acceptodds
Under review as a conference paper at ICLR 2027

SCARFL: Single-Ciphertext Privacy-Preserving Byzantine-Robust Federated Learning

Abstract

Privacy-preserving Byzantine-robust federated learning requires computing geometric statistics of client updates without exposing the updates themselves. Existing baselines like AegisFL achieve this by extracting encrypted scalars from two coefficient-packed ciphertexts per client, which necessitates an interactive consistency check. In this work, we reveal that the complementary packing is mathematically exactly the inverse-index Galois automorphism of the primary packing. Leveraging this insight, we propose SCARFL, which eliminates the redundant client upload by deriving the second ciphertext view directly at the aggregation server while strictly preserving the encrypted scalar interface. To demonstrate the practical viability of this retained interface, we instantiate it with GHARC, an aggregation rule that discovers update clusters and accepts them only when historical-reference evidence passes a security guard. For 30 clients, our Single-CT protocol halves recurring client uploads and reduces total round traffic by 43.0% on HAR and 45.7% on MNIST. Mean round time falls by 11.0% and 9.2%, respectively, with a negligible maximum inner-product error of . Under evaluated untargeted, label-flipping, and scaling attacks, the GHARC instantiation maintains stable clean accuracy and suppresses attack success rates with up to 14 malicious clients. Comprehensive ablations validate the roles of its clustering, clipping, ranking, and adaptive core expansion mechanisms.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.