Pith. sign in

REVIEW 3 major objections 5 minor 59 references

PRoVeFL lets federated learning keep client updates private, filter poisoned ones with complex robust rules, and verify the server did the aggregation correctly, all under multi-server multi-key encryption that is far faster than prior dist

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-11 01:47 UTC pith:JXHWUTPP

load-bearing objection Useful multi-server hybrid for complex robust FL rules with real speedups, but the post-decryption privacy claim does not hold for the core primitives. the 3 major comments →

arxiv 2607.06612 v1 pith:JXHWUTPP submitted 2026-07-07 cs.CR cs.AI

PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning

classification cs.CR cs.AI
keywords federated learningByzantine-robust aggregationmulti-key homomorphic encryptionverifiable aggregationprivacy-preserving machine learningsecure multi-party computationpoisoning attacks
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Federated learning usually forces a painful choice: hide client updates from the server, or detect and remove poisoned updates, or let clients check that the server aggregated honestly. Existing secure systems either support only crude filters such as norm clipping, leak information, or become impractically slow because almost everything must stay encrypted. PRoVeFL claims that a small set of servers holding shares of a multi-key fully homomorphic encryption key, plus a jointly sampled random multiplicative mask, can break the trade-off. Clients send encrypted shares of their updates; servers perform the heavy statistical work of rules such as Krum, Trimmed Mean or FLTrust partly in the clear on masked values, then reassemble a correct global model that any honest server can cryptographically vouch for. The result is a modular framework that is private against all-but-one colluding servers, robust against malicious clients, and verifiable, while running up to two orders of magnitude faster than the closest prior systems that offer comparable distributed-trust guarantees.

Core claim

A multi-server architecture using multi-key fully homomorphic encryption, combined with a secret random multiplicative mask that servers apply to client updates before collaborative decryption, lets complex Byzantine-robust aggregation rules be evaluated largely in the plaintext domain without revealing the underlying updates, while commitment checks give every honest server a way to abort if any other server cheats.

What carries the argument

The jointly generated encrypted random mask Enc(r) that each client multiplies into its update shares; after threshold decryption only the masked intermediate statistics appear, preserving order and relative magnitudes so that sorting, selection and scoring steps of Krum, Trimmed Mean, FLTrust or MESAS can finish in the clear.

Load-bearing premise

Security collapses if every server is dishonest or if the jointly sampled mask becomes known to a coalition of clients and the remaining servers, because the masked intermediate values would then unmask honest clients' updates.

What would settle it

Run the same Krum or Trimmed-Mean aggregation both in the clear and inside PRoVeFL on identical poisoned updates; if the selected global model or the set of filtered clients differs, or if an honest server accepts a forged aggregate that fails the commitment check, the central claim fails.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Complex robust aggregators that previously required cleartext updates can now be used inside privacy-preserving federated learning without redesigning their statistical logic.
  • Clients need only trust that at least one of a small number of servers is honest; they no longer need a single trusted aggregator or expensive zero-knowledge proofs for every coordinate.
  • Communication and computation scale with the number of servers rather than forcing every client into heavy multi-party computation, making larger participant pools practical.
  • The same hybrid mask-and-decrypt pattern can be reused for any aggregation rule whose decisions depend only on order, sign or relative magnitude of masked statistics.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • The same mask-plus-threshold-decryption pattern could be applied to other distributed statistics beyond federated learning, such as secure median or top-k selection in multi-party analytics.
  • If the additive blinding layer is strengthened further, the protocol might tolerate a larger fraction of colluding clients without changing the server-side primitives.
  • The modular design suggests a practical path for vendors who already run multi-party secure aggregation to swap in richer robust rules without rewriting the entire stack.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. PRoVeFL is a multi-server federated-learning framework that aims to provide client-update privacy (via multi-key CKKS-style FHE under an at-least-one-honest-server assumption), Byzantine-robust aggregation for complex rules (Krum, Trimmed Mean, FLTrust, MESAS, etc.), and peer-server verifiability of the aggregation steps via discrete-log commitments. Clients encrypt masked shares under a jointly generated multiplicative mask Enc(r); servers perform method-specific homomorphic operations, collaboratively decrypt only the masked intermediate statistics, verify them against client commitments, and finish selection/filtering in the plaintext domain. Empirical evaluation reports large speed-ups versus Prio and ELSA under a relaxed L∞ defense and shows that the robust rules retain accuracy under Trim and Backdoor attacks when run inside the encrypted pipeline.

Significance. If the privacy, robustness and verifiability claims hold simultaneously, the work would be a useful systems contribution: it is one of the few frameworks that supports non-trivial Byzantine rules (pairwise distances, coordinate-wise sorting, cosine similarity) rather than only norm clipping, while remaining faster than prior distributed-trust baselines. The modular primitive set (LA/PSE/SCO/SF), the concrete instantiations (Figs. 4–6, A.10), the SEAL implementation, and the runtime/communication tables are concrete engineering assets. The security reductions to Ring-LWE and DLP (Theorems 1–3) are the right style of argument for this literature, even if their statements need tightening.

major comments (3)
  1. Theorem 2 (Appendix C) and the privacy claim of §3.1.1 are not established for the core primitives. The hybrid H1 is defined as d'_i = f(r', s_i) (still a function of the secret updates/distances/inner products) yet the proof text asserts that the simulator can output independent random vectors without knowing any client secret; the two statements contradict. Concretely, for FLTrust (Fig. 6) the opened vectors satisfy d_i = r·(u_i ⊙ u_0) and e_i = r/∥u_i∥, so any server recovers the direction of each u_i and, when e_i is also opened, recovers r and therefore the full u_i. For Trimmed-Mean the full set of coordinate-wise differences d_ij = r·(u_i-u_j) determines every update up to global scale and translation; for Krum the scaled distance matrix determines the configuration up to isometry and scale. The additive blinding δ of §4.2.5 does not close these algebraic channels. The claimed pos
  2. The experimental comparison in Tables 3–4 is restricted to a relaxed L∞ / norm-clipping defense because ELSA and Prio do not support Krum/Trimmed-Mean/FLTrust. The headline 100 imes/10 imes speed-ups therefore do not apply to the complex rules that constitute the paper's main algorithmic contribution. Either the complex rules must be benchmarked against the closest available secure baselines (or against a pure-FHE baseline), or the abstract and §6.2.3 claims must be restated so that they match the evaluated defense.
  3. The threat model (§3.1) and the strengthened collusion discussion (§4.2.5) assume that at least one server remains honest and will abort on failed checks, yet the final selected or averaged model is eventually unmasked for the clients. Once r is effectively known (or once a selected plaintext update is published), earlier masked intermediates become fully recoverable. The manuscript never states what is revealed to clients at the end of a round, nor how the final global model is protected from the same algebraic recovery that already works on the intermediate view. This gap must be closed for the privacy guarantee to be well-defined.
minor comments (5)
  1. Table 1 marks PRoVeFL with ✓✓ for robustness coverage; the footnote is helpful but the table itself should list which concrete rules are actually implemented and evaluated.
  2. Figures 7–8 and the runtime-breakdown plots (D.11–D.12) would be clearer with error bars or min/max ranges; the text only says “averaged over 5 runs.”
  3. Notation for the split dimension N/m versus the full dimension N is overloaded in several places (e.g., FLTrust trust-score formula); a short notation table would help.
  4. The polynomial-modulus degree is fixed at 32768; a short sensitivity note on packing efficiency versus security level would strengthen the systems claims.
  5. A few typos remain (e.g., “analsze” in §6.1.2, “The trimmed-mean” capitalization in §4.4.2).

Circularity Check

0 steps flagged

No circularity: PRoVeFL is a self-contained cryptographic construction and empirical evaluation; privacy/robustness/verifiability claims reduce to standard assumptions (RLWE, DLP) and hybrid masking, not to fitted inputs or self-definitional loops.

full rationale

The paper's load-bearing claims are (1) a multi-server MK-FHE protocol that offloads order-preserving statistics to plaintext after multiplicative masking by a joint secret r, (2) instantiation of existing aggregation rules (Krum, Trimmed-Mean, FLTrust, MESAS) via the four primitives LA/PSE/SCO/SF, (3) commitment-based verification under DLP, and (4) measured runtime gains versus Prio/ELSA/RoFL. Theorems 1–3 reduce confidentiality and integrity to decisional Ring-LWE and discrete-log hardness; the hybrid argument of Theorem 2 (even if its simulator claim is imperfect) does not define the target privacy property in terms of itself. No free parameters are fitted to data and then re-predicted; no uniqueness theorem is imported from overlapping authors to forbid alternatives; no known empirical pattern is merely renamed. Ordinary background citations (including one prior paper by a co-author) are not load-bearing for the central construction or the speedup numbers. The work is therefore free of the six enumerated circularity patterns.

Axiom & Free-Parameter Ledger

2 free parameters · 5 axioms · 1 invented entities

The result rests on standard lattice and discrete-log hardness, the multi-server one-honest-server trust model, and the cryptographic correctness of multi-key CKKS-style operations and commitment checks. No data-fitted free parameters drive the central security or speedup claims. The main invented construct is the protocol itself (shared mask + hybrid offload + verification), not a new physical entity.

free parameters (2)
  • FHE polynomial modulus degree = 32768
    Set to 32768 for experiments; affects packing, noise, and runtime but is a standard SEAL parameter choice, not fitted to claim the security theorems.
  • Additive blinding bound B and mask size relative to epsilon and lambda
    B < r·ε/2 and B > 2^λ (with r > 2^{λ+1}/ε) chosen to preserve order while blocking mask recovery (§4.2.5); security-parameter engineering, not data-fit.
axioms (5)
  • standard math Decisional Ring-LWE hardness for multi-key FHE confidentiality
    Invoked as the foundation for ciphertext privacy (Section 2.2.1; Theorem 1).
  • standard math Discrete Logarithm Problem hardness in the commitment group
    Underpins soundness of exponentiation/pairing checks for aggregation integrity (Section 2.3; Theorem 3).
  • domain assumption At least one of the m aggregation servers is honest and will abort on failed verification
    Core threat model for privacy and verifiability (Section 3.1; Table 1; Theorems 1–3).
  • domain assumption Jointly generated multiplicative mask r remains unknown to any single server and to client–server coalitions short of all servers
    Required so that decrypted masked statistics do not reveal plaintexts while preserving order (Section 4.2; Theorem 2).
  • ad hoc to paper Target Byzantine-robust rules can be expressed via linear aggregation, pairwise polynomials, secure comparison/ordering, and selection/filtering under multiplicative masking
    Stated as the modularity condition; authors note Min-Max/Min-Sum-style rules may not fit (Section 4.3–4.4; Limitations 6.2.5).
invented entities (1)
  • PRoVeFL hybrid multi-server aggregation pipeline (shared Enc(r) mask + plaintext offload of SCO/SF + peer commitment verification) no independent evidence
    purpose: Enable complex robust FL rules under multi-key FHE with practical cost and verifiability under one honest server
    The protocol composition is the paper's main construct; components are standard but the hybrid offload pattern is the contribution.

pith-pipeline@v1.1.0-grok45 · 31319 in / 3284 out tokens · 31494 ms · 2026-07-11T01:47:38.127307+00:00 · methodology

0 comments
read the original abstract

Federated Learning (FL) enables multiple clients to collaboratively train machine learning models while retaining data locality, thereby enhancing user privacy. However, traditional FL frameworks rely on a centralized aggregation server and assume honest-but-curious clients, making them susceptible to both server-side inference and client-side poisoning attacks. Although recent work has explored secure and Byzantine-resilient FL protocols, they face a fundamental trade-off among privacy, integrity, and verifiability, and incur substantial computational and communication overhead due to the heavy use of cryptographic primitives. In this work, we propose PRoVeFL-a novel, modular FL framework that is Privacy-preserving, Byzantine-Robust, and ensures Verifiable aggregation. PRoVeFL employs multiple servers leveraging multi-key fully homomorphic encryption. Each client encrypts its local model updates and distributes encrypted shares to all servers. This design enables a hybrid computation model in which ciphertext operations are carefully offloaded to the plaintext domain under strict privacy constraints to efficiently evaluate complex statistical aggregation rules. PRoVeFL is compatible with a wide range of state-of-the-art Byzantine-robust aggregation algorithms (e.g., Krum, Trimmed Mean, FLTrust, norm clipping, MESAS, and more) and further enhances them with verifiability mechanisms that require minimal trust in at least one honest server. We evaluate it across different settings and demonstrate its scalability with varying numbers of parameters and participants. PRoVeFL improves runtime over the prior works, Prio and ELSA, based on distributed trust with comparable security guarantees, up to 100x and 10x, respectively.

Figures

Figures reproduced from arXiv: 2607.06612 by Anil Kumar Pradhan, Carsten Maple, Graham Cormode, Harsh Kasyap, Ugur Ilker Atmaca.

Figure 1
Figure 1. Figure 1: Our Proposed Framework CrowdGuard, and FLAME. We intentionally selected these al￾gorithms because they cover various types of operations, in￾cluding statistical operations, client-provided private input, and server-provided public input. 4.1. System Model and Notation We use the following notation throughout this section. Let n denote the number of clients and f the upper bound on Byzan￾tine (malicious) cl… view at source ↗
Figure 2
Figure 2. Figure 2: Distributed Generation of Mask and Commitment Generator (de [PITH_FULL_IMAGE:figures/full_fig_p007_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: PRoVeFL Working Mechanism. publicly verifiable proof. The peer server verifies these proofs by checking, for every coordinate ℓ, that the pairing or group relation holds, e.g., g di,ℓ ? = hi,ℓ (or the corresponding additive check for a method) holds. If any check fails, then the honest server refuses to release its decrypted share, causing the proto￾col to abort and thus prevent malformed aggregation. 4.2.… view at source ↗
Figure 4
Figure 4. Figure 4: Instantiation of Krum in PRoVeFL the pairing e(·, ·) we obtain e [PITH_FULL_IMAGE:figures/full_fig_p009_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: Trimmed-Mean in PRoVeFL. Upon receiving the masked ciphertexts ci,k = Encpk(r ui,k) for every client i, each server k homomorphically subtracts ev￾ery ordered pair (i, j) to obtain the encrypted coordinate-wise differences Encpk(di j,k) = (ci,k − cj,k), via PSE. A collabora￾tive decryption then reveals only the obfuscated values di j,k = r(ui,k − uj,k). For each coordinate ℓ, the honest peer checks the rel… view at source ↗
Figure 6
Figure 6. Figure 6: FLTrust in PRoVeFL. six statistical operations, including cosine similarity, Euclidean distance, count, variance, maximum, and minimum (PSE). Sub￾sequently, it performs multiple clustering-based statistical tests to prune (LA, SF). Since MESAS covers the full set of statisti￾cal operations, we describe how to tailor it to PRoVeFL. Details can be referred to in Appendix A. 5. Security Analysis This section … view at source ↗
Figure 7
Figure 7. Figure 7: Computation time vs. no. of clients (and servers) for di [PITH_FULL_IMAGE:figures/full_fig_p013_7.png] view at source ↗
Figure 8
Figure 8. Figure 8: Computation time vs. no. of clients (with 2 servers) for di [PITH_FULL_IMAGE:figures/full_fig_p013_8.png] view at source ↗
Figure 9
Figure 9. Figure 9: Accuracy under Trim and Backdoor Attacks for di [PITH_FULL_IMAGE:figures/full_fig_p013_9.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

59 extracted references · 59 canonical work pages · 5 internal anchors

  1. [1]

    H. B. McMahan, E. Moore, D. Ramage, B. A. y Arcas, Federated learning of deep networks using model averag- ing, CoRR abs/1602.05629 (2016).arXiv:1602.05629. URLhttp://arxiv.org/abs/1602.05629

  2. [2]

    McMahan, E

    B. McMahan, E. Moore, D. Ramage, S. Hampson, B. A. y Arcas, Communication-efficient learning of deep net- works from decentralized data, in: Artificial Intelligence and Statistics, PMLR, 2017, pp. 1273–1282

  3. [3]

    Z. Tian, Y . Ding, X. Yu, E. Gong, J. Liu, K. Ren, Towards collaborative anti-money laundering among financial in- stitutions, in: Web Conference, 2025, pp. 4722–4733

  4. [4]

    Mothukuri, R

    V . Mothukuri, R. M. Parizi, S. Pouriyeh, Y . Huang, A. De- hghantanha, G. Srivastava, A survey on security and pri- vacy of federated learning, Future Generation Computer Systems 115 (2021) 619–640

  5. [5]

    M. Nasr, R. Shokri, A. Houmansadr, Comprehensive pri- vacy analysis of deep learning: Passive and active white- box inference attacks against centralized and federated learning, in: IEEE symposium on security and privacy (SP), IEEE, 2019, pp. 739–753

  6. [6]

    Manna, H

    D. Manna, H. Kasyap, S. Tripathy, Milsa: Model interpre- tation based label sniffing attack in federated learning, in: International conference on information systems security, Springer, 2022, pp. 139–154

  7. [7]

    C. Fu, X. Zhang, S. Ji, J. Chen, J. Wu, S. Guo, J. Zhou, A. X. Liu, T. Wang, Label inference attacks against verti- cal federated learning, in: 31st USENIX security sympo- sium, 2022, pp. 1397–1414

  8. [8]

    M. Fang, X. Cao, J. Jia, N. Gong, Local model poisoning attacks to Byzantine-Robust federated learning, in: 29th USENIX security symposium, 2020, pp. 1605–1622

  9. [9]

    Tolpegin, S

    V . Tolpegin, S. Truex, M. E. Gursoy, L. Liu, Data poison- ing attacks against federated learning systems, in: 25th European symposium on research in computer security, Springer, 2020, pp. 480–501

  10. [10]

    Kasyap, S

    H. Kasyap, S. Tripathy, Sine: Similarity is not enough for mitigating local model poisoning attacks in federated learning, Transactions on Dependable and Secure Com- puting 21 (5) (2024) 4481–4494

  11. [11]

    Rathee, C

    M. Rathee, C. Shen, S. Wagh, R. A. Popa, Elsa: Secure aggregation for federated learning with malicious actors, in: Symposium on Security and Privacy (SP), IEEE, 2023, pp. 1961–1979

  12. [12]

    H. Hu, Z. Salcic, L. Sun, G. Dobbie, X. Zhang, Source inference attacks in federated learning, in: International Conference on Data Mining (ICDM), IEEE, 2021, pp. 1102–1107

  13. [13]

    R. Wang, X. Wang, H. Chen, J. Decouchant, S. Picek, N. Laoutaris, K. Liang, Mudguard: Taming malicious majorities in federated learning using privacy-preserving byzantine-robust clustering, ACM Conference on Mea- surement and Analysis of Computing Systems 8 (3) (2024) 1–41

  14. [14]

    J. Bell, A. Gascón, T. Lepoint, B. Li, S. Meiklejohn, M. Raykova, C. Yun, ACORN: input validation for se- cure aggregation, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 4805–4822

  15. [15]

    Roy Chowdhury, C

    A. Roy Chowdhury, C. Guo, S. Jha, L. van der Maaten, Eiffel: Ensuring integrity for federated learning, in: ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 2535–2549

  16. [16]

    J. Gao, B. Hou, X. Guo, Z. Liu, Y . Zhang, K. Chen, J. Li, Secure aggregation is insecure: Category inference attack on federated learning, IEEE Transactions on Dependable and Secure Computing 20 (1) (2021) 147–160

  17. [17]

    G. Xu, H. Li, S. Liu, K. Yang, X. Lin, Verifynet: Secure and verifiable federated learning, IEEE Transactions on Information Forensics and Security 15 (2019) 911–926

  18. [18]

    H. Gao, N. He, T. Gao, Sverifl: Successive verifiable fed- erated learning with privacy-preserving, Information Sci- ences 622 (2023) 98–114

  19. [19]

    Gentry, A fully homomorphic encryption scheme, Stanford university, 2009

    C. Gentry, A fully homomorphic encryption scheme, Stanford university, 2009

  20. [20]

    J. H. Cheon, A. Kim, M. Kim, Y . Song, Homomorphic en- cryption for arithmetic of approximate numbers, in: Ad- vances in cryptology–ASIACRYPT international confer- ence on the theory and applications of cryptology and in- formation security, Springer, 2017, pp. 409–437

  21. [21]

    W. Jin, Y . Yao, S. Han, J. Gu, C. Joe-Wong, S. Ravi, S. Avestimehr, C. He, Fedml-he: An efficient homomorphic-encryption-based privacy-preserving fed- erated learning system, arXiv preprint arXiv:2303.10837 (2023). 15

  22. [22]

    Ma, S.-A

    J. Ma, S.-A. Naas, S. Sigg, X. Lyu, Privacy-preserving federated learning based on multi-key homomorphic en- cryption, International Journal of Intelligent Systems 37 (9) (2022) 5880–5901

  23. [23]

    W. Du, M. Li, L. Wu, Y . Han, T. Zhou, X. Yang, A efficient and robust privacy-preserving framework for cross-device federated learning, Complex & Intelligent Systems 9 (5) (2023) 4923–4937

  24. [24]

    Gehlhar, F

    T. Gehlhar, F. Marx, T. Schneider, A. Suresh, T. Wehrle, H. Yalame, Safefl: Mpc-friendly framework for private and robust federated learning, in: IEEE Security and Pri- vacy Workshops (SPW), IEEE, 2023, pp. 69–76

  25. [25]

    Franzese, A

    N. Franzese, A. Dziedzic, C. A. Choquette-Choo, M. R. Thomas, M. A. Kaleem, S. Rabanser, C. Fang, S. Jha, N. Papernot, X. Wang, Robust and actively secure server- less collaborative learning, Advances in Neural Informa- tion Processing Systems 36 (2023) 39504–39528

  26. [26]

    Blanchard, E

    P. Blanchard, E. M. El Mhamdi, R. Guerraoui, J. Stainer, Machine learning with adversaries: Byzantine tolerant gradient descent, in: Neural Information Processing Sys- tems, 2017, pp. 118–128

  27. [27]

    D. Yin, Y . Chen, R. Kannan, P. Bartlett, Byzantine-robust distributed learning: Towards optimal statistical rates, in: International Conference on Machine Learning, PMLR, 2018, pp. 5650–5659

  28. [28]

    X. Cao, M. Fang, J. Liu, N. Gong, Fltrust: Byzantine- robust federated learning via trust bootstrapping, in: NDSS, 2021

  29. [29]

    Krauß, A

    T. Krauß, A. Dmitrienko, Mesas: Poisoning defense for federated learning resilient against adaptive attackers, in: ACM SIGSAC Conference on Computer and Communi- cations Security, 2023, pp. 1526–1540

  30. [30]

    J. Tang, H. Xu, H. Liao, Y . Zhou, Seaflame: Communication-efficient secure aggregation for feder- ated learning against malicious entities, IACR Transac- tions on Cryptographic Hardware and Embedded Systems 2025 (2) (2025) 69–93

  31. [31]

    R. Xu, B. Li, C. Li, J. B. Joshi, S. Ma, J. Li, Tapfed: Threshold secure aggregation for privacy-preserving fed- erated learning, IEEE Transactions on Dependable and Secure Computing 21 (5) (2024) 4309–4323

  32. [32]

    J. Liu, X. Li, X. Liu, H. Zhang, Y . Miao, R. H. Deng, Defendfl: A privacy-preserving federated learning scheme against poisoning attacks, IEEE Transactions on Neural Networks and Learning Systems (2024)

  33. [33]

    R. Ma, K. Hwang, M. Li, Y . Miao, Trusted model aggre- gation with zero-knowledge proofs in federated learning, IEEE Transactions on Parallel and Distributed Systems (2024)

  34. [34]

    J. Tang, H. Xu, M. Wang, T. Tang, C. Peng, H. Liao, A flexible and scalable malicious secure aggregation proto- col for federated learning, IEEE Transactions on Informa- tion Forensics and Security (2024)

  35. [35]

    RoFL: Robustness of Secure Federated Learning

    L. Burkhalter, H. Lycklama, A. Viand, N. Küchler, A. Hithnawi, Rofl: Attestable robustness for secure feder- ated learning, arXiv preprint arXiv:2107.03311 21 (2021)

  36. [36]

    Corrigan-Gibbs, D

    H. Corrigan-Gibbs, D. Boneh, Prio: Private, robust, and scalable computation of aggregate statistics, in: 14th USENIX symposium on networked systems design and implementation (NSDI 17), 2017, pp. 259–282

  37. [37]

    Addanki, K

    S. Addanki, K. Garbe, E. Jaffe, R. Ostrovsky, A. Poly- chroniadou, Prio+: Privacy preserving aggregate statistics via boolean shares, in: International Conference on Secu- rity and Cryptography for Networks, Springer, 2022, pp. 516–539

  38. [38]

    B. Yin, H. Zhang, J. Lin, F. Kong, L. Yu, Pvfl: Verifiable federated learning and prediction with privacy-preserving, Computers & Security 139 (2024) 103700

  39. [39]

    Huang, G

    Y . Huang, G. Yang, H. Zhou, H. Dai, D. Yuan, S. Yu, Vppfl: A verifiable privacy-preserving federated learning scheme against poisoning attacks, Computers & Security 136 (2024) 103562

  40. [40]

    Shafahi, W

    A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, T. Goldstein, Poison frogs! targeted clean- label poisoning attacks on neural networks, in: Neu- ral Information Processing Systems, NIPS’18, 2018, p. 6106–6116

  41. [41]

    Bagdasaryan, A

    E. Bagdasaryan, A. Veit, Y . Hua, D. Estrin, V . Shmatikov, How to backdoor federated learning, in: Interna- tional Conference on Artificial Intelligence and Statistics, PMLR, 2020, pp. 2938–2948

  42. [42]

    Baruch, M

    G. Baruch, M. Baruch, Y . Goldberg, A little is enough: Circumventing defenses for distributed learning, Ad- vances in Neural Information Processing Systems 32 (2019)

  43. [43]

    Shejwalkar, A

    V . Shejwalkar, A. Houmansadr, Manipulating the byzan- tine: Optimizing model poisoning attacks and defenses for federated learning, in: NDSS, 2021

  44. [44]

    Ganju, Q

    K. Ganju, Q. Wang, W. Yang, C. A. Gunter, N. Borisov, Property inference attacks on fully connected neural net- works using permutation invariant representations, in: ACM SIGSAC conference on computer and communica- tions security, 2018, pp. 619–633

  45. [45]

    Fredrikson, S

    M. Fredrikson, S. Jha, T. Ristenpart, Model inversion at- tacks that exploit confidence information and basic coun- termeasures, in: ACM SIGSAC conference on computer and communications security, 2015, pp. 1322–1333. 16

  46. [46]

    X. Guo, Z. Liu, J. Li, J. Gao, B. Hou, C. Dong, T. Baker, V eri fl: Communication-efficient and fast verifiable aggre- gation for federated learning, IEEE Transactions on Infor- mation Forensics and Security 16 (2020) 1736–1751

  47. [47]

    Z. Wang, Z. Chang, J. Hu, X. Pang, J. Du, Y . Chen, K. Ren, Breaking secure aggregation: Label leakage from aggregated gradients in federated learning, in: IEEE IN- FOCOM 2024-IEEE Conference on Computer Communi- cations, IEEE, 2024, pp. 151–160

  48. [48]

    S. Liu, J. Ren, R. Meng, X. Yan, Y . Miao, Z. Liu, J. Peng, Y . Zou, Z. Wang, H. Li, et al., Secure and robust feder- ated learning under dual-server architecture in internet of things, IEEE Internet of Things Journal (2025)

  49. [49]

    A. I. C. Divisors, Order-preserving encryption using ap- proximate integer common divisors, in: Data Privacy Management, Cryptocurrencies and Blockchain Technol- ogy: ESORICS International Workshops, Springer, 2017, p. 257

  50. [50]

    CrowdGuard: Federated Backdoor Detection in Federated Learning

    P. Rieger, T. Krauß, M. Miettinen, A. Dmitrienko, A.- R. Sadeghi, Crowdguard: Federated backdoor detection in federated learning, arXiv preprint arXiv:2210.07714 (2022)

  51. [51]

    T. D. Nguyen, P. Rieger, H. Chen, H. Yalame, H. Möller- ing, H. Fereidooni, S. Marchal, M. Miettinen, A. Mirho- seini, S. Zeitouni, et al., FLAME: Taming backdoors in federated learning, in: 31st USENIX Security Sympo- sium, 2022, pp. 1415–1432

  52. [52]

    Krizhevsky, G

    A. Krizhevsky, G. Hinton, et al., Learning multiple layers of features from tiny images (2009)

  53. [53]

    LeCun, B

    Y . LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, L. D. Jackel, Backpropagation ap- plied to handwritten zip code recognition, Neural compu- tation 1 (4) (1989) 541–551

  54. [54]

    K. He, X. Zhang, S. Ren, J. Sun, Deep residual learning for image recognition, in: Computer vision and pattern recognition, 2016, pp. 770–778

  55. [55]

    LEAF: A Benchmark for Federated Settings

    S. Caldas, S. M. K. Duddu, P. Wu, T. Li, J. Koneˇcn`y, H. B. McMahan, V . Smith, A. Talwalkar, Leaf: A benchmark for federated settings, arXiv preprint arXiv:1812.01097 (2018)

  56. [56]

    Hochreiter, J

    S. Hochreiter, J. Schmidhuber, Long short-term memory, Neural computation 9 (8) (1997) 1735–1780. Appendix A. PRoVeFL-enabled MESAS (Figure A.10). MESAS is implemented under PRoVeFL by privately com- puting all statistical distances from perturbed client updates and performing the clustering and pruning in the plaintext domain. Each server privately compu...

  57. [57]

    Servers publishe(g 0,g 0)di j,kl as a proof for the correct com- putation, for alld i ∈ {cos i,euc i,count i,var i}

  58. [58]

    Peer Servers: For every coordinateℓand pair (i,j) verify, e(hikℓ (h jkℓ )−1,h ikℓ (h jkℓ )−1) ?=e(g 0,g 0)di j,kl

  59. [59]

    Plaintext operations 9.Euclidean and cosine distances:Now, one of the servers (assuming at least one is honest) compute the total Euclidean and cosine distance

    Abort on the first mismatch. Plaintext operations 9.Euclidean and cosine distances:Now, one of the servers (assuming at least one is honest) compute the total Euclidean and cosine distance. The distances are scaled up byr. How- ever, they preserve order, which is sufficient. 10.Min/Max/COUNT:From all the decrypted count vectors, Min and Max can be calcula...