Enabling Execution Assurance of Federated Learning at Untrusted Participants
Xiaoli Zhang, Fengting Li, Zeyu Zhang, Qi Li, Cong Wang, Jianping Wu
Abstract
Federated learning (FL), as a privacy-preserving machine learning framework, draws growing attention in both industry and academia. It obtains a jointly accurate model by distributing training tasks into data owners and aggregating their model updates. However, FL faces new security problems, as it losses direct control to training processes. One fundamental demand is to ensure whether participants execute training tasks as intended.In this paper, we propose TrustFL, a practical scheme that leverages Trusted Execution Environments (TEEs) to build assurance of participants' training executions with high confidence. Specifically, we use TEE to randomly check a small fraction of all training processes for tunable levels of assurance, while all computations are executed on the co-located faster yet insecure processor (e.g., GPU) for efficiency. To prevent various cheating behaviors like only processing TEE-requested computations or uploading old results, we devise a commitment-based method with specific data selection. We prototype TrustFL using GPU and SGX and evaluate its performance. The results show that TrustFL achieves one/two orders of magnitude speedups compared with naive training with SGX, when assuring correct training with a confidence level of 99%.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 951be1e1-318a-4f40-a33e-553864d54adeCited by top-tier papers4
- The Right to be Forgotten in Federated Learning: An Efficient Realization with Rapid RetrainingYi Liu, Lei Xu, Xingliang Yuan, Cong Wang et al.INFOCOM 2022 · 189 citations
- Privacy-Preserving Learning of Human Activity Predictors in Smart EnvironmentsSharare Zehtabian, Siavash Khodadadeh, Ladislau Bölöni, Damla TurgutINFOCOM 2021 · 11 citations
- BadSampler: Harnessing the Power of Catastrophic Forgetting to Poison Byzantine-robust Federated LearningYi Liu, Cong Wang, Xingliang YuanKDD 2024 · 5 citations
- Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AIHeng Jin, Chaoyu Zhang, Hexuan Yu, Shanghao Shi et al.USENIX Security 2026 · 4 citations
Related papers
- Olive: Oblivious Federated Learning on Trusted Execution Environment Against the Risk of SparsificationFumiyuki Kato, Yang Cao, Masatoshi YoshikawaVLDB 2023 · 14 citations
- AccShield: a New Trusted Execution Environment with Machine-Learning AcceleratorsWei Ren, William Kozlowski, Sandhya Koteshwara, Mengmei Ye et al.DAC 2023 · 11 citations
- Towards Efficient and Practical Multi-party Computation under Inconsistent Trust in TEEsXuanwei Hu, Rujia Li, Yi Liu, Qi WangS&P 2025
- SCALE: Tackling Communication Bottlenecks in Confidential Distributed Machine LearningJoongun Park, Yongqin Wang, Huan Xu, Hanjiang Wu et al.HPCA 2026
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 14 citations
