USENIX Security2026Top-tier venue
Lighthouse: Single-Server Secure Aggregation with O(1) Server-Committee Communication at Scale
Sanjam Garg, Alireza Kavousi, Dimitris Kolonelos, Erkan Tairi, Zhipeng Wang
Abstract
Secure aggregation is a core primitive for privacy-preserving federated learning, enabling a server to compute aggregates of client updates without learning individual inputs. Recent protocols have explored committee-based designs to reduce client overhead and tolerate weakly connected participants. However, existing approaches still incur communication and computation costs that scale with the number of clients and/or the size of model updates. This becomes a serious bottleneck in interaction between the server and the committee, given that model updates are high-dimensional and the committee is a small set of clients. We present Lighthouse, a new secure aggregation protocol that supports one-shot client communication and achieves constant committee computation and communication overhead with the server, independent of both the number of clients and the size of the input vector. Our protocol attains the best-known round complexity of two rounds, matching OPA (CRYPTO 2025) and TACITA (ePrint 2025) and improving upon Flamingo (S&P 2023) and Willow (CRYPTO 2025). Our core technical contribution is a novel application of recent advances in batched threshold encryption, which enables succinct server–committee interaction while preserving security and correctness. Beyond asymptotic improvements over prior works, Lighthouse yields substantial concrete efficiency gains: For an aggregation with 1024 clients, we reduce server-to-committee communication by over 100× and committee-to-server communication by over 300× compared to Flamingo and Willow. Also, we present an extension that supports dynamic client participation, a critical requirement for practical deployments at scale, while preserving the asymptotic and concrete efficiency of the static protocol for clients.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a8b6e80-b221-4cfc-bd85-51298bb564ffBuilds on19
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- hinTS: Threshold Signatures with Silent SetupSanjam Garg, Abhishek Jain, Pratyay Mukherjee, Rohit Sinha et al.S&P 2024 · 48 citations
- Mempool Privacy via Batched Threshold Encryption: Attacks and DefensesArka Rai Choudhuri, Sanjam Garg, Julien Piet, Guru-Vamsi PolicharlaUSENIX Security 2024 · 41 citations
- Threshold Encryption with Silent SetupSanjam Garg, Dimitris Kolonelos, Guru-Vamsi Policharla, Mingyuan WangCRYPTO 2024 · 31 citations
Related papers
- TACITA: Threshold Aggregation without Client InteractionVarun Madathil, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2026 · 2 citations
- NFSA: Non-Forward Secure Aggregation with One Server via Two Layer Secret SharingYufei ZhouCCS 2026
- Willow: Secure Aggregation with One-Shot ClientsJames Bell-Clark, Adrià Gascón, Baiyu Li, Mariana Raykova et al.CRYPTO 2025 · 5 citations
- Janus: Dual-Server Multi-Round Secure Aggregation with Verifiability for Federated LearningLang Pu, Jingjing Gu, Chao Lin, Xinyi HuangICML 2025
- sfOPA: One-Shot Private Aggregation with Single Client Interaction and Its Applications to Federated LearningHarish Karthikeyan, Antigoni PolychroniadouCRYPTO 2025 · 1 citation
