FedSSuper: A Secure and Private Federated Learning Under Trusted Supervision

Ping Zhao, Jin Jiang, Guanglin Zhang · IEEE Transactions on Network Science and Engineering · 2025

Federated Learning (FL) allows multiple clients and a server to jointly learn a global model while keeping their training data private. However, FL has been proved to be vulnerable to Byzantine attacks where malicious clients submit misleading updates to the server to further manipulate the global model, and inference attacks where the curious server infers clients' training data via analyzing their updates. Mitigating both Byzantine and inference attacks is highly challenging since resisting inference attacks prohibits access to clients' updates, but preventing Byzantine attacks requires such access. Several existing works focusing on such two intuitively conflicting events cannot achieve desirable performance with the Byzantine ratio larger than 0.5, and moreover did not consider the non-independent and identically distributed (non-IID) data, especially the completely non-IID cases. To this end, we propose a secure and privateFederated Learning under truStedSupervision (FedSSuper). The intuition of FedSSuper is that the server first deploys a shadow dataset on the clients to supervise the local training on clients and thereby adaptively tame Byzantines. Likewise, clients supervise the aggregation of local updates on the server side via Secret Sharing based Secure P-Parties Computation, thereby resisting inference attacks. Finally, we theoretically prove FedSSuper's security and privacy guarantees against Byzantine and inference attacks, robustness to clients' dropouts, and desirable computation and communication complexity. Extensive experiments on three datasets and comparisons to seven existing defenses demonstrate the superior performance of FedSSuper against two state-of-the-art Byzantine attacks with large Byzantine ratio 0.7 and high level of non-IID data 1.0, as well as the well-designed inference attacks.

Read the paper · More papers on PaperTik