AI 中文总结
研究针对联邦学习中模型更新致数据泄露问题,提出基于两层秘密共享的安全聚合协议,结合多种技术消除用户直接通信与服务器数据转发,设计新编码方法减少开销,实验表明该方案在多方面显著优于现有方法。
AI 中文摘要
联邦学习(FL)在保持数据本地性的同时实现协作模型训练。然而,模型更新导致敏感数据泄露的风险促使使用安全聚合协议。现有基于服务器的安全聚合协议通常要求服务器转发用户间共享的敏感数据,增加通信开销并引入潜在安全风险。本文提出基于两层秘密共享的新型安全聚合协议。通过将Shamir秘密共享与使用伪随机函数(PRF)的2选2加法秘密共享相结合,消除用户间直接通信,无需服务器转发数据。还用密钥同态PRF(KhPRF)扩展协议以支持高维数据聚合并应用于FL,实现单服务器一次性安全聚合且无中间数据转发。为减少用户开销,基于中国剩余定理设计新编码方法。实验结果表明,该方案在辅助节点开销方面显著优于现有方法。例如,用户数为100时,通信效率提高近100倍,计算开销降低约17%。当输入长度为\(2^{18}\)时,用户计算时间可减少51%至75%。
英文摘要
Federated Learning (FL) enables collaborative model training while preserving privacy by keeping data local. However, the risk of sensitive data leakage through model updates necessitates the use of secure aggregation protocols. Existing server-based secure aggregation protocols typically require the server to forward sensitive data shared between users, which increases communication overhead and introduces potential security risks. In this work, we propose a novel secure aggregation protocol based on two-layer secret sharing to address these issues. By combining Shamir's Secret Sharing with 2-out-of-2 additive secret sharing using a Pseudo-Random Function (PRF), our protocol eliminates direct communication between users, thereby removing the need for the server to forward data. We further extend the protocol with Key-homomorphic PRF (KhPRF) to support high-dimensional data aggregation and apply it to FL, enabling one-shot secure aggregation with a single server and no intermediary data forwarding. To reduce user overhead, we design a new encoding method based on the Chinese Remainder Theorem for the almost KhPRF-based mask, reducing the number of KhPRF calls and mitigating the model update expansion issue after masking. Experimental results show that our scheme significantly outperforms existing methods in terms of auxiliary node overhead. For instance, when the number of users is 100, our scheme improves communication efficiency by nearly 100 times and reduces computational overhead by approximately 17\%. Moreover, user computation time can be reduced by 51\% to 75\% when the input length is $2^{18}$.
CommentsAccepted by ACM CCS 2026. This is a full version including appendices