yusufcalisir's picture
deploy: Hugging Face space upload
73ba4f5
|
Raw History Blame Contribute Delete
8.24 kB

Secure Aggregation (Curve25519 SecAgg) Algorithm Specification

1. Problem Solved

Secure Aggregation (SecAgg; Bonawitz et al., 2017) resolves the fundamental privacy risk that a curious or compromised central coordinator could inspect unmasked client weight updates $\Delta w_k$.

SecAgg ensures that the central coordinator learns only the global sum:

S=βˆ‘k=1KΞ”wkS = \sum_{k=1}^K \Delta w_k

while remaining cryptographically blinded to any individual bank's contribution $\Delta w_k$.


2. Implementation in CF-Intelligence

  • Location: backend/app/infrastructure/security/p2p_secagg_driver.py
  • Key Exchange: X25519 (Curve25519 Diffie-Hellman key agreement over $\mathbb{F}_{2^{255}-19}$).
  • Pairwise Zero-Sum Masking: For every pair of active banks $(i, j)$ with $i < j$:
    1. Bank $i$ and Bank $j$ establish a shared secret via Diffie-Hellman: $k_{i,j} = \mathrm{X25519}(\mathrm{sk}_i, \mathrm{pk}_j) = \mathrm{X25519}(\mathrm{sk}_j, \mathrm{pk}_i)$.
    2. A pseudorandom mask vector $s_{i,j} \in \mathbb{R}^d$ is expanded using HMAC-SHA256 seeded with $k_{i,j}$.
    3. Bank $i$ adds $s_{i,j}$ to its update; Bank $j$ subtracts $s_{i,j}$:

Ξ”w~i=Ξ”wi+βˆ‘j>isi,jβˆ’βˆ‘j<isj,i+bi\widetilde{\Delta w}_i = \Delta w_i + \sum_{j > i} s_{i,j} - \sum_{j < i} s_{j,i} + \mathbf{b}_i

where $\mathbf{b}_i$ is Bank $i$'s local self-mask.

  • Sum Cancellation: When all $K$ clients submit their masked updates to the coordinator:

βˆ‘i=1KΞ”w~i=βˆ‘i=1KΞ”wi+βˆ‘i=1K(βˆ‘j>isi,jβˆ’βˆ‘j<isj,i)⏟=0+βˆ‘i=1Kbi\sum_{i=1}^K \widetilde{\Delta w}_i = \sum_{i=1}^K \Delta w_i + \underbrace{\sum_{i=1}^K \left( \sum_{j > i} s_{i,j} - \sum_{j < i} s_{j,i} \right)}_{= 0} + \sum_{i=1}^K \mathbf{b}_i

  • Dropout Resilience: Self-masks $\mathbf{b}_i$ and pairwise seeds are split using $(t, n)$ Shamir's Secret Sharing. If a client drops out before round completion, remaining active peers reveal shares of the dropped client's pairwise keys, enabling the coordinator to subtract orphaned masks without unblinding honest clients.

3. Threat Model & Security Assumptions

  • Adversary Limit: Protects against an honest-but-curious coordinator colluding with up to $N - 2$ corrupted clients.
  • Collusion Bound: Requires at least 2 honest clients $(u, v)$ to guarantee complete confidentiality of model updates; their mutual pairwise mask $s_{u,v}$ prevents the coordinator and all $N - 2$ colluding participants from unblinding individual updates.
  • Information-Theoretic Barrier: In the event of $N - 1$ colluding participants, the remaining client's update is algebraically determined by subtracting known weights from the global sum $S - \sum_{i \neq u} w_i = w_u$, representing the fundamental information-theoretic limit of all additive aggregation protocols.
  • Replay & Tamper Resistance: Ephemeral Curve25519 key agreements combined with round-salted HKDF-SHA256 derivation (cfi:secagg:round:{round_id}) prevent cross-round replay and mask injection attacks.

4. Operational Limitations

  • Communication Rounds: Requires 4 sequential network rounds:
    1. Advertise Keys (Round 0)
    2. Share Encrypted Seeds (Round 1)
    3. Masked Input Collection (Round 2)
    4. Unmasking Shares Verification (Round 3)
  • Computational Complexity: Scale $O(K^2)$ in pairwise key negotiations, optimized for consortium sizes $K \le 50$.

5. Test Suite Verification & Scientific Proofs


6. Communication Cost, Bandwidth Overhead & Wire Size Profiling

6.1 Cryptographic Coordination Payload Breakdown

Across the 4-round Curve25519 SecAgg lifecycle, the wire payload exchanged between $K$ client banks and the central coordinator consists of:

  1. Round 0 (Advertise Keys): Each client broadcasts its ephemeral Curve25519 public key ($32\text{ bytes}$) signed with an Ed25519 identity signature ($64\text{ bytes}$):

PayloadR0=Kβ‹…96(bytes)\mathrm{Payload}_{\mathrm{R0}} = K \cdot 96 \quad (\text{bytes})

  1. Round 1 (Share Encrypted Seeds): Each client transmits $(K - 1)$ encrypted seed shares wrapped with recipient public keys ($\approx 48\text{ bytes}$ ciphertext per peer):

PayloadR1=K(Kβˆ’1)β‹…48(bytes)\mathrm{Payload}_{\mathrm{R1}} = K(K - 1) \cdot 48 \quad (\text{bytes})

  1. Round 2 (Masked Input Collection): Each client transmits its blinded parameter vector $\widetilde{\Delta w}_i \in \mathbb{R}^d$ along with an HMAC-SHA256 message authentication code ($32\text{ bytes}$):

PayloadR2=Kβ‹…(Smodel+32)(bytes)\mathrm{Payload}_{\mathrm{R2}} = K \cdot (S_{\mathrm{model}} + 32) \quad (\text{bytes})

  1. Round 3 (Unmasking Shares): Clients reveal Shamir shares of the blinding seeds for dropped participants or self-masks ($\approx 32\text{ bytes}$ per peer):

PayloadR3=K(Kβˆ’1)β‹…32(bytes)\mathrm{Payload}_{\mathrm{R3}} = K(K - 1) \cdot 32 \quad (\text{bytes})

6.2 Total Wire Volume vs Baseline Protocols ($d = 1{,}969$ parameters, $K=3$ banks, $R=5$ rounds)

Protocol Payload per Round 5-Round Total Volume Relative Overhead vs FedAvg Security & Privacy Guarantee
FED_AVG 31,504 B 0.1502 MB 1.00Γ— No cryptographic blinding (plaintext parameters)
FED_PROX 31,504 B 0.1502 MB 1.00Γ— Identical wire footprint; local proximal loss penalty
CURVE25519_SECAGG 32,752 B 0.1562 MB 1.04Γ— Information-theoretic zero-knowledge server privacy ($+4.0%$ overhead)
SCAFFOLD 63,008 B 0.3004 MB 2.00Γ— Dual parameter + control variate exchange
TENSEAL_CKKS 330,792 B 1.5773 MB 10.50Γ— Fully homomorphic ciphertext expansion ($10.5\times$ bandwidth)

The complete empirical benchmark analysis and 4-panel bandwidth visualization figure are documented in docs/enterprise_benchmark_report.md#24-federated-communication-cost--bandwidth-profiling-benchmark and docs/figures/benchmark_communication.png.