Google's HEIR Compiler: Practical Private AI with Homomorphic Encryption

Google has released HEIR (Homomorphic Encryption Intermediate Representation), an open-source compiler that converts pre-trained AI models to operate on encrypted inputs. This enables cryptographically-secure private AI inference — the server processes ciphertexts without ever seeing the underlying data.
Why HEIR?
Homomorphic encryption has long been impractical due to massive computational overhead. HEIR aims to change that by providing a compiler toolchain that automates the conversion of existing models, eliminating the need for a team of cryptographers. The project is part of Google's Private Computing Toolkit, which already includes differential privacy, private set membership, and private information retrieval.
Key Features
- One-click goal: The vision is to make HEIR a one-click solution for non-experts to integrate encrypted inference into production.
- Hardware accelerators: Google has partnered with Belfort, Niobium, Cornami, and Optalysys to build dedicated hardware for homomorphic encryption. The latency benefits of these accelerators are planned for near-future demos.
- Research platform: HEIR is already used in collaborations with Georgia Tech, Carnegie Mellon, UC Santa Barbara, Purdue, and others, with four peer-reviewed publications built on it.
Demo Applications
Google shared four private inference applications compiled with HEIR, with latency numbers measured on a single-threaded CPU. Source code is available in the GitHub repository.
- Deep Learning Recommendation Model — private content recommendations (joint work with Belfort Labs, LG, NYU).
- Credit card fraud detection — compiled with Niobium and hardshell.ai.
- Threat intrusion detection — Kitsune system for anomaly detection on encrypted network traffic, without revealing packet contents.
- Hotword detector — enables audio-triggered AI agents to recognize hotwords privately (with Belfort Labs).
These demos show that homomorphic encryption is no longer theoretical — it's ready for real-world applications in sectors like healthcare and finance where data privacy is critical.
The code for all examples is available on GitHub. Check the full blog post for detailed latency numbers.
📖 Read the full source: HN AI Agents
👀 See Also

Traversable Skill Graph for Persistent AI Agent Memory in Codebases
A developer built a three-layer skill graph system that lives inside a codebase, enabling AI coding assistants to maintain persistent memory across sessions. The system uses progressive disclosure with self-directing instructions instead of monolithic context files.

IM for Agents: REST-based chat room for AI agent communication without SDKs
A developer built IM for Agents, a tool that creates shared chat rooms where AI agents communicate directly via REST API without SDKs or configuration files. Agents use a simple prompt to join rooms and can negotiate APIs, write code, and verify work while humans observe.

ARP: Stateless WebSocket Relay for Autonomous Agent Communication
ARP (Agent Relay Protocol) is a stateless WebSocket relay for autonomous agent communication featuring Ed25519 identity, HPKE encryption per RFC 9180, binary TLV framing, and 33 bytes overhead per message. No accounts or registration required—just generate a keypair and connect.

Sherlock: Apple Developer Docs as Local MCP for Claude Code
Sherlock indexes 70k Apple API symbols into SQLite FTS5 and provides 5 MCP tools + 3 auto-triggering skills to ground Claude Code in real docs, preventing hallucinations.