Armadillo: Robust Single-Server Secure Aggregation for Federated Learning with Input Validation
Yiping Ma, Yue Guo, Harish Karthikeyan, Antigoni Polychroniadou
Abstract
This paper presents a secure aggregation system Armadillo that has disruptive resistance against adversarial clients, such that any coalition of malicious clients can affect the aggregation result only by misreporting their private inputs in a pre-defined legitimate range. Armadillo is designed for federated learning setting, where a single powerful server interacts with many weak clients iteratively to train models on client's private data. While a few prior works consider disruption resistance under such setting, for an aggregation on n clients they either require high cost per client (Chowdhury et al. CCS '22) or concretely many rounds that is logarithmic in n (Bell et al. USENIX Security '23). Although disruption resistance can be achieved generically with zero-knowledge proof techniques (which we also use in this paper), we realize an efficient system with two new designs: 1) a simple two-layer secure aggregation protocol that requires only simple arithmetic computation; 2) an agreement protocol that removes the effect of malicious clients from the aggregation with low round complexity. With these techniques, Armadillo runs in 3 rounds per aggregation (our round complexity is independent of n) with computationally lightweight server and clients.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b2886d0-40ef-434c-aae0-eca4a8ec4bf4Cited by top-tier papers2
- Heli: Heavy-Light Private AggregationRyan Lehmkuhl, Henry Corrigan-Gibbs, Emma Dauterman, David J. WuUSENIX Security 2026 · 1 citation
- Lighthouse: Single-Server Secure Aggregation with O(1) Server-Committee Communication at ScaleSanjam Garg, Alireza Kavousi, Dimitris Kolonelos, Erkan Tairi et al.USENIX Security 2026 · 1 citation
Builds on22
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- Securing Secure Aggregation: Mitigating Multi-Round Privacy Leakage in Federated LearningJinhyun So, Ramy E. Ali, Basak Güler, Jiantao Jiao et al.AAAI 2023 · 107 citations
- Eluding Secure Aggregation in Federated Learning via Model InconsistencyDario Pasquini, Danilo Francati, Giuseppe AtenieseCCS 2022 · 92 citations
Related papers
- Flamingo: Multi-Round Single-Server Secure Aggregation with Applications to Private Federated LearningYiping Ma, Jess Woods, Sebastian Angel, Antigoni Polychroniadou et al.S&P 2023
- Input Integrity and Authentic Results: Towards Trustworthy Aggregation in Federated LearningZhangshuang Guan, Yulin Zhao, Zhiguo Wan, Wei WangINFOCOM 2025 · 1 citation
- ELSA: Secure Aggregation for Federated Learning with Malicious ActorsMayank Rathee, Conghao Shen, Sameer Wagh, Raluca Ada PopaS&P 2023
- NFSA: Non-Forward Secure Aggregation with One Server via Two Layer Secret SharingYufei ZhouCCS 2026
- Janus: Dual-Server Multi-Round Secure Aggregation with Verifiability for Federated LearningLang Pu, Jingjing Gu, Chao Lin, Xinyi HuangICML 2025
