🤖 AI Summary
This study addresses verification vulnerabilities in federated learning arising from untrusted servers that tamper with models and leak auxiliary information. To mitigate these threats, this work proposes a secure aggregation scheme that balances privacy preservation with low computational overhead. Methodologically, by integrating two-stage aggregation, symmetric encryption, and vector inner-product verification, the approach innovatively binds auxiliary information to output integrity, thereby eliminating reliance on the confidentiality of such information. The proposed scheme safeguards both the privacy and integrity of the global model while maintaining robustness against client dropouts. Furthermore, it significantly reduces computation and communication costs. Experimental evaluations demonstrate that the overall performance of the proposed method surpasses that of existing baseline approaches.
📝 Abstract
Federated learning (FL) typically adopts a server-client architecture, where the server aggregates clients' local models (i.e., the input) and returns the aggregated global model (i.e., the output) to clients. An untrusted server may return a tampered global model to compromise the output integrity. Some existing schemes focus on verifying the output integrity. However, these schemes mostly rely on clients pre-negotiating a set of identical auxiliary information among themselves and keeping it confidential from the server. This dependency creates a verification vulnerability: if the auxiliary information is leaked, the verification method may be circumvented. Additionally, in some privacy-sensitive scenarios (e.g., commercial federated learning), the global model may need to be kept confidential from an untrusted server. However, only a few works achieve the output privacy while addressing verification vulnerability, at the cost of prohibitive computation and communication overhead. To address these challenges simultaneously, we propose a novel provably privacy-preserving FL method called EIFL. Specifically, we adopt a two-stage aggregation and combine it with symmetric encryption to protect the output privacy. To address the verification vulnerability, we propose an efficient verification method based on vector inner product for output integrity, and a random vector generation method for clients to agree on auxiliary information. EIFL innovatively binds the auxiliary information to the output integrity, and eliminates the need to keep the auxiliary information confidential from the server. Moreover, EIFL is robust against client dropout during the verification phase through a simple resending operation. Evaluation results validate the advantages of EIFL over state-of-the-art schemes in terms of computation and communication overhead.