Skip to main content

HEIR: Homomorphic Encryption Intermediate Representation

GitHub Workflow Status (with event) GitHub Contributors GitHub Discussions GitHub License OpenSSF Scorecard

An MLIR-based toolchain for homomorphic encryption compilers. Read the docs at the HEIR website.

For more information on MLIR, see the MLIR homepage.

Quickstart (Python)

Pip install the heir_py package

pip install heir_py

Then run an example:

from heir import compile
from heir.mlir import I64, Secret

@compile()  # defaults to scheme="bgv", OpenFHE backend, and debug=False
def func(x: Secret[I64], y: Secret[I64]):
    sum = x + y
    diff = x - y
    mul = x * y
    expression = sum * diff + mul
    deadcode = expression * mul
    return expression

func.setup()
enc_x = func.encrypt_x(7)
enc_y = func.encrypt_y(8)
result_enc = func.eval(enc_x, enc_y)
result = func.decrypt_result(result_enc)

print(
  f"Expected result for `func`: {func.original(7,8)}, FHE result:"
  f" {result}"
)

This will compile the function above using the BGV scheme to machine code via the OpenFHE backend. Then calling the function will encrypt the inputs, run the function, and return the decrypted result. The function call foo(7, 8) runs the entire encrypt-run-decrypt flow for ease of testing.

Building from source

This project uses bazel for its build system. Install bazelisk to manage the bazel version automatically. Then, with bazel on your path (pointing to bazelisk), run the following to build the main pass-running tool.

bazel build //tools:heir-opt

Or run an end-to-end test like

bazel test //tests/Examples/openfhe/ckks/halevi_shoup_matvec:all

HEIR depends on LLVM (from source) so a clean build may take 30 minutes depending on your machine. For faster builds, use BuildBuddy. Sign up for an account, create an API key, and add the following to .bazelrc.user in the root of the HEIR workspace:

common --remote_header=x-buildbuddy-api-key=<YOUR_API_KEY>
common --config=remote

This should reduce a clean build time to about 5 minutes.

See the bazel tips page for more example commands and tips on using bazel.

Supported backends and schemes

Backend Library BGV BFV CKKS CGGI
OpenFHE
Lattigo
tfhe-rs
Jaxite

Note some backends do not support all schemes.

Contributing

There are many ways to contribute to HEIR:

Citations

The HEIR project can be cited in academic work through the following entry:

@misc{ali2025heir,
      title={HEIR: A Universal Compiler for Homomorphic Encryption},
      author={Asra Ali and Jaeho Choi and Bryant Gipson and Shruthi Gorantala
              and Jeremy Kun and Wouter Legiest and Lawrence Lim and Alexander
              Viand and Meron Zerihun Demissie and Hongren Zheng},
      year={2025},
      eprint={2508.11095},
      archivePrefix={arXiv},
      primaryClass={cs.CR},
      url={https://arxiv.org/abs/2508.11095},
}

Support disclaimer

This is not an officially supported Google product.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

heir_py-2026.8.1.tar.gz (15.3 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

heir_py-2026.8.1-cp310-abi3-manylinux_2_28_x86_64.whl (34.4 MB view details)

Uploaded CPython 3.10+manylinux: glibc 2.28+ x86-64

heir_py-2026.8.1-cp310-abi3-manylinux_2_28_aarch64.whl (32.4 MB view details)

Uploaded CPython 3.10+manylinux: glibc 2.28+ ARM64

heir_py-2026.8.1-cp310-abi3-macosx_11_0_arm64.whl (34.8 MB view details)

Uploaded CPython 3.10+macOS 11.0+ ARM64

File details

Details for the file heir_py-2026.8.1.tar.gz.

File metadata

  • Download URL: heir_py-2026.8.1.tar.gz
  • Upload date:
  • Size: 15.3 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for heir_py-2026.8.1.tar.gz
Algorithm Hash digest
SHA256 62316c5066373ab3104dafc9ae916b88be02711797c665cf614a4fe3c8b8eee5
MD5 3d684842d820eb74a015f2c5f6551498
BLAKE2b-256 b434a2d40baa79703ab97a93e9da5ba4398bcf4e767318c0453ecd815b190289

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.1.tar.gz:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.1-cp310-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.1-cp310-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 7730629886e20b232bfc0614dd20fee3d664d85bacb7cf15725c1fa79507ae86
MD5 4edb3360fbe499155210878fddd45c46
BLAKE2b-256 1f6fa9122308b1a7f63bd27d54b020626d34905858764366fa1d86d0218ada92

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.1-cp310-abi3-manylinux_2_28_x86_64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.1-cp310-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.1-cp310-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 0aad8ccbfb848c64fabf53e94700ef807540ba626a7bb7ce3042ab16d74d5c4f
MD5 9352cbaafbcde2fd264d4d7135248980
BLAKE2b-256 008cdbd7982d73861187ab22cdbb595452cda59d06a4c32fa641ec757a097e40

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.1-cp310-abi3-manylinux_2_28_aarch64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file heir_py-2026.8.1-cp310-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for heir_py-2026.8.1-cp310-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 34e63b92bd3a306fb0986e5a4a9cb3c7875ff0d47660479e1991478851df7964
MD5 066a38a0a49fbeabf662bb78112480bc
BLAKE2b-256 12804c72dc0b7c45a20789b41cf848aab4f51921df41125a28e9bf94047e0d71

See more details on using hashes here.

Provenance

The following attestation bundles were made for heir_py-2026.8.1-cp310-abi3-macosx_11_0_arm64.whl:

Publisher: release.yml on google/heir

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page