🤖 AI Summary
This work addresses the persistent risk of privacy leakage in model updates within clinical EEG federated learning. It proposes a privacy-preserving federated learning framework centered on masked secure aggregation, integrating graph-based communication, threshold secret sharing, local update clipping, and a dropout-resilient mechanism. The framework supports both semi-honest and malicious aggregator settings and optionally incorporates privacy-preserving record linkage for initialization and auxiliary notary-based verification to balance security with practicality. Experiments on the TUH EEG dataset using the Flower framework demonstrate that the approach effectively conceals individual model updates: the semi-honest variant incurs the lowest overhead, while the malicious and notary-augmented variants offer stronger consistency guarantees and lightweight verifiability.
📝 Abstract
Federated learning enables multiple institutions to train shared models without exchanging raw clinical EEG data, but it does not fully prevent privacy leakage from individual model updates. This paper presents a privacy-preserving federated learning framework for clinical EEG data using masking-based secure aggregation as the core protection mechanism. The framework combines graph-based communication, threshold secret sharing, dropout-resilient aggregation, local update clipping, an optional Bloom filter-based privacy-preserving record-linkage initialization module, and auxiliary-notary-based verifiability. It supports both semi-honest and malicious aggregation settings and is implemented using the Flower federated learning framework. The secure-aggregation variants are evaluated in a simulated cross-silo healthcare setting using TUH EEG-derived data under different client configurations. Under the stated assumptions, the secure variants hide individual updates from the aggregation server. The results show that these variants remain compatible with federated model training, although malicious-setting safeguards and lightweight consistency-checking mechanisms introduce additional computation, communication, and round-duration overhead. The semi-honest variant provides the lowest overhead among the secure configurations, while malicious and auxiliary-notary variants offer stronger consistency, integrity, and lightweight verification support at higher cost.