Saeed Ur Rahman1,2, Zhao Chang1,2,*, and Ke Cheng1,2
Zhao Chang
1School of Computer Science and Technology, Xidian University, Xi’an, 710071, China.
2Shaanxi Key Laboratory of Network and System Security, Xidian University, Xi’an, 710071, China.
*Corresponding author
Graph Neural Networks have achieved remarkable success in graph-based learning tasks, but often require access to sensitive data during inference, raising privacy concerns in domains such as healthcare, finance, and cybersecurity. Homomorphic Encryption enables computation on encrypted data; however, directly applying HE to graph neural network operations remains computationally expensive due to complex message-passing and attention mechanisms. This paper presents Hybrid-HE GNN, a privacy-preserving graph inference framework that employs parallel Graph Isomorphism Network (GIN) and Graph Attention Network (GAT) branches followed by learnable gated fusion, with embedding-level homomorphic encryption for secure downstream classification. Graph embeddings are generated in plaintext and subsequently classified under Paillier and CKKS encryption schemes using a Logistic Regression classifier, enabling secure inference while reducing computational overhead. Experimental evaluation on the MUTAG, Cora, and PROTEINS benchmark datasets demonstrates that the proposed framework preserves predictive performance under encrypted inference with only negligible deviation from plaintext execution. The Hybrid-HE GNN achieved encrypted accuracies of 87.74%, 91.10%, and 87.12% on MUTAG, Cora, and PROTEINS, respectively, outperforming baseline GNN models across the evaluated datasets. Furthermore, CKKS batched inference substantially reduced latency compared with Paillier encryption while maintaining equivalent classification performance. These results demonstrate that embedding-level homomorphic encryption provides an effective balance between privacy preservation, predictive accuracy, and computational efficiency for graph neural network inference.
Graph Neural Networks (GNN), Homomorphic Encryption (HE), Privacy-Preserving Inference, Graph Classification, Secure Machine Learning
Saeed Ur Rahman, Zhao Chang, and Ke Cheng (2026). Privacy-Preserving Graph Neural Network Inference Using Homomorphic Encryption for Secure Graph Classification. Journal of Networking and Network Applications, Volume 6, Issue 3, pp. 111–131. https://doi.org/10.33969/J-NaNA.2026.060302.
[1] Z. Wu, S. Pan, F. Chen, G. Long, C. Zhang, and P. S. Yu, “A comprehensive survey on graph neural networks,” IEEE Transactions on Neural Networks and Learning Systems, vol. 32, no. 1, pp. 4–24, 2021.
[2] F. Guan, T. Zhu, W. Zhou et al., “Graph neural networks: A survey on the links between privacy and security,” Artificial Intelligence Review, vol. 57, 2024.
[3] O. Mudannayake, A. Indika, U. Jayasinghe, G. M. Lee, and J. Alawatu-goda, “On privacy-preserved machine learning using secure multi-party computing: Techniques and trends,” Computers, Materials & Continua, vol. 78, no. 3, pp. 5431–5455, 2025, survey of secure computation techniques for privacy-preserving ML.
[4] Y. Zhang, Y. Zhao, Z. Li, X. Cheng, Y. Wang, O. Kotevska, P. S. Yu, and T. Derr, “A survey on privacy in graph neural networks: Attacks, preservation, and applications,” IEEE Transactions on Knowledge and Data Engineering, vol. 36, no. 12, pp. 1–28, 2024.
[5] S. Sajadmanesh, A. S. Shamsabadi, A. Bellet, and D. Gatica-Perez, “GAP: Differentially private graph neural networks with aggregation perturbation,” pp. 3223–3240, 2023.
[6] S. Jiang, H. Yang, Q. Xie, C. Ma, S. Wang, Z. Liu, T. Xiang, and
G. Xing, “Towards compute-efficient byzantine-robust federated learning with fully homomorphic encryption,” vol. 7, 2025, pp. 1657–1668.
[7] R. Ran, N. Xu, T. Liu, W. Wang, G. Quan, and W. Wen, “Penguin: Parallel-packed homomorphic encryption for fast graph convolutional network inference,” vol. 36, pp. 19 104–19 116, 2023.
[8] Z. Kan, H. Han, S. Shi, T. Hua, H. Lu, X. Li, J. Mu, and X. Hu, “FicGCN: Unveiling the homomorphic encryption efficiency from irreg-ular graph convolutional networks,” vol. 267, pp. 28 832–28 848, 2025.
[9] A. Falcetta and M. Roveri, “Privacy-preserving deep learning with homomorphic encryption: An introduction,” IEEE Computational Intel-ligence Magazine, vol. 17, no. 3, pp. 14–25, 2022.
[10] B. Balaban et al., “Privacy-preserving machine learning inference for clinically actionable models,” IEEE Access, vol. 13, pp. 37 431–37 456, 2025.
[11] D. Rahbari, M. Daneshtalab, and M. Jenihhin, “An efficient architecture for edge AI federated learning with homomorphic encryption,” IEEE Access, vol. 13, pp. 97 919–97 929, 2025.
[12] J. Yuan, W. Liu, J. Shi et al., “Approximate homomorphic encryption based privacy-preserving machine learning: A survey,” Artificial Intelli-gence Review, vol. 58, p. 82, 2025.
[13] A. Daigavane, G. Madan, A. Sinha, A. G. Thakurta, G. Aggarwal, and
P. Jain, “Node-level differentially private graph neural networks,” arXiv preprint arXiv:2111.15521, 2021.
[14] N. B. Njungle, E. Jahns, Z. Wu et al., “Guardianml: Anatomy of privacy-preserving machine learning techniques and frameworks,” IEEE Access, vol. 13, pp. 61 483–61 510, 2025.
[15] J. Lee, H. Kang, Y. Lee, W. Choi, J. Eom, M. Deryabin, E. Lee, J. Lee,
D. Yoo, Y. Kim, and J. No, “Privacy-preserving machine learning with fully homomorphic encryption for deep neural network,” IEEE Access, vol. 10, pp. 30 039–30 054, 2022.
[16] A. Benaissa et al., “Tenseal: A library for encrypted tensor operations us-ing homomorphic encryption,” arXiv preprint arXiv:2104.03152, 2021.
[17] I. Abell´an ´Alvarez, J. Delgado Fern´andez, and S. Potenciano Menci, “Privacy-preserving distributed clustering: A fully homomorphic en-crypted approach for time series,” Computers & Security, vol. 157, p. 104579, 2025.
[18] M. Kim and H. Lee, “Polynomial approximations for encrypted neural network inference,” in Proceedings of the ACM Conference on Computer and Communications Security, 2021.
[19] S. Seo and C. Min, “Optimal design of key switching parameters for efficient CKKS bootstrapping,” IEEE Access, vol. 13, pp. 163 431–163 446, 2025.
[20] A. Zuo, Z. Feng, Y. Ping, S. Tao, H. Sun, and Y. Chen, “FedGraphHE: A privacy-preserving federated graph neural network framework with dynamic homomorphic encryption and robust aggregation,” PLoS ONE, vol. 21, no. 1, p. e0339881, 2026.
[21] J.-W. Lee, E. Lee, Y. Lee, Y.-S. Kim, and J.-S. No, High-Precision Bootstrapping of RNS-CKKS Homomorphic Encryption Using Optimal Minimax Polynomial Approximation and Inverse Sine Function, ser. Lecture Notes in Computer Science, 2021, vol. 12697, pp. 618–647.
[22] S. Selvakumar and B. Senthilkumar, “A privacy preserving machine learning framework for medical image analysis using quantized fully connected neural networks with tfhe based inference,” Scientific Reports, vol. 15, p. 27880, 2025.
[23] R. Liu, P. Xing, Z. Deng, A. Li, C. Guan, and H. Yu, “Federated graph neural networks: Overview, techniques, and challenges,” IEEE Transactions on Neural Networks and Learning Systems, vol. 36, no. 3, pp. 4279–4295, 2025.
[24] Y. Liu, X. Qian, H. Li, M. Hao, and S. Guo, “Fast secure aggregation for privacy-preserving federated learning,” pp. 3017–3022, 2022.
[25] R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and
J. Wernsing, “Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy,” pp. 201–210, 2016.
[26] M. Yang, W. Yi, J. Wang, H. Hu, X. Xu, and Z. Li, “Penetralium: Privacy-preserving and memory-efficient neural network inference at the edge,” Future Generation Computer Systems, vol. 156, pp. 30–41, 2024.
[27] X. He, Z. Song, D. Zhang, H. Ju, and Q. Meng, “Homomorphic encryption-based federated active learning on gcns,” Symmetry, vol. 17,
p. 969, 2025.
[28] P. Hu, Z. Lin, W. Pan, Q. Yang, X. Peng, and Z. Ming, “Privacy-preserving graph convolution network for federated item recommenda-tion,” Artificial Intelligence, vol. 324, p. 103996, 2023.
[29] B. Hua and H. Xi, “A privacy preserving intrusion detection framework for iiot in 6g networks using homomorphic encryption and graph neural networks,” Scientific Reports, vol. 16, p. 2297, 2026.
[30] Y. Wu, L. Zhang, X. Chen, and Y. Wang, “Privacy-preserving feder-ated graph neural network learning and applications: A survey,” ACM Computing Surveys, vol. 57, no. 2, pp. 1–34, 2024.
[31] K. Xu, W. Hu, J. Leskovec, and S. Jegelka, “How powerful are graph neural networks?” in International Conference on Learning Represen-tations, 2019.
[32] S. Xie, J. Ye, and W. Ou, “Multi-user encrypted machine learning based on partially homomorphic encryption,” Electronics, vol. 14, no. 3, p. 640, 2025.