Asynchronous Secure Federated Learning with Byzantine aggregators

📅 2026-01-08
🏛️ arXiv.org
📈 Citations: 0
Influential: 0
📄 PDF

career value

244K/year
🤖 AI Summary
This work addresses the vulnerability of asynchronous federated learning to malicious aggregators, which can compromise model integrity and client data privacy, thereby threatening system liveness and confidentiality. To counter this, the paper proposes the first asynchronous secure federated learning framework resilient to Byzantine aggregators. The approach leverages a replicated aggregator architecture, decoupled secure aggregation, and differential privacy via Gaussian noise, effectively mitigating Byzantine attacks without requiring consensus among aggregators. Additionally, a participation-balancing strategy is introduced to dynamically harmonize privacy budgets and model bias in asynchronous settings. Experimental results demonstrate that the proposed method maintains competitive training performance while simultaneously ensuring strong privacy guarantees, system liveness, and robustness against adversarial aggregators.

Technology Category

Application Category

📝 Abstract
Privacy-preserving federated averaging is a central approach for protecting client privacy in federated learning. In this paper, we study this problem in an asynchronous communications setting with malicious aggregators. We propose a new solution to provide federated averaging in this model while protecting the client's data privacy through secure aggregation and differential privacy. Our solution maintains the same performance as the state of the art across all metrics. The main contributions of this paper are threefold. First, unlike existing single- or multi-server solutions, we consider malicious aggregation servers that may manipulate the model to leak clients'data or halt computation. To tolerate this threat, we replicate the aggregators, allowing a fraction of them to be corrupted. Second, we propose a new privacy preservation protocol for protocols in asynchronous communication models with Byzantine aggregators. In this protocol, clients mask their values and add Gaussian noise to their models. In contrast with previous works, we use the replicated servers to unmask the models, while ensuring the liveness of training even if aggregators misbehave. Third, the asynchronous communication model introduces new challenges not present in existing approaches. In such a setting, faster clients may contribute more frequently, potentially reducing their privacy and biasing the training. To address this, we introduce an inclusion mechanism that ensures uniform client participation and balanced privacy budgets. Interestingly, the solution presented in this paper does not rely on agreement between aggregators. Thus, we circumvent the known impossibility of consensus in asynchronous settings where processes might crash. Additionally, this feature increases availability, as a consensus-based algorithm only progresses in periods of low latency.
Problem

Research questions and friction points this paper is trying to address.

asynchronous federated learning
Byzantine aggregators
secure aggregation
differential privacy
client privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Asynchronous Federated Learning
Byzantine Aggregators
Secure Aggregation
Differential Privacy
Inclusion Mechanism
🔎 Similar Papers
No similar papers found.