Secure Neural Network in Federated Learning with Model Aggregation under Multiple Keys

Zoe L. Jiang, Hui Guo, Yijian Pan, Yang Liu, Xuan Wang, Jun Zhang · 2021

Federated learning is a privacy preserving machine learning paradigm which trains model on distributed datasets. Homomorphic encryption can be used to protect local model parameters during model aggregation. However, most homomorphic encryption only supports single key. To enhance security, we should allow different clients encrypt their local models by different keys. In this paper, we propose a secure neural network in federated learning and support multiple keys. A double-trapdoor encryption scheme is adapted. We rely on two non-colluding cloud servers. The clients upload the encrypted local models to the first cloud server, which can be decrypted by the second server using one trapdoor. To avoid privacy leakage, the first cloud server runs ciphertext perturbation before sending data to the second server. The aggregated model will be sent back to clients for decryption individually. Benchmark dataset is used for evaluation and the experimental results show that our scheme is competitive in terms of accuracy with some sacrifice of efficiency.

Read the paper · More papers on PaperTik