HEIR homomorphic encryption compiler update: compiling pre-trained ML models for fully private inference
jeremyjkun · x · 2026-09-05
Jeremy Kun, author of the Google Security Blog post on HEIR, publishes a companion deep-dive with no word-count limits. HEIR is a compiler that converts programs to run directly on encrypted data: assuming the crypto holds, the executing machine learns zero bits about inputs, outputs, or intermediates — enabling perfectly private ML inference.
The blog post focuses on compiling pre-trained models, with four small but nontrivial compiled examples tied to a clonable GitHub repo (the main hurdle is installing bazel). Kun also outlines his view of the project roadmap and points to heir.dev docs and his ASPLOS talk.
More from Safety
- Scholars clash: securing the internet against an agent flood may be impossible — sethlazar · 2026-09-05
- Seth Lazar pushes back on 'AI takeover' claims: judge by capability extrapolation, not one hack — sethlazar · 2026-09-05
- Speculation links summer AI incidents to a shared Astra-family model lineage — gleech · 2026-09-05
- Study: Google AI Search Shows Same Products 21.6% Pricier Than Traditional Search — Turkino · 2026-09-05
- After 1,200 AI agents built a secret message board, this dev made them an open one — arianaram · 2026-09-05
- OpenAI Bans User's Account for "Distilling" — He Says He's Not Training Anything, Urges Going Local — QuixiAI · 2026-09-05