Harnessing Sparsification in Federated Learning: A Secure, Efficient, and Differentially Private Realization
Shuangqing Xu, Yifeng Zheng, Zhongyun Hua
Abstract
Federated learning (FL) enables multiple clients to jointly train a model by sharing only gradient updates for aggregation instead of raw data. Due to the transmission of very high-dimensional gradient updates from many clients, FL is known to suffer from a communication bottleneck. Meanwhile, the gradients shared by clients as well as the trained model may also be exploited for inferring private local datasets, making privacy still a critical concern in FL. We present Clover, a novel system framework for communication-efficient, secure, and differentially private FL. To tackle the communication bottleneck in FL, Clover follows a standard and commonly used approach---top-k gradient sparsification, where each client sparsifies its gradient update such that only k largest gradients (measured by magnitude) are preserved for aggregation. Clover provides a tailored mechanism built out of a trending distributed trust setting involving three servers, which allows to efficiently aggregate multiple sparse vectors (top-k sparsified gradient updates) into a dense vector while hiding the values and indices of non-zero elements in each sparse vector. This mechanism outperforms a baseline built on the general distributed ORAM technique by several orders of magnitude in server-side communication and runtime, with also smaller client communication cost. We further integrate this mechanism with a lightweight distributed noise generation mechanism to offer differential privacy (DP) guarantees on the trained model. To harden Clover with security against a malicious server, we devise a series of lightweight mechanisms for integrity checks on the server-side computation. Extensive experiments show that Clover can achieve utility comparable to vanilla FL with central DP and no use of top-k sparsification. Meanwhile, achieving malicious security introduces negligible overhead in client-server communication, and only modest overhead in server-side communication and runtime, compared to the semi-honest security counterpart.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6bdecf6c-d058-45e7-bea7-57c99bc1d688Builds on36
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 · 1,917 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
Related papers
- Camel: Communication-Efficient and Maliciously Secure Federated Learning in the Shuffle Model of Differential PrivacyShuangqing Xu, Yifeng Zheng, Zhongyun HuaCCS 2024 · 5 citations
- Dordis: Efficient Federated Learning with Dropout-Resilient Differential PrivacyZhifeng Jiang, Wei Wang, Ruichuan ChenEuroSys 2024 · 14 citations
- LSHFed: Robust and Communication-Efficient Federated Learning with Locally-Sensitive Hashing Gradient MappingGuanjie Cheng, Mengzhen Yang, Xinkui Zhao, Shuyi Yu et al.AAAI 2026
- PARSIFAL: Private and Robust Sign Federated LearningRunze Lei, Pinghui Wang, Juxiang Zeng, Chenxu Wang et al.KDD 2025
- FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State ChannelsRuonan Chen, Ye Dong, Yizhong Liu, Tingyu Fan et al.WWW 2025 · 6 citations
