Paper 2024/2082
ClusterGuard: Secure Clustered Aggregation for Federated Learning with Robustness
Abstract
Federated Learning, as a multi-party machine learning paradigm, has garnered significant attention, but model updates may still leak sensitive information. Secure aggregation protocols are considered an effective solution for privacy protection in Federated Learning. However, in large-scale federated learning systems, designing efficient and practical secure aggregation remains a critical challenge. Moreover, while secure aggregation effectively conceals model updates, it unintentionally complicates the detection and mitigation of poisoning attacks, thereby exposing the system to vulnerabilities from both data and model poisoning. To address these challenges, we propose ClusterGuard, a secure clustered aggregation scheme. ClusterGuard leverages Verifiable Random Function (VRF) to ensure fair and transparent client clustering. Within each cluster, it employs a lightweight key-homomorphic masking mechanism combined with verifiable secret sharing to enable secure and efficient aggregation. Furthermore, we design a dual filtering mechanism based on cosine similarity and norm to effectively detect and resist poisoning attacks. We provide two variants of ClusterGuard for both client-server and decentralized environments with blockchains, respectively. Extensive experiments on standard datasets demonstrate that ClusterGuard achieves over $2\times$ efficiency improvement compared to advanced secure aggregation methods. Even with 20% of clients being malicious, the trained model maintains accuracy comparable to the original model, outperforming state-of-the-art robustness solutions. ClusterGuard provides a more efficient, secure, and robust solution for practical federated learning.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Federated learningSecure aggregationByzantine robustness
- Contact author(s)
-
zhaoyulin22 @ mails ucas ac cn
wanzhiguo @ zhejianglab com
guanzs @ zju edu cn
18311081686 @ 163 com
gagamazel @ 163 com - History
- 2025-08-18: last of 2 revisions
- 2024-12-27: received
- See all versions
- Short URL
- https://ia.cr/2024/2082
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/2082,
author = {Yulin Zhao and Zhiguo Wan and Zhangshuang Guan and Guannan Li and Miao Guo},
title = {{ClusterGuard}: Secure Clustered Aggregation for Federated Learning with Robustness},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/2082},
year = {2024},
url = {https://eprint.iacr.org/2024/2082}
}