Paper 2026/2074

Revisiting Malicious Private Aggregation: Formalization, Weaknesses, and Enhancements

Ananya Appan, University of Illinois Urbana-Champaign
Pranav Shriram Arunachalaramanan, University of Illinois Urbana-Champaign
David Heath, University of Illinois Urbana-Champaign
Ling Ren, University of Illinois Urbana-Champaign
Abstract

Private aggregation schemes enable aggregation of sensitive data across clients without leaking any individual client's input. Their applications include privacy-preserving federated learning, private heavy hitters, and anonymous systems. Many private aggregation schemes assume two non-colluding servers and aim to guarantee privacy even when one server is malicious, i.e., the malicious server learns an aggregation result that includes all honest client inputs. However, many private aggregation schemes in the literature fail to achieve privacy, which we believe is in large part due to a lack of formalism for the nuanced variations of privacy guarantees. In this work, we present ideal functionalities for several variants of private aggregation. We also formalize a common paradigm underlying most prior private aggregation schemes. The formal treatment helps us identify security flaws or underspecifications in existing private aggregation schemes. We then present modular modifications or fill in critical details to help prior schemes in the share-aggregate paradigm securely realize the private aggregation functionalities we formally define, including in settings where clients may have unreliable networks.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Private AggregationPrivacy Preserving Aggregate StatisticsPrivacy Preserving Federated Learning
Contact author(s)
aappan2 @ illinois edu
psa3 @ illinois edu
daheath @ illinois edu
renling @ illinois edu
History
2026-09-19: approved
2026-09-17: received
See all versions
Short URL
https://ia.cr/2026/2074
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2074,
      author = {Ananya Appan and Pranav Shriram Arunachalaramanan and David Heath and Ling Ren},
      title = {Revisiting Malicious Private Aggregation: Formalization, Weaknesses, and Enhancements},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2074},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2074}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.