<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">64161</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.064161</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>HEaaN-ID3: Fully Homomorphic Privacy-Preserving ID3-Decision Trees Using CKKS</article-title>
<alt-title alt-title-type="left-running-head">HEaaN-ID3: Fully Homomorphic Privacy-Preserving ID3-Decision Trees Using CKKS</alt-title>
<alt-title alt-title-type="right-running-head">HEaaN-ID3: Fully Homomorphic Privacy-Preserving ID3-Decision Trees Using CKKS</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Lee</surname><given-names>Dain</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="author-notes" rid="afn1">#</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Shin</surname><given-names>Hojune</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="author-notes" rid="afn1">#</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Choi</surname><given-names>Jihyeon</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Lee</surname><given-names>Younho</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref><email>younholee@seoultech.ac.kr</email></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Data Science, Seoul National University of Science and Technology</institution>, <addr-line>Seoul, 01811</addr-line>, <country>Republic of Korea</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Industrial Engineering, Seoul National University of Science and Technology</institution>, <addr-line>Seoul, 01811</addr-line>, <country>Republic of Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Younho Lee. Email: <email>younholee@seoultech.ac.kr</email></corresp>
<fn id="afn1">
<p><sup>#</sup>These authors contributed equally to this work</p>
</fn>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>03</day><month>07</month><year>2025</year>
</pub-date>
<volume>84</volume>
<issue>2</issue>
<fpage>3673</fpage>
<lpage>3705</lpage>
<history>
<date date-type="received">
<day>07</day>
<month>2</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>23</day>
<month>5</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_64161.pdf"></self-uri>
<abstract>
<p>In this study, we investigated privacy-preserving ID3 Decision Tree (PPID3) training and inference based on fully homomorphic encryption (FHE), which has not been actively explored due to the high computational cost associated with managing numerous child nodes in an ID3 tree. We propose HEaaN-ID3, a novel approach to realize PPID3 using the Cheon-Kim-Kim-Song (CKKS) scheme. HEaaN-ID3 is the first FHE-based ID3 framework that completes both training and inference without any intermediate decryption, which is especially valuable when decryption keys are inaccessible or a single-cloud security domain is assumed. To enhance computational efficiency, we adopt a modified Gini impurity (MGI) score instead of entropy to evaluate information gain, thereby avoiding costly inverse operations. In addition, we fully leverage the Single Instruction Multiple Data (SIMD) property of CKKS to parallelize computations at multiple tree nodes. Unlike previous approaches that require decryption at each node or rely on two-party secure computation, our method enables a fully non-interactive training and inference pipeline in the encrypted domain. We validated the proposed scheme using UCI datasets with both numerical and nominal features, demonstrating inference accuracy comparable to plaintext implementations in Scikit-Learn. Moreover, experiments show that HEaaN-ID3 significantly reduces training and inference time per node relative to earlier FHE-based approaches.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Homomorphic encryption</kwd>
<kwd>privacy preserving machine learning</kwd>
<kwd>applied cryptography</kwd>
<kwd>information security</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Institute of Information communications Technology Planning Evaluation</funding-source>
<award-id>2022-0-01047</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Decision trees (DT) are widely used despite their simpler structure compared to advanced machine learning algorithms, such as deep neural networks. This is because of the ease of use of these simpler structures in various domains and their ability to yield explainable models.</p>
<p>Currently, research in privacy-preserving machine learning and information encryption is rapidly advancing. In particular, studies on encryption based on chaotic systems and neural network applications have yielded notable results [<xref ref-type="bibr" rid="ref-1">1</xref>]. Additionally, homomorphic encryption (HE)-based machine learning algorithms have garnered significant attention owing to the growing importance of privacy-preserving machine learning [<xref ref-type="bibr" rid="ref-2">2</xref>&#x2013;<xref ref-type="bibr" rid="ref-6">6</xref>]. These algorithms allow us to perform any computation on encrypted data that can also be performed on plaintext, thereby enabling us to train an encrypted model using encrypted training data. Thus, these algorithms ensure a secure and privacy-preserving solution for machine learning, because classification can be performed using an encrypted model on an encrypted input without any decay in the process.</p>
<p>In this paper, we propose a fully homomorphic version of Iterative Dichotomiser 3 (ID3) [<xref ref-type="bibr" rid="ref-7">7</xref>] using the Cheon-Kim-Kim-Song (CKKS) method [<xref ref-type="bibr" rid="ref-8">8</xref>], named HEaaN-ID3. HEaaN-ID3 is based on a variant of the original ID3 algorithm [<xref ref-type="bibr" rid="ref-7">7</xref>] and can handle both nominal and ordinal categorical variables. This creates as many child nodes as the number of categories in a categorical variable. Despite the advantages of enabling secure computation in untrusted cloud environments and allowing clients to utilize server computing resources without revealing sensitive information, a privacy-preserving homomorphic ID3<xref ref-type="fn" rid="fn-1"><sup>1</sup></xref><fn id="fn-1">
<label>1</label>
<p>This refers to a privacy-preserving ID3 DT, where training and inference are performed only with homomorphic operations without using decryption, except for decrypting the inference result.</p>
</fn> has not been realized to date. The reason is that the large number of child nodes results in high computational overhead in both training and inference. However, existing privacy-preserving binary DTs that use FHE cannot handle the data of nominal categorical variables.</p>
<p>HEaaN-ID3 has the unique characteristic of not utilizing a decryption function during training. Despite the potential of homomorphic encryption in machine learning, recent studies have required decryption during the training process for various reasons. This is owing to the slow and impractical performance of algorithms that use only homomorphic operations, or the lack of methods for performing specific operations without decryption. As a result, decryption has been necessary in the training process [<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>While decryption during the training step can reduce the computational cost of privacy-preserving machine learning, it may not be feasible in certain situations. For instance, if the training data consists of data from multiple parties, some participants may not consent to using decryption key for fear of exposure of their data. Furthermore, if there is a large amount of data to be decrypted, the entity with the decryption key may not have sufficient computational power, causing a bottleneck that is not desirable for users of the learned data.</p>
<p>Additionally, HEaaN-ID3 enables a single-cloud service model. We do not have to assume that there are multiple cloud services in separate security domains. Thus, we can realize the execution environment of HEaaN-ID3 at a lower cost than those that require multiple cloud service models [<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>The key challenge in developing HEaaN-ID3, which enables training without decryption, is to achieve an affordable level of speed for training and inference, even with operations supported by FHE, which are known as heavy operations. For this purpose, we employ the CKKS FHE to leverage its beneficial features as much as possible. In addition, we employed the following:</p>
<p>First, in the proposed method, we adopt the modified Gini impurity (MGI) score [<xref ref-type="bibr" rid="ref-11">11</xref>] instead of entropy or the original Gini score for the split rule. The use of the MGI eliminates the need for complex inverse operations, allowing for efficient calculations when performed homomorphically with encrypted inputs. Because the MGI must be calculated at every non-leaf node in the DT, it can significantly reduce the amount of computation required for training. It is quite significant&#x2014;while MGI performs computations using only addition and multiplication, calculating the traditional Gini impurity requires an additional <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> operation. The exact computational demands and multiplication depth for <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> are not disclosed. However, according to previous studies [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>], it is presumed that these methods involve high-degree polynomials. Therefore, the multiplication depth is roughly proportional to the logarithm of the polynomial&#x2019;s degree, and the total number of multiplication operations is expected to be on the order of several tens. Our experiments demonstrate that there is no significant difference in terms of inference accuracy when using the MGI score compared with using the entropy as the original ID3 implemented in the scikit learn library.</p>
<p>The second optimization involves making full use of the single instruction multiple data (SIMD) feature of CKKS FHE. Here, the SIMD refers to one of the features of the CKKS homomorphic encryption scheme, in which the structure of a ciphertext is in the form of a vector, enabling vectorized operations between ciphertexts. This is different from traditional SIMD, which requires additional hardware-level costs. During the training and classification of homomorphic decision trees, every node in the tree must be processed, resulting in high computational costs. In the training process, determining the variables for branching based on the MGI score in an encrypted state involves the following steps: (1) calculate the distribution of target categories for all combinations of variables, (2) compute the MGI score for each variable, (3) find the minimum score among them, and (4) identify the minimum score variable. This process can consume a significant amount of computation if there are many combinations of variables and categories to be calculated, because each case must be calculated individually in an encrypted state for each node during training. This amount of computation is unacceptable when the number of nodes in a DT is large.</p>
<p>However, as HEaaN-ID3 can deal with the step (1) efficiently by using SIMD and MGI, training can be performed without decryption. This is in contrast to a recent work [<xref ref-type="bibr" rid="ref-10">10</xref>], where the calculation of step (2) is delegated to a client who has the decryption key, and the output of step (2) is sent to the client, who then decrypts it. Subsequently, the client performs steps (3) and (4) using the decrypted plaintext. The result is then encrypted again and sent back to the server for continued training.</p>
<p>In the inference task, the split conditions in all non-leaf nodes must be evaluated in HEaaN-ID3, unlike plaintext inference, which only evaluates the split functions in a sequence of non-leaf nodes in a path from the root node to a leaf node. This raises the inference complexity from logarithmic to polynomial, in terms of the number of nodes in the tree.</p>
<p>However, in HEaaN-ID3, certain computations required by nodes at the same level can be performed simultaneously by utilizing the SIMD function. The number of slots required for each node is determined by the number of variables involved in training and the number of categories for each variable. When the number of required slots is significantly smaller than the total number of available slots in a ciphertext, multiple nodes&#x2019; training can be performed at once. This approach was computationally more efficient than that described in [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>In addition, we discovered and solved various problems that can occur when realizing homomorphic DT, especially during training. First, there are some cases that are difficult to handle with encrypted data, such as the case where in no training data is mapped to a certain node in the tree. The next problem is that there are multiple cases where in their MGI scores are almost identical. We address these situations while maintaining the efficiency of training and inference as much as possible.</p>
<p>We verified the performance of HEaaN-ID3 with widely used dataset in the UCI repository [<xref ref-type="bibr" rid="ref-13">13</xref>], such as Iris, Wine, and Cancer, which consist of multiple numerical variables, after binning them as well as the data of nominal categorical variables such as soybean and breast cancer. We verified that the same level of accuracy was obtained using HEaaN-ID3 compared to the training and inference algorithms with plaintext version of the data implemented in the Scikit-learn library [<xref ref-type="bibr" rid="ref-14">14</xref>].</p>
<p>The following are primary contributions of this paper.
<list list-type="bullet">
<list-item>
<p>Homomorphic ID3 Decision Training on encrypted state without decryption: This study is the first to perform the entire ID3 decision tree algorithm training in an encrypted state. We propose an optimization method to address high computational costs of Fully Homomorphic Encryption (FHE) during training. Our approach leverages CKKS encryption&#x2019;s SIMD characteristics and uses a modified Gini impurity score. In the same environment, our proposed method required approximately 7.41% more time to process a single node than the method proposed in [<xref ref-type="bibr" rid="ref-10">10</xref>] for the Iris dataset. However, their study executed most computations in plaintext after decryption. Our research demonstrates the feasibility of conducting the entire training process securely and efficiently in an encrypted state.</p></list-item>
<list-item>
<p>Efficient inference: We propose a method that enables efficient inference with encrypted inputs and models. The proposed method maximizes efficiency by leveraging the SIMD feature of CKKS to process nodes at the same level simultaneously. In our experiments using the UCI dataset, the most similar method proposed in [<xref ref-type="bibr" rid="ref-10">10</xref>] took 2.3 s to evaluate 31 nodes. In contrast, our approach evaluated 16,105 nodes, the largest number of nodes, in just 657.32 ms.</p></list-item>
</list></p>
<p>The remainder of this paper is structured as follows. <xref ref-type="sec" rid="s2">Section 2</xref> compares existing studies according to the proposed requirements and <xref ref-type="sec" rid="s3">Section 3</xref> explains the fundamental concepts necessary to understand this research. <xref ref-type="sec" rid="s4">Section 4</xref> details the system and security models of the proposed method. In <xref ref-type="sec" rid="s5">Section 5</xref>, the training and inference methods of the proposed HEaaN-ID3 are described. <xref ref-type="sec" rid="s6">Section 6</xref> provides the performance evaluation results of the schemes used and the proposed method in this study. <xref ref-type="sec" rid="s7">Section 7</xref> offers a security analysis of the proposed method. In <xref ref-type="sec" rid="s8">Section 8</xref>, we discusses whether the established objectives have been successfully achieved and how accuracy is maintained in exceptional situations. Finally, <xref ref-type="sec" rid="s9">Section 9</xref> presents the conclusion.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>Related works are summarized in <xref ref-type="table" rid="table-1">Table 1</xref>. It checks whether the existing work satisfies the goals specified in <xref ref-type="sec" rid="s4_3">Section 4.3</xref>. The last column of <xref ref-type="table" rid="table-1">Table 1</xref> indicates whether the corresponding works deal with an ID3 or other types of DTs.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Summary of related work</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Goal</th>
<th>(1)</th>
<th>(2)</th>
<th>(3)</th>
<th>(4)</th>
<th>(5)</th>
<th>ID3</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-20">20</xref>&#x2013;<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>O</td>
<td>X</td>
<td>N/<inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>X</td>
<td>N/<inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>X</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-37">37</xref>,<xref ref-type="bibr" rid="ref-38">38</xref>]</td>
<td>O</td>
<td>X</td>
<td>N/<inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>X</td>
<td>N/<inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>X</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-39">39</xref>&#x2013;<xref ref-type="bibr" rid="ref-42">42</xref>]</td>
<td>O</td>
<td>X</td>
<td>N/<inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>X</td>
<td>N/<inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msup><mml:mi>A</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>O</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>O</td>
<td>O</td>
<td>O</td>
<td>X</td>
<td>X</td>
<td>O</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-10">10</xref>]</td>
<td>O</td>
<td>O</td>
<td>O</td>
<td>X</td>
<td>O</td>
<td>X</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>&#x2013;<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td colspan="5">No training algorithm</td>
<td></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-43">43</xref>&#x2013;<xref ref-type="bibr" rid="ref-47">47</xref>]</td>
<td colspan="5">No training algorithm</td>
<td></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-26">26</xref>&#x2013;<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-31">31</xref>,<xref ref-type="bibr" rid="ref-48">48</xref>]</td>
<td colspan="5">No training algorithm</td>
<td></td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-1fn1" fn-type="other">
<p>Note: <inline-formula id="ieqn-10"><sup>1</sup></inline-formula>Inference privacy is out of scope; <sup>2</sup>No cloud server exists in their settings.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p>The research on privacy-preserving decision trees (PPDTs) can be categorized into two primary approaches: those that mainly deal with the inference process [<xref ref-type="bibr" rid="ref-15">15</xref>&#x2013;<xref ref-type="bibr" rid="ref-19">19</xref>] and those that emphasize the training phase [<xref ref-type="bibr" rid="ref-20">20</xref>&#x2013;<xref ref-type="bibr" rid="ref-24">24</xref>]. Despite significant advances, these studies face common challenges, such as an increase in communication overhead as the complexity of the tree grows and a rise in the amount of interaction required during both training and inference stages. For a detailed comparison of the existing methodologies, refer to [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>Recent developments in the field of PPDT have introduced a variety of approaches. In Liu et al.&#x2019;s PPDT framework [<xref ref-type="bibr" rid="ref-9">9</xref>], the Cloud Service Provider (CSP) and the Evaluation Service Provider (ESP) operated within distinct security domains while utilizing Pailler&#x2019;s Partial Homomorphic Encryption (PHE). This setup allowed for secure and efficient computations on encrypted data by employing two-party secure computation protocols, enabling resource-intensive PPDT training and evaluation processes. However, one challenge arises in a multi-user multi-key environment where both the CSP and ESP share a master decryption key. This creates a potential vulnerability, as collusion between the two entities could compromise all user data. Without a reliable method to detect malicious collusion, the practical implementation of such a system is hindered.</p>
<p>Reference [<xref ref-type="bibr" rid="ref-25">25</xref>] presented a method that leverages multiple cloud servers, where one server performs decryption. Due to this setup, it is not directly comparable to HEaaN-ID3. Liang et al. proposed an approach to evaluate PPDTs by using efficient cryptographic techniques [<xref ref-type="bibr" rid="ref-26">26</xref>]. While this method achieves excellent classification performance, it lacks a solution for training and overlooks situations where multiple splits are needed during tree evaluation. Zheng et al. put forward a PPDT evaluation scheme using additive secret sharing [<xref ref-type="bibr" rid="ref-27">27</xref>], but their approach required two distinct cloud service providers and does not address training using encrypted data.</p>
<p>Cong et al. recently proposed a highly efficient method for securely evaluating decision trees utilizing GSW-based homomorphic encryption, particularly with TFHE [<xref ref-type="bibr" rid="ref-28">28</xref>]. Their approach introduced PolyComp(), a homomorphic comparison function that efficiently extracts constant terms from RLWE-based ciphertext, as outlined in [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>]. Additionally, they harnessed the advantages of homomorphic XNOR operations characteristic of GSW-based encryption, which made bit-wise encrypted value comparisons more effective. Building on this, they developed a streamlined homomorphic tree traversal algorithm, facilitating smooth computation between encrypted and plaintext values&#x2014;highlighting the distinct benefits of GSW-based homomorphic encryption.</p>
<p>Similarly, reference [<xref ref-type="bibr" rid="ref-31">31</xref>] introduced an efficient inference method for privacy-preserving binary decision trees encrypted with TFHE. Their technique integrated algorithms for blind node selection and blind array access. Unfortunately, this approach also does not address the challenge of privacy-preserving training for encrypted data.</p>
<p>The work most relevant to ours is that of [<xref ref-type="bibr" rid="ref-10">10</xref>], which addresses a privacy-preserving binary decision tree. They proposed a method capable of training and evaluating encrypted data using CKKS. Independent of Cheon et al.&#x2019;s method [<xref ref-type="bibr" rid="ref-12">12</xref>], it proposes an efficient sign function for encrypted input, which returns (an encryption of) 1 for positive numbers and <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>1 for negative numbers, and suggested an effective training/inference method based on this.</p>
<p>Among alternative FHE models, the hybrid approach was proposed in [<xref ref-type="bibr" rid="ref-10">10</xref>], its training speed is more efficient than that of the proposed method. However, a limitation of this method is that it delegates the calculation of the information gain for each case of data and determines the case with the greatest information gain to an external entity. The external entity receives the ciphertexts containing the information gain for each case from the cloud server performing the training, decrypts them, encrypts the information for the case with the greatest information gain, and delivers it to the cloud server. The external entity should not collude with the cloud server because it has decryption capability. Because this exposes important information related to the model, according to an external entity, the entity should be a trusted party, such as the owner of the data. This can be unsuitable for certain situations in which privacy-preserving decision tree (PPDT) to perform machine learning with data from multiple security tasks. In this case, some data owners may not want to decrypt ciphertexts derived from their data.</p>
<p>There is research proposing privacy decision tree evaluation (PDTE) based on the replicated secret sharing (RSS) scheme from a different perspective [<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-35">35</xref>]. These studies proposed methods to enhance security by using multiple cloud servers. They followed an approach where the information of the model and the input values used for evaluation are distributed among three computing servers in an outsourced environment. This approach assumed that there is no possibility of malicious collaboration between the servers. The study in [<xref ref-type="bibr" rid="ref-36">36</xref>] not only conducted the inference process but also carried out the training process. This study also utilized RSS, which necessitates additional assumptions. Since these papers do not meet the conditions outlined in <xref ref-type="sec" rid="s4_3">4.3</xref>, it is not appropriate to compare them directly with the method proposed in this paper.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Backgrounds</title>
<sec id="s3_1">
<label>3.1</label>
<title>Notation</title>
<p>The notations used in this study are listed in <xref ref-type="table" rid="table-2">Table 2</xref>. If a vector is entirely composed of either <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula>s or <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mrow><mml:mover><mml:mn>1</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula>s and a ciphertext are operands in an expression, we suppose the vector&#x2019;s size is <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>M</mml:mi></mml:math></inline-formula>. If the description of the vector does not specify all <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>M</mml:mi></mml:math></inline-formula> slots, we assume the undescribed slots are set to zero.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Notations and conventions</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Symbol</th>
<th>Meaning</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Independent variable (features) <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Number of categories in <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mtext>&#xA0;</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>Y</mml:mi></mml:math></inline-formula></td>
<td>Target variable whose number of categories is <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>t</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>The number of rows in training data.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mover><mml:mi>z</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>, <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mi>z</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mover><mml:mi>z</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>M</mml:mi></mml:msup></mml:math></inline-formula> and <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> is its encryption.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>d</mml:mi></mml:math></inline-formula></td>
<td>Total number of independent variables <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>Number of categories for the variable with the most categories among all independent variables in the system.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mrow><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula>: The depth of a DT, <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula>: current level processed, <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mrow><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:msup><mml:mi>n</mml:mi><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mi>t</mml:mi><mml:mi>h</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>M</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>M</mml:mi></mml:math></inline-formula>: total number of slots in a ciphertext</td>
</tr>
<tr>
<td><inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mo stretchy="false">[</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mi>B</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mrow><mml:mo>{</mml:mo><mml:mi>n</mml:mi><mml:mo>:</mml:mo><mml:mi>a</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>b</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>B</mml:mi><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> (<inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>B</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>). <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow></mml:math></inline-formula> can be omitted.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:mi>c</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>: <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>i</mml:mi></mml:math></inline-formula>-th slot of <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>c</mml:mi><mml:mo stretchy="false">[</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>: <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>j</mml:mi></mml:math></inline-formula>th slot of <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>c</mml:mi></mml:math></inline-formula> <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mo stretchy="false">(</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mi>i</mml:mi><mml:mspace width="negativethinmathspace" /><mml:mo>,</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mi>j</mml:mi><mml:mspace width="negativethinmathspace" /><mml:mo>&#x2208;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mo stretchy="false">[</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mn>0</mml:mn><mml:mspace width="negativethinmathspace" /><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mspace width="negativethinmathspace" /><mml:mo stretchy="false">]</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula></td>
<td>Evaluation key, secret key and public key</td>
</tr>
<tr>
<td><inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mi>k</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>Key switching key from user <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>i</mml:mi></mml:math></inline-formula> to user <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>j</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mrow><mml:mover><mml:mn>1</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>A vector where every slot is 1 (0).</td>
</tr>
<tr>
<td><inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msup><mml:mrow><mml:mover><mml:mn>1</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>A vector of consecutive 1s(0s) whose length is <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mi>a</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mi>a</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>)</td>
</tr>
<tr>
<td><inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:mover><mml:mn>1</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mi>f</mml:mi></mml:msup></mml:math></inline-formula></td>
<td>A vector consisting of <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mi>f</mml:mi></mml:math></inline-formula> consecutive repetitions of <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:mover><mml:mn>1</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The total length of this vector is always less than or equal to <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>M</mml:mi></mml:math></inline-formula>. It also can be used to represent the ciphertext of the vector.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>,<inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td># of multiplication and rotation required for ApproxInverse()</td>
</tr>
<tr>
<td><inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The position of the node in the proposed DT, where <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>i</mml:mi></mml:math></inline-formula> represents the level of the node and <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mi>j</mml:mi></mml:math></inline-formula> represents the position of the node in level <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>i</mml:mi></mml:math></inline-formula>. <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the root node. <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>The training data used for training <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>. <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mrow><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is training data of the root node.</td>
</tr>
<tr>
<td><inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td>The total number of nodes in the generated tree. <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Decision Tree</title>
<p>DTs are widely used to construct classifiers for real-world applications. They are categorized as non-parametric methods, which implies that they do not require assumptions regarding the distribution of the underlying data. In addition, a DT has the advantages of high interpretability, because decision rules are extracted during its growth [<xref ref-type="bibr" rid="ref-49">49</xref>]. Depending on the rule induction method, DT algorithms can be classified as greedy or randomDTs. However, in a single DT model, the greedy approach has been more popular than the random approach. Various greedy DT algorithms have been developed for several years and the typical algorithms are Iterative Dichotomiser 3 (ID3) [<xref ref-type="bibr" rid="ref-7">7</xref>], C4.5 [<xref ref-type="bibr" rid="ref-50">50</xref>], C5.0 [<xref ref-type="bibr" rid="ref-51">51</xref>] Classification and Regression Tree (CART) [<xref ref-type="bibr" rid="ref-52">52</xref>], <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:msup><mml:mi>&#x03C7;</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula> Automatic Interaction Detection (CHAID) and a Scalable Parallel Classifier for Data Mining (SPRINT) [<xref ref-type="bibr" rid="ref-53">53</xref>].</p>
<p>The ID3 algorithm is primarily used to handle nominal datasets. It generates a decision tree based on maximizing Information Gain, which is a measure of the reduction in entropy that results from splitting a dataset based on a specific attribute. Entropy, in this context, is a measure of uncertainty or disorder within the data, quantifying how mixed the data is. ID3 works by selecting, at each iteration, the attribute that minimizes entropy the most, effectively splitting the data in a way that makes it more homogeneous. This process is repeated to construct an optimal decision tree.</p>
<p>While ID3 is efficient and provides a high level of interpretability, it can struggle with noisy data and is prone to overfitting, where the model becomes too tailored to the training data and performs poorly on unseen data. To address these limitations, successor algorithms like C4.5 were developed, which include mechanisms to handle noise and prevent overfitting.</p>
<p>Regardless of the greedy DT algorithm, DTs are built by the process of top-down rule induction in the &#x201C;greedy&#x201D; way. At each iteration, DT algorithms determine a rule that splits the node into child nodes, by maximizing the splitting criterion function. Different DT algorithms employ various splitting criteria.</p>
<p>In this study, we propose a privacy-preserving ID3 using FHE for datasets consisting of nominal categorical attributes. We borrowed several elements from ID3. ID3 determines an attribute that splits the current node into child nodes individually corresponding to each category in the attribute among the unused attributes using the information gain based on entropy as a splitting criterion function, which requires the calculation of <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>. According to [<xref ref-type="bibr" rid="ref-54">54</xref>], to efficiently perform entropy operations, an approximated entropy function (ApEn) is proposed. The proposed method involved maximum and comparison operations throughout the process, followed by a natural logarithm operation. As a result, it requires more computationally complex and intensive calculations compared to MGI, which primarily consists of additions and multiplications. Owing to the high computational cost of calculating <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> on an encrypted input, this study utilizes MGI to reduce the computation cost. MGI is a variation of the Gini impurity <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for sample set <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>S</mml:mi></mml:math></inline-formula>, defined as follows:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi><mml:mi mathvariant="normal">&#x2216;</mml:mi><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>i</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>c</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Herein, <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mi>C</mml:mi></mml:math></inline-formula> represents the set of target classes in <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mi>S</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> indicates the probability of the specific sample set in <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mi>S</mml:mi></mml:math></inline-formula> (e.g., <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the probability of target class <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mi>i</mml:mi></mml:math></inline-formula>, which can be defined as the proportion of the class <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mi>i</mml:mi></mml:math></inline-formula> in <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mi>S</mml:mi></mml:math></inline-formula>). Additionally, <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mi>A</mml:mi></mml:math></inline-formula> represents the attribute used for the split. The attribute to maximize the difference between the Gini impurity of the current node and the weighted Gini impurity of the child nodes is selected for the split rule. Because the Gini impurity of the current node is identical for all possible split rules at the current node, the gain based on the Gini impurity depends on the weighted average of the Gini impurities of the child nodes obtained using attributes <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mi>A</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which can be formulated as follows:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> represents the Gini impurity for the set of samples in child node <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mi>t</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula> denotes the size (cardinality) of a set, <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mi>T</mml:mi></mml:math></inline-formula> is the set of all child nodes, and <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> indicate the samples assigned to node <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mi>t</mml:mi></mml:math></inline-formula> and those samples within <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mi>t</mml:mi></mml:math></inline-formula> that belong to class <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mi>c</mml:mi></mml:math></inline-formula>, respectively. Because <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula> is the common factor for all split rules, the best split rule is a rule to maximize <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac></mml:math></inline-formula>, which requires the division operation.</p>
<p>Unlike the gain of the Gini impurity, the gain of the MGI uses the squares of <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as weights for <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as follows [<xref ref-type="bibr" rid="ref-11">11</xref>]:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>M</mml:mi><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>A</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup><mml:mi>G</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>S</mml:mi><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:mfrac><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x2212;</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Under the MGI framework, the best split is determined by minimizing <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>, a form that eliminates the need for division. According to the literature [<xref ref-type="bibr" rid="ref-11">11</xref>], one of the Gini impurities and the MGI are not always superior to the other; thus, considering the computational cost, we decided to use the MGI. By binning a numerical feature into several bins, a continuous feature can be treated as a categorical feature; thus, it is possible to apply the same algorithm to a dataset consisting of categorical features.</p>
<p>In addition, while MGI is effective in reducing bias and improving classification performance, it tends to be more sensitive to data variability in terms of variance. From the bias perspective, MGI leads to more accurate classification results compared to the traditional Gini impurity. According to the study in [<xref ref-type="bibr" rid="ref-11">11</xref>], a decision tree trained based on the MGI criterion achieved an average classification error rate of 29.05%, which is lower than the 30.31% obtained using Gini impurity, demonstrating improved overall classification performance. On the other hand, in terms of variance, MGI tends to generate a larger number of decision rules and exhibits greater standard deviation across datasets. On average, MGI produces 482.29 decision rules, which is significantly more than the 143.43 rules generated by Gini impurity. Additionally, the standard deviation of the classification error rate is the highest at 27.43%, indicating that the model is more responsive to changes in data characteristics. Due to these characteristics, MGI is advantageous for high-precision splitting but should be applied with caution when consistency across datasets is important. In homomorphic encryption environments, applying entropy-based metrics can be computationally expensive and inefficient. MGI, on the other hand, eliminates the need for division operations, making it a more practical choice while still maintaining strong classification performance under such constraints.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>CKKS</title>
<p>CKKS is an FHE method in which multiplication can be performed efficiently on two encrypted complex numbers [<xref ref-type="bibr" rid="ref-8">8</xref>]. Although it only supports approximate arithmetic over encrypted data, numerous privacy-preserving applications have adopted it because of its extremely fast computation speed [<xref ref-type="bibr" rid="ref-55">55</xref>]. In addition, ciphertexts can contain numerous complex numbers. Thus, the CKKS operations function as vector operations. For example, a vector of complex numbers can be encrypted into a ciphertext in CKKS, and the result of the multiplication between two ciphertexts is a ciphertext that contains the vector that has the result of a component-wise multiplication of the underlying two vectors in the input ciphertexts. This can significantly enhance the performance of privacy-preserving machine-learning algorithms that are implemented in addition CKKS operations. Moreover, the CKKS scheme is designed based on the Ring Learning With Errors (RLWE) problem and incorporates randomness during encryption, resulting in different ciphertexts even when encrypting the same plaintext multiple times. Therefore, an attacker cannot infer the original plaintext even if they attempt to encrypt arbitrary plaintexts, which ensures that the scheme satisfies IND-CPA security.</p>
<p>CKKS supports the following algorithms:</p>
<p><inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">y</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mn>1</mml:mn><mml:mi>&#x03BB;</mml:mi></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> uses security parameter <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mi>&#x03BB;</mml:mi></mml:math></inline-formula> as the input and returns <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>.</p>
<p><inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">E</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> outputs <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> that maintains the vector structure as <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>.</p>
<p><inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">D</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> outputs <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula> if <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> is a valid encryption from <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>, which is a result of <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:mrow><mml:mi mathvariant="sans-serif">E</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi></mml:mrow></mml:math></inline-formula> or is created through a set of operations with valid ciphertexts with correct <inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mi>s</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> is also correct. Else it returns <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mi mathvariant="normal">&#x22A5;</mml:mi></mml:math></inline-formula>.</p>
<p><inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> produces a new ciphertext <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mi>c</mml:mi></mml:math></inline-formula>, which is an encryption of <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>+</mml:mo><mml:mover><mml:mi>y</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula> (<inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mover><mml:mi>x</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>y</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>). We may denote it as <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x229E;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> (<inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x229F;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>) to simplify the description.</p>
<p><inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> outputs a new ciphertext that is an encryption of <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (<inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>) for given <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mi>k</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">C</mml:mi></mml:mrow></mml:math></inline-formula>. We may describe it as <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x229E;</mml:mo><mml:mi>k</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x229F;</mml:mo><mml:mi>k</mml:mi></mml:math></inline-formula>) to simplify the description.</p>
<p><inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mi mathvariant="sans-serif">L</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> returns <inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>&#x2019;s level <inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:mi>l</mml:mi></mml:math></inline-formula>, the number of further possible multiplications with ciphertext <inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:mrow><mml:mi mathvariant="bold">x</mml:mi></mml:mrow></mml:math></inline-formula>.</p>
<p><inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> returns an (approximate) encryption of (<inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>) whose level is <inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">L</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">L</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. We denote this as <inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x22A1;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> to simplify the description.</p>
<p><inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> outputs a <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:msup><mml:mi>c</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> that is an encryption of (<inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mi>k</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>) where <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mi>k</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">C</mml:mi></mml:mrow></mml:math></inline-formula>. The level of <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:msup><mml:mi>c</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> is decremented from the level of <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> by 1. We describe it as <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x22A1;</mml:mo><mml:mi>k</mml:mi></mml:math></inline-formula> to simplify the notation.</p>
<p><inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> returns an encryption of <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. If <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mi>i</mml:mi></mml:math></inline-formula><inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, we set <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>i</mml:mi><mml:mo>+</mml:mo><mml:mi>M</mml:mi></mml:math></inline-formula> to make <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>.</p>
<p><inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">B</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> returns a new ciphertext <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:msup><mml:mi>c</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> that has an approximation of <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> if <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:mrow><mml:mi mathvariant="sans-serif">L</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>, the number of multiplication levels required to perform <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mrow><mml:mi mathvariant="sans-serif">B</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> depends on the bootstrapping algorithm used and security parameter.</p>
<p><inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mo>&#x2219;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">w</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">k</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> considers <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow></mml:math></inline-formula> and returns <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:mi>c</mml:mi></mml:math></inline-formula> that is an encryption of <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mi>i</mml:mi></mml:msup><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>.</mml:mo><mml:mo>,</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mi>i</mml:mi></mml:msup><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. It consumes one level as a single <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> with two ciphertexts.</p>
<p>We assume that the rescaling algorithm in [<xref ref-type="bibr" rid="ref-8">8</xref>] is executed inside the <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> algorithm, as in [<xref ref-type="bibr" rid="ref-3">3</xref>]. In addition, if bootstrapping is required to perform multiplication, it is assumed to be performed automatically. The corresponding part is omitted for clarity in the description of the algorithm. In addition, we use the RNS-CKKS implementation, which is aided by the GPU, to enhance the performance [<xref ref-type="bibr" rid="ref-55">55</xref>&#x2013;<xref ref-type="bibr" rid="ref-58">58</xref>].</p>
<p>The following parameters were used for CKKS: the number of slots is 32,768, 9 multiplications are allowed between the bootstrapping operations, the initial number of multiplication depth possible before the first bootstrapping is 21, and <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> is 3. Upon bootstrapping, we can consume 9 multiplicative depth until the next bootstrapping.</p>
<p>We used a method reported in the literature [<xref ref-type="bibr" rid="ref-12">12</xref>], expressed as <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: it considers a ciphertext <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> and returns an encryption of a vector <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> where <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; 1 if <inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>&gt;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>; <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; 0 if <inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, or <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> otherwise (<inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>). We also used the method reported in [<xref ref-type="bibr" rid="ref-3">3</xref>] to create an inverse of an input ciphertext, which is written as <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: it assumes a ciphertext <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> and returns an encryption of the multiplicative inverse of the values in <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> [<xref ref-type="bibr" rid="ref-3">3</xref>].</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Models</title>
<sec id="s4_1">
<label>4.1</label>
<title>System Setting and Protocol Overview</title>
<p>We followed the system setting introduced in the literature [<xref ref-type="bibr" rid="ref-3">3</xref>]. The aim of this setting is to combine data from multiple security domains to produce a better model for inference. In addition, according to [<xref ref-type="bibr" rid="ref-3">3</xref>], owing to the legal regulation in South Korea, the inference result should be investigated by a trusted third party (here in, the Key Manager (KM)) to check whether the inference result has certain information regarding the privacy breach of the original data for training. Therefore, in this setting, KM is involved in the inferences.</p>
<p>The system has three types of participants: users (<inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>m</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>), <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula>, and cloud server (<inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula>). A user is a participant who owns data for training or transfers input data to request inferences after encryption. The <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> receives the system evaluation key from <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> and receives the encrypted training data from users to perform training. Consequently, the encrypted training model is stored and managed in its own storage. After training is completed, the <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> performs an inference using the encrypted input data from the users. The encrypted inference result is delivered to the user through <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> after the investigation is completed. A summary of all the participants and the operating protocols is shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>System setting and protocol overview</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-1.tif"/>
</fig>
<p>The goal of this setting is, as described in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, for a set of the companies with data of different attributes to combine their data to create a model with high prediction accuracy for the target variable of each company&#x2019;s interest. Therefore, the owners of the training data and the entities that aim to obtain the inference result with their input are the same set of entities (users in this setting). To separate the training data owners from the entity who want to obtain the inference results, the public keys of the clients should be registered in the <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula>. In this case, if a client is an individual person, many keys must be registered in <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula>, and all the inference results for all clients should be processed via <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula>, which renders <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> a bottleneck in the inference process. Therefore, different settings are required such cases.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>The goal of system setting (a: Training, b: Inference)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-2.tif"/>
</fig>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Security Model</title>
<p>Analogous to previous study [<xref ref-type="bibr" rid="ref-59">59</xref>], each participant in the protocol can play the role of an adversary, and their behavior is defined as an honest-but-curious (HBC) model.</p>
<p>The proposed method considers two aspects of privacy: First, the <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> should not be able to access the encrypted information sent by the user. Second, the user should not be able to access information regarding the model created by the <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula>. Assuming <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> is a trusted third party, privacy can be defined as follows:</p>
<p>First, the <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> is considered an attacker. The information to which the <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> has access includes encrypted data and metadata. During the training process, users encrypt and send their training data, and the <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> creates a model using this data. In the inference process, a user sends encrypted input information and the <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> performs the computation in an encrypted state and delivers the resulting ciphertext to the <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula>.</p>
<p>Thus, the <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> only has access to the ciphertext input and cannot obtain the original information through the ciphertext. Based on this situation and the ciphertext-only attack (CPA) model, the privacy of the <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> in the proposed method can be defined.</p>
<p>(<inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> Privacy in the proposed protocol) We consider that the proposed protocol supports <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula>-privacy if <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> wins the following game with a non-negligible advantage:
<list list-type="simple">
<list-item><label>1.</label><p>The <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> generates two sets of messages for training and inference, denote as <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mover><mml:msub><mml:mi>m</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mover><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. These are then sent to the user.</p></list-item>
<list-item><label>2.</label><p>The user randomly selects a bit value <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mi>b</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>)</p></list-item>
<list-item><label>3.</label><p>The user and the <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> run the proposed protocol with <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:mrow><mml:mover><mml:msub><mml:mi>m</mml:mi><mml:mi>b</mml:mi></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula>. Essentially, <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mrow><mml:mover><mml:msub><mml:mi>m</mml:mi><mml:mi>b</mml:mi></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:math></inline-formula> is provided to the <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> in an encrypted form.</p></list-item>
<list-item><label>4.</label><p><inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> can encrypt any desired message using the system public key.</p></list-item>
<list-item><label>5.</label><p>Finally, the <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> outputs a message to guess which message is used in the protocol, denote as <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:msup><mml:mi>b</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula>.</p></list-item>
<list-item><label>6.</label><p><inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> wins if <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>b</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula>.</p></list-item>
</list></p>
<p>Second, we examined the privacy of the model during inference. The key concern is whether the user can extract information about the model from the received output. In our proposed method, except for the <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> which is a trusted entity, users receive only the inference result, and no additional information is obtained. This implies that if users can gain information about the model from the inference output of our proposed method, the same outcome is possible in the plaintext version of the model and the inference input scenario. The issue of model information exposure from inference results in conventional machine learning is beyond the scope of this study. Thus, we did not address this aspect further, as explored in research [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Problem Definition</title>
<p>We designed HEaaN-ID3 to maintain the same requirements as proposed in [<xref ref-type="bibr" rid="ref-60">60</xref>].
<list list-type="simple">
<list-item><label>1.</label><p>Training data privacy: The information belonging to one data owner must remain confidential and not be accessible by any other participants.</p></list-item>
<list-item><label>2.</label><p>Model privacy: No participant should have access to any details about the model.</p></list-item>
<list-item><label>3.</label><p>Inference privacy: The CS must not gain access to any details about the inputs submitted by users for classification.</p></list-item>
<list-item><label>4.</label><p>Non-interactive training: After the training data owner submits the data to the CS, the entire training process is handled independently by the CS, without requiring any assistance from other entities.</p></list-item>
<list-item><label>5.</label><p>Single security domain for CS: CSs cooperate with each other because they exist in a single security domain, and it is impossible to use decryption keys.</p></list-item>
</list></p>
<p>Please note that requirements (2) and (3) can be demonstrated using the security model described in <xref ref-type="sec" rid="s4_2">Section 4.2</xref>. The other conditions should be considered individually.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>HEaaN-ID3</title>
<p>We explain training and inference process of HEaaN-ID3. First, we discuss how the data is encrypted and explain how each node of HEaaN-ID3 is represented in an encrypted state. Then, we describe the key algorithm steps in the training process and how to select the optimal splitting variables using encrypted data. Finally, we provide a detailed discussion of the inference process using the encrypted model resulting from the training process and its optimized handling methods.</p>
<sec id="s5_1">
<label>5.1</label>
<title>Data Representation</title>
<p>Let <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:msub><mml:mi>X</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> be the independent variables, and <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:mi>Y</mml:mi></mml:math></inline-formula> be the target variable. Each category is represented by a positive integer. Each independent variable <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:msub><mml:mi>X</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:math></inline-formula> has <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:msub><mml:mi>n</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:math></inline-formula> categories <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:msub><mml:mi>n</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow><mml:mo>+</mml:mo></mml:msup></mml:math></inline-formula> and <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">m</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">m</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. Let the number of categories in <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:mi>Y</mml:mi></mml:math></inline-formula> be <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:mi>t</mml:mi></mml:math></inline-formula>. We define <inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:mi>n</mml:mi><mml:mo>:=</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">m</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> and <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:mi>N</mml:mi><mml:mo>:=</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p>We suppose that the training data are composed of a set of <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:math></inline-formula> rows, where the <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:mi>i</mml:mi></mml:math></inline-formula>-th row is represented as a tuple of vectors (<inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:msubsup><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mn>1</mml:mn><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mi>d</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mover><mml:mi>y</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula>), where <inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:msubsup><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mi>j</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:msup><mml:mrow><mml:mover><mml:mi>y</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> is the one-hot encoding vector of a category value in <inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:msub><mml:mi>X</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:mi>Y</mml:mi></mml:math></inline-formula> whose length are <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mi>n</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:mi>t</mml:mi></mml:math></inline-formula>, respectively. That is, <inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:msubsup><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mi>j</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. Here, <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and the other components are zeroes if the value in <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:msub><mml:mi>X</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:math></inline-formula> in the <inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mi>i</mml:mi></mml:math></inline-formula>-row is <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:mi>k</mml:mi></mml:math></inline-formula>. For every <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x003C;</mml:mo><mml:mi>k</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>.</p>
<p>For efficient calculation, we grouped the values in the same position in the one-hot encoded vectors of each variable. Thus, we organized a set of vectors <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:msub><mml:mrow><mml:mover><mml:mi>b</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for all <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:msub><mml:mrow><mml:mover><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for all <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:mi>q</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. We call this the Bin Mask Vector [<xref ref-type="bibr" rid="ref-3">3</xref>]. For efficient computation, we attach <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:msup><mml:mrow><mml:mover><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> to every <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:mover><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula> and <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:msub><mml:mrow><mml:mover><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to make their lengths <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:mi>N</mml:mi></mml:math></inline-formula>. Therefore, every <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:mi>b</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>. This is depicted in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Data representation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-3.tif"/>
</fig>
<p>We generated encrypted training data by placing all the data for a single variable into the same ciphertext. Therefore, we assume <inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:mi>M</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>. We supposed <inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the number of the variables of which the training data can be accommodated in the single ciphertext (<inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo></mml:math></inline-formula>). The number of ciphertexts <inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:mi>u</mml:mi></mml:math></inline-formula> used to create the training data was calculated as <inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:math></inline-formula>. Let <inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:msub><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mover><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x22EF;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mover><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>n</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>. For the encrypted data, we can create a set of ciphertexts <inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>u</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x222A;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>y</mml:mi><mml:mi>q</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>q</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>u</mml:mi><mml:mo>+</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x22EF;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mi>u</mml:mi><mml:mo>+</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mn>0</mml:mn><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mspace width="thinmathspace" /><mml:mo>&#x2217;</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>N</mml:mi><mml:mspace width="thinmathspace" /><mml:mo>&#x2217;</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>y</mml:mi><mml:mi>q</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mover><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x22EF;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mover><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mn>0</mml:mn><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mspace width="thinmathspace" /><mml:mo>&#x2217;</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>N</mml:mi><mml:mspace width="thinmathspace" /><mml:mo>&#x2217;</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>.</p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>(Encrypted) Tree Representation</title>
<p>We consider the Iterative Dichotomiser 3 (ID3) [<xref ref-type="bibr" rid="ref-7">7</xref>] algorithm. As depicted in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>-(1), non-leaf nodes set the independent variable that splits the node, denoted as <inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. The leaf nodes represent the predicted value of the node as <inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. In the proposed HEaaN-ID3, both <inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> are maintained in an encrypted state. Additionally, as shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>-(2), HEaaN-ID3 also stores the predicted value in non-leaf nodes. Since the data is encrypted, it is impossible to know whether valid data exists in the corresponding node. Predicted value made from nodes processed with invalid data cannot produce correct results, so the predicted value must be updated with that of the parent node containing valid data. The ciphertext used to perform this process is denoted as <inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>(A)-Tree representation ((1): original decision tree, (2): homomorphic DT)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-4.tif"/>
</fig>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Training</title>
<p>To visually present the training process of the tree&#x2014;including data encryption, MGI computation, and SIMD optimization&#x2014;a flowchart is illustrated in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>. When the training process begins, as shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>-(1), the input data is encrypted to initiate the process. At this stage, the SIMD technique is used to pack multiple data into a single ciphertext, in order to improve computational efficiency. The steps from <xref ref-type="fig" rid="fig-5">Fig. 5</xref>-(2) to <xref ref-type="fig" rid="fig-5">Fig. 5</xref>-(5) constitute the core of the algorithm, which is executed in the encrypted domain. These steps proceed as follows: (2) measures the most frequent Y label at each node; (3) generates a ciphertext that contains information used to determine whether the data at a node is valid; (4) sets the splitting criteria for the node. Here, MGI is used to enhance computational efficiency; (5) updates the data for the child nodes based on the determined splitting criteria. At the bottom of the tree, i.e., the leaf nodes, there is no need to create further child nodes, so only steps (2) and (3) are performed.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>CalculateMaxY</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-5.tif"/>
</fig>
<p>In addition, the training algorithm of HEaaN-ID3 is specified in Algorithm 1. It first performs training <inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> with the initial training data <inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> then repeats for all nodes in the tree up to the depth provided as input. The following provides a detailed description of each algorithm.</p>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-12.tif"/>
</fig>
<p>The <inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">Y</mml:mi></mml:mrow></mml:math></inline-formula>() in line #5 of Algorithm 1 finds the most frequent Y label of the target variable at each node. Using the data from <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, the process of <inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">Y</mml:mi></mml:mrow></mml:math></inline-formula>() is illustrated in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. It calculates the distribution of the target variable values from the data. This process involves <inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> rotations and addition operations, resulting in the frequency of each category being placed in the first slot of each ciphertext. The total <inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:mi>t</mml:mi></mml:math></inline-formula> ciphertexts generated in this manner are sequentially combined to create a ciphertext called <inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, after which a multiplication operation is performed with a ciphertext that has only the first <inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:mi>t</mml:mi></mml:math></inline-formula> slots set to 1. This operation removes unnecessary values from the ciphertext. Next, the <inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is passed through the <inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> function in Appendix A.1 of [<xref ref-type="bibr" rid="ref-60">60</xref>] that sets the slot with the largest value to 1 and the others to 0. Finally, <inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> rotations are applied to generate <inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>, multiplying by a constant corresponding to the number of rotations at each step.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>CalculateMaxY</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-6.tif"/>
</fig>
<p>Line #6 of Algorithm 1 is the step where the input data of the corresponding node is checked for validity. Since the data is encrypted, it is not possible to verify whether the node information has been generated from valid values. Consequently, all nodes are generated regardless of the data&#x2019;s validity, necessitating additional measures to handle nodes created from invalid data. In <inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">Y</mml:mi></mml:mrow></mml:math></inline-formula>(), instead of combining the ciphertexts representing the distribution of each Y label into a single ciphertext through rotation, a new ciphertext is created by adding all the individual ciphertexts together. Let the ciphertext for this operation be denoted as <inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>. The reciprocal can be obtained through <inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. According to the properties of <inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> mentioned in [<xref ref-type="bibr" rid="ref-3">3</xref>], if <inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, then <inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> becomes 0, and if it is not 0, <inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula> becomes 1. Finally, this result is applied in line #8 of Algorithm 1 to obtain <inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x27E6;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x27E7;</mml:mi></mml:mrow></mml:math></inline-formula>, which represents the predicted value for the corresponding node.</p>
<p>A critical part of the training process is finding the splitting variable <inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> that minimizes the MGI score. This corresponds to line #11 of Algorithm 1. The function <inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">V</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> proceeds in two steps: first, it calculates the frequency of each classified case, and then, it compares the information gain based on the MGI scores for all possible cases. To explain the first step of <inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">V</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, we begin by creating a ciphertext <inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> that stores all MGI scores for each variable. Here, <inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mi>j</mml:mi></mml:math></inline-formula> represents the position of a node at the same level. Since the number of independent variables used is <inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:mi>d</mml:mi></mml:math></inline-formula>, only the first <inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mi>d</mml:mi></mml:math></inline-formula> slots from the left in the ciphertext <inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are used.</p>
<p>The key of the first step is calculating the frequency by determining the distribution of the target variable for each value of the independent variables using the result of <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>y</mml:mi><mml:mi>q</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x22A1;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mi>q</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>u</mml:mi><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. The ciphertexts generated through multiplication are processed using <inline-formula id="ieqn-322"><mml:math id="mml-ieqn-322"><mml:msub><mml:mi>log</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> rotation and addition operations to ensure that the frequency is stored in the first slot of the <inline-formula id="ieqn-323"><mml:math id="mml-ieqn-323"><mml:mi>N</mml:mi></mml:math></inline-formula> slots, which are divided according to the categories of each variable. Any slots that do not contain valid values are then set to zero.</p>
<p>The second step is to identify the variable with the highest Information Gain (IG) among the independent variables based on the results obtained from the previous process. The IG is computed as the difference between the MGI score of the parent node and the sum of the MGI scores of all children. To determine the independent variable that maximizes IG, it is sufficient to search for the independent variable that minimizes the sum of the MGI scores for the child nodes because the parent is fixed to the current node. Therefore, this step calculates the sum of the MGI scores for each independent variable and stores them in separate slots in the ciphertext.</p>
<p>In the plaintext version, the two steps can be described as follows: First, calculate <inline-formula id="ieqn-324"><mml:math id="mml-ieqn-324"><mml:mover><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mover><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>+</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>+</mml:mo><mml:mover><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula> and then compute <inline-formula id="ieqn-325"><mml:math id="mml-ieqn-325"><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mover><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>&#x22C5;</mml:mo><mml:mover><mml:msub><mml:mi>y</mml:mi><mml:mi>q</mml:mi></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover></mml:math></inline-formula>. Based on this result, calculate <inline-formula id="ieqn-326"><mml:math id="mml-ieqn-326"><mml:mi>G</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:msub><mml:mi>i</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>q</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>t</mml:mi></mml:munderover><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x2212;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>q</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>t</mml:mi></mml:munderover><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>q</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula> to obtain the final MGI score for the corresponding variable.</p>
<p>Finally, the independent variable that has the smallest MGI score among the <inline-formula id="ieqn-327"><mml:math id="mml-ieqn-327"><mml:mi>d</mml:mi></mml:math></inline-formula> values stored in the ciphertext <inline-formula id="ieqn-328"><mml:math id="mml-ieqn-328"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> for each node is determined, where <inline-formula id="ieqn-329"><mml:math id="mml-ieqn-329"><mml:mi>j</mml:mi></mml:math></inline-formula> corresponds to the node ID. This involves identifying the position <inline-formula id="ieqn-330"><mml:math id="mml-ieqn-330"><mml:mi>i</mml:mi></mml:math></inline-formula> of the slot that contains the minimum value (i.e., this means <inline-formula id="ieqn-331"><mml:math id="mml-ieqn-331"><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> maximizes IG) within each <inline-formula id="ieqn-332"><mml:math id="mml-ieqn-332"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> obtained from the second step. Because locating the slot with the minimum value is computationally expensive in the CKKS sheme, we implement the <inline-formula id="ieqn-333"><mml:math id="mml-ieqn-333"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> function in Appendix A.1 of [<xref ref-type="bibr" rid="ref-60">60</xref>] to reduce the computational cost. This function efficiently reduces the number of operations by consolidating the values of multiple <inline-formula id="ieqn-334"><mml:math id="mml-ieqn-334"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> ciphertexts into a single ciphertext. Subsequently, it identifies the position of the slot with the minimum value within each group of <inline-formula id="ieqn-335"><mml:math id="mml-ieqn-335"><mml:mi>d</mml:mi></mml:math></inline-formula> slots. Only the slot with the minimum value is assigned a value of 1, whereas the remaining slots are set to 0. This approach is effective because the number of slots in a ciphertext, denoted as <inline-formula id="ieqn-336"><mml:math id="mml-ieqn-336"><mml:mi>M</mml:mi></mml:math></inline-formula>, is often much larger than the number of independent variables, <inline-formula id="ieqn-337"><mml:math id="mml-ieqn-337"><mml:mi>d</mml:mi></mml:math></inline-formula>. Consequently, the number of operations required to determine the minimum value is reduced by a factor of <inline-formula id="ieqn-338"><mml:math id="mml-ieqn-338"><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi></mml:math></inline-formula>.</p>
<p>The final step of the training process is to update the training data for the child nodes. This corresponds to line #12 of Algorithm 1. To aid understanding, we will explain this in plaintext as depicted in <xref ref-type="fig" rid="fig-7">Fig. 7</xref>. The child nodes of the currently processing node only use the data corresponding to the classification result of the current node. For example, assume that the variable selected for classification at the current node is <inline-formula id="ieqn-339"><mml:math id="mml-ieqn-339"><mml:msub><mml:mi>X</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>. To generate the training data for the first child node, we multiply the column where <inline-formula id="ieqn-340"><mml:math id="mml-ieqn-340"><mml:msub><mml:mi>X</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> by the entire training dataset. Similarly, we multiply each of the <inline-formula id="ieqn-341"><mml:math id="mml-ieqn-341"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> columns to generate the data for all child nodes of the corresponding node. In the encrypted state, a single ciphertext is created by copying each column&#x2019;s data <inline-formula id="ieqn-342"><mml:math id="mml-ieqn-342"><mml:mi>N</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> times and then multiplying it by a total of <inline-formula id="ieqn-343"><mml:math id="mml-ieqn-343"><mml:mi>u</mml:mi><mml:mo>+</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula> ciphertexts.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>UpdateData-plaintext version</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-7.tif"/>
</fig>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>Inference</title>
<p>We describe a strategy for representing the original model shown in <xref ref-type="fig" rid="fig-4">Fig.4</xref>-(1) in an encrypted state and for performing inference using the encrypted model. <xref ref-type="fig" rid="fig-4">Fig. 4</xref>-(2) shows the representation of the plaintext model in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>-(1) with encrypted values. <xref ref-type="fig" rid="fig-8">Fig. 8</xref> illustrates the encrypted model in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>-(2) using ciphertexts. Observably, <inline-formula id="ieqn-344"><mml:math id="mml-ieqn-344"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-345"><mml:math id="mml-ieqn-345"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-346"><mml:math id="mml-ieqn-346"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula>) values of all nodes at the same level are stored in a single ciphertext, denoted as <inline-formula id="ieqn-347"><mml:math id="mml-ieqn-347"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo>.</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-348"><mml:math id="mml-ieqn-348"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>.</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-349"><mml:math id="mml-ieqn-349"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub><mml:mo>.</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>l</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) on different slot positions.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>(B)-Tree representation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-8.tif"/>
</fig>
<p>In <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, the <inline-formula id="ieqn-350"><mml:math id="mml-ieqn-350"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-351"><mml:math id="mml-ieqn-351"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-352"><mml:math id="mml-ieqn-352"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> values were pre-processed: as they can be computed independently from the input data for inference, they were pre-computed. The actual inference process was performed using <inline-formula id="ieqn-353"><mml:math id="mml-ieqn-353"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> from the middle in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, <inline-formula id="ieqn-354"><mml:math id="mml-ieqn-354"><mml:msubsup><mml:mi>c</mml:mi><mml:mrow><mml:mi>y</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup></mml:math></inline-formula> in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, and <inline-formula id="ieqn-355"><mml:math id="mml-ieqn-355"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub></mml:math></inline-formula> at the bottom in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>.</p>
<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> illustrates an example of the inference process using a HEaaN-ID3 tree represented in <xref ref-type="fig" rid="fig-8">Fig. 8</xref> with an input at the top of <xref ref-type="fig" rid="fig-9">Fig. 9</xref>. The input comprises four independent variables, each with up to three categories. In the example, the input is (<inline-formula id="ieqn-356"><mml:math id="mml-ieqn-356"><mml:msub><mml:mi>X</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-357"><mml:math id="mml-ieqn-357"><mml:msub><mml:mi>X</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-358"><mml:math id="mml-ieqn-358"><mml:msub><mml:mi>X</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-359"><mml:math id="mml-ieqn-359"><mml:msub><mml:mi>X</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>) &#x003D; (2, 1, 1, 1). The owner of this input encrypts it after representing it as a form of Bin Mask Vector [<xref ref-type="bibr" rid="ref-3">3</xref>] (0, 1, 0, 1, 0, 0, 1, 0, 0, 1, 0, 0). We duplicated it as much as possible to ensure that the size of the input vector was the same as the number of slots in the ciphertext before encryption. The size of the input vector was <inline-formula id="ieqn-360"><mml:math id="mml-ieqn-360"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi></mml:math></inline-formula>, which was duplicated by <inline-formula id="ieqn-361"><mml:math id="mml-ieqn-361"><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo></mml:math></inline-formula> times. The resultant ciphertext is expressed as follows: <inline-formula id="ieqn-362"><mml:math id="mml-ieqn-362"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in <xref ref-type="fig" rid="fig-9">Fig. 9</xref> was sent to the CS.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>An example of inference process</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-9.tif"/>
</fig>
<p>Once the input ciphertext is received, CS begins the inference process. Unlike in the plaintext version, the inference process proceeds in reverse order, starting from the leaf nodes and moving towards the root. Among all possible outputs in the leaf nodes, one is chosen for each of their parent nodes based on the input values of the variables used for splitting by the parents. After the choice is made, every parent node has a target value which is from one of its children<xref ref-type="fn" rid="fn-2"><sup>2</sup></xref><fn id="fn-2">
<label>2</label>
<p>The parent may use its own target value if no children is valid.</p>
</fn>. We update the tree such that the parent nodes become the leaf nodes. Thus, the depth of the tree is decreased by one. We then repeat the process until only the root node remains in the tree with a target value, which is returned as the final inference result.</p>
<p>In addition, the split conditions on the nodes in the same levels were performed in parallel using a cryptographic SIMD operation. This contributes significantly to the efficient inference of the proposed method.</p>
<p>For convenience, we provide a detailed explanation of the inference process depicted in <xref ref-type="fig" rid="fig-9">Fig. 9</xref>, under the assumption that <inline-formula id="ieqn-363"><mml:math id="mml-ieqn-363"><mml:mi>M</mml:mi><mml:mo>&#x2265;</mml:mo><mml:msubsup><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> for convenience. The process consisted of four main steps, as follows. Step <inline-formula id="ieqn-364"><mml:math id="mml-ieqn-364"><mml:mrow><mml:mo>&#x2461;</mml:mo></mml:mrow></mml:math></inline-formula> involves extracting from <inline-formula id="ieqn-365"><mml:math id="mml-ieqn-365"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> the values corresponding to the variables used for split at every non-leaf node in a tree. To achieve this, we perform a multiplication operation between the values of <inline-formula id="ieqn-366"><mml:math id="mml-ieqn-366"><mml:msub><mml:mi>c</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>.</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>l</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-367"><mml:math id="mml-ieqn-367"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> for each level <inline-formula id="ieqn-368"><mml:math id="mml-ieqn-368"><mml:mi>i</mml:mi></mml:math></inline-formula> in the tree. The resulting values are stored in <inline-formula id="ieqn-369"><mml:math id="mml-ieqn-369"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>l</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Step <inline-formula id="ieqn-370"><mml:math id="mml-ieqn-370"><mml:mrow><mml:mo>&#x2462;</mml:mo></mml:mrow></mml:math></inline-formula> aligns the extracted results to specific fixed positions to ensure accessibility. This is achieved by applying rotation operations O(<inline-formula id="ieqn-371"><mml:math id="mml-ieqn-371"><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mi>d</mml:mi></mml:math></inline-formula>) times. In Step <inline-formula id="ieqn-372"><mml:math id="mml-ieqn-372"><mml:mrow><mml:mo>&#x2462;</mml:mo></mml:mrow></mml:math></inline-formula>, we reposition the values in <inline-formula id="ieqn-373"><mml:math id="mml-ieqn-373"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to proceed to further processing. In step <inline-formula id="ieqn-374"><mml:math id="mml-ieqn-374"><mml:mrow><mml:mo>&#x2463;</mml:mo></mml:mrow></mml:math></inline-formula>, we make the spacing between neighboring components of the encrypted one-hot encoding vectors obtained in the previous step equal to the number of <inline-formula id="ieqn-375"><mml:math id="mml-ieqn-375"><mml:msubsup><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> slots, where is the current level. This rendered the inference process more efficient.</p>
<p>Using <inline-formula id="ieqn-376"><mml:math id="mml-ieqn-376"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msubsup></mml:math></inline-formula>s created in the training process and <inline-formula id="ieqn-377"><mml:math id="mml-ieqn-377"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>s created in the previous steps, we obtain the inference result through Steps <inline-formula id="ieqn-378"><mml:math id="mml-ieqn-378"><mml:mrow><mml:mrow><mml:mo>&#x2464;</mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> to <inline-formula id="ieqn-379"><mml:math id="mml-ieqn-379"><mml:mrow><mml:mo>&#x246C;</mml:mo></mml:mrow></mml:math></inline-formula>. This process of multiplying <inline-formula id="ieqn-380"><mml:math id="mml-ieqn-380"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-381"><mml:math id="mml-ieqn-381"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> at the leaf level. It then processes one level at a time from its parent level, moving upward until it reaches the root level. The calculation of <inline-formula id="ieqn-382"><mml:math id="mml-ieqn-382"><mml:msubsup><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msubsup></mml:math></inline-formula> from <inline-formula id="ieqn-383"><mml:math id="mml-ieqn-383"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-384"><mml:math id="mml-ieqn-384"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> is performed as follows: <inline-formula id="ieqn-385"><mml:math id="mml-ieqn-385"><mml:mrow><mml:mo>&#x2466;</mml:mo></mml:mrow></mml:math></inline-formula> to <inline-formula id="ieqn-386"><mml:math id="mml-ieqn-386"><mml:mrow><mml:mo>&#x2467;</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-387"><mml:math id="mml-ieqn-387"><mml:mrow><mml:mo>&#x246A;</mml:mo></mml:mrow></mml:math></inline-formula> to <inline-formula id="ieqn-388"><mml:math id="mml-ieqn-388"><mml:mrow><mml:mo>&#x246B;</mml:mo></mml:mrow></mml:math></inline-formula>. Finally, after Step <inline-formula id="ieqn-389"><mml:math id="mml-ieqn-389"><mml:mrow><mml:mo>&#x246C;</mml:mo></mml:mrow></mml:math></inline-formula>, we obtain the inference result <inline-formula id="ieqn-390"><mml:math id="mml-ieqn-390"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>y</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> while processing the root level. The final step involves moving the resultant y value into the first slot in <inline-formula id="ieqn-391"><mml:math id="mml-ieqn-391"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>y</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>. This should be done at Step <inline-formula id="ieqn-392"><mml:math id="mml-ieqn-392"><mml:mrow><mml:mo>&#x246D;</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
<p>A detailed description of the tree inference protocol is presented in <xref ref-type="fig" rid="fig-10">Fig. 10</xref>. In the description, SumGroup() and AdjustMargin() presented as Algorithm 2 and Algorithm 3 correspond to Steps <inline-formula id="ieqn-393"><mml:math id="mml-ieqn-393"><mml:mrow><mml:mo>&#x2462;</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-394"><mml:math id="mml-ieqn-394"><mml:mrow><mml:mo>&#x2465;</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-395"><mml:math id="mml-ieqn-395"><mml:mrow><mml:mo>&#x2469;</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-396"><mml:math id="mml-ieqn-396"><mml:mrow><mml:mo>&#x2463;</mml:mo></mml:mrow></mml:math></inline-formula> in <xref ref-type="fig" rid="fig-9">Fig. 9</xref>, respectively.</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>The proposed HEaaN-ID3 inference algorithm</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-10.tif"/>
</fig>
<fig id="fig-13">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-13.tif"/>
</fig>
<fig id="fig-14">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-14.tif"/>
</fig>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Experimental Results</title>
<p>The experimental results of the proposed FHDT on various datasets are presented in this section. The experimental environment was an AMD RYZEN 5950X CPU, NVIDIA Quadro RTX A6000 48 GB GPU, 128 GB RAM. <xref ref-type="sec" rid="s6_1">Section 6.1</xref> provides the performance of the basic operations in CKKS. In <xref ref-type="sec" rid="s6_2">Section 6.2</xref>, we compare the performance of the proposed method with that of [<xref ref-type="bibr" rid="ref-10">10</xref>]. Although the execution environment and the parameters used for CKKS HE were different, we observed that the soft-step function in [<xref ref-type="bibr" rid="ref-10">10</xref>] and the ApproxSign() function in our environment had similar execution times. To the best of our knowledge, the multiplication depth and polynomial degree used are the same in both functions; therefore, we can infer that the performance difference between the two methods can be derived to some extent from the differences in their execution times measured in each environment.</p>
<sec id="s6_1">
<label>6.1</label>
<title>CKKS</title>
<p><xref ref-type="table" rid="table-3">Table 3</xref> lists the performance of the CKKS unit operations and subroutines. Boot() operations required 130.3 ms as we employed a GPU [<xref ref-type="bibr" rid="ref-55">55</xref>]. Approximately 600 ms was required for ApproxSign() used for the proposed training algorithm. The relative error of ApproxInv() was measured as <inline-formula id="ieqn-420"><mml:math id="mml-ieqn-420"><mml:mn>5.592</mml:mn><mml:mi>E</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>07</mml:mn><mml:mo>&#x00B1;</mml:mo><mml:mn>6.03</mml:mn><mml:mi>E</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>07</mml:mn><mml:mi mathvariant="normal">&#x0025;</mml:mi></mml:math></inline-formula>. The relative errors of the other unit operations are less than <inline-formula id="ieqn-421"><mml:math id="mml-ieqn-421"><mml:mn>1</mml:mn><mml:mi>E</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>05</mml:mn><mml:mi mathvariant="normal">&#x0025;</mml:mi></mml:math></inline-formula>. We used the GPU version of the HEaaN library for CKKS (<ext-link ext-link-type="uri" xlink:href="https://heaan.it">https://heaan.it</ext-link>).</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Average time (ms) of CKKS operations and basic subroutines</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Add</th>
<th>Mult (lv. 11)</th>
<th>Mult (lv. 4)</th>
<th>Rot</th>
</tr>
</thead>
<tbody>
<tr>
<td>0.037 <inline-formula id="ieqn-422"><mml:math id="mml-ieqn-422"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.18 <inline-formula id="ieqn-423"><mml:math id="mml-ieqn-423"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0064</td>
<td>0.14 <inline-formula id="ieqn-424"><mml:math id="mml-ieqn-424"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0031</td>
<td>0.15 <inline-formula id="ieqn-425"><mml:math id="mml-ieqn-425"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0077</td>
</tr>
<tr>
<td>Boot</td>
<td>ApproxSign</td>
<td>ApproxInv</td>
<td></td>
</tr>
<tr>
<td>130.3 <inline-formula id="ieqn-426"><mml:math id="mml-ieqn-426"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.20</td>
<td>600.4 <inline-formula id="ieqn-427"><mml:math id="mml-ieqn-427"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.91</td>
<td>307.5 <inline-formula id="ieqn-428"><mml:math id="mml-ieqn-428"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.53</td>
<td></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>HEaaN-ID3</title>
<p>We evaluated the performance of the proposed HEaaN-ID3 using the data listed in <xref ref-type="table" rid="table-4">Table 4</xref>. They belong to the UCI repository [<xref ref-type="bibr" rid="ref-13">13</xref>], and for binning the numeric variables, the Scott and Sturges binning method was used.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Dataset parameter</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Data set</th>
<th><inline-formula id="ieqn-429"><mml:math id="mml-ieqn-429"><mml:mi mathvariant="bold-italic">t</mml:mi></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-430"><mml:math id="mml-ieqn-430"><mml:mi mathvariant="bold-italic">d</mml:mi></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-431"><mml:math id="mml-ieqn-431"><mml:msub><mml:mi mathvariant="bold-italic">n</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">m</mml:mi><mml:mi mathvariant="bold-italic">a</mml:mi><mml:mi mathvariant="bold-italic">x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></th>
<th><inline-formula id="ieqn-432"><mml:math id="mml-ieqn-432"><mml:msub><mml:mi mathvariant="bold-italic">s</mml:mi><mml:mi mathvariant="bold-italic">z</mml:mi></mml:msub></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td>Iris Scott</td>
<td>3</td>
<td>4</td>
<td>9</td>
<td>100</td>
</tr>
<tr>
<td>Iris Sturges</td>
<td></td>
<td></td>
<td>9</td>
<td></td>
</tr>
<tr>
<td>Wine Scott</td>
<td>3</td>
<td>13</td>
<td>11</td>
<td>118</td>
</tr>
<tr>
<td>Wine Sturges</td>
<td></td>
<td></td>
<td>9</td>
<td></td>
</tr>
<tr>
<td>Cancer Scott</td>
<td>2</td>
<td>30</td>
<td>18</td>
<td>379</td>
</tr>
<tr>
<td>Cancer Sturges</td>
<td></td>
<td></td>
<td>11</td>
<td></td>
</tr>
<tr>
<td>Breast cancer</td>
<td>2</td>
<td>9</td>
<td>11</td>
<td>184</td>
</tr>
<tr>
<td>Soybean</td>
<td>15</td>
<td>35</td>
<td>7</td>
<td>374</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s6_2_1">
<label>6.2.1</label>
<title>Inference</title>
<p><xref ref-type="fig" rid="fig-11">Fig. 11</xref> shows the results for the inference time. Compared to the performance of the method in [<xref ref-type="bibr" rid="ref-10">10</xref>], which requires 2.3 s to process a total of 31 nodes, HEaaN-ID3 requires 657.32 ms even for depth 4 DT trained with the Breast Cancer data, which has 16105 nodes. This indicates that HEaaN-ID3 is superior when considering the number of nodes in the tree. Unfortunately, the inference time increased sharply as the tree depth increased, indicating that the tree depth of the proposed method should be limited. However, in an ID3 DT, owing to the large number of child nodes in the tree, it is possible to achieve a high inference accuracy with a shallow tree depth compared to a binary DT.</p>
<fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Inference time (The color of the bar indicates the execution time per level of the tree. Because the inference procedure iterates per level, as the depth of the tree increases, the number of iterations also increases. The execution time for each level is described in the table below each bar in the graph)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_64161-fig-11.tif"/>
</fig>
<p>The inference is performed from the leaf level to the root level. Therefore, if the tree is deep, a bootstrapping operation occurs when processing at the lower level. Thus, the execution time of Level 1 becomes very long if the depth of the tree is three or more. In addition, the number of nodes at the low (close to the leaf) level was extremely large, owing to the characteristics of ID3. Therefore, when the depth of the tree increases, the execution time at a low level increases. As shown in <xref ref-type="fig" rid="fig-11">Fig. 11</xref>, for the DT of depth 4 trained with the Breast Cancer data, the processing time for the level 4 of 14641 nodes is 319.47 ms, and in the case of the depth 4 DT with Soybean data, 164.79 ms is required to process the level 4 of 2401 nodes.</p>

<p>Regarding inference accuracy, <xref ref-type="table" rid="table-5">Table 5</xref> shows that the performance of HEaaN-ID3 is comparable to that of the well-known Scikit-Learn [<xref ref-type="bibr" rid="ref-14">14</xref>] library, which is evaluated using plaintext data.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Accuracy comparison: HEaaN-ID3 (H) vs. Scikit-learn (S) (%) (depth: the depth of DT) [<xref ref-type="bibr" rid="ref-14">14</xref>]</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th align="center" rowspan="3">Data set</th>
<th colspan="8">Depth</th>
<th align="center">Average difference</th>
</tr>
<tr>
<th colspan="2">1</th>
<th colspan="2">2</th>
<th colspan="2">3</th>
<th colspan="2">4</th>
<th/>
</tr>
<tr>
<th>H</th>
<th>S</th>
<th>H</th>
<th>S</th>
<th>H</th>
<th>S</th>
<th>H</th>
<th>S</th>
<th/>
</tr>
</thead>
<tbody>
<tr>
<td>Iris Scott</td>
<td>92.67</td>
<td>92.67</td>
<td>96.00</td>
<td>94.00</td>
<td>96.00</td>
<td>94.67</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>&#x2212;1.11</td>
</tr>
<tr>
<td>Iris Sturges</td>
<td>96.00</td>
<td>96.00</td>
<td>93.11</td>
<td>92.00</td>
<td>93.11</td>
<td>92.67</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>&#x2212;0.52</td>
</tr>
<tr>
<td>Wine Scott</td>
<td>76.26</td>
<td>74.76</td>
<td>86.72</td>
<td>84.84</td>
<td>86.72</td>
<td>85.41</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>&#x2212;1.57</td>
</tr>
<tr>
<td>Wine Sturges</td>
<td>80.37</td>
<td>80.37</td>
<td>90.17</td>
<td>86.01</td>
<td>88.62</td>
<td>86.01</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>&#x2212;2.26</td>
</tr>
<tr>
<td>Cancer Scott</td>
<td>89.28</td>
<td>89.28</td>
<td>90.63</td>
<td>91.39</td>
<td>90.69</td>
<td>90.51</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>0.19</td>
</tr>
<tr>
<td>Cancer Sturges</td>
<td>91.03</td>
<td>91.03</td>
<td>91.10</td>
<td>91.56</td>
<td>91.16</td>
<td>91.74</td>
<td>&#x2013;</td>
<td>&#x2013;</td>
<td>0.35</td>
</tr>
<tr>
<td>Breast cancer</td>
<td>68.95</td>
<td>69.67</td>
<td>66.55</td>
<td>66.79</td>
<td>65.95</td>
<td>67.51</td>
<td>65.57</td>
<td>65.70</td>
<td>0.66</td>
</tr>
<tr>
<td>Soybean</td>
<td>30.96</td>
<td>30.96</td>
<td>37.66</td>
<td>36.83</td>
<td>51.12</td>
<td>53.20</td>
<td>58.35</td>
<td>57.82</td>
<td>0.18</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_2_2">
<label>6.2.2</label>
<title>Training</title>
<p><xref ref-type="table" rid="table-6">Table 6</xref> compares the training times of the proposed method with those of [<xref ref-type="bibr" rid="ref-10">10</xref>]. For a fair comparison, the estimated time after adjusting the experimental environment from [<xref ref-type="bibr" rid="ref-10">10</xref>] to that of this study is 0.851 min for the Iris dataset with a depth of 4. When comparing the training time per node, HEaaN-ID3 takes 0.029 min, while [<xref ref-type="bibr" rid="ref-10">10</xref>] takes 0.027 min. Although [<xref ref-type="bibr" rid="ref-10">10</xref>] is slightly faster in terms of performance, the proposed method in this study provides safer training as it does not involve decryption during the training process.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Training time comparison (minutes): HEaaN-ID3 vs. [<xref ref-type="bibr" rid="ref-10">10</xref>] (The total number of nodes in the trees is given in parentheses)</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Data set</th>
<th>Depth 1</th>
<th>Depth 2</th>
<th>Depth 3</th>
<th>Depth 4</th>
<th>[<xref ref-type="bibr" rid="ref-10">10</xref>] (Depth 4)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Iris Scott</td>
<td>0.38796 (10)</td>
<td>2.2340 (91)</td>
<td>24.136 (820)</td>
<td>&#x2013;</td>
<td>47 (31)</td>
</tr>
<tr>
<td>Iris Sturges</td>
<td>0.38821 (10)</td>
<td>2.2415 (91)</td>
<td>24.148 (820)</td>
<td>&#x2013;</td>
<td></td>
</tr>
<tr>
<td>Wine Scott</td>
<td>0.54727 (12)</td>
<td>3.4450 (133)</td>
<td>44.802 (1464)</td>
<td>&#x2013;</td>
<td>148 (31)</td>
</tr>
<tr>
<td>Wine Sturges</td>
<td>0.50409 (10)</td>
<td>2.5195 (91)</td>
<td>25.441 (820)</td>
<td>&#x2013;</td>
<td></td>
</tr>
<tr>
<td>Cancer Scott</td>
<td>0.97279 (19)</td>
<td>10.688 (343)</td>
<td>206.75 (6175)</td>
<td>&#x2013;</td>
<td>278 (31)</td>
</tr>
<tr>
<td>Cancer Sturges</td>
<td>0.74613 (12)</td>
<td>4.3056 (133)</td>
<td>45.989 (1464)</td>
<td>&#x2013;</td>
<td></td>
</tr>
<tr>
<td>Breast cancer</td>
<td>0.47718 (12)</td>
<td>3.2868 (133)</td>
<td>38.011 (1464)</td>
<td>499.41 (16105)</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Soybean</td>
<td>0.99063 (8)</td>
<td>3.2193 (57)</td>
<td>27.470 (400)</td>
<td>296.43 (2801)</td>
<td>&#x2013;</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Security Analysis of the Proposed Method</title>
<p>In this section, we present the security analysis. Under the assumption of the HBC (Honest-But-Curious) model, we assessed whether any participant (either <inline-formula id="ieqn-433"><mml:math id="mml-ieqn-433"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> or <inline-formula id="ieqn-434"><mml:math id="mml-ieqn-434"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>) could obtain information from the ciphertexts they received from other participants. We first assume <inline-formula id="ieqn-435"><mml:math id="mml-ieqn-435"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> to be a trusted third party and it is well-known that the CKKS scheme supports CPA (Chosen Plaintext Attack) security [<xref ref-type="bibr" rid="ref-61">61</xref>].</p>
<p>We begin by considering the case where the <inline-formula id="ieqn-436"><mml:math id="mml-ieqn-436"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> is an adversary. If the <inline-formula id="ieqn-437"><mml:math id="mml-ieqn-437"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> can obtain any information from the ciphertexts it receives from the users, it will compromise the CPA security of the underlying CKKS scheme. However, in the proposed protocol, the <inline-formula id="ieqn-438"><mml:math id="mml-ieqn-438"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> receives only ciphertexts, excluding certain metadata; therefore, it cannot obtain any information from them.</p>
<p>Subsequently, we considered a scenario in which users acted as adversaries and attempted to obtain information from other users&#x2019; ciphertexts or from the results of homomorphic computation using <inline-formula id="ieqn-439"><mml:math id="mml-ieqn-439"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula>. Unlike in the <inline-formula id="ieqn-440"><mml:math id="mml-ieqn-440"><mml:mrow><mml:mi mathvariant="sans-serif">C</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi></mml:mrow></mml:math></inline-formula> case, users receive the inference result, which is a decryption result. Therefore, the situation must be assessed differently. Because users receive only the inference result and there are no other users&#x2019; ciphertexts, we must verify that the inference result does not reveal any information about the models or data used for inference. Nevertheless, with our method, the amount of information that a user can obtain from inference is the same as if the same protocol is used without encryption. Hence, we can conclude that users cannot obtain any meaningful information from ciphertexts that does not belong to them or cannot be derived from their ciphertexts because even the corresponding plaintext-version of the ID3 DT protocol may reveal the same amount of information as the proposed method. In conclusion, based on the aforementioned argument, we can affirm that our method is secure in the HBC setting and that <inline-formula id="ieqn-441"><mml:math id="mml-ieqn-441"><mml:mrow><mml:mi mathvariant="sans-serif">K</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi></mml:mrow></mml:math></inline-formula> is a trusted third party.</p>
<p>To set up a key distribution, HEaaN-ID3 follows the same settings as [<xref ref-type="bibr" rid="ref-3">3</xref>]. Therefore, please refer to [<xref ref-type="bibr" rid="ref-3">3</xref>] for the security of the key distribution.</p>
</sec>
<sec id="s8">
<label>8</label>
<title>Discussion</title>
<sec id="s8_1">
<label>8.1</label>
<title>Checking the Objectives Met by HEaaN-ID3</title>
<p>In <xref ref-type="sec" rid="s5">Section 5</xref>, we determine whether HEaaN-ID3 satisfies the five objectives presented in the Problem Definition. For 1) Data privacy, 2) Model privacy, and 3) Inference privacy: We can confirm these based on the analysis of security in <xref ref-type="sec" rid="s7">Section 7</xref>. Regarding 4), because of the features of HEaaN-ID3, if a user encrypts and delivers the training data to the CS, it can generate a model without the help of other participants; thus, it is satisfied. Finally, for compound 5), HEaaN-ID3 used a single CS that does not have access to the decryption key. Therefore, the condition is satisfied.</p>
</sec>
<sec id="s8_2">
<label>8.2</label>
<title>Correctness in Exceptional Situation</title>
<p>HEaaN-ID3 aims to address situations not considered in [<xref ref-type="bibr" rid="ref-10">10</xref>] during the training process. These situations include the following.
<list list-type="bullet">
<list-item>
<p>Scenarios in which the number of training data branches to a specific node is zero.</p></list-item>
<list-item>
<p>Dealing with multiple variables or pairs of variables and condition that maximize information gain at a specific node.</p></list-item>
</list></p>
<p>Although these cases were not discussed in detail in [<xref ref-type="bibr" rid="ref-10">10</xref>], they may still occur. However, reference [<xref ref-type="bibr" rid="ref-10">10</xref>] can handle these situations because all information gain values can be viewed in plaintext form during training. In the proposed method, wherein everything is processed in an encrypted state, these cases must be addressed to prevent any potential impact on the accuracy of the inference results.</p>
<p><italic>When there is no data branching to a specific node</italic>: For example, consider a scenario in which training is performed at a node in a DT and there is no training data branching to that node. In this case, all BMV values in <inline-formula id="ieqn-442"><mml:math id="mml-ieqn-442"><mml:mi>T</mml:mi><mml:mi>D</mml:mi></mml:math></inline-formula> became zero, leading to a MGI score to become 0. Consequently, all <inline-formula id="ieqn-443"><mml:math id="mml-ieqn-443"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> values become 1, and the <inline-formula id="ieqn-444"><mml:math id="mml-ieqn-444"><mml:msub><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:msub></mml:math></inline-formula> value of the corresponding node is set to 0. This sets the <inline-formula id="ieqn-445"><mml:math id="mml-ieqn-445"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> value of the corresponding node to zero and the training process continues with the child nodes.</p>
<p>If the <inline-formula id="ieqn-446"><mml:math id="mml-ieqn-446"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> value of a node is zero, all values returned by that node and its descendants are ignored during the inference process. Therefore, the result of the inference process is returned from a node whose <inline-formula id="ieqn-447"><mml:math id="mml-ieqn-447"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> value is one of the ancestor nodes. The closest ancestor was selected if more than two ancestors were present. In addition, if there is at least one row of training data, the <inline-formula id="ieqn-448"><mml:math id="mml-ieqn-448"><mml:msub><mml:mi>c</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> value of the root node is always equal to one. This ensures that HEaaN-ID3 returns the correct result, even when there is no data branching in a specific node.</p>
<p><italic>When there are multiple variables that maximize information gain</italic>: In this scenario, the result of the function <inline-formula id="ieqn-449"><mml:math id="mml-ieqn-449"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> has a ciphertext with multiple slots of value 1, representing the number of variables (and branching conditions) that maximize information gain. To address this, the function <inline-formula id="ieqn-450"><mml:math id="mml-ieqn-450"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">m</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is called to select only one slot with a value of 1 and set the others to zero. The chosen variable (and branching condition) are then used to split the current node, and the training process proceeds normally to the next step.</p>
</sec>
<sec id="s8_3">
<label>8.3</label>
<title>Computation Complexity Analysis and Comparision with [<xref ref-type="bibr" rid="ref-10">10</xref>]</title>
<p>The most relevant study to HEaaN-ID3 was by Adiakavia et al. in 2022 [<xref ref-type="bibr" rid="ref-10">10</xref>]. In this subsection, HEaaN-ID3 is compared [<xref ref-type="bibr" rid="ref-10">10</xref>]. The first point to discuss is the differences in the perspective of the system model. In [<xref ref-type="bibr" rid="ref-10">10</xref>], the client has all the data required to learn and classify. During the training process, the client encrypts the training data and sends them to a server. The server learns using the received encrypted data. For critical operations that require heavy computation, the encrypted ciphertext is sent to the client, who then deciphers it, performs critical operations, and encrypts the result before sending it back to the server. In this case, the server and the client must perform <inline-formula id="ieqn-451"><mml:math id="mml-ieqn-451"><mml:mi>h</mml:mi></mml:math></inline-formula> rounds of communication to train a tree with a depth of <inline-formula id="ieqn-452"><mml:math id="mml-ieqn-452"><mml:mi>h</mml:mi></mml:math></inline-formula>. However, the communication volume for each round increases geometrically in proportion to the level of the tree being processed.</p>
<p>HEaaN-ID3, on the other hand, allows multiple users to encrypt their data and send them to the cloud server, where training can take place without further communication. This eliminates the cost and difficulty of communication between the decryption key holder and the cloud server during the training process. Consequently, the proposed method is more advantageous in environments wherein communication with the decryption key holder is expensive or difficult or when the decryption key holder has limited computational resources.</p>
<p><xref ref-type="table" rid="table-7">Table 7</xref> presents the execution time for a single node, but since FindMaxGroupPos() and FindMinGroupPos() are executed simultaneously for all nodes at the same level, the execution time per single node can be estimated by dividing by the number of nodes at that level <inline-formula id="ieqn-453"><mml:math id="mml-ieqn-453"><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>. In addition, since inference is performed by level, only the &#x201D;Reconstructing model for efficient inference&#x201D; step in the training process represents the execution time for a single level. We suppose <inline-formula id="ieqn-454"><mml:math id="mml-ieqn-454"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the number of the variables of which the training data can be accommodated in the ciphertext (<inline-formula id="ieqn-455"><mml:math id="mml-ieqn-455"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo></mml:math></inline-formula>). The number of ciphertexts <inline-formula id="ieqn-456"><mml:math id="mml-ieqn-456"><mml:mi>u</mml:mi></mml:math></inline-formula> used to create the training data was calculated as <inline-formula id="ieqn-457"><mml:math id="mml-ieqn-457"><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="sans-serif">c</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:math></inline-formula>. Additionally, for a fair comparison, Line 11 of Algorithm 1 should be excluded from the comparison and its execution time is not included in <xref ref-type="table" rid="table-8">Table 8</xref>, since the method in [<xref ref-type="bibr" rid="ref-10">10</xref>] performed the Gini impurity calculation by decrypting the data.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Computation cost analysis of the proposed training algorithm</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th colspan="2">Lines 5&#x007E;8 in Algorithm 1</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-458"><mml:math id="mml-ieqn-458"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-459"><mml:math id="mml-ieqn-459"><mml:mn>2</mml:mn><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-460"><mml:math id="mml-ieqn-460"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-461"><mml:math id="mml-ieqn-461"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-462"><mml:math id="mml-ieqn-462"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-463"><mml:math id="mml-ieqn-463"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td>Etc.</td>
<td><inline-formula id="ieqn-464"><mml:math id="mml-ieqn-464"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-465"><mml:math id="mml-ieqn-465"><mml:mn>5</mml:mn><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mo mathvariant="sans-serif" stretchy="false">(</mml:mo><mml:mo mathvariant="sans-serif" stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="2"><bold>Line 11 in Algorithm 1</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-466"><mml:math id="mml-ieqn-466"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-467"><mml:math id="mml-ieqn-467"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>u</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-468"><mml:math id="mml-ieqn-468"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-469"><mml:math id="mml-ieqn-469"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-470"><mml:math id="mml-ieqn-470"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-471"><mml:math id="mml-ieqn-471"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>u</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Etc.</td>
<td><inline-formula id="ieqn-472"><mml:math id="mml-ieqn-472"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-473"><mml:math id="mml-ieqn-473"><mml:mn>6</mml:mn><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="2"><bold>Line 12 in Algorithm 1</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-474"><mml:math id="mml-ieqn-474"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-475"><mml:math id="mml-ieqn-475"><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>u</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-476"><mml:math id="mml-ieqn-476"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-477"><mml:math id="mml-ieqn-477"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-478"><mml:math id="mml-ieqn-478"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-479"><mml:math id="mml-ieqn-479"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-480"><mml:math id="mml-ieqn-480"><mml:mn>2</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="2"><bold>Reconstructing model for efficient inference</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-481"><mml:math id="mml-ieqn-481"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-482"><mml:math id="mml-ieqn-482"><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-483"><mml:math id="mml-ieqn-483"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-484"><mml:math id="mml-ieqn-484"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>l</mml:mi><mml:mi>v</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-485"><mml:math id="mml-ieqn-485"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-486"><mml:math id="mml-ieqn-486"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>l</mml:mi><mml:mi>v</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-487"><mml:math id="mml-ieqn-487"><mml:mn>2</mml:mn></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Computation cost analysis of the training algorithm in [<xref ref-type="bibr" rid="ref-10">10</xref>]</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th colspan="4">Non-leaf node</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-488"><mml:math id="mml-ieqn-488"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-489"><mml:math id="mml-ieqn-489"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-490"><mml:math id="mml-ieqn-490"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>Depth</td>
</tr>
<tr>
<td><inline-formula id="ieqn-491"><mml:math id="mml-ieqn-491"><mml:mn>2</mml:mn><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msup><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-492"><mml:math id="mml-ieqn-492"><mml:mn>2</mml:mn><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msup><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-493"><mml:math id="mml-ieqn-493"><mml:mn>2</mml:mn><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-494"><mml:math id="mml-ieqn-494"><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="4"><bold>Leaf node</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-495"><mml:math id="mml-ieqn-495"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-496"><mml:math id="mml-ieqn-496"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-497"><mml:math id="mml-ieqn-497"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>Depth</td>
</tr>
<tr>
<td><inline-formula id="ieqn-498"><mml:math id="mml-ieqn-498"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-499"><mml:math id="mml-ieqn-499"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0</td>
<td>1</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The analysis of the computation complexity in [<xref ref-type="bibr" rid="ref-10">10</xref>] shows that for each non-leaf node, the training algorithm performs a total of <inline-formula id="ieqn-500"><mml:math id="mml-ieqn-500"><mml:mn>2</mml:mn><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula> homomorphic multiplications and the same number of additions. In addition, the algorithm invokes the <inline-formula id="ieqn-501"><mml:math id="mml-ieqn-501"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> function <inline-formula id="ieqn-502"><mml:math id="mml-ieqn-502"><mml:mn>2</mml:mn><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> times. Since each homomorphic operation is performed separately per sample, feature, and threshold, the total computational load scales quadratically with the number of features <inline-formula id="ieqn-503"><mml:math id="mml-ieqn-503"><mml:mi>d</mml:mi></mml:math></inline-formula> and linearly with the number of samples <inline-formula id="ieqn-504"><mml:math id="mml-ieqn-504"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:math></inline-formula> and class count <inline-formula id="ieqn-505"><mml:math id="mml-ieqn-505"><mml:mi>t</mml:mi></mml:math></inline-formula>. Furthermore, the multiplicative depth per node corresponds to the depth of <inline-formula id="ieqn-506"><mml:math id="mml-ieqn-506"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> plus one, which is approximately <inline-formula id="ieqn-507"><mml:math id="mml-ieqn-507"><mml:mn>5</mml:mn></mml:math></inline-formula> in practice.</p>
<p>In contrast, the HEaaN-ID3 training algorithm significantly reduces the number of operations by leveraging SIMD operation. As summarized in <xref ref-type="table" rid="table-7">Table 7</xref>, the number of multiplications per node is bounded by <inline-formula id="ieqn-508"><mml:math id="mml-ieqn-508"><mml:mn>2</mml:mn><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>u</mml:mi></mml:math></inline-formula>, which results in a total complexity of <inline-formula id="ieqn-509"><mml:math id="mml-ieqn-509"><mml:mrow><mml:mi>O</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>u</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Moreover, the number of <inline-formula id="ieqn-510"><mml:math id="mml-ieqn-510"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> invocations is limited to <inline-formula id="ieqn-511"><mml:math id="mml-ieqn-511"><mml:mrow><mml:mi>O</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mn>4</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> through the use of the <inline-formula id="ieqn-512"><mml:math id="mml-ieqn-512"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> subroutine. This may result in a slightly greater multiplicative depth compared to [<xref ref-type="bibr" rid="ref-10">10</xref>] as the number of features increases, the total number of high-cost nonlinear operations is substantially lower. Consequently, the proposed HEaaN-ID3 method provides a more efficient and scalable approach to privacy-preserving decision tree training, particularly in high-dimensional or large-sample scenarios.</p>

<p>The analysis of the usage frequency of each homomorphic operation and depth of multiplication in the inference method in [<xref ref-type="bibr" rid="ref-10">10</xref>] is straightforward. For all non-leaf nodes, this method executes the <inline-formula id="ieqn-513"><mml:math id="mml-ieqn-513"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> algorithm twice, multiplication twice and addition once. As a result, the total computation consists of <inline-formula id="ieqn-514"><mml:math id="mml-ieqn-514"><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula> runs of <inline-formula id="ieqn-515"><mml:math id="mml-ieqn-515"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and multiplication, and <inline-formula id="ieqn-516"><mml:math id="mml-ieqn-516"><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> runs of additions. In addition, the multiplication depth consumed by each node is the multiplication depth incurred during the execution of <inline-formula id="ieqn-517"><mml:math id="mml-ieqn-517"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> increased by one, and the width becomes <inline-formula id="ieqn-518"><mml:math id="mml-ieqn-518"><mml:msup><mml:mn>2</mml:mn><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mtext>width of&#xA0;</mml:mtext><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">g</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> if the node is located at level <inline-formula id="ieqn-519"><mml:math id="mml-ieqn-519"><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula> of the tree.</p>
<p>The analysis of the HEaaN-ID3 inference algorithm is presented in <xref ref-type="table" rid="table-9">Table 9</xref>. Since the inference process is performed level by level, the computation cost specified in <xref ref-type="table" rid="table-9">Table 9</xref> corresponds to a single level. To enable efficient inference, the information of the leaf nodes is precomputed during the training phase, so the inference process is carried out only up to the level preceding the depth. As shown in <xref ref-type="table" rid="table-9">Table 9</xref>, the computational cost of the inference process is determined by the value of <inline-formula id="ieqn-520"><mml:math id="mml-ieqn-520"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The dataset with the largest <inline-formula id="ieqn-521"><mml:math id="mml-ieqn-521"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> requires the longest inference time under the same tree depth. In contrast to [<xref ref-type="bibr" rid="ref-10">10</xref>], the number of required invocation for ApproxSign() is <inline-formula id="ieqn-522"><mml:math id="mml-ieqn-522"><mml:mn>0</mml:mn></mml:math></inline-formula>. This is replaced by an additional multiplication, which is linearly proportional to the depth. Also in terms of depth, ApproxSign() requires a multiplication operation depth of at least 4, so we can see that the proposed method is more favorable.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Computation cost analysis of HEaaN-ID3 inference algorithm</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th colspan="2">Parameters: <inline-formula id="ieqn-523"><mml:math id="mml-ieqn-523"><mml:mi mathvariant="bold-italic">N</mml:mi><mml:mi mathvariant="bold-italic">u</mml:mi><mml:msub><mml:mi mathvariant="bold-italic">m</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">n</mml:mi><mml:mi mathvariant="bold-italic">f</mml:mi></mml:mrow></mml:msub><mml:mo mathvariant="bold">=</mml:mo><mml:mo mathvariant="bold" fence="false" stretchy="false">&#x2308;</mml:mo><mml:mo mathvariant="bold" stretchy="false">(</mml:mo><mml:msubsup><mml:mi mathvariant="bold-italic">n</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">m</mml:mi><mml:mi mathvariant="bold-italic">a</mml:mi><mml:mi mathvariant="bold-italic">x</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">l</mml:mi><mml:mi mathvariant="bold-italic">v</mml:mi></mml:mrow></mml:msubsup><mml:mo mathvariant="bold">&#x2217;</mml:mo><mml:msub><mml:mi mathvariant="bold-italic">n</mml:mi><mml:mrow><mml:mi mathvariant="bold-italic">m</mml:mi><mml:mi mathvariant="bold-italic">a</mml:mi><mml:mi mathvariant="bold-italic">x</mml:mi></mml:mrow></mml:msub><mml:mo mathvariant="bold">&#x2217;</mml:mo><mml:mi mathvariant="bold-italic">d</mml:mi><mml:mo mathvariant="bold" stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi mathvariant="bold-italic">M</mml:mi><mml:mo mathvariant="bold" fence="false" stretchy="false">&#x2309;</mml:mo></mml:math></inline-formula></th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-524"><mml:math id="mml-ieqn-524"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-525"><mml:math id="mml-ieqn-525"><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-526"><mml:math id="mml-ieqn-526"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-527"><mml:math id="mml-ieqn-527"><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-528"><mml:math id="mml-ieqn-528"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-529"><mml:math id="mml-ieqn-529"><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>f</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-530"><mml:math id="mml-ieqn-530"><mml:mn>7</mml:mn></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s8_4">
<label>8.4</label>
<title>Scalability of the Proposed Method</title>
<p>As shown in <xref ref-type="table" rid="table-7">Tables 7</xref> and <xref ref-type="table" rid="table-9">9</xref>, when the number of features, the variety of categories, and the size of the dataset become very large, the proposed method requires a significant amount of computation. To overcome this, each data owner is encouraged to perform feature selection in advance, which would allow the proposed method to be executed more efficiently. However, pruning is difficult to apply to encrypted trees. Because the data remain encrypted and cannot be checked directly, optimization techniques such as pruning cannot be applied. As a result, the structure of the decision tree generated during training becomes fixed and can grow inefficiently. In particular, due to the characteristics of the HEaaN-ID3 training algorithm, each internal node generates up to <inline-formula id="ieqn-531"><mml:math id="mml-ieqn-531"><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> child nodes, corresponding to the maximum number of categories of the explanatory variable. Therefore, when the tree depth is <inline-formula id="ieqn-532"><mml:math id="mml-ieqn-532"><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula>, the total number of nodes is given by <inline-formula id="ieqn-533"><mml:math id="mml-ieqn-533"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. As the depth increases, the total number of nodes grows exponentially, which leads to the number of slots required for encrypted computation exceeding what a single ciphertext can handle. Consequently, multiple ciphertexts must be used, resulting in increased computational overhead. This structure negatively impacts the scalability of the system.</p>

<p>However, on the other hand, if the depth of the ID3 decision tree is not large, the proposed method can still enable efficient training and inference. According to [<xref ref-type="bibr" rid="ref-7">7</xref>], the ID3 algorithm typically stops splitting and creates a leaf node when any of the following three conditions are met:
<list list-type="bullet">
<list-item>
<p>There are no remaining attributes available for splitting.</p></list-item>
<list-item>
<p>All data at the current node belong to the same class.</p></list-item>
<list-item>
<p>The information gain is zero or below a certain threshold.</p></list-item>
</list></p>
<p>Since all of these conditions are determined based on the actual data values, they cannot be directly applied in an encrypted setting. Therefore, estimating the typical depth of an ID3 tree, or the number of nodes generally generated, in advance is valuable for analyzing the scalability of the proposed method.</p>
<p>To this end, we compared the datasets and resulting tree structures (i.e., total number of nodes) used in existing studies on privacy-preserving ID3 decision trees. For example, reference [<xref ref-type="bibr" rid="ref-37">37</xref>] used the UCI Car dataset (car100, car50, car25), which contains 6 attributes and a total of 1728 instances, and generated 407, 248, and 178 nodes, respectively. Although [<xref ref-type="bibr" rid="ref-7">7</xref>] is a study on traditional ID3, it also provides information on the number of nodes generated in the ID3 decision tree. In [<xref ref-type="bibr" rid="ref-7">7</xref>], a chess dataset with 49 attributes and 715 instances resulted in a tree with 150 nodes, and a similar number of nodes was observed for another dataset with 39 attributes and 551 instances. Our proposed method generates a significantly larger number of nodes even at lower depths, as shown in <xref ref-type="table" rid="table-6">Table 6</xref>. This demonstrates that the proposed approach can produce a sufficiently shallower ID3 decision tree without pruning, thereby maintaining practical classification performance without requiring excessive tree depth.</p>

<p>Moreover, HEaaN-ID3 does not need to consider scalability with respect to high-dimensional datasets. As previously discussed, the proposed method is capable of generating a sufficient number of nodes even at shallow tree depths, enabling effective learning without excessive branching or complex tree structures. One of the most common methods for representing categorical data numerically is one-hot encoding, which was also adopted in this study. However, as noted in [<xref ref-type="bibr" rid="ref-62">62</xref>], this approach assigns a separate dimension to each category value, causing the dimensionality of the input vector to grow rapidly as the number of categories increases. This results in increased model complexity, a larger number of training parameters, and a higher risk of overfitting. In particular, high-dimensional input often leads to sparse data representations, which are known to negatively affect both training efficiency and generalization performance. Therefore, the proposed method achieves both practical scalability and efficiency by avoiding unnecessary expansion of tree depth and input dimensionality while still maintaining strong classification performance.</p>
<p>The inference algorithm proposed in this paper has a computational complexity that depends on the depth of the tree, which is closely related to scalability. However, as previously discussed, compared to existing studies, the proposed HEaaN-ID3 was able to achieve sufficient classification performance by generating a large number of nodes even at relatively low depths, without requiring an excessively deep tree. Thanks to this structural characteristic, the number of leaf nodes required during the inference process is also limited. Therefore, the level of complexity presented in this paper is sufficient to ensure practical efficiency in real-world applications.</p>
<p>HEaaN-ID3 does not consider structural scalability in terms of the decision tree itself (i.e., excessive increases in tree depth) for the reasons previously discussed. However, scalability with respect to large-scale datasets must be addressed. In particular, when the number of rows in the training data exceeds the number of slots <inline-formula id="ieqn-534"><mml:math id="mml-ieqn-534"><mml:mi>M</mml:mi></mml:math></inline-formula> that a single ciphertext can hold, it becomes necessary to use multiple ciphertexts to process the data, which leads to increased computational complexity. To handle such cases, this paper presents a generalized training algorithm that accommodates scenarios where the dataset size <inline-formula id="ieqn-535"><mml:math id="mml-ieqn-535"><mml:msub><mml:mi>s</mml:mi><mml:mi>z</mml:mi></mml:msub><mml:mo>&gt;</mml:mo><mml:mi>M</mml:mi></mml:math></inline-formula>, and analyzes the corresponding computational complexity in <xref ref-type="table" rid="table-10">Table 10</xref>. This demonstrates that while HEaaN-ID3 limits structural expansion, it can effectively ensure scalability with respect to data size. Each process represents the complexity computed when training the entire tree, and the training complexity per single node can be obtained by dividing by the total number of nodes, given as <inline-formula id="ieqn-536"><mml:math id="mml-ieqn-536"><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Additionally, <inline-formula id="ieqn-537"><mml:math id="mml-ieqn-537"><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-538"><mml:math id="mml-ieqn-538"><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represent the number of ciphertexts required when using FindMaxGroupPos() and FindMinGroupPos() in Appendix A.1 of [<xref ref-type="bibr" rid="ref-60">60</xref>]. To use these two algorithms, each node requires <inline-formula id="ieqn-539"><mml:math id="mml-ieqn-539"><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mn>4</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>1.5</mml:mn></mml:math></inline-formula> slots. Since this process is performed per level, the number of ciphertext slots required to process one level is proportional to the number of nodes at that level. Therefore, the values of <inline-formula id="ieqn-540"><mml:math id="mml-ieqn-540"><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-541"><mml:math id="mml-ieqn-541"><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are given by <inline-formula id="ieqn-542"><mml:math id="mml-ieqn-542"><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mn>4</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>1.5</mml:mn><mml:mo>&#x2217;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo></mml:math></inline-formula>.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Computation cost analysis of the generalized training algorithm</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th colspan="2">Lines 5&#x007E;8 in Algorithm 1</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-543"><mml:math id="mml-ieqn-543"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-544"><mml:math id="mml-ieqn-544"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-545"><mml:math id="mml-ieqn-545"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-546"><mml:math id="mml-ieqn-546"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-547"><mml:math id="mml-ieqn-547"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-548"><mml:math id="mml-ieqn-548"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Etc.</td>
<td><inline-formula id="ieqn-549"><mml:math id="mml-ieqn-549"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-550"><mml:math id="mml-ieqn-550"><mml:mn>5</mml:mn><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">I</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">v</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mo mathvariant="sans-serif" stretchy="false">(</mml:mo><mml:mo mathvariant="sans-serif" stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">a</mml:mi><mml:mi mathvariant="sans-serif">x</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="2"><bold>Line 11 in Algorithm 1</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-551"><mml:math id="mml-ieqn-551"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-552"><mml:math id="mml-ieqn-552"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-553"><mml:math id="mml-ieqn-553"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-554"><mml:math id="mml-ieqn-554"><mml:mo stretchy="false">[</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>2</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-555"><mml:math id="mml-ieqn-555"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-556"><mml:math id="mml-ieqn-556"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2217;</mml:mo><mml:mi>N</mml:mi><mml:mi>u</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Etc.</td>
<td><inline-formula id="ieqn-557"><mml:math id="mml-ieqn-557"><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-558"><mml:math id="mml-ieqn-558"><mml:mn>6</mml:mn><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi><mml:mrow><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">e</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="sans-serif">F</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">i</mml:mi><mml:mi mathvariant="sans-serif">n</mml:mi><mml:mi mathvariant="sans-serif">G</mml:mi><mml:mi mathvariant="sans-serif">r</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">p</mml:mi><mml:mi mathvariant="sans-serif">P</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">s</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td colspan="2"><bold>Line 12 in Algorithm 1</bold></td>
</tr>
<tr>
<td><inline-formula id="ieqn-559"><mml:math id="mml-ieqn-559"><mml:mrow><mml:mi mathvariant="sans-serif">M</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">l</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-560"><mml:math id="mml-ieqn-560"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mi>N</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>M</mml:mi><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-561"><mml:math id="mml-ieqn-561"><mml:mrow><mml:mi mathvariant="sans-serif">R</mml:mi><mml:mi mathvariant="sans-serif">o</mml:mi><mml:mi mathvariant="sans-serif">t</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-562"><mml:math id="mml-ieqn-562"><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>d</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-563"><mml:math id="mml-ieqn-563"><mml:mrow><mml:mi mathvariant="sans-serif">A</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mi mathvariant="sans-serif">d</mml:mi><mml:mrow><mml:mo mathvariant="sans-serif">/</mml:mo></mml:mrow><mml:mi mathvariant="sans-serif">S</mml:mi><mml:mi mathvariant="sans-serif">u</mml:mi><mml:mi mathvariant="sans-serif">b</mml:mi></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-564"><mml:math id="mml-ieqn-564"><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>mul.depth</td>
<td><inline-formula id="ieqn-565"><mml:math id="mml-ieqn-565"><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>All operations in Lines 5&#x007E;8 of Algorithm 1 increase linearly with the number of target classes <inline-formula id="ieqn-566"><mml:math id="mml-ieqn-566"><mml:mi>t</mml:mi></mml:math></inline-formula> per node. However, the main factor that significantly increases the computational cost in this part is FindMaxGroupPos(). This algorithm is affected by the number of nodes at the corresponding level, <inline-formula id="ieqn-567"><mml:math id="mml-ieqn-567"><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, which causes the computational cost to grow exponentially. Similarly, the process in Line 11 of Algorithm 1 also uses the FindMinGroupPos() algorithm, and its cost increases exponentially due to its dependence on <inline-formula id="ieqn-568"><mml:math id="mml-ieqn-568"><mml:msup><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>. Additionally, since the processes in Line 11 and Line 12 of Algorithm 1 are not executed at the leaf nodes, they are only applied to the portion of the tree that excludes the leaf nodes. The complexity of the &#x201D;Reconstructing model for efficient inference&#x201D; process is the same as that in <xref ref-type="table" rid="table-7">Table 7</xref>, and thus it has been omitted.</p>

</sec>
<sec id="s8_5">
<label>8.5</label>
<title>Security Threat Analysis</title>
<p>In this study, we propose a homomorphic encryption&#x2014;based framework, HEaaN-ID3, and since all computations are performed on encrypted data, we believe that strong security satisfying the requirements of <xref ref-type="sec" rid="s4_3">Section 4.3</xref> can be achieved. However, because the focus of this work is on the implementation of HEaaN-ID3 itself, various existing defense strategies against threats such as malicious actors, model inversion attacks, data poisoning attacks, and side-channel attacks&#x2014;though they can also be realized under homomorphic encryption&#x2014;are excluded from the scope of this research. The studies proposing defense strategies for each of these attacks are described below.</p>
<p>First, malicious actors refer to entities that attempt to exploit system vulnerabilities to modify data, leak information, or maliciously manipulate model updates. In a typical environment, these threats can be countered by applying encryption and secure communication protocols (e.g., TLS) during data collection and transmission, as well as by employing input data validation and anomaly detection techniques. Moreover, in federated learning environments, the impact of malicious actors can be minimized using secure aggregation techniques [<xref ref-type="bibr" rid="ref-63">63</xref>] and Byzantine-tolerant gradient descent algorithms [<xref ref-type="bibr" rid="ref-64">64</xref>]. Additionally, if malicious actors perform side-channel attacks, there is a risk that auxiliary information&#x2014;such as memory access patterns, power consumption, or execution time&#x2014;generated during encryption computations could be exploited to leak encryption keys or internal states. To defend against this, techniques such as constant-time implementations, randomization of memory access patterns, cache partitioning, and the addition of random noise are employed. In particular, reference [<xref ref-type="bibr" rid="ref-65">65</xref>] demonstrated that these defensive measures can be effectively applied by using cache attacks on AES implementations as an example.</p>
<p>Second, model inversion attacks are techniques in which an attacker leverages the model&#x2019;s output information (e.g., prediction probabilities, confidence scores, etc.) to reverse-engineer sensitive information from the training data. Previous research has proposed methods to limit the exposure of sensitive information, such as injecting noise into the output [<xref ref-type="bibr" rid="ref-66">66</xref>] and applying softmax post-processing [<xref ref-type="bibr" rid="ref-67">67</xref>].</p>
<p>Finally, data poisoning attacks refer to attacks where maliciously manipulated data is inserted into the training dataset to distort the model&#x2019;s learning outcomes or induce specific behaviors. There are studies based on Differential Privacy (DP) that mitigate these attacks by adding noise during gradient computation [<xref ref-type="bibr" rid="ref-68">68</xref>] or performing gradient clipping [<xref ref-type="bibr" rid="ref-69">69</xref>] to limit the contribution of each data sample during training.</p>
</sec>
</sec>
<sec id="s9">
<label>9</label>
<title>Conclusion</title>
<p>In this study, we proposed HEaaN-ID3, a privacy-preserving ID3 DT using CKKS homomorphic encryption. The ID3 DT enables the training and classification of data consisting of nominal categorical variables, which is differentiated from the existing binary tree-based classification. This requires a comparison operation over input data. However, because the number of child nodes is equal to the number of categories of the variable selected for splitting, to the best of our knowledge, there has been no implementation using only homomorphic encryption owing to the high computational cost. HEaaN-ID3 can generate a model using only encrypted training data without the help of other decryption key-owning entities, and when encrypted input data are received based on this model, classification results can also be obtained without the help of other entities. To demonstrate the practicality of the proposed method, we conducted a performance evaluation after implementing the HEaaN-ID3. The results showed that the training time per node was a few tens of times faster than that in [<xref ref-type="bibr" rid="ref-10">10</xref>], and the required wall-clock time for classification was within a few hundred milliseconds. We also confirmed that the classification performance was similar to that of the plaintext DT implemented in the Scikit-Learn library. The proposed method can be utilized when decryption keys are difficult to use or when the security of the training data is very important; thus, no decryption of the training data or its derivation is mandatory.</p>
</sec>
</body>
<back>
<ack>
<p>The authors sincerely appreciate the editors and anonymous reviewers for their valuable comments and suggestions.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported by Institute of Information communications Technology Planning Evaluation (IITP) grant funded by the Korea government (MSIT) [No. 2022-0-01047, Development of statistical analysis algorithm and module using homomorphic encryption based on real number operation, 100%].</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: Conceptualization: Younho Lee; methodology: Dain Lee, Hojune Shin, Jihyeon Choi and Younho Lee; software: Dain Lee, Hojune Shin, Jihyeon Choi and Younho Lee; validation: Dain Lee, Hojune Shin, Jihyeon Choi and Younho Lee; writing&#x2014;original draft preparation: Dain Lee, Hojune Shin, Jihyeon Choi and Younho Lee; writing&#x2014;review and editing: Dain Lee, Hojune Shin, Jihyeon Choi and Younho Lee; project administration: Younho Lee; funding acquisition: Younho Lee. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Not applicable.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gao</surname> <given-names>S</given-names></string-name>, <string-name><surname>Iu</surname> <given-names>HHC</given-names></string-name>, <string-name><surname>Erkan</surname> <given-names>U</given-names></string-name>, <string-name><surname>Simsek</surname> <given-names>C</given-names></string-name>, <string-name><surname>Toktas</surname> <given-names>A</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>Y</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>A 3D memristive cubic map with dual discrete memristors: design, implementation, and application in image encryption</article-title>. <source>IEEE Trans Circuits Syst Video Technol</source>. <year>2025</year>. doi:<pub-id pub-id-type="doi">10.1109/tcsvt.2025.3545868</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>G</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>JW</given-names></string-name>, <string-name><surname>Shin</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>M-K</given-names></string-name></person-group>. <article-title>HETAL: efficient privacy-preserving transfer learning with homomorphic encryption</article-title>. In: <conf-name>Proceedings of the International Conference on Machine Learning (ICML); 2023 Jul 23&#x2013;29; Honolulu, HI, USA</conf-name>. p. <fpage>19010</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Seo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Nam</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chae</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name></person-group>. <article-title>HEaaN-STAT: a privacy-preserving statistical analysis toolkit for large-scale numerical, ordinal, and categorical data</article-title>. <source>IEEE Trans Dependable Secure Comput</source>. <year>2023</year>;<volume>21</volume>(<issue>3</issue>):<fpage>1224</fpage>&#x2013;<lpage>1241</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2023.3275649</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Gul</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Fully homomorphic encryption with applications to privacy-preserving machine learning; [bachelor&#x2019;s thesis], Cambridge, MA, USA: Harvard College</article-title>; <year>2023</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>D</given-names></string-name>, <string-name><surname>Guyot</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Optimized privacy-preserving CNN inference with fully homomorphic encryption</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2023</year>;<volume>18</volume>(<issue>11</issue>):<fpage>2175</fpage>&#x2013;<lpage>87</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2023.3263631</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yazdinejad</surname> <given-names>A</given-names></string-name>, <string-name><surname>Dehghantanha</surname> <given-names>A</given-names></string-name>, <string-name><surname>Karimipour</surname> <given-names>H</given-names></string-name>, <string-name><surname>Srivastava</surname> <given-names>G</given-names></string-name>, <string-name><surname>Parizi</surname> <given-names>RM</given-names></string-name></person-group>. <article-title>A robust privacy-preserving federated learning model against model poisoning attacks</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2024</year>;<volume>19</volume>:<fpage>6693</fpage>&#x2013;<lpage>6708</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2024.3420126</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Quinlan</surname> <given-names>JR</given-names></string-name></person-group>. <article-title>Induction of decision trees</article-title>. <source>Mach Learn</source>. <year>1986</year>;<volume>1</volume>(<issue>1</issue>):<fpage>81</fpage>&#x2013;<lpage>106</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Song</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Homomorphic encryption for arithmetic of approximate numbers</article-title>. In: <conf-name>International Conference on the Theory and Application of Cryptology and Information Security</conf-name>; <year>2017 Dec 3&#x2013;7</year>; <publisher-loc>Hong Kong, China</publisher-loc>. p. <fpage>409</fpage>&#x2013;<lpage>37</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>R</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Su</surname> <given-names>J</given-names></string-name>, <string-name><surname>Qiao</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Towards practical privacy-preserving decision tree training and evaluation in the cloud</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2020</year>;<volume>15</volume>:<fpage>2914</fpage>&#x2013;<lpage>29</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2020.2980192</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Akavia</surname> <given-names>A</given-names></string-name>, <string-name><surname>Leibovich</surname> <given-names>M</given-names></string-name>, <string-name><surname>Resheff</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Ron</surname> <given-names>R</given-names></string-name>, <string-name><surname>Shahar</surname> <given-names>M</given-names></string-name>, <string-name><surname>Vald</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Privacy-preserving decision trees training and prediction</article-title>. <source>ACM Trans Priv Secur</source>. <year>2022</year>;<volume>25</volume>(<issue>3</issue>):<fpage>1</fpage>&#x2013;<lpage>30</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3517197</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>B&#x0103;dulescu</surname> <given-names>LA</given-names></string-name></person-group>. <article-title>Experiments for a better Gini index splitting criterion for data mining decision trees algorithms</article-title>. In: <conf-name>2020 24th International Conference on System Theory, Control and Computing (ICSTCC)</conf-name>; <year>2020 Oct 8&#x2013;10</year>; <publisher-loc>Sinaia, Romania</publisher-loc>. p. <fpage>208</fpage>&#x2013;<lpage>12</lpage>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>D</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Efficient homomorphic comparison methods with optimal complexity</article-title>. In: <conf-name>International Conference on the Theory and Application of Cryptology and Information Security</conf-name>; <year>2020 Dec 7&#x2013;11</year>; <publisher-loc>Daejeon, Republic of Korea</publisher-loc>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Markelle Kelly KN Rachel Longjohn</collab></person-group>. <article-title>The UCI machine learning repository [Internet]</article-title>; <year>2023</year> <comment>[cited 2025 Apr 28]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://archive.ics.uci.edu">https://archive.ics.uci.edu</ext-link>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pedregosa</surname> <given-names>F</given-names></string-name>, <string-name><surname>Varoquaux</surname> <given-names>G</given-names></string-name>, <string-name><surname>Gramfort</surname> <given-names>A</given-names></string-name>, <string-name><surname>Michel</surname> <given-names>V</given-names></string-name>, <string-name><surname>Thirion</surname> <given-names>B</given-names></string-name>, <string-name><surname>Grisel</surname> <given-names>O</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Scikit-learn: machine learning in Python</article-title>. <source>J Mach Learn Res</source>. <year>2011</year>;<volume>12</volume>:<fpage>2825</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Barni</surname> <given-names>M</given-names></string-name>, <string-name><surname>Failla</surname> <given-names>P</given-names></string-name>, <string-name><surname>Kolesnikov</surname> <given-names>V</given-names></string-name>, <string-name><surname>Lazzeretti</surname> <given-names>R</given-names></string-name>, <string-name><surname>Sadeghi</surname> <given-names>AR</given-names></string-name>, <string-name><surname>Schneider</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Secure evaluation of private linear branching programs with medical applications</article-title>. In: <conf-name>Computer Security&#x2014;ESORICS 2009: 14th European Symposium on Research in Computer Security</conf-name>; <year>2009 Sep 21&#x2013;23</year>; <publisher-loc>Saint-Malo, France</publisher-loc>. p. <fpage>424</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bost</surname> <given-names>R</given-names></string-name>, <string-name><surname>Popa</surname> <given-names>RA</given-names></string-name>, <string-name><surname>Tu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Goldwasser</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Machine learning classification over encrypted data</article-title>. In: <conf-name>NDSS Symposium 2015; 2015 Feb 8&#x2013;11; San Diego, CA, USA</conf-name>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Brickell</surname> <given-names>J</given-names></string-name>, <string-name><surname>Porter</surname> <given-names>DE</given-names></string-name>, <string-name><surname>Shmatikov</surname> <given-names>V</given-names></string-name>, <string-name><surname>Witchel</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Privacy-preserving remote diagnostics</article-title>. In: <conf-name>Proceedings of the 14th ACM Conference on Computer and Communications Security</conf-name>; <year>2007 Nov 2&#x2013;Oct 31</year>; <publisher-loc>Alexandria VA, USA</publisher-loc>. p. <fpage>498</fpage>&#x2013;<lpage>507</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>De Cock</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dowsley</surname> <given-names>R</given-names></string-name>, <string-name><surname>Horst</surname> <given-names>C</given-names></string-name>, <string-name><surname>Katti</surname> <given-names>R</given-names></string-name>, <string-name><surname>Nascimento</surname> <given-names>AC</given-names></string-name>, <string-name><surname>Poon</surname> <given-names>WS</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Efficient and private scoring of decision trees, support vector machines and logistic regression models based on pre-computation</article-title>. <source>IEEE Trans Dependable Secure Comput</source>. <year>2017</year>;<volume>16</volume>(<issue>2</issue>):<fpage>217</fpage>&#x2013;<lpage>30</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2017.2679189</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Joye</surname> <given-names>M</given-names></string-name>, <string-name><surname>Salehi</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Private yet efficient decision tree evaluation</article-title>. In: <conf-name>Data and Applications Security and Privacy XXXII: 32nd Annual IFIP WG 11.3 Conference, DBSec 2018</conf-name>; <year>2018 Jul 16&#x2013;18</year>; <publisher-loc>Bergamo, Italy</publisher-loc>. p. <fpage>243</fpage>&#x2013;<lpage>59</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>De Hoogh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Schoenmakers</surname> <given-names>B</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>P</given-names></string-name>, <string-name><surname>op den Akker</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Practical secure decision tree learning in a teletreatment application</article-title>. In: <conf-name>Financial Cryptography and Data Security: 18th International Conference, FC 2014</conf-name>; <publisher-loc>Christ Church,
Barbados</publisher-loc>; <year>2014 Mar 3&#x2013;7</year>. p. <fpage>179</fpage>&#x2013;<lpage>94</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Du</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhan</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Building decision tree classifier on private data</article-title>. In: <conf-name>CRPIT &#x2019;14: Proceedings of the IEEE International Conference on Privacy, Security and Data Mining</conf-name>; <year>2002 Dec 1</year>; <publisher-loc>Maebashi City, Japan</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Emek&#x00E7;i</surname> <given-names>F</given-names></string-name>, <string-name><surname>Sahin</surname> <given-names>OD</given-names></string-name>, <string-name><surname>Agrawal</surname> <given-names>D</given-names></string-name>, <string-name><surname>El Abbadi</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Privacy preserving decision tree learning over multiple parties</article-title>. <source>Data Knowl Eng</source>. <year>2007</year>;<volume>63</volume>(<issue>2</issue>):<fpage>348</fpage>&#x2013;<lpage>61</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Agrawal</surname> <given-names>R</given-names></string-name>, <string-name><surname>Srikant</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Privacy-preserving data mining</article-title>. In: <conf-name>Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data</conf-name>; <year>2000 May 15&#x2013;18</year>; <publisher-loc>Dallas, TX, USA</publisher-loc>. p. <fpage>439</fpage>&#x2013;<lpage>50</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lory</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Enhancing the efficiency in privacy preserving learning of decision trees in partitioned databases</article-title>. In: <conf-name>Privacy in Statistical Databases: UNESCO Chair in Data Privacy, International Conference, PSD 2012</conf-name>; <year>2012 Sep 26&#x2013;28</year>; <publisher-loc>Palermo, Italy</publisher-loc>. p. <fpage>322</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>ZL</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yiu</surname> <given-names>SM</given-names></string-name></person-group>. <article-title>Privacy-preserving ID3 data mining over encrypted data in outsourced environments with multiple keys</article-title>. In: <conf-name>2017 IEEE International Conference on Computational Science and Engineering (CSE) and IEEE International Conference on Embedded and Ubiquitous Computing (EUC)</conf-name>; <year>2017 Jul 21&#x2013;24</year>; <publisher-loc>Guangzhou, China</publisher-loc>. p. <fpage>548</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Qin</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Xue</surname> <given-names>L</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>X</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Efficient and privacy-preserving decision tree classification for health monitoring systems</article-title>. <source>IEEE Internet Things J</source>. <year>2021</year>;<volume>8</volume>(<issue>16</issue>):<fpage>12528</fpage>&#x2013;<lpage>39</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2021.3066307</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Duan</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>R</given-names></string-name>, <string-name><surname>Nepal</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Securely and efficiently outsourcing decision tree inference</article-title>. <source>IEEE Trans Dependable Secure Comput</source>. <year>2022</year>;<volume>19</volume>(<issue>3</issue>):<fpage>1841</fpage>&#x2013;<lpage>55</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2020.3040012</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cong</surname> <given-names>K</given-names></string-name>, <string-name><surname>Das</surname> <given-names>D</given-names></string-name>, <string-name><surname>Park</surname> <given-names>J</given-names></string-name>, <string-name><surname>Pereira</surname> <given-names>HV</given-names></string-name></person-group>. <article-title>SortingHat: efficient private decision tree evaluation via homomorphic encryption and transciphering</article-title>. In: <conf-name>Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security</conf-name>; <year>2022 Nov 7&#x2013;11</year>; <publisher-loc>Los Angeles, CA, USA</publisher-loc>. p. <fpage>563</fpage>&#x2013;<lpage>77</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Song</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name></person-group>. <article-title>Secure searching of biomarkers through hybrid homomorphic encryption scheme</article-title>. <source>BMC Med Genomics</source>. <year>2017</year>;<volume>10</volume>(<issue>2</issue>):<fpage>69</fpage>&#x2013;<lpage>76</lpage>. doi:<pub-id pub-id-type="doi">10.1186/s12920-017-0280-3</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>P</given-names></string-name>, <string-name><surname>Jo</surname> <given-names>E</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>An efficient search algorithm for large encrypted data by homomorphic encryption</article-title>. <source>Electron</source>. <year>2021</year>;<volume>10</volume>(<issue>4</issue>):<fpage>484</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics10040484</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Azogagh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Delfour</surname> <given-names>V</given-names></string-name>, <string-name><surname>Gambs</surname> <given-names>S</given-names></string-name>, <string-name><surname>Killijian</surname> <given-names>MO</given-names></string-name></person-group>. <article-title>PROBONITE: private one-branch-only non-interactive decision tree evaluation</article-title>. In: <conf-name>Proceedings of the 10th Workshop on Encrypted Computing &#x0026; Applied Homomorphic Cryptography. WAHC&#x2019;22</conf-name>; <year>2022 Nov 7</year>; <publisher-loc>Los Angeles, CA, USA</publisher-loc>. p. <fpage>23</fpage>&#x2013;<lpage>33</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3560827.3563377</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cheng</surname> <given-names>N</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>N</given-names></string-name>, <string-name><surname>Mitrokotsa</surname> <given-names>A</given-names></string-name>, <string-name><surname>Morita</surname> <given-names>H</given-names></string-name>, <string-name><surname>Tozawa</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Constant-round private decision tree evaluation for secret shared data</article-title>. <source>Proc Priv Enhanc Technol</source>. <year>2024</year>;<volume>2024</volume>(<issue>1</issue>):<fpage>397</fpage>&#x2013;<lpage>412</lpage>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Song</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>EC</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Mostree: malicious secure private decision tree evaluation with sublinear communication</article-title>. In: <conf-name>Proceedings of the 39th Annual Computer Security Applications Conference</conf-name>; <year>2023 Dec 4&#x2013;8</year>; <publisher-loc>Austin, TX, USA</publisher-loc>. p. <fpage>799</fpage>&#x2013;<lpage>813</lpage>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ji</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>T</given-names></string-name>, <string-name><surname>Li</surname> <given-names>L</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>K</given-names></string-name></person-group>. <article-title>UC secure private branching program and decision tree evaluation</article-title>. <source>IEEE Trans Dependable Secure Comput</source>. <year>2022</year>;<volume>20</volume>(<issue>4</issue>):<fpage>2836</fpage>&#x2013;<lpage>48</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2022.3202916</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Song</surname> <given-names>X</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kong</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Secure outsourcing evaluation for sparse decision trees</article-title>. <source>IEEE Trans Dependable Secure Comput</source>. <year>2024</year>;<volume>21</volume>(<issue>6</issue>):<fpage>5228</fpage>&#x2013;<lpage>5241</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2024.3372505</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Bai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Koh</surname> <given-names>YS</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>GTree: GPU-friendly privacy-preserving decision tree training and inference</article-title>. <comment>arXiv:230500645. 2023</comment>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vaidya</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kantarc&#x0131;o&#x011F;lu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Clifton</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Privacy-preserving naive bayes classification</article-title>. <source>VLDB J</source>. <year>2008</year>;<volume>17</volume>(<issue>4</issue>):<fpage>879</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00778-006-0041-y</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>She</surname> <given-names>R</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>PS</given-names></string-name></person-group>. <article-title>Classification spanning private databases</article-title>. In: <conf-name>AAAI&#x2019;06: Proceedings of the 21st National Conference on Artificial Intelligence</conf-name>; <year>2006 Jul 16&#x2013;20</year>; <publisher-loc>Boston, MA, USA</publisher-loc>. p. <fpage>293</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>ZL</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Fang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>E</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Securely outsourcing ID3 decision tree in cloud computing</article-title>. <source>Wirel Commun Mob Comput</source>. <year>2018</year>;<volume>2018</volume>:<fpage>2385150</fpage>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>ZL</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yiu</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Outsourcing privacy preserving ID3 decision tree algorithm over encrypted data-sets for two-parties</article-title>. In: <conf-name>2017 IEEE Trustcom/BigDataSE/ICESS</conf-name>; <year>2017 Aug 1&#x2013;4</year>; <publisher-loc>Sydney, NSW, Australia</publisher-loc>. p. <fpage>1070</fpage>&#x2013;<lpage>5</lpage>. doi:<pub-id pub-id-type="doi">10.1109/trustcom/bigdatase/icess.2017.354</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Samet</surname> <given-names>S</given-names></string-name>, <string-name><surname>Miri</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Privacy preserving ID3 using Gini index over horizontally partitioned data</article-title>. In: <conf-name>2008 IEEE/ACS International Conference on Computer Systems and Applications</conf-name>; <year>2008 Mar 31&#x2013;Apr 4</year>; <publisher-loc>Doha, Qatar</publisher-loc>. p. <fpage>645</fpage>&#x2013;<lpage>51</lpage>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Xiao</surname> <given-names>MJ</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>LS</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>YL</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Privacy preserving ID3 algorithm over horizontally partitioned data</article-title>. In: <conf-name>Sixth International Conference on Parallel and Distributed Computing Applications and Technologies (PDCAT&#x2019;05)</conf-name>; <year>2005 Dec 5&#x2013;8</year>; <publisher-loc>Dalian, China</publisher-loc>. p. <fpage>239</fpage>&#x2013;<lpage>43</lpage>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kiss</surname> <given-names>&#x00C1;</given-names></string-name>, <string-name><surname>Naderpour</surname> <given-names>M</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Asokan</surname> <given-names>N</given-names></string-name>, <string-name><surname>Schneider</surname> <given-names>T</given-names></string-name></person-group>. <article-title>SoK: modular and efficient private decision tree evaluation</article-title>. <source>Proc Priv Enh Technol</source>. <year>2019</year>;<volume>2019</volume>(<issue>2</issue>):<fpage>187</fpage>&#x2013;<lpage>208</lpage>. doi:<pub-id pub-id-type="doi">10.2478/popets-2019-0026</pub-id>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Tai</surname> <given-names>RK</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>JP</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chow</surname> <given-names>SS</given-names></string-name></person-group>. <article-title>Privacy-preserving decision trees evaluation via linear functions</article-title>. In: <conf-name>Computer Security&#x2013;ESORICS 2017: 22nd European Symposium on Research in Computer Security</conf-name>; <year>2017 Sep 11&#x2013;15</year>; <publisher-loc>Oslo, Norway</publisher-loc>. p. <fpage>494</fpage>&#x2013;<lpage>512</lpage>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>DJ</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>T</given-names></string-name>, <string-name><surname>Naehrig</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lauter</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Privately evaluating decision trees and random forests</article-title>. <source>Proc Priv Enh Technol</source>. <year>2016</year>;<volume>4</volume>(<issue>4</issue>):<fpage>335</fpage>&#x2013;<lpage>55</lpage>. doi:<pub-id pub-id-type="doi">10.1515/popets-2016-0043</pub-id>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tueno</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kerschbaum</surname> <given-names>F</given-names></string-name>, <string-name><surname>Katzenbeisser</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Private evaluation of decision trees using sublinear cost</article-title>. <source>Proc Priv Enh Technol</source>. <year>2019</year>;<volume>2019</volume>(<issue>1</issue>):<fpage>266</fpage>&#x2013;<lpage>86</lpage>. doi:<pub-id pub-id-type="doi">10.2478/popets-2019-0015</pub-id>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wj</surname> <given-names>Lu</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>JJ</given-names></string-name>, <string-name><surname>Sakuma</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Non-interactive and output expressive private comparison from homomorphic encryption</article-title>. In: <conf-name>Proceedings of the 2018 on Asia Conference on Computer and Communications Security; 2018 Jun 4; Incheon, Republic of Korea</conf-name>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Tueno</surname> <given-names>A</given-names></string-name>, <string-name><surname>Boev</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Kerschbaum</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Non-interactive private decision tree evaluation</article-title>. In: <conf-name>Data and Applications Security and Privacy XXXIV: 34th Annual IFIP WG 11.3 Conference, DBSec 2020</conf-name>; <year>Jun 25&#x2013;26</year>; <publisher-loc>Regensburg, Germany</publisher-loc>. p. <fpage>174</fpage>&#x2013;<lpage>94</lpage>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huysmans</surname> <given-names>J</given-names></string-name>, <string-name><surname>Dejaeger</surname> <given-names>K</given-names></string-name>, <string-name><surname>Mues</surname> <given-names>C</given-names></string-name>, <string-name><surname>Vanthienen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Baesens</surname> <given-names>B</given-names></string-name></person-group>. <article-title>An empirical evaluation of the comprehensibility of decision table, tree and rule based predictive models</article-title>. <source>Decis Support Syst</source>. <year>2011</year>;<volume>51</volume>(<issue>1</issue>):<fpage>141</fpage>&#x2013;<lpage>54</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.dss.2010.12.003</pub-id>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Quinlan</surname> <given-names>JR</given-names></string-name></person-group>. <source>C4.5: programs for machine learning</source>. <publisher-loc>San Francisco, CA, USA</publisher-loc>: <publisher-name>Morgan Kaufmann Publishers Inc</publisher-name>; <year>1993</year>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Quinlan</surname> <given-names>JR</given-names></string-name></person-group>. <article-title>Improved use of continuous attributes in C4.5</article-title>. <source>J Artif Intell</source>. <year>1996</year>;<volume>4</volume>:<fpage>77</fpage>&#x2013;<lpage>90</lpage>. doi:<pub-id pub-id-type="doi">10.1613/jair.279</pub-id>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Breiman</surname> <given-names>L</given-names></string-name>, <string-name><surname>Friedman</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Olshen</surname> <given-names>RA</given-names></string-name>, <string-name><surname>Stone</surname> <given-names>CJ</given-names></string-name></person-group>. <source>Classification and regression trees</source>. <publisher-loc>London, UK</publisher-loc>: <publisher-name>Routledge</publisher-name>; <year>2017</year>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Shafer</surname> <given-names>J</given-names></string-name>, <string-name><surname>Agrawal</surname> <given-names>R</given-names></string-name>, <string-name><surname>Mehta</surname> <given-names>M</given-names></string-name></person-group>. <article-title>SPRINT: a scalable parallel classifier for data mining</article-title>. In: <conf-name>VLDB &#x2019;96: Proceedings of the 22th International Conference on Very Large Data Bases</conf-name>; <year>1996 Sep 3&#x2013;6</year>; <publisher-loc>Mumbai, India</publisher-loc>. p. <fpage>544</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Delgado-Bonal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Marshak</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Approximate entropy and sample entropy: a comprehensive tutorial</article-title>. <source>Entropy</source>. <year>2019</year>;<volume>21</volume>(<issue>6</issue>):<fpage>541</fpage>. doi:<pub-id pub-id-type="doi">10.3390/e21060541</pub-id>; <pub-id pub-id-type="pmid">33267255</pub-id></mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jung</surname> <given-names>W</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ahn</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Over 100x faster bootstrapping in fully homomorphic encryption through memory-centric optimization with GPUs</article-title>. <source>IACR Trans Cryptogr Hardw Embed Syst</source>. <year>2021</year>;<volume>2021</volume>(<issue>4</issue>):<fpage>114</fpage>&#x2013;<lpage>48</lpage>. doi:<pub-id pub-id-type="doi">10.46586/tches.v2021.i4.114-148</pub-id>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Han</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ki</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Better bootstrapping for approximate homomorphic encryption</article-title>. In: <conf-name>Cryptographers&#x2019; Track at the RSA Conference</conf-name>; <year>2020 Feb 24&#x2013;28</year>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>364</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Han</surname> <given-names>K</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Song</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A full RNS variant of approximate homomorphic encryption</article-title>. In: <conf-name>International Conference on Selected Areas in Cryptography</conf-name>; <year>2018 Aug 15&#x2013;17</year>; <publisher-loc>Calgary, AB, Canada</publisher-loc>. p. <fpage>347</fpage>&#x2013;<lpage>68</lpage>.</mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>JW</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>E</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>YS</given-names></string-name>, <string-name><surname>No</surname> <given-names>JS</given-names></string-name></person-group>. <article-title>High-precision bootstrapping of RNS-CKKS homomorphic encryption using optimal minimax polynomial approximation and inverse sine function</article-title>. In: <conf-name>Annual International Conference on the Theory and Applications of Cryptographic Techniques</conf-name>; <year>2021 Oct 17&#x2013;21</year>; <publisher-loc>Zagreb, Croatia</publisher-loc>. p. <fpage>618</fpage>&#x2013;<lpage>47</lpage>.</mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Han</surname> <given-names>B</given-names></string-name>, <string-name><surname>Shin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Choi</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>HEaaN-NB: non-interactive privacy-preserving Naive Bayes using CKKS for secure outsourced cloud computing</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>(<issue>196</issue>):<fpage>110762</fpage>&#x2013;<lpage>80</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2024.3438161</pub-id>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Shin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Choi</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>D</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Fully homomorphic training and inference on binary decision tree and random forest</article-title>. In: <conf-name>Computer Security&#x2014;ESORICS 2024: 29th European Symposium on Research in Computer Security; 2024 Sep 16&#x2013;20; Bydgoszcz, Poland</conf-name>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Cheon</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Hong</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Remark on the security of ckks scheme in practice</article-title>. <source>Cryptology EPrint Archive</source>. <comment>[cited 2025 May 22]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://eprint.iacr.org/2020/1581">https://eprint.iacr.org/2020/1581</ext-link>.</mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Micci-Barreca</surname> <given-names>D</given-names></string-name></person-group>. <article-title>A preprocessing scheme for high-cardinality categorical attributes in classification and prediction problems</article-title>. <source>ACM SIGKDD Explor Newsletter</source>. <year>2001</year>;<volume>3</volume>(<issue>1</issue>):<fpage>27</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1145/507533.507538</pub-id>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Blanchard</surname> <given-names>P</given-names></string-name>, <string-name><surname>El Mhamdi</surname> <given-names>EM</given-names></string-name>, <string-name><surname>Guerraoui</surname> <given-names>R</given-names></string-name>, <string-name><surname>Stainer</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Machine learning with adversaries: byzantine tolerant gradient descent</article-title>. <source>Adv Neural Inf Process Syst</source>. <year>2017</year>;<volume>30</volume>:<fpage>119</fpage>&#x2013;<lpage>29</lpage>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Yin</surname> <given-names>D</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Kannan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Bartlett</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Byzantine-robust distributed learning: towards optimal statistical rates</article-title>. In: <conf-name>International Conference on Machine Learning</conf-name>; <year>2018 Jul 10&#x2013;15</year>; <publisher-loc>Stockholm, Sweden</publisher-loc>. p. <fpage>5650</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Osvik</surname> <given-names>DA</given-names></string-name>, <string-name><surname>Shamir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Tromer</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Cache attacks and countermeasures: the case of AES</article-title>. In: <conf-name>Topics in Cryptology&#x2013;CT-RSA 2006: The Cryptographers&#x2019; Track at the RSA Conference 2006</conf-name>; <year>2005 Feb 13&#x2013;17</year>; <publisher-loc>San Jose, CA, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>20</lpage>.</mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Fredrikson</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jha</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ristenpart</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Model inversion attacks that exploit confidence information and basic countermeasures</article-title>. In: <conf-name>Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security</conf-name>; <year>2015 Oct 12&#x2013;16</year>; <publisher-loc>Denver, CO, USA</publisher-loc>. p. <fpage>1322</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Nasr</surname> <given-names>M</given-names></string-name>, <string-name><surname>Shokri</surname> <given-names>R</given-names></string-name>, <string-name><surname>Houmansadr</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning</article-title>. In: <conf-name>2019 IEEE Symposium on Security and Privacy (SP)</conf-name>; <year>2019 May 19&#x2013;23</year>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>739</fpage>&#x2013;<lpage>53</lpage>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Abadi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chu</surname> <given-names>A</given-names></string-name>, <string-name><surname>Goodfellow</surname> <given-names>I</given-names></string-name>, <string-name><surname>McMahan</surname> <given-names>HB</given-names></string-name>, <string-name><surname>Mironov</surname> <given-names>I</given-names></string-name>, <string-name><surname>Talwar</surname> <given-names>K</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Deep learning with differential privacy</article-title>. In: <conf-name>Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security</conf-name>; <year>2016 Oct 24&#x2013;28</year>; <publisher-loc>Vienna, Austria</publisher-loc>. p. <fpage>308</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Steinhardt</surname> <given-names>J</given-names></string-name>, <string-name><surname>Koh</surname> <given-names>PWW</given-names></string-name>, <string-name><surname>Liang</surname> <given-names>PS</given-names></string-name></person-group>. <article-title>Certified defenses for data poisoning attacks</article-title>. <source>Adv Neural Inf Process Syst</source>. <year>2017</year>;<volume>30</volume>:<fpage>3517</fpage>&#x2013;<lpage>29</lpage>.</mixed-citation></ref>
</ref-list>
</back></article>