpage>. <pub-id pub-id-type="doi">10.1002/cpe.630</pub-id></citation></ref>
<ref id="B38"><label>38.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Xie</surname><given-names>P</given-names></name><name><surname>Bilenko</surname><given-names>M</given-names></name><name><surname>Finley</surname><given-names>T</given-names></name><name><surname>Gilad-Bachrach</surname><given-names>R</given-names></name><name><surname>Lauter</surname><given-names>K</given-names></name><name><surname>Naehrig</surname><given-names>M</given-names></name></person-group>. <comment>Crypto-nets: neural networks over encrypted data [Preprint] (2014). available at: arXiv:1412.6181</comment>.</citation></ref>
<ref id="B39"><label>39.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Wu</surname><given-names>D</given-names></name><name><surname>Haven</surname><given-names>J</given-names></name></person-group>. <comment><italic>Using homomorphic encryption for large scale statistical analysis</italic>. FHE-SI-Report, Univ. Stanford (2012). Technical Report TR-dwu4</comment>.</citation></ref>
<ref id="B40"><label>40.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Ishiyama</surname><given-names>T</given-names></name><name><surname>Suzuki</surname><given-names>T</given-names></name><name><surname>Yamana</surname><given-names>H</given-names></name></person-group>. <comment>Highly accurate CNN inference using approximate activation functions over homomorphic encryption. In: <italic>2020 IEEE International Conference on Big Data (Big Data)</italic>. IEEE (2020). p. 3989&#x2013;95</comment>.</citation></ref>
<ref id="B41"><label>41.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Irvin</surname><given-names>J</given-names></name><name><surname>Rajpurkar</surname><given-names>P</given-names></name><name><surname>Ko</surname><given-names>M</given-names></name><name><surname>Yu</surname><given-names>Y</given-names></name><name><surname>Ciurea-Ilcus</surname><given-names>S</given-names></name><name><surname>Chute</surname><given-names>C</given-names></name></person-group>, et al. <comment>Chexpert: a large chest radiograph dataset with uncertainty labels and expert comparison. In: <italic>Proceedings of the AAAI Conference on Artificial Intelligence</italic>. Vol. 33 (2019). p. 590&#x2013;7</comment>.</citation></ref>
<ref id="B42"><label>42.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Duong</surname><given-names>DH</given-names></name><name><surname>Mishra</surname><given-names>PK</given-names></name><name><surname>Yasuda</surname><given-names>M</given-names></name></person-group>. <comment>Efficient secure matrix multiplication over LWE-based homomorphic encryption</comment>. <source>Tatra Mt. Math. Publ.</source> (<year>2016</year>) <volume>67</volume>:<fpage>69</fpage>&#x2013;<lpage>83</lpage>. <pub-id pub-id-type="doi">10.1515/tmmp-2016-0031</pub-id></citation></ref>
<ref id="B43"><label>43.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Halevi</surname><given-names>S</given-names></name><name><surname>Shoup</surname><given-names>V</given-names></name></person-group>. <article-title>Design and implementation of HElib: a homomorphic encryption library</article-title>. <source>IACR Cryptol ePrint Arch</source>. (<year>2020</year>) <volume>2020</volume>:<fpage>1481</fpage>.</citation></ref>
<ref id="B44"><label>44.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Boemer</surname><given-names>F</given-names></name><name><surname>Lao</surname><given-names>Y</given-names></name><name><surname>Cammarota</surname><given-names>R</given-names></name><name><surname>Wierzynski</surname><given-names>C</given-names></name></person-group>. <comment>nGraph-HE: a graph compiler for deep learning on homomorphically encrypted data. In: <italic>Proceedings of the 16th ACM International Conference on Computing Frontiers. CF &#x2019;19</italic></comment>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>2019</year>). p. <fpage>3</fpage>&#x2013;<lpage>13</lpage>. <pub-id pub-id-type="doi">10.1145/3310273.3323047</pub-id></citation></ref>
<ref id="B45"><label>45.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Boemer</surname><given-names>F</given-names></name><name><surname>Costache</surname><given-names>A</given-names></name><name><surname>Cammarota</surname><given-names>R</given-names></name><name><surname>Wierzynski</surname><given-names>C</given-names></name></person-group>. <comment>nGraph-HE2: a high-throughput framework for neural network inference on encrypted data. In: <italic>Proceedings of the 7th ACM Workshop on Encrypted Computing &#x0026; Applied Homomorphic Cryptography WAHC&#x2019;19</italic></comment>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>2019</year>). p. <fpage>45</fpage>&#x2013;<lpage>56</lpage>. <pub-id pub-id-type="doi">10.1145/3338469.3358944</pub-id></citation></ref>
<ref id="B46"><label>46.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Cyphers</surname><given-names>S</given-names></name><name><surname>Bansal</surname><given-names>AK</given-names></name><name><surname>Bhiwandiwalla</surname><given-names>A</given-names></name><name><surname>Bobba</surname><given-names>J</given-names></name><name><surname>Brookhart</surname><given-names>M</given-names></name><name><surname>Chakraborty</surname><given-names>A</given-names></name></person-group>, et al. <comment>Intel ngraph: an intermediate representation, compiler, and executor for deep learning [Preprint] (2018). Available at: arXiv:1801.08058</comment>.</citation></ref>
<ref id="B47"><label>47.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Boemer</surname><given-names>F</given-names></name><name><surname>Cammarota</surname><given-names>R</given-names></name><name><surname>Demmler</surname><given-names>D</given-names></name><name><surname>Schneider</surname><given-names>T</given-names></name><name><surname>Yalame</surname><given-names>H</given-names></name></person-group>. <comment>MP2ML: a mixed-protocol machine learning framework for private inference. In: <italic>Proceedings of the 2020 Workshop on Privacy-Preserving Machine Learning in Practice PPMLP&#x2019;20</italic></comment>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>2020</year>). p. <fpage>43</fpage>&#x2013;<lpage>45</lpage>. <pub-id pub-id-type="doi">10.1145/3411501.3419425</pub-id></citation></ref>
<ref id="B48"><label>48.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Dathathri</surname><given-names>R</given-names></name><name><surname>Kostova</surname><given-names>B</given-names></name><name><surname>Saarikivi</surname><given-names>O</given-names></name><name><surname>Dai</surname><given-names>W</given-names></name><name><surname>Laine</surname><given-names>K</given-names></name><name><surname>Musuvathi</surname><given-names>M</given-names></name></person-group>. <comment>Eva: an encrypted vector arithmetic language and compiler for efficient homomorphic computation. In: <italic>Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation PLDI 2020</italic></comment>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>2020</year>). p. <fpage>546</fpage>&#x2013;<lpage>61</lpage>. <pub-id pub-id-type="doi">10.1145/3385412.3386023</pub-id></citation></ref>
<ref id="B49"><label>49.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Yao</surname><given-names>AC</given-names></name></person-group>. <comment>How to generate and exchange secrets. In: <italic>27th Annual Symposium on Foundations of Computer Science</italic> (1986). p. 162&#x2013;7. Available from: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/SFCS.1986.25">https://doi.org/10.1109/SFCS.1986.25</ext-link></comment>.</citation></ref>
<ref id="B50"><label>50.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>[Dataset] Aharoni</surname><given-names>E</given-names></name><name><surname>Adir</surname><given-names>A</given-names></name><name><surname>Baruch</surname><given-names>M</given-names></name><name><surname>Drucker</surname><given-names>N</given-names></name><name><surname>Ezov</surname><given-names>G</given-names></name><name><surname>Farkash</surname><given-names>A</given-names></name></person-group>, et al. <comment>Helayers: a tile tensors framework for large neural networks on encrypted data.</comment> <source>Privacy Enhancing Technology Symposium (PETs) 2023</source> (<year>2023</year>).</citation></ref>
<ref id="B51"><label>51.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Jiang</surname><given-names>X</given-names></name><name><surname>Kim</surname><given-names>M</given-names></name><name><surname>Lauter</surname><given-names>K</given-names></name><name><surname>Song</surname><given-names>Y</given-names></name></person-group>. <comment>Secure outsourced matrix computation and application to neural networks. In: <italic>Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security CCS &#x2019;18</italic></comment>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name> (<year>2018</year>). p. <fpage>1209</fpage>&#x2013;<lpage>22</lpage>. <pub-id pub-id-type="doi">10.1145/3243734.3243837</pub-id></citation></ref>
<ref id="B52"><label>52.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Cabrero-Holgueras</surname><given-names>J</given-names></name><name><surname>Pastrana</surname><given-names>S</given-names></name></person-group>. <comment>Towards automated homomorphic encryption parameter selection with fuzzy logic and linear programming [Preprint] (2023). Available at: arXiv:2302.08930</comment>.</citation></ref></ref-list>
<app-group><app id="app1"><title>Appendix A. Baseline convolution algorithms</title>
<p>In this appendix we overview the base algorithms upon which we improve the proposed in <xref ref-type="sec" rid="s3b">Section 3.2</xref>. First we describe the base convolution algorithm (<xref ref-type="app" rid="app1a">Section A.1</xref>), its base result transformation (<xref ref-type="app" rid="app1b">Section A.2</xref> and the introduction of Stride (<xref ref-type="app" rid="app1c">Section A.3</xref>) and padding (<xref ref-type="app" rid="app1d">Section A.4</xref>).</p>
<sec id="app1a"><title>A.1. Convolution</title>
<p>We propose a general algorithm that permits the application of the convolution operation to arbitrary matrices using SIMD operations. As a starting point, we based the algorithm on examples proposed for matrices of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM612"><mml:mn>3</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula> using kernel filters of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM613"><mml:mn>2</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula> (<xref ref-type="bibr" rid="B18">18</xref>).</p>
<p>The algorithm takes as input a plaintext filter <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM614"><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula> of dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM615"><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula>. The filter is applied to a ciphertext vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM616"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> (in RC format) that corresponds to an encrypted input matrix, i.e., <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM617"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM618"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> being the encryption key and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM619"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:math></inline-formula> the input data in cleartext. The algorithm leverages the fact that the dimensions of filters are shorter than input matrices and that we can operate them in plaintext. Thus, it computes the convolution between each pixel of the filter and the input matrix (i.e., represented by a ciphertext) and adds the partial results for each pixel. The algorithm is described in <xref ref-type="table" rid="A11">Algorithm 11</xref>.</p>
<table-wrap id="A11" position="float"><label>Algorithm 11</label>
<caption><p>2D Convolution</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM620"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM621"><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM622"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in CRF or SCRF format<break/>&#x2003;<bold>function</bold> C<sc>ONVOLUTION</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM623"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>,<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM624"><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<bold>for</bold> {<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM625"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<bold>for</bold> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM626"><mml:mi>j</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM627"><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x226A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>j</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM628"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM629"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Depending on whether we use stride or not, we consider a different result layout. In our work, we name two, the Convolution Resulting Format (CRF) for non-stridden convolution and the Stridden Convolution Resulting Format (SCRF) for stridden convolutions. These layouts include <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM630"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> meaningless values between the values of the result (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM631"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) designated by the input matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM632"><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> and filter size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM633"><mml:mrow><mml:mi mathvariant="script">F</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>. Generally, these formats are not valid for consecutive operations (layers), therefore Result Transformation algorithms are needed, and we describe them next.</p>
</sec>
<sec id="app1b"><title>A.2. Result transformation for CRF format</title>
<p>In the CRF format, the amount of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM634"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> values is given by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM635"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM636"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. Therefore, a Result Transformation algorithm is developed to transform the CRF format to the Row-Column format (named RT-CRF-RC). The original layout splits the useful rows <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM637"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM638"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> values, therefore, the algorithm creates bitmasks for the rows and shifts them to the appropriate position on the resulting RC format. This processing is described in <xref ref-type="table" rid="A12">Algorithm 12</xref>.</p>
<table-wrap id="A12" position="float"><label>Algorithm 12</label>
<caption><p>Result Transformation CRF to RC</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM639"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>R</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in CRF format, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM640"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM641"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM642"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, in RC format<break/>&#x2003;<bold>function</bold> RT-CRF-RC (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM643"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM644"><mml:mi>h</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM645"><mml:mi>w</mml:mi></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM646"><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:math></inline-formula> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM647"><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM648"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM649"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM650"><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>w</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM651"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM652"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM653"><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>R</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x226A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>o</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM654"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM655"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="app1c"><title>A.3. Stride</title>
<p>Sometimes, the input matrices to a convolutional layer are high resoultion images (i.e., have long dimensions <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM656"><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>). Processing these images demands high performance cost, since the convolutions extract features from small areas (as defined by the kernel). To avoid processing large portions of the images, the process can be optimized by skipping the result of parts of the convolutions. The amount of data to be skipped is defined by a <italic>stride</italic> tuple <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM657"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. That is, considering that in a normal convolution the output shape is defined by <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM658"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM659"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, stridden convolutions reduce the output shape by a factor of the stride <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM660"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> such that <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM661"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM662"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula>.</p>
<p>Given the convolution algorithm is based on the filter size, the reduction of output elements does not affect the convolution algorithm itself, but it does provide a different layout for the output format. In such a layout, the elements are more scattered than without stride. For reference, we name this layout Strided Convolution Resulting Format (SCRF). As with the CRF format, we cannot directly use the output layout in consecutive layers. Thus, we propose an algorithm that translates from this layout to the RC, dubbed RT-SCRF-RC, described in <xref ref-type="table" rid="A13">Algorithm 13</xref>. In this algorithm, we use a formula to determine where the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM663"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> elements for the stride output are placed and extract them iterative addition through bitmasks.</p>
<table-wrap id="A13" position="float"><label>Algorithm 13</label>
<caption><p>Result Transformation SCRF to RC</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM664"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>R</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> in SCRF format, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM665"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM666"><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM667"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM668"><mml:mi>p</mml:mi></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM669"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> in RC format<break/>&#x2003;<bold>function</bold> RT-SCRF-RC (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM670"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM671"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo><mml:mrow><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub></mml:mfrac></mml:mstyle></mml:mrow></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM672"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo><mml:mrow><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi>w</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mfrac></mml:mstyle></mml:mrow></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM673"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM674"><mml:mi>j</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM675"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>x</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM676"><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM677"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>C</mml:mi><mml:mi>R</mml:mi><mml:mi>F</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x226A;</mml:mo><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM678"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>C</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="app1d"><title>A.4. SIMD padding</title>
<p>In many modern CNN architectures, it is common to chain multiple convolutional layers. While in the first convolutional layer it is possible to introduce padding in &#x201C;cleartext&#x201D; (i.e., the data owner can add it at the end of the ciphertext before encryption), for consecutive ones, it is required to do it privately.</p>
<p>The proposed algorithm takes a bidimensional linearized ciphertext array <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM679"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and pads it uniformly with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM680"><mml:mi>p</mml:mi></mml:math></inline-formula> zeroes on each dimension. It initially assumes a Row-Column format where the remaining entries of the vector are set to zero. The algorithm extracts each row, and computes the necessary shifting for a row, defined by the formula <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM681"><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2223;</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>h</mml:mi></mml:math></inline-formula>. The details are described in <xref ref-type="table" rid="A14">Algorithm 14</xref>. This algorithm outputs a Row-Column format directly usable by the convolution algorithm described in <xref ref-type="sec" rid="s3b1">Section 3.2.1</xref>. Furthermore, it does not affect the Result Transformation algorithm.</p>
<table-wrap id="A14" position="float"><label>Algorithm 14</label>
<caption><p>2D Padding</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
</colgroup>
<tbody>
<tr>
<td valign="top" align="left"><bold>Input:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM682"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>w</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, in RC Format, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM683"><mml:mi>p</mml:mi></mml:math></inline-formula><break/><bold>Output:</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM684"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:mrow><mml:mi>Q</mml:mi></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mi>N</mml:mi></mml:msup><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="script">M</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, in RC format<break/>&#x2003;<bold>function</bold> P<sc>ADDING</sc> (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM685"><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM686"><mml:mi>p</mml:mi></mml:math></inline-formula>)<break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM687"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>h</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM688"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>w</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>for</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM689"><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>h</mml:mi></mml:math></inline-formula> <bold>do</bold><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM690"><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>w</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM691"><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;&#x2003;<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM692"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2295;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2299;</mml:mo><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>t</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x226B;</mml:mo><mml:mi>s</mml:mi><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula><break/>&#x2003;&#x2003;<bold>end for</bold><break/>&#x2003;&#x2003;<bold>return</bold> <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM693"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula><break/>&#x2003;<bold>end function</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec></app>
</app-group>
</back>
</article>