Skip to content

Updates to v1.6.1 - #1367

Merged
dsuponitskiy merged 2 commits into
mainfrom
dev
Oct 9, 2026
Merged

dsuponitskiy merged 2 commits into
mainfrom
dev

Conversation

@yspolyakov

Copy link
Copy Markdown
Contributor

No description provided.

yspolyakov and others added 2 commits October 6, 2026 16:53
#1365)

* Fold the uniform-secret overflow bound K into the CoeffsToSlots matrix

Single-iteration CKKS bootstrapping with a UNIFORM_TERNARY secret produced
wrong values (absolute error ~0.3, Decode throwing) for a 50-bit scaling
factor with a 60-bit first modulus, for FLEXIBLEAUTO and FIXEDAUTO alike.

After the modulus raise, the ciphertext was multiplied by the scalar
2^-deg/(K*N). The 64-bit constant encoder keeps only
log2(scalingFactor) - log2(K*N) - deg bits of a constant that small (about
19 bits at a 50-bit scaling factor), and the relative error is amplified by
the integer overflow of the raised message and by 2^correctionFactor. With
K = 512 the scalar was an exact power of two, so the truncation only became
visible once K was raised to 648.

K is now folded into the CoeffsToSlots matrix at setup, as it already was for
the sparse secret distributions and for functional bootstrapping, and the
runtime scalar is the exact power of two 2^-deg/N. The same change is applied
to the StC-first variant and to FE functional bootstrapping, which used the
same runtime scalar. Measured precision matches the K = 512 version.

A new UTCKKSRNS_BOOT row (uniform secret, FLEXIBLEAUTO, 50-bit scaling
factor, level budget {3, 3}, 8 slots) fails without the fix and passes with it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Throw on bootstrapping with a precomputation from another variant

Regular, FBT and FEFBT setups fold different overflow bounds K into the CoeffsToSlots matrix, so
sharing precomputations across variants gives wrong results. Tag the precomputation with its setup
and check the tag at runtime.

* Fix wrong transform in EvalBootstrapPrecompute for COMPLEX

Match the pair-matrix condition of EvalBootstrapSetup and drop a duplicate m_U0Pre computation.
Added a serialization test for this path.

* Move the duplicated overflow-bound switch into GetModRaiseOverflowBound. Also remove the dead k variable from the eval functions and fix the "~19 bits" comment.

---------

Co-authored-by: Yuriy Polyakov <ypolyakod@dualitytech.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Dmitriy Suponitskiy <dsuponitskiy@dualitytech.com>
Co-authored-by: Yuriy Polyakov <ypolyakod@dualitytech.com>
@yspolyakov yspolyakov added this to the Release 1.6.1 milestone Oct 9, 2026
@yspolyakov yspolyakov added the new release new release label Oct 9, 2026
@dsuponitskiy
dsuponitskiy merged commit b59e1f2 into main Oct 9, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new release new release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants