Paper 2025/1289
AlphaFL: Secure Aggregation with Malicious$^2$ Security for Federated Learning against Dishonest Majority
Abstract
Federated learning (FL) proposes to train a global machine learning model across distributed datasets. However, the aggregation protocol as the core component in FL is vulnerable to well-studied attacks, such as inference attacks, poisoning attacks [71] and malicious participants who try to deviate from the protocol [24]. Therefore, it is crucial to achieve both malicious security and poisoning resilience from cryptographic and FL perspectives, respectively. Prior works either achieve incomplete malicious security [76], address issues by using expensive cryptographic tools [22, 59] or assume the availability of a clean dataset on the server side [32]. In this work, we propose AlphaFL, a two-server secure aggregation protocol achieving both malicious security in the universal composability (UC) framework [19] and poisoning resilience in FL (thus malicious$^2$) against a dishonest majority. We design maliciously secure multi-party computation (MPC) protocols [24, 26, 48] and introduce an efficient input commitment protocol tolerating server-client collusion (dishonest majority). We also propose an efficient input commitment protocol for the non-collusion case (honest majority), which triples the efficiency in time and quadruples that in communication, compared to the state-of-the-art solution in MP-SPDZ [46]. To achieve poisoning resilience, we carry out $L_\infty$ and $L_2$-Norm checks with a dynamic $L_2$-Norm bound by introducing a novel silent select protocol, which improves the runtime by at least two times compared to the classic select protocol. Combining these, AlphaFL achieves malicious$^2$ security at a cost of 25% − 79% more runtime overhead than the state-of-the-art semi-malicious counterpart Elsa [76], with even less communication cost.
Note: This is an extended version. We provide additional security analysis and extended proofs to clarify our results.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. PETS 2025
- Keywords
- Federated LearningSecure AggregationMulti-Party ComputationPoisoning Resilience
- Contact author(s)
-
yufan jiang @ kit edu
maryam zarezadeh @ barkhauseninstitut org
t dai @ lancaster ac uk
stefan koepsell @ barkhauseninstitut org - History
- 2026-06-24: last of 4 revisions
- 2025-07-15: received
- See all versions
- Short URL
- https://ia.cr/2025/1289
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1289,
author = {Yufan Jiang and Maryam Zarezadeh and Tianxiang Dai and Stefan Köpsell},
title = {{AlphaFL}: Secure Aggregation with Malicious$^2$ Security for Federated Learning against Dishonest Majority},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1289},
year = {2025},
url = {https://eprint.iacr.org/2025/1289}
}