Paper 2026/2183
Vespa: Efficient Secure Aggregation with Integrity Defense under Server Privacy
Abstract
Secure aggregation with input validation enables a server to securely compute the summation of private data from multiple clients while verifying that the inputs satisfy specific constraints. However, the practical deployment of this paradigm at scale is hindered by two primary limitations. First, existing schemes suffer from severe efficiency bottlenecks due to their reliance on generic, computationally expensive zero-knowledge proofs (ZKPs). Second, the scope of input validation is currently restricted to norm checks (e.g., $L_2$ and $L_\infty$) against public bounds. This paper presents \textsf{Vespa}, a single-server secure aggregation scheme that simultaneously achieves practical efficiency and expands validation capabilities to support both \textit{norm checks against public bounds} and \textit{similarity checks against private server inputs}. Specifically, we design a novel validity-weighted secure aggregation protocol over committed inputs, built upon highly efficient vector oblivious linear evaluation (VOLE). To efficiently realize input validation, we introduce customized $L_2$ and $L_\infty$ norm checks based on VOLE-based ZKPs, centered around optimized range proofs with reduced range sizes. Furthermore, we extend our framework to support advanced similarity-based checks against private server inputs, instantiated with widely used Euclidean and cosine similarities. This allows \textsf{Vespa} to first filter out invalid inputs using norm checks, followed by performing fine-grained validation via similarity metrics. We compare our scheme with the state-of-the-art secure aggregation works, including RoFL (S\&P 2023), ACORN (USENIX Security 2023), and Armadillo (CCS 2025), and extensive evaluation shows that our $L_2$ and $L_\infty$ norm checks achieve runtime improvements of up to $2\sim 3$ and $1\sim 3$ orders of magnitude, respectively. Our similarity checks also achieve practical performance, consuming only around $94$ seconds for an $818$k-entry vector.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. Accepted by NDSS 2027
- Keywords
- Secure aggregationInput validationVOLE-ZK
- Contact author(s)
-
jiahu @ std uestc edu cn
hongweili @ uestc edu cn
menghao303 @ gmail com
chenhanxiao chx @ gmail com
p xing @ std uestc edu cn
wenbo_jiang @ uestc edu cn
dongxiao liu @ uestc edu cn
haiyangxue @ smu edu sg
robertdeng @ smu edu sg - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2183
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2183,
author = {Jia Hu and Hongwei Li and Meng Hao and Hanxiao Chen and Pengzhi Xing and Wenbo Jiang and Dongxiao Liu and Haiyang Xue and Robert H. Deng},
title = {Vespa: Efficient Secure Aggregation with Integrity Defense under Server Privacy},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2183},
year = {2026},
url = {https://eprint.iacr.org/2026/2183}
}