[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118594-en":3,"doc-seo-118594-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118594,1374391974585,"Genevieve","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Strengthening Privacy in Robust Federated Learning through Secure Aggregation","Federated Learning enables collaborative model training without exposing raw local data, yet its aggregation process remains vulnerable to poisoning attacks exploiting the linearity of FedAvg. FedQV, a quadratic-voting-based alternative, mitigates poisoning by penalizing clients that deviate too much from truthful behavior, but it still faces privacy attacks that infer sensitive information from clients’ local models. This work shows how to implement Secure Aggregation on top of FedQV to counter both poisoning and privacy threats, validated via multiple attacks and effectiveness results.","Strengthening Privacy in Robust Federated Learning  \nthrough Secure Aggregation  \nTianyue Chu  \nIMDEA Networks Institute Universidad Carlos III de Madrid  \nDevris¸ ˙Is¸ler  \nIMDEA Networks Institute Universidad Carlos III de Madrid  \nNikolaos Laoutaris IMDEA Networks Institute  \nAbstract—Federated Learning (FL) has evolved into a pivotal paradigm for collaborative machine learning, enabling a centralised server to compute a global model by aggregating the local models trained by clients. However, the distributed nature of FL renders it susceptible to poisoning attacks that exploit its linear aggregation rule called FEDAVG. To address this vulnerability, FEDQV has been recently introduced as a superior alternative to FEDAVG, specifically designed to mitigate poisoning attacks by taxing more than linearly deviating clients. Nevertheless, FEDQV remains exposed to privacy attacks that aim to infer private information from clients’ local models. To counteract such privacy threats, a well-known approach is to use a Secure Aggregation (SA) protocol to ensure that the server is unable to inspect individual trained models as it aggregates them. In this work, we show how to implement SA on top of FED QV in order to address both poisoning and privacy attacks. We mount several privacy attacks against FED QV and demonstrate the effectiveness of SA in countering them.  \nI. INTRODUCTION  \nFederated Learning (FL) [15], [18] is a recent distributed learning paradigm designed for machine learning across multiple clients. It enables clients to collectively train a global model via a centralised server, all without divulging their raw local training data to the server. Generally, an FL involves an iterative process encompassing three key steps: the serversends the current global model to the clients or a selected subset of them; each selected client trains their local model using its local training data and sending the local model updates back to the server; then the server aggregates the received local model updates adhering to an aggregation method, and utilises it to update the global model. A prominent example of an FL aggregation method is FEDAVG [18] developed by Google and applied in tasks such as Google’s emoji [19] and next-word prediction [13] for mobile device keyboards. FEDAVG employs a weighted averaging mechanism for local model updates. This weighting is determined by the sizes of the local training datasets, making FEDAVG an effective and widely adopted approach in the realm of FL.  \nHowever, FEDAVG is vulnerable to poisoning attacks, where even a single malicious client can arbitrarily manipulate the global model [2] . This arises from the equal treatment of  \nWorkshop on AI Systems with Confidential Computing (AISCC) 2024  \n26 February 2024, San Diego, CA, USA ISBN 979-8-9894372-4-5  \n[https://dx.doi.org/10.14722/aiscc.2024.23012](https://dx.doi.org/10.14722/aiscc.2024.23012)[ ](https://dx.doi.org/10.14722/aiscc.2024.23012)[www.ndss-symposium.org](www.ndss-symposium.org)  \nall local data points, resembling the “one person one vote (1p1v)” election rule. To address this inherent vulnerability, Chu et al. [8] recently proposed a novel method called FED QV, as a superior alternative for FEDAVG in the aggregation process. FEDQV draws inspiration from Quadratic Voting [16], showcasing improved efficiency and robustness compared to 1p1v. Functioning as a truthful mechanism, FEDQV compels clients, including potentially malicious ones, to provide truthful information rather than misinformation. This commitment to truthfulness is reinforced by its masked voting role and limited budget mechanism. FEDQV stands out for its simplicity and adaptability, which can be seamlessly integrated into Byzantine-robust FL defence schemes, enhancing their defence capabilities. This characteristic positions FED QV asa promising solution to mitigate vulnerabilities observed in FEDAVG concerning poisoning attacks.  \nIn addition to the risk of poisoning att","cbCain5gHXhMjR48","https://ap.wps.com/l/cbCain5gHXhMjR48","pdf",680787,1,6,"English","en",105,"# Introduction\n## Federated Learning and FedAvg\n## Poisoning attacks and FedQV\n## Privacy attacks and Secure Aggregation\n## Paper contributions","[{\"question\":\"What privacy risk remains even when using FedQV instead of FedAvg?\",\"answer\":\"FedQV can still be targeted by privacy attacks that infer private information from clients’ local models through inference and reconstruction.\"},{\"question\":\"How does Secure Aggregation help protect client privacy in federated learning?\",\"answer\":\"Secure Aggregation prevents the server from inspecting individual trained models during aggregation, so the server cannot access sensitive client updates or learn their private data.\"},{\"question\":\"What does the paper contribute regarding defenses against both poisoning and privacy attacks?\",\"answer\":\"It implements Secure Aggregation on top of FedQV by adapting SECAGG to the distinctive FedQV voting mechanism, and then evaluates the approach against multiple privacy attacks to demonstrate effectiveness.\"}]","Strengthening Privacy in Robust Federated Learning through Secure Aggregation | PDF",1785684426,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"strengthening-privacy-in-robust-federated-learning-through-secure-aggregation","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/strengthening-privacy-in-robust-federated-learning-through-secure-aggregation/118594/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy risk remains even when using FedQV instead of FedAvg?","Question",{"text":75,"@type":76},"FedQV can still be targeted by privacy attacks that infer private information from clients’ local models through inference and reconstruction.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Secure Aggregation help protect client privacy in federated learning?",{"text":80,"@type":76},"Secure Aggregation prevents the server from inspecting individual trained models during aggregation, so the server cannot access sensitive client updates or learn their private data.",{"name":82,"@type":73,"acceptedAnswer":83},"What does the paper contribute regarding defenses against both poisoning and privacy attacks?",{"text":84,"@type":76},"It implements Secure Aggregation on top of FedQV by adapting SECAGG to the distinctive FedQV voting mechanism, and then evaluates the approach against multiple privacy attacks to demonstrate effectiveness.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]