Armadillo: Robust Single-Server Secure Aggregation for Federated Learning with Input Validation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ma, Yiping, Guo, Yue, Karthikeyan, Harish, Polychroniadou, Antigoni
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911264609927168
author Ma, Yiping
Guo, Yue
Karthikeyan, Harish
Polychroniadou, Antigoni
author_facet Ma, Yiping
Guo, Yue
Karthikeyan, Harish
Polychroniadou, Antigoni
contents This paper presents a secure aggregation system Armadillo that has disruptive resistance against adversarial clients, such that any coalition of malicious clients (within the tolerated threshold) can affect the aggregation result only by misreporting their private inputs in a pre-defined legitimate range. Armadillo is designed for federated learning setting, where a single powerful server interacts with many weak clients iteratively to train models on client's private data. While a few prior works consider disruption resistance under such setting, they either incur high per-client cost (Chowdhury et al. CCS '22) or require many rounds (Bell et al. USENIX Security '23). Although disruption resistance can be achieved generically with zero-knowledge proof techniques (which we also use in this paper), we realize an efficient system with two new designs: 1) a simple two-layer secure aggregation protocol that requires only simple arithmetic computation; 2) an agreement protocol that removes the effect of malicious clients from the aggregation with low round complexity. With these techniques, Armadillo completes each secure aggregation in 3 rounds while keeping the server and clients computationally lightweight.
format Preprint
id arxiv_https___arxiv_org_abs_2511_10863
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Armadillo: Robust Single-Server Secure Aggregation for Federated Learning with Input Validation
Ma, Yiping
Guo, Yue
Karthikeyan, Harish
Polychroniadou, Antigoni
Cryptography and Security
This paper presents a secure aggregation system Armadillo that has disruptive resistance against adversarial clients, such that any coalition of malicious clients (within the tolerated threshold) can affect the aggregation result only by misreporting their private inputs in a pre-defined legitimate range. Armadillo is designed for federated learning setting, where a single powerful server interacts with many weak clients iteratively to train models on client's private data. While a few prior works consider disruption resistance under such setting, they either incur high per-client cost (Chowdhury et al. CCS '22) or require many rounds (Bell et al. USENIX Security '23). Although disruption resistance can be achieved generically with zero-knowledge proof techniques (which we also use in this paper), we realize an efficient system with two new designs: 1) a simple two-layer secure aggregation protocol that requires only simple arithmetic computation; 2) an agreement protocol that removes the effect of malicious clients from the aggregation with low round complexity. With these techniques, Armadillo completes each secure aggregation in 3 rounds while keeping the server and clients computationally lightweight.
title Armadillo: Robust Single-Server Secure Aggregation for Federated Learning with Input Validation
topic Cryptography and Security
url https://arxiv.org/abs/2511.10863