Improved Robust Verifiable Federated Learning Based on Packed Secret Sharing
Jinhyuk Choi ⋅ Hyung Tae Lee
Abstract
Achieving both privacy and robustness against poisoning attacks remains a central challenge in federated learning (FL), since hiding individual updates makes attacks harder to detect and mitigate. Recently, Mai et al. (NeurIPS 2024) proposed RFLPA, a packed-secret-sharing (PSS)-based realization of FLTrust, which weights client updates by their cosine similarity to a trusted server update. In this paper, we show that RFLPA contains design flaws and mathematical errors in its use of PSS, making the protocol theoretically unsound and practically non-functional. We then propose an improved verifiable FL framework that restores correctness while retaining efficiency. Our key insight is a reinterpretation of the algebraic structure of PSS, which leads to a new transposed degree reduction algorithm and a pairwise verification technique for dot products. These primitives enable local matrix-based operations without complex circuit evaluation and substantially reduce communication rounds compared with BGW-style computation. Building on them, we redesign the verifiable aggregation algorithm of RFLPA by introducing perpendicular vectors, reducing cosine similarity verification to a single dot-product check and eliminating costly verifiable secret sharing during enrollment. The resulting framework strictly improves efficiency, fixes the flaws of prior work, and preserves $N/3$-robustness in malicious settings. Our implementation and empirical evaluation confirm the feasibility of the resulting protocol for high-dimensional FL updates.
Chat is not available.
Successful Page Load