Input Integrity and Authentic Results: Towards Trustworthy Aggregation in Federated Learning
Zhangshuang Guan, Yulin Zhao, Zhiguo Wan, Wei Wang
Abstract
Federated learning (FL) is a collaborative machine learning approach that allows multiple clients to train a model jointly while keeping their data local, thus enhancing privacy. A critical component of FL is secure aggregation (SA), which protects user privacy during the server-side aggregation of client updates. However, current state-of-the-art (SOTA) SA schemes, such as LERNA and Flamingo, have significant limitations. They require at least 3 round-trip communications to handle client dropouts, making them inefficient. Additionally, they are vulnerable to malicious attacks from both clients (input data poisoning) and the server (aggregation manipulation). To address these issues, we propose the first 2-round-trip trustworthy aggregation scheme, called HyperSA, which guarantees both input integrity and result authenticity. HyperSA achieves its goal with two key techniques: a consistent authenticated decryption mechanism and a three-step chain proof procedure. The former, implemented through consistent threshold key recovery, reduces the communication round trips from 3 to 2. The latter, comprising three zero-knowledge proofs chained together, enables misbehavior detection, ensuring that all clients receive authentic aggregation results. We implemented HyperSA and conducted a comprehensive evaluation. Both theoretical analysis and experimental results demonstrate the practicality and efficiency of our design compared to existing SOTA schemes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Janus: Dual-Server Multi-Round Secure Aggregation with Verifiability for Federated LearningLang Pu, Jingjing Gu, Chao Lin, Xinyi HuangICML 2025
- ELSA: Secure Aggregation for Federated Learning with Malicious ActorsMayank Rathee, Conghao Shen, Sameer Wagh, Raluca Ada PopaS&P 2023
- Aion: Robust and Efficient Multi-Round Single-Mask Secure Aggregation Against Malicious ParticipantsYizhong Liu, Zixiao Jia, Xiao Chen, Song Bian et al.USENIX Security 2025
- RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure AggregationPeihua Mai, Ran Yan, Yan PangNeurIPS 2024 · 51 citations
- Secure and Verifiable Data Collaboration with Low-Cost Zero-Knowledge ProofsYizheng Zhu, Yuncheng Wu, Zhaojing Luo, Beng Chin Ooi et al.VLDB 2024 · 14 citations
