Willow: Secure Aggregation with One-Shot Clients
James Bell-Clark, Adrià Gascón, Baiyu Li, Mariana Raykova, Phillipp Schoppmann
Abstract
A common drawback of secure vector summation protocols in the single-server model is that they impose at least one synchronization point between all clients contributing to the aggregation. This results in clients waiting on each other to advance through the rounds of the protocol, leading to large latency (or failures due to too many dropouts) even if the protocol is computationally efficient. In this paper we propose protocols in the single-server model where clients contributing data to the aggregation (i) send a single message to the server and (ii) can join aggregation sessions dynamically whenever they have resources, i.e., without the need for synchronizing their reporting time with any other clients. Our approach is based on a committee of parties that aid in the computation by running a setup phase before data collection starts, and a verification/decryption phase once it ends. Unlike existing committee-based protocols such as Flamingo (S&P 2023), the cost for committee members can be made sub-linear in the number of clients, and does not depend on the size of the input client vectors. Our experimental evaluation shows that our protocol, even while allowing dynamic client participation, is competitive with the state of the art protocols that do not have that feature in both computation and communication.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a5768eb9-557d-4f45-8254-b47ae5ffd267Cited by top-tier papers8
- TACITA: Threshold Aggregation without Client InteractionVarun Madathil, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2026 · 2 citations
- Heli: Heavy-Light Private AggregationRyan Lehmkuhl, Henry Corrigan-Gibbs, Emma Dauterman, David J. WuUSENIX Security 2026 · 1 citation
- Vεrity: Verifiable Local Differential PrivacyJames Bell-Clark, Adrià Gascón, Baiyu Li, Mariana Raykova et al.USENIX Security 2026 · 1 citation
- Lighthouse: Single-Server Secure Aggregation with O(1) Server-Committee Communication at ScaleSanjam Garg, Alireza Kavousi, Dimitris Kolonelos, Erkan Tairi et al.USENIX Security 2026 · 1 citation
- sfOPA: One-Shot Private Aggregation with Single Client Interaction and Its Applications to Federated LearningHarish Karthikeyan, Antigoni PolychroniadouCRYPTO 2025 · 1 citation
Related papers
- Flamingo: Multi-Round Single-Server Secure Aggregation with Applications to Private Federated LearningYiping Ma, Jess Woods, Sebastian Angel, Antigoni Polychroniadou et al.S&P 2023
- Janus: Dual-Server Multi-Round Secure Aggregation with Verifiability for Federated LearningLang Pu, Jingjing Gu, Chao Lin, Xinyi HuangICML 2025
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Secure Single-Server Aggregation with (Poly)Logarithmic OverheadJames Henry Bell, Kallista A. Bonawitz, Adrià Gascón, Tancrède Lepoint et al.CCS 2020 · 13 citations
- ACORN: Input Validation for Secure AggregationJames Bell, Adrià Gascón, Tancrède Lepoint, Baiyu Li et al.USENIX Security 2023
