acceptodds
Under review as a conference paper at ICLR 2027

DiSHE: Dispersion-Guided Selective Homomorphic Encryption for Federated Learning

Abstract

Homomorphic encryption (HE) lets a federated learning server aggregate client updates that it cannot read, but encrypting every parameter is expensive. Selective HE therefore encrypts only part of each update, usually under a single mask that all clients agree on. We present DiSHE, a selective CKKS protocol in which each client chooses its own mask. Updates are cut on a public grid of ciphertext-aligned chunks, so masks that differ across clients still aggregate slot by slot. Clients rank chunks by chunk gradient dispersion (CGD), the per-coordinate sample variance of per-example gradients on a small round-start probe, and always encrypt the classifier head. The same scores define a family of aggregation rules between FedAvg and inverse-dispersion weighting. Because encryption leaves the aggregated values unchanged, the learned model depends, in exact arithmetic, only on the aggregation rule; we characterize the resulting family, including a lower bound on every client's weight, and bound the ciphertext part of the stateless broadcast. With ResNet-18, five non-IID clients, ten rounds, and a nominal encryption ratio of 10%, the final global test accuracy of DiSHE is within 0.83 points of MaskCrypt and FedML-HE on CIFAR-10 and SVHN, and within 2.30 points on Fashion-MNIST. It exceeds our clipping-and-noise versions of FAS and ParaAegis by 4.96–49.51 points. At a 10% ratio, DiSHE needs no mask exchange and has the lowest per-round protocol time (1.51 s versus 1.82-15.54 s) of the five implementations. In masked-gradient attacks on LeNet-5, DiSHE is the only method that blocks both analytic label attacks, iDLG and iLRG, in every attempt.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.