AegisFL: Efficient and Flexible Privacy-Preserving Byzantine-Robust Cross-silo Federated Learning
Dong Chen, Hongyuan Qu, Guangwu Xu
Abstract
Privacy attacks and poisoning attacks are two of the thorniest problems in federated learning (FL). Homomorphic encryption (HE), which allows certain mathematical operations to be done in the ciphertext state, provides a way to solve these two problems simultaneously. However, existing Paillier-based and CKKS-based privacypreserving byzantine-robust FL (PBFL) solutions not only suffer from low efficiency but also expose the final model to the server. Additionally, these methods are limited to one robust aggregation algorithm (AGR) and are therefore vulnerable to AGR-tailored poisoning attacks. In this paper, we present AegisFL, an efficient PBFL system that provides the flexibility to change the AGR. We first observe that the core of the existing advanced AGRs is to calculate the inner products, L 2 norms and mean values for vectors. Based on this observation, we tailor a packing scheme for PBFL, which fits perfectly with RLWE-based fully homomorphic encryption. Under this packing scheme, the server only needs to perform one ciphertext multiplication to construct any required AGR, while the global model only belongs to honest clients. Finally, we conduct extensive experiments on different datasets and adversary settings, which also confirm the effectiveness and efficiency of our scheme.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ee6d7a1c-bdb0-4496-b25a-0e4d415811b8Builds on7
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Leakage of Dataset Properties in Multi-Party Machine LearningWanrong Zhang, Shruti Tople, Olga OhrimenkoUSENIX Security 2021 · 92 citations
- FLAME: Taming Backdoors in Federated LearningThien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame et al.USENIX Security 2022
Related papers
- Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated LearningRunhua Xu, Shiqi Gao, Chao Li, James Joshi et al.NeurIPS 2024 · 29 citations
- RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure AggregationPeihua Mai, Ran Yan, Yan PangNeurIPS 2024 · 51 citations
- FLSeg: Enhancing Privacy and Robustness in Federated Learning under Heterogeneous Data via Model SegmentationZichun Su, Zhi Lu, Yutong Wu, Renfei Shen et al.ICCV 2025
- Efficient and Straggler-Resistant Homomorphic Encryption for Heterogeneous Federated LearningNan Yan, Yuqing Li, Jing Chen, Xiong Wang et al.INFOCOM 2024 · 27 citations
- FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State ChannelsRuonan Chen, Ye Dong, Yizhong Liu, Tingyu Fan et al.WWW 2025 · 6 citations
