Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

EPRA-VFL: A privacy-preserving and efficient verifiable federated learning scheme with robust aggregation

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

EPRA-VFL: A privacy-preserving and efficient verifiable federated learning scheme with robust aggregation

Similar Papers
  • Research Article
  • Cite Count Icon 40
  • 10.1109/jiot.2022.3229122
Privacy Preservation for Federated Learning With Robust Aggregation in Edge Computing
  • Apr 15, 2023
  • IEEE Internet of Things Journal
  • Wentao Liu + 6 more

Benefiting from the powerful data analysis and prediction capabilities of artificial intelligence (AI), the data on the edge is often transferred to the cloud center for centralized training to obtain an accurate model. To resist the risk of privacy leakage due to frequent data transmission between the edge and the cloud, federated learning (FL) is engaged in the edge paradigm, uploading the model updated on the edge server (ES) to the central server for aggregation, instead of transferring data directly. However, the adversarial ES can infer the update of other ESs from the aggregated model and the update may still expose some characteristics of data of other ESs. Besides, there is a certain probability that the entire aggregation is disrupted by the adversarial ESs through uploading a malicious update. In this article, a privacy-preserving FL scheme with robust aggregation in edge computing is proposed, named FL-RAEC. First, the hybrid privacy-preserving mechanism is constructed to preserve the integrity and privacy of the data uploaded by the ESs. For the robust model aggregation, a phased aggregation strategy is proposed. Specifically, anomaly detection based on autoencoder is performed while some ESs are selected for anonymous trust verification at the beginning. In the next stage, via multiple rounds of random verification, the trust score of each ES is assessed to identify the malicious participants. Eventually, FL-RAEC is evaluated in detail, depicting that FL-RAEC has strong robustness and high accuracy under different attacks.

  • Conference Article
  • Cite Count Icon 11
  • 10.1109/trustcom56396.2022.00087
Privacy-Preserving Robust Federated Learning with Distributed Differential Privacy
  • Dec 1, 2022
  • Fayao Wang + 4 more

Federated Learning (FL) has attracted significant interest, as it provides a distributed machine learning paradigm to share data resources during model training process. However, sharing the gradients or model weights uploaded by clients or the final model aggregated by the server can lead to privacy disclosures and executing correctness issues. Specifically, the original data can be easily inferred through analyzing the shared gradients, and malicious users can disrupt the model aggregation to result in a destruction of the model accuracy. To address these issues, we propose a novel FL scheme with providing both privacy protection and robust aggregation. By using the distributed differential privacy and range proof technologies, the proposed scheme resists semi-honest servers and malicious users, while protecting the global model and providing the high accuracy. Both privacy analysis and experiments are given to demonstrate the effectiveness of our scheme.

  • Research Article
  • 10.3389/fpubh.2026.1762346
A robust and verifiable federated learning framework for preventing data poisonous threats in e-health
  • Jan 1, 2026
  • Frontiers in Public Health
  • Etidal Alruwaili + 1 more

IntroductionFederated Learning (FL) has become an attractive approach for e-health because it allows multiple institutions to collaboratively train machine learning models without directly sharing sensitive patient data. Despite these advantages, FL systems are still susceptible to poisoning attacks in which malicious participants manipulate model updates to degrade performance or embed hidden backdoors. Such threats raise serious concerns for medical applications, where reliability, transparency, and regulatory compliance are essential.MethodsIn this work, we introduce FedSecure-Chain, a modular framework designed to improve the reliability of federated learning environments. The proposed approach combines three phases: an anomaly detection stage applied before aggregation to identify suspicious client updates, a robust aggregation strategy to limit the influence of potentially malicious contributions, and a lightweight blockchain layer that records model updates and client trust information to ensure traceability and auditing. The framework was evaluated on Breast Cancer datasets using TabNet and compact multilayer perceptron (MLP) models under several poisoning attack scenarios and different non-IID data distributions.ResultsThe experimental evaluation indicates that integrating anomaly detection with robust aggregation significantly reduces the impact of poisoning attacks on the global model. In addition, the blockchain logging layer enables transparent tracking of model updates while introducing only limited overhead. Overall, the proposed framework maintains stable model performance even in the presence of adversarial participants.DiscussionThe results suggest that combining defensive learning strategies with transparent logging mechanisms can strengthen trust in federated healthcare systems. By improving resilience to adversarial manipulation while keeping computational and operational costs manageable, Our method represents a practical step toward secure and trustworthy federated learning for healthcare applications.

  • Research Article
  • Cite Count Icon 10
  • 10.3389/fnins.2023.1181703
A novel federated deep learning scheme for glioma and its subtype classification.
  • May 23, 2023
  • Frontiers in Neuroscience
  • Muhaddisa Barat Ali + 3 more

Deep learning (DL) has shown promising results in molecular-based classification of glioma subtypes from MR images. DL requires a large number of training data for achieving good generalization performance. Since brain tumor datasets are usually small in size, combination of such datasets from different hospitals are needed. Data privacy issue from hospitals often poses a constraint on such a practice. Federated learning (FL) has gained much attention lately as it trains a central DL model without requiring data sharing from different hospitals. We propose a novel 3D FL scheme for glioma and its molecular subtype classification. In the scheme, a slice-based DL classifier, EtFedDyn, is exploited which is an extension of FedDyn, with the key differences on using focal loss cost function to tackle severe class imbalances in the datasets, and on multi-stream network to exploit MRIs in different modalities. By combining EtFedDyn with domain mapping as the pre-processing and 3D scan-based post-processing, the proposed scheme makes 3D brain scan-based classification on datasets from different dataset owners. To examine whether the FL scheme could replace the central learning (CL) one, we then compare the classification performance between the proposed FL and the corresponding CL schemes. Furthermore, detailed empirical-based analysis were also conducted to exam the effect of using domain mapping, 3D scan-based post-processing, different cost functions and different FL schemes. Experiments were done on two case studies: classification of glioma subtypes (IDH mutation and wild-type on TCGA and US datasets in case A) and glioma grades (high/low grade glioma HGG and LGG on MICCAI dataset in case B). The proposed FL scheme has obtained good performance on the test sets (85.46%, 75.56%) for IDH subtypes and (89.28%, 90.72%) for glioma LGG/HGG all averaged on five runs. Comparing with the corresponding CL scheme, the drop in test accuracy from the proposed FL scheme is small (-1.17%, -0.83%), indicating its good potential to replace the CL scheme. Furthermore, the empirically tests have shown that an increased classification test accuracy by applying: domain mapping (0.4%, 1.85%) in case A; focal loss function (1.66%, 3.25%) in case A and (1.19%, 1.85%) in case B; 3D post-processing (2.11%, 2.23%) in case A and (1.81%, 2.39%) in case B and EtFedDyn over FedAvg classifier (1.05%, 1.55%) in case A and (1.23%, 1.81%) in case B with fast convergence, which all contributed to the improvement of overall performance in the proposed FL scheme. The proposed FL scheme is shown to be effective in predicting glioma and its subtypes by using MR images from test sets, with great potential of replacing the conventional CL approaches for training deep networks. This could help hospitals to maintain their data privacy, while using a federated trained classifier with nearly similar performance as that from a centrally trained one. Further detailed experiments have shown that different parts in the proposed 3D FL scheme, such as domain mapping (make datasets more uniform) and post-processing (scan-based classification), are essential.

  • Research Article
  • Cite Count Icon 13
  • 10.1016/j.ipm.2024.103929
PRoT-FL: A privacy-preserving and robust Training Manager for Federated Learning
  • Oct 11, 2024
  • Information Processing and Management
  • Idoia Gamiz + 4 more

PRoT-FL: A privacy-preserving and robust Training Manager for Federated Learning

  • Research Article
  • Cite Count Icon 232
  • 10.1016/j.future.2021.09.015
An adaptive federated learning scheme with differential privacy preserving
  • Sep 15, 2021
  • Future Generation Computer Systems
  • Xiang Wu + 5 more

An adaptive federated learning scheme with differential privacy preserving

  • Research Article
  • Cite Count Icon 13
  • 10.1109/tifs.2024.3477912
CareFL: Contribution Guided Byzantine-Robust Federated Learning
  • Jan 1, 2024
  • IEEE Transactions on Information Forensics and Security
  • Qihao Dong + 7 more

Byzantine-robust federated learning (FL) endeavors to empower service providers in acquiring a precise global model, even in the presence of potentially malicious FL clients. While considerable strides have been taken in the development of robust aggregation algorithms for FL in recent years, their efficacy is confined to addressing particular forms of Byzantine attacks, and they exhibit vulnerabilities when confronted with a spectrum of attack vectors. Notably, a prevailing issue lies in the heavy reliance of these algorithms on the examination of local model gradients. It is worth noting that an attacker possesses the ability to manipulate a carefully chosen small gradient of a model within a context where there could be millions of gradients available, thereby facilitating adaptive attacks. Drawing inspiration from the foundational Shapley value methodology in game theory, we introduce an effective FL scheme named <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace>. This scheme is designed to provide robustness against a spectrum of state-of-the-art Byzantine attacks. Unlike approaches that rely on the examination of gradients, <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace> employs a universal metric, the loss of the local model—independent of specific gradients, to identify potentially malicious clients. Specifically, in each aggregation round, the FL server trains a reference model using a small auxiliary dataset— the auxiliary dataset can be removed with a slight defense degradation trade-off. It employs the Shapley value to assess the contribution of each client-submitted model in minimizing the global model loss. Subsequently, the server selects client models closer to the reference model in terms of Shapley values for the global model update. To reduce the computational overhead of <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace> when the number of clients is relatively scaled-up, we construct its variant, namely <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace>+ generally by grouping clients. Extensive experimentation conducted on well-established MNIST and CIFAR-10 datasets, encompassing diverse model architectures, including AlexNet, demonstrates that <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace> consistently achieves accuracy levels comparable to those attained under attack-free conditions when faced with five formidable attacks. <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">CareFL</monospace> and CareFL+ outperform six existing state-of-the-art Byzantine-robust FL aggregation methods, including <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FLTrust</monospace>, across both IID and non-IID data distribution settings.

  • Conference Article
  • Cite Count Icon 4
  • 10.1145/3696410.3714666
FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State Channels
  • Apr 22, 2025
  • Ruonan Chen + 7 more

Federated Learning (FL) is a distributed machine learning paradigm that allows multiple clients to train models collaboratively without sharing local data. Numerous works have explored security and privacy protection in FL, as well as its integration with blockchain technology. However, existing FL works still face critical issues. i) It is difficult to achieving poisoning robustness and data privacy while ensuring high model accuracy. Malicious clients can launch poisoning attacks that degrade the global model. Besides, aggregators can infer private data from the gradients, causing privacy leakages. Existing privacy-preserving poisoning defense FL solutions suffer from decreased model accuracy and high computational overhead. ii) Blockchain-assisted FL records iterative gradient updates on-chain to prevent model tampering, yet existing schemes are not compatible with practical blockchains and incur high costs for maintaining the gradients on-chain. Besides, incentives are overlooked, where unfair reward distribution hinders the sustainable development of the FL community. In this work, we propose FLock, a robust and privacy-preserving FL scheme based on practical blockchain state channels. First, we propose a lightweight secure Multi-party Computation (MPC)-friendly robust aggregation method through quantization, median, and Hamming distance, which could resist poisoning attacks against up to <50% malicious clients. Besides, we propose communication-efficient Shamir's secret sharing-based MPC protocols to protect data privacy with high model accuracy. Second, we utilize blockchain off-chain state channels to achieve immutable model records and incentive distribution. FLock achieves cost-effective compatibility with practical cryptocurrency platforms, e.g. Ethereum, along with fair incentives, by merging the secure aggregation into a multi-party state channel. In addition, a pipelined Byzantine Fault-Tolerant (BFT) consensus is integrated where each aggregator can reconstruct the final aggregated results. Lastly, we implement FLock and the evaluation results demonstrate that FLock enhances robustness and privacy, while maintaining efficiency and high model accuracy. Even with 25 aggregators and 100 clients, FLock can complete one secure aggregation for ResNet in 2 minutes over a WAN. FLock successfully implements secure aggregation with such a large number of aggregators, thereby enhancing the fault tolerance of the aggregation.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 20
  • 10.3390/s23084087
Hierarchical Trajectory Planning for Narrow-Space Automated Parking with Deep Reinforcement Learning: A Federated Learning Scheme
  • Apr 18, 2023
  • Sensors (Basel, Switzerland)
  • Zheng Yuan + 4 more

Collision-free trajectory planning in narrow spaces has become one of the most challenging tasks in automated parking scenarios. Previous optimization-based approaches can generate accurate parking trajectories, but these methods cannot compute feasible solutions with extremely complex constraints in a limited time. Recent research uses neural-network-based approaches that can generate time-optimized parking trajectories in linear time. However, the generalization of these neural network models in different parking scenarios has not been considered thoroughly and the risk of privacy compromise exists in the case of centralized training. To address the above issues, this paper proposes a hierarchical trajectory planning method with deep reinforcement learning in the federated learning scheme (HALOES) to rapidly and accurately generate collision-free automated parking trajectories in multiple narrow spaces. HALOES is a federated learning based hierarchical trajectory planning method to fully exert high-level deep reinforcement learning and the low-level optimization-based approach. HALOES further fuse the deep reinforcement learning model parameters to improve the generalization capabilities with a decentralized training scheme. The federated learning scheme in HALOES aims to protect the privacy of the vehicle’s data during model parameter aggregation. Simulation results show that the proposed method can achieve efficient automatic parking in multiple narrow spaces, improve planning time from to compared to other state-of-the-art methods (e.g., hybrid A*, OBCA) and maintain the same level of trajectory accuracy while having great model generalization.

  • PDF Download Icon
  • Research Article
  • 10.54097/6jamgy43
PPBRFL: Privacy-Preserving Byzantine-Robust Federated Learning
  • Feb 3, 2024
  • Frontiers in Computing and Intelligent Systems
  • Qun Zhou

Federated learning is a distributed machine learning approach that allows the neural network to be trained without exposing private user data. Despite its advantages, federated learning schemes still face two critical security challenges: user privacy disclosure and Byzantine robustness. The adversary may try to infer the private data from the trained local gradients or compromise the global model update. To tackle the above challenges, we propose PPBRFL, a privacy-preserving Byzantine-robust federated learning scheme. To resist Byzantine attacks, we design a novel Byzantine-robust aggregation method based on&#x0D; cosine similarity, which can guarantee the global model update and improve the model’s classification accuracy. Furthermore, we introduce a reward and penalty mechanism that considers users’ behavior to mitigate the impact of Byzantine users on the global model. To protect user privacy, we utilize symmetric homomorphic encryption to encrypt the users’ trained local models, which requires low computation cost while maintaining model accuracy. We conduct the experimental assessment of the performance of PPBRFL. The experimental results show that PPBRFL maintains model classification accuracy while ensuring privacy preservation and Byzantine robustness compared to traditional federated learning scheme.

  • Conference Article
  • 10.1145/3727353.3727504
A Federated Learning Scheme for Enhanced Privacy Protection and Resistance to Byzantine Attacks
  • Jan 10, 2025
  • Zijun Guo + 3 more

As distributed data sources grow, and privacy protection becomes more important, federated learning (FL) is becoming an important way to model by collaboration under data privacy constraints. However, existing federated learning schemes still suffer from data privacy preservation and security problems. We propose a federated learning scheme that also helps better preserve privacy and defend against Byzantine attacks. This type of scheme is based on discrete stochastic noise, using multi-layer privacy preservation to protect private data and defend against Byzantine attacks. First, we propose a dual-layer protection mechanism of adding discrete noise and differential privacy noise, both of which aim at protecting against inference attacks and data privacy. Second, we introduce a dual server architecture to separate aggregation and privacy processing to mitigate the server collusion risk. Lastly, we use a secure aggregation defense strategy to mitigate the negative effect of Byzantine nodes on the global model. It is also shown that our improved scheme performs better than the original LSFL scheme in terms of its inference resistance and privacy protection.

  • Research Article
  • Cite Count Icon 37
  • 10.1109/tgrs.2023.3244136
Federated Deep Learning With Prototype Matching for Object Extraction From Very-High-Resolution Remote Sensing Images
  • Jan 1, 2023
  • IEEE Transactions on Geoscience and Remote Sensing
  • Xiaokang Zhang + 3 more

Deep convolutional neural networks (DCNNs) have become the leading tools for object extraction from very-high-resolution (VHR) remote sensing images. However, the label scarcity problem of local datasets hinders the prediction performances of DCNNs, and privacy concerns regarding remote sensing data often arise in the traditional deep learning schemes. To cope with these problems, we propose a novel federated learning scheme with prototype matching (FedPM) to collaboratively learn a richer DCNN model by leveraging remote sensing data distributed among multiple clients. This scheme conducts federated optimization of DCNNs by aggregating clients’ knowledge in the gradient space without compromising data privacy. Specifically, the prototype matching method is developed to regularize the local training using prototypical representations while reducing the distribution divergence across heterogeneous image data. Furthermore, the derived deviations across local and global prototypes are applied to quantify the effects of local models on the decision boundary and optimize the global model updating via the attention-weighted aggregation scheme. Finally, the sparse ternary compression (STC) method is used to alleviate communication costs. Extensive experimental results derived from VHR aerial and satellite image datasets verify that the FedPM can dramatically improve the prediction performance of DCNNs on object extraction with lower communication costs. To the best of our knowledge, this is the first time federated learning has been applied for remote sensing visual tasks.

  • Conference Article
  • Cite Count Icon 60
  • 10.1109/icoin48656.2020.9016505
Self Organizing Federated Learning Over Wireless Networks: A Socially Aware Clustering Approach
  • Jan 1, 2020
  • Latif U Khan + 3 more

The significant proliferation of the Internet of Things (IoT) devices generates an enormous amount of data. Availability of such a large amount of data offers opportunities for using machine learning to enable intelligence in numerous applications. However, centralized machine learning schemes are based on migrating the data from devices to a centralized location for training. Such migration of data from user devices to a centralized location suffers from significant privacy concerns. To cope with this privacy preservation challenge, federated learning is a viable solution which enables learning in a distributed manner without migrating the data from devices to a centralized location. In this paper, we propose a novel federated learning scheme that offers federated learning without using centralized cloud server. First, we present a clustering algorithm based on social awareness which is followed by cluster head selection. Second, we formulate an optimization problem to minimize global federated learning time. Due to the NP-hard nature of the formulated optimization problem, we propose a heuristic algorithm to optimize the global federated learning time. Finally, we present numerical results to validate our proposed algorithm.

  • Research Article
  • Cite Count Icon 20
  • 10.1145/3634686
A Privacy Preserving System for Movie Recommendations Using Federated Learning
  • Nov 27, 2024
  • ACM Transactions on Recommender Systems
  • David Neumann + 3 more

Recommender systems have become ubiquitous in the past years. They solve the tyranny of choice problem faced by many users, and are utilized by many online businesses to drive engagement and sales. Besides other criticisms, like creating filter bubbles within social networks, recommender systems are often reproved for collecting considerable amounts of personal data. However, to personalize recommendations, personal information is fundamentally required. A recent distributed learning scheme called federated learning has made it possible to learn from personal user data without its central collection. Consequently, we present a recommender system for movie recommendations, which provides privacy and thus trustworthiness on multiple levels: First and foremost, it is trained using federated learning and thus, by its very nature, privacy-preserving, while still enabling users to benefit from global insights. Furthermore, a novel federated learning scheme, called FedQ, is employed, which not only addresses the problem of non-i.i.d.-ness and small local datasets, but also prevents input data reconstruction attacks by aggregating client updates early. Finally, to reduce the communication overhead, compression is applied, which significantly compresses the exchanged neural network parametrizations to a fraction of their original size. We conjecture that this may also improve data privacy through its lossy quantization stage.

  • Conference Article
  • 10.1117/12.2682414
SVFL: A secure and verifiable federated learning scheme
  • Jun 20, 2023
  • Wang Meilin

Federated learning can effectively alleviate the data privacy problem of the participants, but the parameters or gradients passed in the model training may still leak the private data of the participants. Worse, aggregation server may return fake aggregation results. Existing solutions either use complex cryptographic primitives such as zero-knowledge proofs, or require interaction among participants, causing them high computation or communication overhead. Therefore, this paper proposes a secure and verifiable federated learning (SVFL) scheme. Specifically, SVFL performs privacy protection by introducing noise that can be offset during the aggregation process, and utilizes linear homomorphic hash to verify the correctness of the aggregation results. Compared with existing schemes, SVFL hardly loses accuracy due to the introduced security mechanism, and has low computation and communication overhead. Experimental results show that the performance of SVFL is almost consistent with the original federated learning without any protection, which makes SVFL applicable to edge devices. The computation and communication overhead of SVFL does not increase with the number of participants, which makes SVFL applicable to high-concurrency scenarios.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant