Paper 2026/564

TAPAS: Efficient Two-Server Asymmetric Private Aggregation Beyond Prio(+)

Harish Karthikeyan, JPMorgan AI Research, JPMorgan AlgoCRYPT CoE
Antigoni Polychroniadou, JPMorgan AI Research, JPMorgan AlgoCRYPT CoE
Abstract

Privacy‑preserving aggregation is a cornerstone for AI systems that learn from distributed data without exposing individual records, especially in federated learning and telemetry. Existing two‑server protocols (e.g., Prio and successors) set a practical baseline by validating inputs while preventing any single party from learning users’ values, but they impose symmetric costs on both servers and communication that scales with the per‑client input dimension $L$. Modern learning tasks routinely involve dimensionalities $L$ in the tens to hundreds of millions of model parameters. We present TAPAS, a two‑server asymmetric private aggregation scheme that addresses these limitations along four dimensions: (i) no trusted setup or preprocessing, (ii) server‑side communication that is independent of $L$ (iii) post‑quantum security based solely on standard lattice assumptions (LWE, SIS), and (iv) stronger robustness with identifiable abort and full malicious security for the servers. A key design choice is intentional asymmetry: one server bears the $O(L)$ aggregation and verification work, while the other operates as a lightweight facilitator with computation independent of $L$. This reduces total cost, enables the secondary server to run on commodity hardware, and strengthens the non‑collusion assumption of the servers. One of our main contributions is a suite of new and efficient lattice-based zero-knowledge proofs; to our knowledge, we are the first to establish privacy and correctness with identifiable abort in the two-server setting.

Note: Updated Copyright

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
secure aggregationtwo-serverpriolattice-based zkp
Contact author(s)
harish @ nyu edu
antigonipoly @ gmail com
History
2026-03-26: revised
2026-03-20: received
See all versions
Short URL
https://ia.cr/2026/564
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/564,
      author = {Harish Karthikeyan and Antigoni Polychroniadou},
      title = {{TAPAS}: Efficient Two-Server Asymmetric Private Aggregation Beyond Prio(+)},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/564},
      year = {2026},
      url = {https://eprint.iacr.org/2026/564}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.