arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

EIFL:在联邦学习中针对不可信服务器高效保护全局模型的隐私与完整性

EIFL: Efficiently Protecting Global Model Privacy and Integrity Against an Untrusted Server in Federated Learning

Zehui Liao, Qiang Li, Binghui Wang

arXiv 2610.11511首次发表:更新:

发表机构

College of Computer Science and Technology, Jilin University; Department of Computer Science, Illinois Institute of Technology(吉林大学计算机科学与技术学院; 伊利诺伊理工学院计算机科学系)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

EIFL是一种联邦学习方法,通过两阶段聚合与对称加密保护全局模型隐私,以向量内积验证方法解决辅助信息泄露漏洞,且开销优于现有方案。

AI 中文摘要

联邦学习(FL)通常采用服务器-客户端架构,服务器聚合客户端的本地模型(即输入)并将聚合后的全局模型(即输出)返回给客户端。不可信服务器可能返回被篡改的全局模型,以破坏输出完整性。一些现有方案专注于验证输出完整性,但这些方案大多依赖客户端之间预先协商一组相同的辅助信息,并对服务器保密,这种依赖会产生验证漏洞:若辅助信息泄露,验证方法可能被规避。此外,在一些隐私敏感场景(如商业联邦学习)中,全局模型需要对不可信服务器保密,但仅有少数工作在解决验证漏洞的同时实现了输出隐私,且代价是过高的计算与通信开销。为同时应对这些挑战,我们提出一种名为EIFL的新型可证明隐私保护联邦学习方法。具体而言,我们采用两阶段聚合并结合对称加密来保护输出隐私;为解决验证漏洞,我们提出一种基于向量内积的高效输出完整性验证方法,以及一种供客户端协商辅助信息的随机向量生成方法。EIFL创新性地将辅助信息与输出完整性绑定,消除了对服务器保密辅助信息的需求,且在验证阶段通过简单的重发操作对客户端掉线具有鲁棒性。评估结果验证,EIFL在计算与通信开销方面优于最先进的方案。

英文摘要

Federated learning (FL) typically adopts a server-client architecture, where the server aggregates clients' local models (i.e., the input) and returns the aggregated global model (i.e., the output) to clients. An untrusted server may return a tampered global model to compromise the output integrity. Some existing schemes focus on verifying the output integrity. However, these schemes mostly rely on clients pre-negotiating a set of identical auxiliary information among themselves and keeping it confidential from the server. This dependency creates a verification vulnerability: if the auxiliary information is leaked, the verification method may be circumvented. Additionally, in some privacy-sensitive scenarios (e.g., commercial federated learning), the global model may need to be kept confidential from an untrusted server. However, only a few works achieve the output privacy while addressing verification vulnerability, at the cost of prohibitive computation and communication overhead. To address these challenges simultaneously, we propose a novel provably privacy-preserving FL method called EIFL. Specifically, we adopt a two-stage aggregation and combine it with symmetric encryption to protect the output privacy. To address the verification vulnerability, we propose an efficient verification method based on vector inner product for output integrity, and a random vector generation method for clients to agree on auxiliary information. EIFL innovatively binds the auxiliary information to the output integrity, and eliminates the need to keep the auxiliary information confidential from the server. Moreover, EIFL is robust against client dropout during the verification phase through a simple resending operation. Evaluation results validate the advantages of EIFL over state-of-the-art schemes in terms of computation and communication overhead.

Commentssubmitted to IEEE Transactions on Dependable and Secure Computing

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑