SLVR: Securely Leveraging Client Validation for Robust Federated Learning

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Choi, Jihye, Rachuri, Sai Rahul, Wang, Ke, Jha, Somesh, Wang, Yizhen
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912229923749888
author Choi, Jihye
Rachuri, Sai Rahul
Wang, Ke
Jha, Somesh
Wang, Yizhen
author_facet Choi, Jihye
Rachuri, Sai Rahul
Wang, Ke
Jha, Somesh
Wang, Yizhen
contents Federated Learning (FL) enables collaborative model training while keeping client data private. However, exposing individual client updates makes FL vulnerable to reconstruction attacks. Secure aggregation mitigates such privacy risks but prevents the server from verifying the validity of each client update, creating a privacy-robustness tradeoff. Recent efforts attempt to address this tradeoff by enforcing checks on client updates using zero-knowledge proofs, but they support limited predicates and often depend on public validation data. We propose SLVR, a general framework that securely leverages clients' private data through secure multi-party computation. By utilizing clients' data, SLVR not only eliminates the need for public validation data, but also enables a wider range of checks for robustness, including cross-client accuracy validation. It also adapts naturally to distribution shifts in client data as it can securely refresh its validation data up-to-date. Our empirical evaluations show that SLVR improves robustness against model poisoning attacks, particularly outperforming existing methods by up to 50% under adaptive attacks. Additionally, SLVR demonstrates effective adaptability and stable convergence under various distribution shift scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2502_08055
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SLVR: Securely Leveraging Client Validation for Robust Federated Learning
Choi, Jihye
Rachuri, Sai Rahul
Wang, Ke
Jha, Somesh
Wang, Yizhen
Cryptography and Security
Machine Learning
Federated Learning (FL) enables collaborative model training while keeping client data private. However, exposing individual client updates makes FL vulnerable to reconstruction attacks. Secure aggregation mitigates such privacy risks but prevents the server from verifying the validity of each client update, creating a privacy-robustness tradeoff. Recent efforts attempt to address this tradeoff by enforcing checks on client updates using zero-knowledge proofs, but they support limited predicates and often depend on public validation data. We propose SLVR, a general framework that securely leverages clients' private data through secure multi-party computation. By utilizing clients' data, SLVR not only eliminates the need for public validation data, but also enables a wider range of checks for robustness, including cross-client accuracy validation. It also adapts naturally to distribution shifts in client data as it can securely refresh its validation data up-to-date. Our empirical evaluations show that SLVR improves robustness against model poisoning attacks, particularly outperforming existing methods by up to 50% under adaptive attacks. Additionally, SLVR demonstrates effective adaptability and stable convergence under various distribution shift scenarios.
title SLVR: Securely Leveraging Client Validation for Robust Federated Learning
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2502.08055