EIFFeL: Ensuring Integrity for Federated Learning
Amrita Roy Chowdhury, Chuan Guo, Somesh Jha, Laurens van der Maaten
Abstract
Federated learning (FL) enables clients to collaborate with a server to train a machine learning model. To ensure privacy, the server performs secure aggregation of updates from the clients. Unfortunately, this prevents verification of the well-formedness (integrity) of the updates as the updates are masked. Consequently, malformed updates designed to poison the model can be injected without detection. In this paper, we formalize the problem of ensuring both update privacy and integrity in FL and present a new system, EIF-FeL, that enables secure aggregation of verified updates. EIFFeL is a general framework that can enforce arbitrary integrity checks and remove malformed updates from the aggregate, without violating privacy. Our empirical evaluation demonstrates the practicality of EIFFeL. For instance, with 100 clients and 10% poisoning, EIFFeL can train an MNIST classification model to the same accuracy as that of a non-poisoned federated learner in just 2.4s per iteration. CCS Concepts • Security and privacy → Cryptography; Privacy-preserving protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers19
- Secure and Verifiable Data Collaboration with Low-Cost Zero-Knowledge ProofsYizheng Zhu, Yuncheng Wu, Zhaojing Luo, Beng Chin Ooi et al.VLDB 2024 · 14 citations
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
- Poisoning Attack on Federated Knowledge Graph EmbeddingEnyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong et al.WWW 2024 · 6 citations
- Benchmarking Secure Sampling Protocols for Differential PrivacyYucheng Fu, Tianhao WangCCS 2024 · 5 citations
- LZKSA: Lattice-Based Special Zero-Knowledge Proofs for Secure Aggregation's Input VerificationZhi Lu, Songfeng LuCCS 2025 · 2 citations
Builds on17
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- The Distributed Discrete Gaussian Mechanism for Federated Learning with Secure AggregationPeter Kairouz, Ziyu Liu, Thomas SteinkeICML 2021 · 291 citations
Related papers
- PARSIFAL: Private and Robust Sign Federated LearningRunze Lei, Pinghui Wang, Juxiang Zeng, Chenxu Wang et al.KDD 2025
- Camel: Communication-Efficient and Maliciously Secure Federated Learning in the Shuffle Model of Differential PrivacyShuangqing Xu, Yifeng Zheng, Zhongyun HuaCCS 2024 · 5 citations
- Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning AttacksHamid Mozaffari, Virat Shejwalkar, Amir HoumansadrUSENIX Security 2023
- RoFL: Robustness of Secure Federated LearningHidde Lycklama, Lukas Burkhalter, Alexander Viand, Nicolas Küchler et al.S&P 2023
- ELSA: Secure Aggregation for Federated Learning with Malicious ActorsMayank Rathee, Conghao Shen, Sameer Wagh, Raluca Ada PopaS&P 2023
