[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84134-en":3,"doc-seo-84134-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84134,687197207057,"Sage","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","PRoVeFL Private Robust and Verifiable Aggregation in Federated Learning","Federated Learning enables collaborative model training while keeping data local, but standard FL depends on a centralized aggregator and honest-but-curious clients, which remain vulnerable to server inference and client poisoning. Existing secure and Byzantine-resilient protocols face a trade-off among privacy, integrity, and verifiability, often with heavy cryptographic overhead. PRoVeFL proposes a modular framework using multi-key fully homomorphic encryption across multiple servers to achieve privacy-preserving Byzantine-robust, verifiable aggregation with scalable runtime gains and minimal trust assumptions.","PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning  \nHarsh Kasyapa,c,∗, Anil Kumar Pradhanb,∗, Ugur Ilker Atmacac,e,∗, Graham Cormoded , Carsten Maplec  \na Indian Institute of Technology (BHU), Varanasi, India  \nb Vaulttree,, Ireland  \nc University of Warwick, Coventry, UK  \nd University of Oxford, Oxford, UK  \ne Abdullah Gul University, Kayseri, Turkiye  \nAbstract  \nFederated Learning (FL) enables multiple clients to collaboratively train machine learning models while retaining data locality, thereby enhancing user privacy. However, traditional FL frameworks rely on a centralized aggregation server and assume honestbut-curious clients, making them susceptible to both server-side inference and client-side poisoning attacks. Although recent work has explored secure and Byzantine-resilient FL protocols, they face a fundamental trade-off among privacy, integrity, and verifiability, and incur substantial computational and communication overhead due to the heavy use of cryptographic primitives.  \nIn this work, we propose PRoVeFL–a novel, modular FL framework that is Privacy-preserving, Byzantine-Robust, and ensures Verifiable aggregation. PRoVeFL employs multiple servers leveraging multi-key fully homomorphic encryption. Each client encrypts its local model updates and distributes encrypted shares to all servers. This design enables a hybrid computation model in which ciphertext operations are carefully offloaded to the plaintext domain under strict privacy constraints to efficiently evaluate complex statistical aggregation rules. PRoVeFL is compatible with a wide range of state-of-the-art Byzantine-robust aggregation algorithms (e.g., Krum, Trimmed Mean, FLTrust, norm clipping, MESAS, and more) and further enhances them with verifiability mechanisms that require minimal trust in at least one honest server. We evaluate it across different settings and demonstrate its scalability with varying numbers of parameters and participants. PRoVeFL improves runtime over the prior works, Prio and ELSA, based on distributed trust with comparable security guarantees, up to 100× and 10×, respectively.  \nKeywords: Federated learning, Byzantine-robust aggregation, Multi-key homomorphic encryption, Verifiable aggregation, Privacy-preserving machine learning  \n1. Introduction To address such threats, three interrelated properties should  \n[ cs .CR] 7 Jul 2026  \n∗ Corresponding author. First three authors have equal contribution.  \nEmail addresses: [hkasyap.cse@iitbhu.ac.in](hkasyap.cse@iitbhu.ac.in) (Harsh Kasyap), [anil@vaulttree.com](anil@vaulttree.com) (Anil Kumar Pradhan), [ugur-ilker.atmaca@warwick.ac.uk](ugur-ilker.atmaca@warwick.ac.uk) (Ugur Ilker Atmaca),  \n[graham.cormode@cs.ox.ac.uk](graham.cormode@cs.ox.ac.uk) (Graham Cormode), [cm@warwick.ac.uk](cm@warwick.ac.uk)  \n(Carsten Maple)  \nbe achieved together: privacy, Byzantine robustness, and verifiability [11] . Just hiding raw data is not sufficient for privacy. As several studies [7, 12] have confirmed, gradient updates can leak private information. Thus, other privacy-enhancing technologies (PETs), such as Secure Multi-Party Computation (SMPC), Fully Homomorphic Encryption (FHE), and Differential Privacy (DP), are integrated to enhance privacy. While such protocols can hide clients’ updates from the server, they can also make it harder to identify malicious updates. Recent work has proposed to combine secure aggregation with robustness measures, yet these often incur high computational and communication costs or rely on relaxed trust assumptions. They are not flexible enough to support a variety of Byzantine-robust aggregation rules, and instead enforce simple heuristics, such as via norm clipping [11] . Other approaches, such as MUDGUARD [13], employ a privacy-preserving clustering method. This can protect the global model against most malicious clients, but it significantly increases the complexity and cost of aggregation. Similarly, ELSA [11], ACORN [14], and EIF","cbCaihLdUDUzuM6c","https://ap.wps.com/l/cbCaihLdUDUzuM6c","pdf",737863,5,1,19,"English","en",105,"# Abstract\n# Introduction\n## Privacy vs integrity vs verifiability\n## Verifiability of aggregation\n## Role of fully homomorphic encryption (FHE)","[{\"question\":\"What problem does PRoVeFL address in federated learning?\",\"answer\":\"PRoVeFL targets the security gap in traditional federated learning where a centralized server and client assumptions enable server inference and client poisoning. It aims to jointly provide privacy, Byzantine robustness, and verifiable aggregation.\"},{\"question\":\"How does PRoVeFL provide verifiable aggregation without relying on a fully trusted server?\",\"answer\":\"PRoVeFL uses multiple servers and verifiability mechanisms that require minimal trust in at least one honest server. Encrypted shares and cryptographic proof-based checks help ensure the reported global update matches the correct aggregation.\"},{\"question\":\"What role does multi-key fully homomorphic encryption (FHE) play in PRoVeFL?\",\"answer\":\"PRoVeFL employs multi-key fully homomorphic encryption so clients encrypt local model updates and distribute encrypted shares. Ciphertext operations are carefully offloaded to evaluate complex statistical aggregation rules under strict privacy constraints.\"}]",1784193226,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"provefl-private-robust-and-verifiable-aggregation-in-federated-learning","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/provefl-private-robust-and-verifiable-aggregation-in-federated-learning/84134/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does PRoVeFL address in federated learning?","Question",{"text":76,"@type":77},"PRoVeFL targets the security gap in traditional federated learning where a centralized server and client assumptions enable server inference and client poisoning. It aims to jointly provide privacy, Byzantine robustness, and verifiable aggregation.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does PRoVeFL provide verifiable aggregation without relying on a fully trusted server?",{"text":81,"@type":77},"PRoVeFL uses multiple servers and verifiability mechanisms that require minimal trust in at least one honest server. Encrypted shares and cryptographic proof-based checks help ensure the reported global update matches the correct aggregation.",{"name":83,"@type":74,"acceptedAnswer":84},"What role does multi-key fully homomorphic encryption (FHE) play in PRoVeFL?",{"text":85,"@type":77},"PRoVeFL employs multi-key fully homomorphic encryption so clients encrypt local model updates and distribute encrypted shares. Ciphertext operations are carefully offloaded to evaluate complex statistical aggregation rules under strict privacy constraints.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":20,"slug":137},"General","general"]