Paper 2025/2238
arya-STARK: Aggregation-Robust Yet Authentic Training via STARK Proofs
Abstract
We present arya-STARK, a unified post-quantum secure framework that enables Aggregation-Robust Yet Authentic training in Federated Learning through transparent zk-STARK proofs. Current federated learning deployments remain vulnerable to malicious or Byzantine clients capable of submitting statistically valid yet adversarial gradients, while also relying on quantum-fragile primitives for authentication. arya-STARK bridges these gaps by combining (i) transparent, hash-based zk-STARK proofs to verify gradient-descent updates at the AIR level, (ii) CRYSTALS-Dilithium signatures to guarantee post-quantum authentication of client commitments, and (iii) a Byzantine-resilient aggregation layer integrating $\ell_2$-clipping and trimmed-mean filtering to mitigate poisoning and backdoor attacks. We introduce a new finite-field encoding scheme that supports exact reconstruction of signed real-valued gradients inside STARK execution traces, enabling full verifiability without leaking client data. Our Rust-based proof-of-concept demonstrates that arya-STARK achieves scalable proof generation, microsecond-level verification, and strong robustness against up to 20% Byzantine clients while preserving high model accuracy. To our knowledge, this is the first system to unify post-quantum authentication, transparent zero-knowledge verification, and Byzantine-robust aggregation into a single architecture for secure federated learning.
Note: This submission presents a complete research prototype and proof of concept of arya-STARK, a post-quantum secure and verifiable federated learning framework. All experimental results reported in the paper were obtained using a Rust-based implementation executed on a commodity laptop, demonstrating the practicality of the approach under conservative hardware assumptions. To support reproducibility, the reference implementation, execution scripts, and configuration files used for the experimental evaluation are made available through an anonymized public repository. The artefacts are provided to enable reviewers to inspect the system architecture, verify the reported measurements, and reproduce the experiments. This submission is intended as a full research paper. The artefacts are provided for transparency and reproducibility only and are not subject to a separate artefact evaluation process. Any future extensions (e.g., multi-server aggregation, differential privacy integration, or hardware acceleration) are outside the scope of the current submission and are discussed as directions for future work.
Metadata
- Available format(s)
- -- withdrawn --
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- PQCML-DSA 65FIPS204zk-STARKFederated LearningzkFL
- Contact author(s)
- fal abdoulahad @ gmail com
- History
- 2026-05-09: withdrawn
- 2025-12-12: received
- See all versions
- Short URL
- https://ia.cr/2025/2238
- License
-
CC BY