End-to-End Verifiable and Robust Federated Learning

📅 2026-09-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该论文提出一种可验证的联邦学习协议,结合密码承诺与非交互零知识证明方法,解决拜占庭客户端更新和聚合器可审计性问题。
📝 Abstract
Federated learning enables multiple parties to train a shared model without centralizing raw data with the help of an aggregator, but introduces integrity risks once participants or infrastructure are not fully trustworthy. Two requirements are particularly important: robustness to poisoned or Byzantine client updates, and verifiability of the aggregator so that clients or third parties can audit the reported aggregation without learning individual updates. Existing work has largely treated these goals separately, and efficient public verifiability for robust, outlier-excluding aggregation remains limited. We present a verifiable federated learning protocol that makes a robust aggregation pipeline publicly auditable. Our design combines cryptographic commitments with non-interactive zero-knowledge proofs to certify both (i) cosine-similarity-based outlier exclusion and (ii) aggregation over the selected set, without revealing individual client updates to verifiers. In experiments under representative poisoning attacks, our method maintains high accuracy, with an average accuracy loss below 4\% across the evaluated configurations, while keeping verification overhead practical: proof artifacts can be generated and verified within minutes at the scale studied. In summary, our results show that robust outlier exclusion and public verifiability can be jointly achieved in a federated learning setting.
Problem

Research questions and friction points this paper is trying to address.

federated learning
robustness
verifiability
Byzantine clients
aggregator
Innovation

Methods, ideas, or system contributions that make the work stand out.

Verifiable Federated Learning
Robust Aggregation
Non-interactive Zero-knowledge Proofs
Cryptographic Commitments
🔎 Similar Papers
No similar papers found.
D
Doryan Lesaignoux
AIT Austrian Institute of Technology, Vienna, Austria
E
Enrique Mármol Campos
Department of Computer Engineering, University of Murcia, Murcia, Spain
Gabriele Spini
Gabriele Spini
AIT Austrian Institute of Technology, Vienna, Austria
J
José L. Hernández-Ramos
Department of Computer Engineering, University of Murcia, Murcia, Spain
Stephan Krenn
Stephan Krenn
AIT Austrian Institute of Technology GmbH
CryptographySecurityPrivacy