推进用于私有平均聚合的多秘密密钥同态加密
Pushing Forward Multi-Secret-Key Homomorphic Encryption for Private Average Aggregation
浏览论文内容
中文总结 AI 辅助
本研究针对联邦学习私有平均聚合问题,提出基于RLWE同态加密的轻量级多秘密密钥协议,降低了密文扩张与在线开销,性能优于现有方案。
中文摘要 AI 辅助
联邦学习允许多个客户端在保持本地数据集隔离的情况下训练共享模型,但交换的模型更新仍可能泄露敏感信息,使得私有聚合成为实际部署中的核心组件,尤其是在跨筒仓场景中。同态加密天然适配联邦学习的客户端-聚合器通信模式,但传统单密钥部署依赖强非合谋假设。多方同态加密消除了这一限制,不过近期受限解密访问下的攻击要求协同解密时使用方差大的模糊噪声,这会显著增加密文大小和实现复杂度。本研究提出基于RLWE同态加密的轻量级多秘密密钥协议,用于私有平均聚合。我们的构建偏离了常规多方蓝图,避免生成集体公钥,而是让每个客户端用自身密钥加密其更新,生成的密文仍可兼容同态聚合与协同解密。通过在解密过程中显式跟踪并抵消密文噪声,该协议无需使用依赖λ的大模糊噪声。我们用基于BFV的精确变体和基于CKKS的近似变体实例化该构建,在半诚实模型中证明其安全性(针对腐败聚合器及最多L-1个客户端的敌手),并将其通信与运行时性能与最先进的基于MHE的聚合方案对比。结果显示,所提方法大幅降低了密文扩张和在线开销,同时保留了实用的同态聚合性能。
英文摘要
Federated Learning enables multiple clients to train a shared model while keeping their local datasets isolated. However, the exchanged model updates may still leak sensitive information, making private aggregation a central building block in practical deployments, especially in the cross-silo setting. Homomorphic Encryption naturally fits the client--aggregator communication pattern of Federated Learning, but conventional single-key deployments rely on strong non-collusion assumptions. Multiparty Homomorphic Encryption removes this limitation, although recent attacks under restricted decryption access require large-variance smudging noise during collaborative decryption, which significantly increases ciphertext size and implementation complexity. In this work, we propose lightweight multi-secret-key protocols for private average aggregation based on RLWE-based Homomorphic Encryption. Our construction departs from the usual multiparty blueprint by avoiding the generation of a collective public key. Instead, each client encrypts its update under its own secret key, while the resulting ciphertexts remain compatible with homomorphic aggregation and collaborative decryption. By explicitly tracking and cancelling the ciphertext noise during decryption, the protocol removes the need for large $λ$-dependent smudging noise. We instantiate the construction with both exact BFV-based and approximate CKKS-based variants, prove its security in the semi-honest model against an adversary corrupting the aggregator and up to $L-1$ clients, and compare its communication and runtime performance with state-of-the-art MHE-based aggregation. Our results show that the proposed approach substantially reduces ciphertext expansion and online cost, while preserving practical homomorphic aggregation performance.
发表机构
- atlanTTic, Universidade de Vigo(维戈大学 atlanTTic 研究中心)
机构由 AI 辅助整理,请以论文原文为准。