- The paper introduces FedHENet, which combines frozen ImageNet features, closed-form ROLANN training, and CKKS encryption to produce an exact one-round federated model without sharing sensitive correlations in plaintext.
- FedHENet maintains roughly 83.6% CIFAR-10 accuracy under IID, highly non-IID, and single-class settings, outperforming FedAvg and FedProx by more than 40 points in the 10-client single-class scenario and by over 8 points with 500 clients.
- The framework reduces energy consumption by up to 70%, lowers total communication, and adds less than 5% computational overhead for encryption, but depends on the pretrained backbone and leaves plaintext SVD-factor privacy and large-scale deployment insufficiently validated.
FedHENet extends the FedHEONN framework (2602.13024) from tabular data to image classification, positioning itself within "Frugal FL": a design philosophy that prioritizes minimal computation, communication, and energy expenditure alongside privacy guarantees. The core observation motivating the work is that dominant FL algorithms such as FedAvg and FedProx rely on iterative optimization of deep networks, which incurs three costs: client drift under non-IID data, hundreds of communication rounds, and exposure of shared gradients to privacy attacks. FedHENet sidesteps all three by replacing iterative local training with a closed-form, single-round aggregation procedure protected by homomorphic encryption (HE).
Method
The architecture decouples representation learning from classification. All clients share a frozen, ImageNet-pretrained feature extractor (ResNet-18 in the experiments) that maps local images to compact embeddings Xk∈Rmk×n. On top of these embeddings, each client trains a Regularized One-Layer Neural Network (ROLANN) classifier, which minimizes the MSE measured before the activation function on desired pre-activation outputs. This choice converts the regularized least-squares problem into a linear system solvable in closed form, which is what enables exact, single-round global aggregation.
Each client computes a truncated SVD of XkFk (where Fk=diag(fk′) contains activation derivatives evaluated at the desired pre-activations) together with the matrix
Mk=Xk(fk′⊙fk′⊙dˉk),
a weighted correlation between features and pre-activation targets. The authors identify Mk as the only transmitted component carrying sensitive statistical dependencies on raw data; accordingly it is encrypted with CKKS homomorphic encryption, chosen for its support of approximate arithmetic over real numbers. The SVD factors (Uk,Sk) are sent in plaintext.
The coordinator concatenates plaintext SVD factors to obtain global (U,S), sums the ciphertexts homomorphically to obtain [[M]], and publishes the globally optimal weights
W=U(S⋅S+λI)−1UT[[M]]
to clients over MQTT, which provides lightweight asynchronous, fault-tolerant messaging. Because this expression is the exact solution of the regularized least-squares objective over the union of all client data, aggregation is mathematically exact rather than approximate — a property the paper argues is the source of its robustness to heterogeneity.
Accuracy and robustness
Experiments use CIFAR-10 and CIFAR-100 with Dirichlet-based non-IID partitions (α∈{1.0,0.1}) plus an extreme "single-class" scenario, against FedAvg and FedProx using the same frozen backbone. Baselines were given 10 rounds on CIFAR-10 and 50 on CIFAR-100, with round counts selected so the iterative methods reached stable convergence — a favorable setup for the baselines.
| Dataset |
XkFk0 |
Setting |
FedAvg |
FedProx |
FedHENet |
| CIFAR-10 |
10 |
XkFk1 |
85.34 |
85.28 |
83.69 |
| CIFAR-10 |
10 |
single-class |
33.26 |
40.75 |
83.65 |
| CIFAR-10 |
500 |
XkFk2 |
75.18 |
75.18 |
83.59 |
| CIFAR-100 |
100 |
XkFk3 |
59.11 |
59.08 |
56.63 |
| CIFAR-100 |
100 |
single-class |
52.61 |
52.60 |
56.91 |
Two findings stand out. First, in the extreme single-class scenario with 10 clients, the iterative baselines collapse to 33–40% accuracy due to client drift, while FedHENet holds at approximately 83.65% — essentially identical to its IID performance. This invariance across heterogeneity levels is the paper's strongest empirical claim: because aggregation is exact, data distribution skew does not degrade the solution. Second, at scale (XkFk4), FedHENet exceeds FedAvg by more than 8 points under XkFk5. On CIFAR-100, results are more mixed: FedAvg and FedProx retain a roughly 2.5-point advantage in near-IID settings after 50 rounds, though FedHENet wins in the heterogeneous regimes where the baselines show instability. Notably, FedHENet's accuracy is also nearly constant across all heterogeneity settings and client counts (83.6–83.8% on CIFAR-10), whereas baseline accuracy degrades substantially as XkFk6 grows.
Efficiency and sustainability
The efficiency results are substantial. On CIFAR-10 with 10 clients, FedHENet consumes 11.5 Wh versus 30.2–36.5 Wh for the baselines (roughly 70% savings) and completes in 3.07 minutes versus 8.55–10.11 minutes. Communication volume is also lower despite FedHENet's larger per-round payload, since only one round occurs: 331 MB versus 358 MB at XkFk7, and 9.7 GB versus 16.8 GB at XkFk8. On CIFAR-100, where baselines needed 50 rounds, energy consumption is halved (118.9 Wh vs. ~236–249 Wh).
The paper emphasizes a frequently neglected component of FL's carbon footprint: hyperparameter tuning. Iterative methods require grid searches over learning rates, decay schedules, and local epochs to avoid divergence, multiplying total lifecycle energy. FedHENet is hyperparameter-free (aside from the regularization strength XkFk9), eliminating this phase entirely. Per-round accuracy traces reinforce the point: baselines oscillate between 45% and 77% accuracy across rounds under Fk=diag(fk′)0 while expending over three times FedHENet's energy to converge.
Encryption overhead
Applying CKKS encryption inflates the transmitted payload by approximately 2.25× but adds negligible computational cost (<5%, about 840 ms per client) with no accuracy change (83.69% with and without HE). The authors conclude that strong cryptographic privacy is compatible with the frugal design, while conceding that overhead scales linearly with client count and could become material in very large federations.
Limitations and open questions
Several constraints bound the reported results. Accuracy depends entirely on the quality of the frozen, ImageNet-pretrained backbone; the framework performs no fine-tuning, so performance on domains far from ImageNet's distribution is untested. The evaluation is limited to CIFAR-scale images on a single workstation, and the authors themselves note that validation on heterogeneous edge hardware (e.g., Raspberry Pi clusters) remains future work, as does evaluation with alternative backbones such as Vision Transformers. The plaintext transmission of Fk=diag(fk′)1 rests on the assumption that these factors do not permit reconstruction of raw data — a claim asserted rather than formally analyzed, and one that invites scrutiny given known gradient-leakage attacks. Finally, the linear scaling of CKKS overhead with client count leaves open whether the approach remains practical for federations with tens of thousands of participants.
Conclusion
FedHENet demonstrates that replacing iterative gradient descent with analytically exact, HE-protected aggregation over frozen features yields competitive or superior accuracy under severe data heterogeneity, with up to 70% energy savings, lower total communication, and no tuning burden. Its principal trade-off is dependence on a fixed pretrained extractor, which caps achievable accuracy on out-of-distribution tasks and accounts for the modest deficit on CIFAR-100 in near-IID conditions.