Paper 2025/1289

AlphaFL: Secure Aggregation with Malicious$^2$ Security for Federated Learning against Dishonest Majority

Yufan Jiang, Karlsruhe Institute of Technology, KASTEL Security Research Labs
Maryam Zarezadeh, Barkhausen Institut
Tianxiang Dai, Lancaster University Leipzig
Stefan Köpsell, Barkhausen Institut
Abstract

Federated learning (FL) proposes to train a global machine learning model across distributed datasets. However, the aggregation protocol as the core component in FL is vulnerable to well-studied attacks, such as inference attacks, poisoning attacks [71] and malicious participants who try to deviate from the protocol [24]. Therefore, it is crucial to achieve both malicious security and poisoning resilience from cryptographic and FL perspectives, respectively. Prior works either achieve incomplete malicious security [76], address issues by using expensive cryptographic tools [22, 59] or assume the availability of a clean dataset on the server side [32]. In this work, we propose AlphaFL, a two-server secure aggregation protocol achieving both malicious security in the universal composability (UC) framework [19] and poisoning resilience in FL (thus malicious$^2$) against a dishonest majority. We design maliciously secure multi-party computation (MPC) protocols [24, 26, 48] and introduce an efficient input commitment protocol tolerating server-client collusion (dishonest majority). We also propose an efficient input commitment protocol for the non-collusion case (honest majority), which triples the efficiency in time and quadruples that in communication, compared to the state-of-the-art solution in MP-SPDZ [46]. To achieve poisoning resilience, we carry out $L_\infty$ and $L_2$-Norm checks with a dynamic $L_2$-Norm bound by introducing a novel silent select protocol, which improves the runtime by at least two times compared to the classic select protocol. Combining these, AlphaFL achieves malicious$^2$ security at a cost of 25% − 79% more runtime overhead than the state-of-the-art semi-malicious counterpart Elsa [76], with even less communication cost.

Note: This is an extended version. We provide additional security analysis and extended proofs to clarify our results.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. PETS 2025
Keywords
Federated LearningSecure AggregationMulti-Party ComputationPoisoning Resilience
Contact author(s)
yufan jiang @ kit edu
maryam zarezadeh @ barkhauseninstitut org
t dai @ lancaster ac uk
stefan koepsell @ barkhauseninstitut org
History
2026-06-24: last of 4 revisions
2025-07-15: received
See all versions
Short URL
https://ia.cr/2025/1289
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1289,
      author = {Yufan Jiang and Maryam Zarezadeh and Tianxiang Dai and Stefan Köpsell},
      title = {{AlphaFL}: Secure Aggregation with Malicious$^2$ Security for Federated Learning against Dishonest Majority},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1289},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1289}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.