REVIEW 3 major objections 5 minor 59 references
PRoVeFL lets federated learning keep client updates private, filter poisoned ones with complex robust rules, and verify the server did the aggregation correctly, all under multi-server multi-key encryption that is far faster than prior dist
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-11 01:47 UTC pith:JXHWUTPP
load-bearing objection Useful multi-server hybrid for complex robust FL rules with real speedups, but the post-decryption privacy claim does not hold for the core primitives. the 3 major comments →
PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
A multi-server architecture using multi-key fully homomorphic encryption, combined with a secret random multiplicative mask that servers apply to client updates before collaborative decryption, lets complex Byzantine-robust aggregation rules be evaluated largely in the plaintext domain without revealing the underlying updates, while commitment checks give every honest server a way to abort if any other server cheats.
What carries the argument
The jointly generated encrypted random mask Enc(r) that each client multiplies into its update shares; after threshold decryption only the masked intermediate statistics appear, preserving order and relative magnitudes so that sorting, selection and scoring steps of Krum, Trimmed Mean, FLTrust or MESAS can finish in the clear.
Load-bearing premise
Security collapses if every server is dishonest or if the jointly sampled mask becomes known to a coalition of clients and the remaining servers, because the masked intermediate values would then unmask honest clients' updates.
What would settle it
Run the same Krum or Trimmed-Mean aggregation both in the clear and inside PRoVeFL on identical poisoned updates; if the selected global model or the set of filtered clients differs, or if an honest server accepts a forged aggregate that fails the commitment check, the central claim fails.
If this is right
- Complex robust aggregators that previously required cleartext updates can now be used inside privacy-preserving federated learning without redesigning their statistical logic.
- Clients need only trust that at least one of a small number of servers is honest; they no longer need a single trusted aggregator or expensive zero-knowledge proofs for every coordinate.
- Communication and computation scale with the number of servers rather than forcing every client into heavy multi-party computation, making larger participant pools practical.
- The same hybrid mask-and-decrypt pattern can be reused for any aggregation rule whose decisions depend only on order, sign or relative magnitude of masked statistics.
Where Pith is reading between the lines
- The same mask-plus-threshold-decryption pattern could be applied to other distributed statistics beyond federated learning, such as secure median or top-k selection in multi-party analytics.
- If the additive blinding layer is strengthened further, the protocol might tolerate a larger fraction of colluding clients without changing the server-side primitives.
- The modular design suggests a practical path for vendors who already run multi-party secure aggregation to swap in richer robust rules without rewriting the entire stack.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. PRoVeFL is a multi-server federated-learning framework that aims to provide client-update privacy (via multi-key CKKS-style FHE under an at-least-one-honest-server assumption), Byzantine-robust aggregation for complex rules (Krum, Trimmed Mean, FLTrust, MESAS, etc.), and peer-server verifiability of the aggregation steps via discrete-log commitments. Clients encrypt masked shares under a jointly generated multiplicative mask Enc(r); servers perform method-specific homomorphic operations, collaboratively decrypt only the masked intermediate statistics, verify them against client commitments, and finish selection/filtering in the plaintext domain. Empirical evaluation reports large speed-ups versus Prio and ELSA under a relaxed L∞ defense and shows that the robust rules retain accuracy under Trim and Backdoor attacks when run inside the encrypted pipeline.
Significance. If the privacy, robustness and verifiability claims hold simultaneously, the work would be a useful systems contribution: it is one of the few frameworks that supports non-trivial Byzantine rules (pairwise distances, coordinate-wise sorting, cosine similarity) rather than only norm clipping, while remaining faster than prior distributed-trust baselines. The modular primitive set (LA/PSE/SCO/SF), the concrete instantiations (Figs. 4–6, A.10), the SEAL implementation, and the runtime/communication tables are concrete engineering assets. The security reductions to Ring-LWE and DLP (Theorems 1–3) are the right style of argument for this literature, even if their statements need tightening.
major comments (3)
- Theorem 2 (Appendix C) and the privacy claim of §3.1.1 are not established for the core primitives. The hybrid H1 is defined as d'_i = f(r', s_i) (still a function of the secret updates/distances/inner products) yet the proof text asserts that the simulator can output independent random vectors without knowing any client secret; the two statements contradict. Concretely, for FLTrust (Fig. 6) the opened vectors satisfy d_i = r·(u_i ⊙ u_0) and e_i = r/∥u_i∥, so any server recovers the direction of each u_i and, when e_i is also opened, recovers r and therefore the full u_i. For Trimmed-Mean the full set of coordinate-wise differences d_ij = r·(u_i-u_j) determines every update up to global scale and translation; for Krum the scaled distance matrix determines the configuration up to isometry and scale. The additive blinding δ of §4.2.5 does not close these algebraic channels. The claimed pos
- The experimental comparison in Tables 3–4 is restricted to a relaxed L∞ / norm-clipping defense because ELSA and Prio do not support Krum/Trimmed-Mean/FLTrust. The headline 100 imes/10 imes speed-ups therefore do not apply to the complex rules that constitute the paper's main algorithmic contribution. Either the complex rules must be benchmarked against the closest available secure baselines (or against a pure-FHE baseline), or the abstract and §6.2.3 claims must be restated so that they match the evaluated defense.
- The threat model (§3.1) and the strengthened collusion discussion (§4.2.5) assume that at least one server remains honest and will abort on failed checks, yet the final selected or averaged model is eventually unmasked for the clients. Once r is effectively known (or once a selected plaintext update is published), earlier masked intermediates become fully recoverable. The manuscript never states what is revealed to clients at the end of a round, nor how the final global model is protected from the same algebraic recovery that already works on the intermediate view. This gap must be closed for the privacy guarantee to be well-defined.
minor comments (5)
- Table 1 marks PRoVeFL with ✓✓ for robustness coverage; the footnote is helpful but the table itself should list which concrete rules are actually implemented and evaluated.
- Figures 7–8 and the runtime-breakdown plots (D.11–D.12) would be clearer with error bars or min/max ranges; the text only says “averaged over 5 runs.”
- Notation for the split dimension N/m versus the full dimension N is overloaded in several places (e.g., FLTrust trust-score formula); a short notation table would help.
- The polynomial-modulus degree is fixed at 32768; a short sensitivity note on packing efficiency versus security level would strengthen the systems claims.
- A few typos remain (e.g., “analsze” in §6.1.2, “The trimmed-mean” capitalization in §4.4.2).
Circularity Check
No circularity: PRoVeFL is a self-contained cryptographic construction and empirical evaluation; privacy/robustness/verifiability claims reduce to standard assumptions (RLWE, DLP) and hybrid masking, not to fitted inputs or self-definitional loops.
full rationale
The paper's load-bearing claims are (1) a multi-server MK-FHE protocol that offloads order-preserving statistics to plaintext after multiplicative masking by a joint secret r, (2) instantiation of existing aggregation rules (Krum, Trimmed-Mean, FLTrust, MESAS) via the four primitives LA/PSE/SCO/SF, (3) commitment-based verification under DLP, and (4) measured runtime gains versus Prio/ELSA/RoFL. Theorems 1–3 reduce confidentiality and integrity to decisional Ring-LWE and discrete-log hardness; the hybrid argument of Theorem 2 (even if its simulator claim is imperfect) does not define the target privacy property in terms of itself. No free parameters are fitted to data and then re-predicted; no uniqueness theorem is imported from overlapping authors to forbid alternatives; no known empirical pattern is merely renamed. Ordinary background citations (including one prior paper by a co-author) are not load-bearing for the central construction or the speedup numbers. The work is therefore free of the six enumerated circularity patterns.
Axiom & Free-Parameter Ledger
free parameters (2)
- FHE polynomial modulus degree =
32768
- Additive blinding bound B and mask size relative to epsilon and lambda
axioms (5)
- standard math Decisional Ring-LWE hardness for multi-key FHE confidentiality
- standard math Discrete Logarithm Problem hardness in the commitment group
- domain assumption At least one of the m aggregation servers is honest and will abort on failed verification
- domain assumption Jointly generated multiplicative mask r remains unknown to any single server and to client–server coalitions short of all servers
- ad hoc to paper Target Byzantine-robust rules can be expressed via linear aggregation, pairwise polynomials, secure comparison/ordering, and selection/filtering under multiplicative masking
invented entities (1)
-
PRoVeFL hybrid multi-server aggregation pipeline (shared Enc(r) mask + plaintext offload of SCO/SF + peer commitment verification)
no independent evidence
read the original abstract
Federated Learning (FL) enables multiple clients to collaboratively train machine learning models while retaining data locality, thereby enhancing user privacy. However, traditional FL frameworks rely on a centralized aggregation server and assume honest-but-curious clients, making them susceptible to both server-side inference and client-side poisoning attacks. Although recent work has explored secure and Byzantine-resilient FL protocols, they face a fundamental trade-off among privacy, integrity, and verifiability, and incur substantial computational and communication overhead due to the heavy use of cryptographic primitives. In this work, we propose PRoVeFL-a novel, modular FL framework that is Privacy-preserving, Byzantine-Robust, and ensures Verifiable aggregation. PRoVeFL employs multiple servers leveraging multi-key fully homomorphic encryption. Each client encrypts its local model updates and distributes encrypted shares to all servers. This design enables a hybrid computation model in which ciphertext operations are carefully offloaded to the plaintext domain under strict privacy constraints to efficiently evaluate complex statistical aggregation rules. PRoVeFL is compatible with a wide range of state-of-the-art Byzantine-robust aggregation algorithms (e.g., Krum, Trimmed Mean, FLTrust, norm clipping, MESAS, and more) and further enhances them with verifiability mechanisms that require minimal trust in at least one honest server. We evaluate it across different settings and demonstrate its scalability with varying numbers of parameters and participants. PRoVeFL improves runtime over the prior works, Prio and ELSA, based on distributed trust with comparable security guarantees, up to 100x and 10x, respectively.
Figures
Reference graph
Works this paper leans on
-
[1]
H. B. McMahan, E. Moore, D. Ramage, B. A. y Arcas, Federated learning of deep networks using model averag- ing, CoRR abs/1602.05629 (2016).arXiv:1602.05629. URLhttp://arxiv.org/abs/1602.05629
work page internal anchor Pith review Pith/arXiv arXiv 2016
-
[2]
B. McMahan, E. Moore, D. Ramage, S. Hampson, B. A. y Arcas, Communication-efficient learning of deep net- works from decentralized data, in: Artificial Intelligence and Statistics, PMLR, 2017, pp. 1273–1282
work page 2017
-
[3]
Z. Tian, Y . Ding, X. Yu, E. Gong, J. Liu, K. Ren, Towards collaborative anti-money laundering among financial in- stitutions, in: Web Conference, 2025, pp. 4722–4733
work page 2025
-
[4]
V . Mothukuri, R. M. Parizi, S. Pouriyeh, Y . Huang, A. De- hghantanha, G. Srivastava, A survey on security and pri- vacy of federated learning, Future Generation Computer Systems 115 (2021) 619–640
work page 2021
-
[5]
M. Nasr, R. Shokri, A. Houmansadr, Comprehensive pri- vacy analysis of deep learning: Passive and active white- box inference attacks against centralized and federated learning, in: IEEE symposium on security and privacy (SP), IEEE, 2019, pp. 739–753
work page 2019
- [6]
-
[7]
C. Fu, X. Zhang, S. Ji, J. Chen, J. Wu, S. Guo, J. Zhou, A. X. Liu, T. Wang, Label inference attacks against verti- cal federated learning, in: 31st USENIX security sympo- sium, 2022, pp. 1397–1414
work page 2022
-
[8]
M. Fang, X. Cao, J. Jia, N. Gong, Local model poisoning attacks to Byzantine-Robust federated learning, in: 29th USENIX security symposium, 2020, pp. 1605–1622
work page 2020
-
[9]
V . Tolpegin, S. Truex, M. E. Gursoy, L. Liu, Data poison- ing attacks against federated learning systems, in: 25th European symposium on research in computer security, Springer, 2020, pp. 480–501
work page 2020
- [10]
- [11]
-
[12]
H. Hu, Z. Salcic, L. Sun, G. Dobbie, X. Zhang, Source inference attacks in federated learning, in: International Conference on Data Mining (ICDM), IEEE, 2021, pp. 1102–1107
work page 2021
-
[13]
R. Wang, X. Wang, H. Chen, J. Decouchant, S. Picek, N. Laoutaris, K. Liang, Mudguard: Taming malicious majorities in federated learning using privacy-preserving byzantine-robust clustering, ACM Conference on Mea- surement and Analysis of Computing Systems 8 (3) (2024) 1–41
work page 2024
-
[14]
J. Bell, A. Gascón, T. Lepoint, B. Li, S. Meiklejohn, M. Raykova, C. Yun, ACORN: input validation for se- cure aggregation, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 4805–4822
work page 2023
-
[15]
A. Roy Chowdhury, C. Guo, S. Jha, L. van der Maaten, Eiffel: Ensuring integrity for federated learning, in: ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 2535–2549
work page 2022
-
[16]
J. Gao, B. Hou, X. Guo, Z. Liu, Y . Zhang, K. Chen, J. Li, Secure aggregation is insecure: Category inference attack on federated learning, IEEE Transactions on Dependable and Secure Computing 20 (1) (2021) 147–160
work page 2021
-
[17]
G. Xu, H. Li, S. Liu, K. Yang, X. Lin, Verifynet: Secure and verifiable federated learning, IEEE Transactions on Information Forensics and Security 15 (2019) 911–926
work page 2019
-
[18]
H. Gao, N. He, T. Gao, Sverifl: Successive verifiable fed- erated learning with privacy-preserving, Information Sci- ences 622 (2023) 98–114
work page 2023
-
[19]
Gentry, A fully homomorphic encryption scheme, Stanford university, 2009
C. Gentry, A fully homomorphic encryption scheme, Stanford university, 2009
work page 2009
-
[20]
J. H. Cheon, A. Kim, M. Kim, Y . Song, Homomorphic en- cryption for arithmetic of approximate numbers, in: Ad- vances in cryptology–ASIACRYPT international confer- ence on the theory and applications of cryptology and in- formation security, Springer, 2017, pp. 409–437
work page 2017
-
[21]
W. Jin, Y . Yao, S. Han, J. Gu, C. Joe-Wong, S. Ravi, S. Avestimehr, C. He, Fedml-he: An efficient homomorphic-encryption-based privacy-preserving fed- erated learning system, arXiv preprint arXiv:2303.10837 (2023). 15
work page internal anchor Pith review Pith/arXiv arXiv 2023
- [22]
-
[23]
W. Du, M. Li, L. Wu, Y . Han, T. Zhou, X. Yang, A efficient and robust privacy-preserving framework for cross-device federated learning, Complex & Intelligent Systems 9 (5) (2023) 4923–4937
work page 2023
-
[24]
T. Gehlhar, F. Marx, T. Schneider, A. Suresh, T. Wehrle, H. Yalame, Safefl: Mpc-friendly framework for private and robust federated learning, in: IEEE Security and Pri- vacy Workshops (SPW), IEEE, 2023, pp. 69–76
work page 2023
-
[25]
N. Franzese, A. Dziedzic, C. A. Choquette-Choo, M. R. Thomas, M. A. Kaleem, S. Rabanser, C. Fang, S. Jha, N. Papernot, X. Wang, Robust and actively secure server- less collaborative learning, Advances in Neural Informa- tion Processing Systems 36 (2023) 39504–39528
work page 2023
-
[26]
P. Blanchard, E. M. El Mhamdi, R. Guerraoui, J. Stainer, Machine learning with adversaries: Byzantine tolerant gradient descent, in: Neural Information Processing Sys- tems, 2017, pp. 118–128
work page 2017
-
[27]
D. Yin, Y . Chen, R. Kannan, P. Bartlett, Byzantine-robust distributed learning: Towards optimal statistical rates, in: International Conference on Machine Learning, PMLR, 2018, pp. 5650–5659
work page 2018
-
[28]
X. Cao, M. Fang, J. Liu, N. Gong, Fltrust: Byzantine- robust federated learning via trust bootstrapping, in: NDSS, 2021
work page 2021
- [29]
-
[30]
J. Tang, H. Xu, H. Liao, Y . Zhou, Seaflame: Communication-efficient secure aggregation for feder- ated learning against malicious entities, IACR Transac- tions on Cryptographic Hardware and Embedded Systems 2025 (2) (2025) 69–93
work page 2025
-
[31]
R. Xu, B. Li, C. Li, J. B. Joshi, S. Ma, J. Li, Tapfed: Threshold secure aggregation for privacy-preserving fed- erated learning, IEEE Transactions on Dependable and Secure Computing 21 (5) (2024) 4309–4323
work page 2024
-
[32]
J. Liu, X. Li, X. Liu, H. Zhang, Y . Miao, R. H. Deng, Defendfl: A privacy-preserving federated learning scheme against poisoning attacks, IEEE Transactions on Neural Networks and Learning Systems (2024)
work page 2024
-
[33]
R. Ma, K. Hwang, M. Li, Y . Miao, Trusted model aggre- gation with zero-knowledge proofs in federated learning, IEEE Transactions on Parallel and Distributed Systems (2024)
work page 2024
-
[34]
J. Tang, H. Xu, M. Wang, T. Tang, C. Peng, H. Liao, A flexible and scalable malicious secure aggregation proto- col for federated learning, IEEE Transactions on Informa- tion Forensics and Security (2024)
work page 2024
-
[35]
RoFL: Robustness of Secure Federated Learning
L. Burkhalter, H. Lycklama, A. Viand, N. Küchler, A. Hithnawi, Rofl: Attestable robustness for secure feder- ated learning, arXiv preprint arXiv:2107.03311 21 (2021)
work page internal anchor Pith review Pith/arXiv arXiv 2021
-
[36]
H. Corrigan-Gibbs, D. Boneh, Prio: Private, robust, and scalable computation of aggregate statistics, in: 14th USENIX symposium on networked systems design and implementation (NSDI 17), 2017, pp. 259–282
work page 2017
-
[37]
S. Addanki, K. Garbe, E. Jaffe, R. Ostrovsky, A. Poly- chroniadou, Prio+: Privacy preserving aggregate statistics via boolean shares, in: International Conference on Secu- rity and Cryptography for Networks, Springer, 2022, pp. 516–539
work page 2022
-
[38]
B. Yin, H. Zhang, J. Lin, F. Kong, L. Yu, Pvfl: Verifiable federated learning and prediction with privacy-preserving, Computers & Security 139 (2024) 103700
work page 2024
- [39]
-
[40]
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, T. Goldstein, Poison frogs! targeted clean- label poisoning attacks on neural networks, in: Neu- ral Information Processing Systems, NIPS’18, 2018, p. 6106–6116
work page 2018
-
[41]
E. Bagdasaryan, A. Veit, Y . Hua, D. Estrin, V . Shmatikov, How to backdoor federated learning, in: Interna- tional Conference on Artificial Intelligence and Statistics, PMLR, 2020, pp. 2938–2948
work page 2020
- [42]
-
[43]
V . Shejwalkar, A. Houmansadr, Manipulating the byzan- tine: Optimizing model poisoning attacks and defenses for federated learning, in: NDSS, 2021
work page 2021
- [44]
-
[45]
M. Fredrikson, S. Jha, T. Ristenpart, Model inversion at- tacks that exploit confidence information and basic coun- termeasures, in: ACM SIGSAC conference on computer and communications security, 2015, pp. 1322–1333. 16
work page 2015
-
[46]
X. Guo, Z. Liu, J. Li, J. Gao, B. Hou, C. Dong, T. Baker, V eri fl: Communication-efficient and fast verifiable aggre- gation for federated learning, IEEE Transactions on Infor- mation Forensics and Security 16 (2020) 1736–1751
work page 2020
-
[47]
Z. Wang, Z. Chang, J. Hu, X. Pang, J. Du, Y . Chen, K. Ren, Breaking secure aggregation: Label leakage from aggregated gradients in federated learning, in: IEEE IN- FOCOM 2024-IEEE Conference on Computer Communi- cations, IEEE, 2024, pp. 151–160
work page 2024
-
[48]
S. Liu, J. Ren, R. Meng, X. Yan, Y . Miao, Z. Liu, J. Peng, Y . Zou, Z. Wang, H. Li, et al., Secure and robust feder- ated learning under dual-server architecture in internet of things, IEEE Internet of Things Journal (2025)
work page 2025
-
[49]
A. I. C. Divisors, Order-preserving encryption using ap- proximate integer common divisors, in: Data Privacy Management, Cryptocurrencies and Blockchain Technol- ogy: ESORICS International Workshops, Springer, 2017, p. 257
work page 2017
-
[50]
CrowdGuard: Federated Backdoor Detection in Federated Learning
P. Rieger, T. Krauß, M. Miettinen, A. Dmitrienko, A.- R. Sadeghi, Crowdguard: Federated backdoor detection in federated learning, arXiv preprint arXiv:2210.07714 (2022)
work page internal anchor Pith review Pith/arXiv arXiv 2022
-
[51]
T. D. Nguyen, P. Rieger, H. Chen, H. Yalame, H. Möller- ing, H. Fereidooni, S. Marchal, M. Miettinen, A. Mirho- seini, S. Zeitouni, et al., FLAME: Taming backdoors in federated learning, in: 31st USENIX Security Sympo- sium, 2022, pp. 1415–1432
work page 2022
-
[52]
A. Krizhevsky, G. Hinton, et al., Learning multiple layers of features from tiny images (2009)
work page 2009
- [53]
-
[54]
K. He, X. Zhang, S. Ren, J. Sun, Deep residual learning for image recognition, in: Computer vision and pattern recognition, 2016, pp. 770–778
work page 2016
-
[55]
LEAF: A Benchmark for Federated Settings
S. Caldas, S. M. K. Duddu, P. Wu, T. Li, J. Koneˇcn`y, H. B. McMahan, V . Smith, A. Talwalkar, Leaf: A benchmark for federated settings, arXiv preprint arXiv:1812.01097 (2018)
work page internal anchor Pith review Pith/arXiv arXiv 2018
-
[56]
S. Hochreiter, J. Schmidhuber, Long short-term memory, Neural computation 9 (8) (1997) 1735–1780. Appendix A. PRoVeFL-enabled MESAS (Figure A.10). MESAS is implemented under PRoVeFL by privately com- puting all statistical distances from perturbed client updates and performing the clustering and pruning in the plaintext domain. Each server privately compu...
work page 1997
-
[57]
Servers publishe(g 0,g 0)di j,kl as a proof for the correct com- putation, for alld i ∈ {cos i,euc i,count i,var i}
-
[58]
Peer Servers: For every coordinateℓand pair (i,j) verify, e(hikℓ (h jkℓ )−1,h ikℓ (h jkℓ )−1) ?=e(g 0,g 0)di j,kl
-
[59]
Abort on the first mismatch. Plaintext operations 9.Euclidean and cosine distances:Now, one of the servers (assuming at least one is honest) compute the total Euclidean and cosine distance. The distances are scaled up byr. How- ever, they preserve order, which is sufficient. 10.Min/Max/COUNT:From all the decrypted count vectors, Min and Max can be calcula...
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.