🤖 AI Summary
This study addresses the inherent challenge in federated learning where the opacity of local training impedes client compliance verification and defense against malicious updates. To this end, we propose OPFL, an optimistic verification framework that introduces the first secure multi-party computation (MPC)-based training replay mechanism. By calibrating empirical bounds offline, OPFL resolves the difficulty of verifying gradients that lack bit-level consistency under privacy constraints, effectively distinguishing benign numerical deviations from adversarial manipulations while substantially reducing overhead through randomized sampling audits. Experimental results demonstrate that the proposed framework achieves a 0% attack success rate, outperforming full MPC and zero-knowledge proof baselines with speedups of 98.6× and 625.5×, respectively, while exhibiting strong generalizability of the empirical bounds.
📝 Abstract
Federated learning enables multiple clients to collaboratively train models without sharing their private data. However, the lack of visibility into local training makes it difficult to verify whether clients follow the prescribed training procedure or submit malicious updates, such as model poisoning. A natural approach is to replay client training for verification. However, privacy-preserving replay produces numerical results that cannot be directly matched with local client execution because the two run in different environments. We present OPFL, an optimistic verification framework for privacy-preserving federated learning. To protect data privacy, OPFL performs replay inside secure multi-party computation (MPC). Although gradients computed on MPC and local GPUs are not bitwise identical, we observe that their absolute differences are stable and bounded. OPFL therefore calibrates an empirical boundary offline and uses it to distinguish benign numerical deviations from malicious manipulation. To reduce the cost of expensive MPC replay, OPFL adopts optimistic verification by post auditing only sampled training steps. Experiments on LeNet, BERT, and Qwen show that the boundary generalizes across datasets, input lengths, and GPUs, while achieving $0$\% ASR against model poisoning and PGD-based attacks. On a LeNet workload, at $p=0.01$, OPFL is approximately $98.6\times$ faster than full MPC-based FL and $625.5\times$ faster than ZK-based approach.