用可验证函数加密防恶意客户端,保护联邦学习隐私与安全
VFEFL: Privacy-Preserving Federated Learning against Malicious Clients via Verifiable Functional Encryption
- 提出跨密文去中心化可验证函数加密方案,支持多维密文关系验证
- 设计鲁棒聚合规则,有效识别恶意客户端并保障模型精度
- 无需双服务器或可信第三方,实现高隐私性与系统可靠性
联邦学习是一种分布式学习范式,可在不暴露本地数据的前提下实现协同模型训练,从而保护数据隐私。然而,其也带来新威胁:模型反演攻击使明文传输本地模型变得不安全,而分布式特性使其特别易受恶意客户端攻击。为此,本文提出基于可验证函数加密的隐私保护联邦学习框架(VFEFL),无需非共谋双服务器假设或额外可信第三方。具体而言,提出一种新型跨密文去中心化可验证函数加密(CC-DVFE)方案,支持对多维密文间特定关系的验证,并给出形式化定义、安全模型与安全证明。基于该方案,设计包含新型鲁棒聚合规则的隐私保护联邦学习框架,可在对抗环境下有效训练高精度模型。最后,提供形式化分析与实证评估,结果表明本方法在实现隐私保护、鲁棒性、可验证性与模型保真度的同时,消除了对非共谋双服务器或可信第三方的依赖。
原文摘要 · Abstract (English)
Federated learning is a promising distributed learning paradigm that enables collaborative model training without exposing local client data, thereby protecting data privacy. However, it also brings new threats and challenges. The advancement of model inversion attacks has rendered the plaintext transmission of local models insecure, while the distributed nature of federated learning makes it particularly vulnerable to attacks raised by malicious clients. To protect data privacy and prevent malicious client attacks, this paper proposes a privacy-preserving Federated Learning framework based on Verifiable Functional Encryption (VFEFL), without a non-colluding dual-server assumption or additional trusted third-party. Specifically, we propose a novel Cross-Ciphertext Decentralized Verifiable Functional Encryption (CC-DVFE) scheme that enables the verification of specific relationships over multi-dimensional ciphertexts. This scheme is formally treated, in terms of definition, security model and security proof. Furthermore, based on the proposed CC-DVFE scheme, we design a privacy-preserving federated learning framework that incorporates a novel robust aggregation rule to detect malicious clients, enabling the effective training of high-accuracy models under adversarial settings. Finally, we provide the formal analysis and empirical evaluation of VFEFL. The results demonstrate that our approach achieves the desired privacy protection, robustness, verifiability and fidelity, while eliminating the reliance on non-colluding dual-server assumption or trusted third parties required by most existing methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。