RoFL: Robustness of Secure Federated Learning
Hidde Lycklama, Lukas Burkhalter, Alexander Viand, Nicolas Küchler, Anwar Hithnawi
Abstract
Even though recent years have seen many attacks exposing severe vulnerabilities in Federated Learning (FL), a holistic understanding of what enables these attacks and how they can be mitigated effectively is still lacking. In this work, we demystify the inner workings of existing (targeted) attacks. We provide new insights into why these attacks are possible and why a definitive solution to FL robustness is challenging. We show that the need for ML algorithms to memorize tail data has significant implications for FL integrity. This phenomenon has largely been studied in the context of privacy; our analysis sheds light on its implications for ML integrity. We show that certain classes of severe attacks can be mitigated effectively by enforcing constraints such as norm bounds on clients' updates. We investigate how to efficiently incorporate these constraints into secure FL protocols in the single-server setting. Based on this, we propose RoFL, a new secure FL system that extends secure aggregation with privacy-preserving input validation. Specifically, RoFL can enforce constraints such as and bounds on high-dimensional encrypted model updates.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aaf5e2da-e10d-4428-97a1-3ce176f46ba6Cited by top-tier papers18
- RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure AggregationPeihua Mai, Ran Yan, Yan PangNeurIPS 2024 · 51 citations
- Secure and Verifiable Data Collaboration with Low-Cost Zero-Knowledge ProofsYizheng Zhu, Yuncheng Wu, Zhaojing Luo, Beng Chin Ooi et al.VLDB 2024 · 14 citations
- Private Analytics via Streaming, Sketching, and Silently Verifiable ProofsMayank Rathee, Yuwen Zhang, Henry Corrigan-Gibbs, Raluca Ada PopaS&P 2024 · 8 citations
- LZKSA: Lattice-Based Special Zero-Knowledge Proofs for Secure Aggregation's Input VerificationZhi Lu, Songfeng LuCCS 2025 · 2 citations
- Heli: Heavy-Light Private AggregationRyan Lehmkuhl, Henry Corrigan-Gibbs, Emma Dauterman, David J. WuUSENIX Security 2026 · 1 citation
Builds on27
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
Related papers
- Eluding Secure Aggregation in Federated Learning via Model InconsistencyDario Pasquini, Danilo Francati, Giuseppe AtenieseCCS 2022 · 92 citations
- EIFFeL: Ensuring Integrity for Federated LearningAmrita Roy Chowdhury, Chuan Guo, Somesh Jha, Laurens van der MaatenCCS 2022 · 70 citations
- ELSA: Secure Aggregation for Federated Learning with Malicious ActorsMayank Rathee, Conghao Shen, Sameer Wagh, Raluca Ada PopaS&P 2023
- DeTA: Minimizing Data Leaks in Federated Learning via Decentralized and Trustworthy AggregationPau-Chen Cheng, Kevin Eykholt, Zhongshu Gu, Hani Jamjoom et al.EuroSys 2024 · 15 citations
- RobFL: Robust Federated Learning via Feature Center Separation and Malicious Center DetectionTing Zhou, Ning Liu, Bo Song, Hongtao Lv et al.ICDE 2024 · 3 citations
