Paper 2024/2082

ClusterGuard: Secure Clustered Aggregation for Federated Learning with Robustness

Yulin Zhao, University of Chinese Academy of Sciences
Zhiguo Wan, Zhejiang Lab
Zhangshuang Guan, Zhejiang University
Guannan Li, Tsinghua University
Miao Guo, Network Investment (Beijing) Technology Co.Ltd.
Abstract

Federated Learning, as a multi-party machine learning paradigm, has garnered significant attention, but model updates may still leak sensitive information. Secure aggregation protocols are considered an effective solution for privacy protection in Federated Learning. However, in large-scale federated learning systems, designing efficient and practical secure aggregation remains a critical challenge. Moreover, while secure aggregation effectively conceals model updates, it unintentionally complicates the detection and mitigation of poisoning attacks, thereby exposing the system to vulnerabilities from both data and model poisoning. To address these challenges, we propose ClusterGuard, a secure clustered aggregation scheme. ClusterGuard leverages Verifiable Random Function (VRF) to ensure fair and transparent client clustering. Within each cluster, it employs a lightweight key-homomorphic masking mechanism combined with verifiable secret sharing to enable secure and efficient aggregation. Furthermore, we design a dual filtering mechanism based on cosine similarity and norm to effectively detect and resist poisoning attacks. We provide two variants of ClusterGuard for both client-server and decentralized environments with blockchains, respectively. Extensive experiments on standard datasets demonstrate that ClusterGuard achieves over $2\times$ efficiency improvement compared to advanced secure aggregation methods. Even with 20% of clients being malicious, the trained model maintains accuracy comparable to the original model, outperforming state-of-the-art robustness solutions. ClusterGuard provides a more efficient, secure, and robust solution for practical federated learning.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Federated learningSecure aggregationByzantine robustness
Contact author(s)
zhaoyulin22 @ mails ucas ac cn
wanzhiguo @ zhejianglab com
guanzs @ zju edu cn
18311081686 @ 163 com
gagamazel @ 163 com
History
2025-08-18: last of 2 revisions
2024-12-27: received
See all versions
Short URL
https://ia.cr/2024/2082
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/2082,
      author = {Yulin Zhao and Zhiguo Wan and Zhangshuang Guan and Guannan Li and Miao Guo},
      title = {{ClusterGuard}: Secure Clustered Aggregation for Federated Learning with Robustness},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/2082},
      year = {2024},
      url = {https://eprint.iacr.org/2024/2082}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.