arXiv:2509.08709cs.LGcs.CR2025-09中稿 · PoPETs 2026被引 2

用可信执行环境实现恶意安全的联邦学习,支持客户端审计。

Securing Private Federated Learning in a Malicious Setting: A Scalable TEE-Based Approach with Client Auditing

  • 服务器端用临时可信模块生成可验证的操作证明
  • 少量客户端参与审计,通信和计算开销小
  • 首次在恶意服务器下保障差分隐私,适合实际部署

在跨设备私有联邦学习中,差分隐私跟随正则化领导者(DP-FTRL)是一种有前景的隐私保护方法。然而现有方法假设服务器为半诚实,未解决恶意服务器下的安全性问题,这源于其状态依赖特性,在客户端可能退出或被攻破的实际场景下尤为严重。虽然可信执行环境(TEEs)看似可行,但直接实现可能因状态管理引发分叉攻击或可用性问题。为此,本文提出一种新型服务器扩展,作为受信任计算基(TCB)实现恶意安全的DP-FTRL。TCB通过服务器端的瞬态TEE模块生成可验证的服务器操作证明,部分被选中的客户端以极小的额外通信与计算开销参与证明审计。该方案缩小了TCB规模,同时保持系统可扩展性与活性。我们基于交互式差分隐私提供了形式化证明,证实了在恶意设置下的隐私保障。实验表明,该框架在多个真实场景下对客户端仅引入恒定的小幅开销。

原文摘要 · Abstract (English)

In cross-device private federated learning, differentially private follow-the-regularized-leader (DP-FTRL) has emerged as a promising privacy-preserving method. However, existing approaches assume a semi-honest server and have not addressed the challenge of securely removing this assumption. This is due to its statefulness, which becomes particularly problematic in practical settings where clients can drop out or be corrupted. While trusted execution environments (TEEs) might seem like an obvious solution, a straightforward implementation can introduce forking attacks or availability issues due to state management. To address this problem, our paper introduces a novel server extension that acts as a trusted computing base (TCB) to realize maliciously secure DP-FTRL. The TCB is implemented with an ephemeral TEE module on the server side to produce verifiable proofs of server actions. Some clients, upon being selected, participate in auditing these proofs with small additional communication and computational demands. This extension solution reduces the size of the TCB while maintaining the system's scalability and liveness. We provide formal proofs based on interactive differential privacy, demonstrating privacy guarantee in malicious settings. Finally, we experimentally show that our framework adds small constant overhead to clients in several realistic settings.

联邦学习差分隐私可信执行环境安全计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。