EFU: Enforcing Federated Unlearning via Functional Encryption

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Mohammadi, Samaneh, Tsouvalas, Vasileios, Symeonidis, Iraklis, Balador, Ali, Ozcelebi, Tanir, Flammini, Francesco, Meratnia, Nirvana
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916891115651072
author Mohammadi, Samaneh
Tsouvalas, Vasileios
Symeonidis, Iraklis
Balador, Ali
Ozcelebi, Tanir
Flammini, Francesco
Meratnia, Nirvana
author_facet Mohammadi, Samaneh
Tsouvalas, Vasileios
Symeonidis, Iraklis
Balador, Ali
Ozcelebi, Tanir
Flammini, Francesco
Meratnia, Nirvana
contents Federated unlearning (FU) algorithms allow clients in federated settings to exercise their ''right to be forgotten'' by removing the influence of their data from a collaboratively trained model. Existing FU methods maintain data privacy by performing unlearning locally on the client-side and sending targeted updates to the server without exposing forgotten data; yet they often rely on server-side cooperation, revealing the client's intent and identity without enforcement guarantees - compromising autonomy and unlearning privacy. In this work, we propose EFU (Enforced Federated Unlearning), a cryptographically enforced FU framework that enables clients to initiate unlearning while concealing its occurrence from the server. Specifically, EFU leverages functional encryption to bind encrypted updates to specific aggregation functions, ensuring the server can neither perform unauthorized computations nor detect or skip unlearning requests. To further mask behavioral and parameter shifts in the aggregated model, we incorporate auxiliary unlearning losses based on adversarial examples and parameter importance regularization. Extensive experiments show that EFU achieves near-random accuracy on forgotten data while maintaining performance comparable to full retraining across datasets and neural architectures - all while concealing unlearning intent from the server. Furthermore, we demonstrate that EFU is agnostic to the underlying unlearning algorithm, enabling secure, function-hiding, and verifiable unlearning for any client-side FU mechanism that issues targeted updates.
format Preprint
id arxiv_https___arxiv_org_abs_2508_07873
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle EFU: Enforcing Federated Unlearning via Functional Encryption
Mohammadi, Samaneh
Tsouvalas, Vasileios
Symeonidis, Iraklis
Balador, Ali
Ozcelebi, Tanir
Flammini, Francesco
Meratnia, Nirvana
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
Federated unlearning (FU) algorithms allow clients in federated settings to exercise their ''right to be forgotten'' by removing the influence of their data from a collaboratively trained model. Existing FU methods maintain data privacy by performing unlearning locally on the client-side and sending targeted updates to the server without exposing forgotten data; yet they often rely on server-side cooperation, revealing the client's intent and identity without enforcement guarantees - compromising autonomy and unlearning privacy. In this work, we propose EFU (Enforced Federated Unlearning), a cryptographically enforced FU framework that enables clients to initiate unlearning while concealing its occurrence from the server. Specifically, EFU leverages functional encryption to bind encrypted updates to specific aggregation functions, ensuring the server can neither perform unauthorized computations nor detect or skip unlearning requests. To further mask behavioral and parameter shifts in the aggregated model, we incorporate auxiliary unlearning losses based on adversarial examples and parameter importance regularization. Extensive experiments show that EFU achieves near-random accuracy on forgotten data while maintaining performance comparable to full retraining across datasets and neural architectures - all while concealing unlearning intent from the server. Furthermore, we demonstrate that EFU is agnostic to the underlying unlearning algorithm, enabling secure, function-hiding, and verifiable unlearning for any client-side FU mechanism that issues targeted updates.
title EFU: Enforcing Federated Unlearning via Functional Encryption
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
url https://arxiv.org/abs/2508.07873