Spaces:
Runtime error
Download docs/algorithms/secure_aggregation.md from yusufcalisir/Collaborative-Fraud-Intelligence-Simulator: direct link, hf CLI and curl.
- Browser
- Download file 8.24 kB
-
https://huggingface.co/spaces/yusufcalisir/Collaborative-Fraud-Intelligence-Simulator/resolve/main/docs/algorithms/secure_aggregation.md
- Command line
-
hf download hf://spaces/yusufcalisir/Collaborative-Fraud-Intelligence-Simulator/docs/algorithms/secure_aggregation.md
-
curl -L -o secure_aggregation.md https://huggingface.co/spaces/yusufcalisir/Collaborative-Fraud-Intelligence-Simulator/resolve/main/docs/algorithms/secure_aggregation.md
Secure Aggregation (Curve25519 SecAgg) Algorithm Specification
1. Problem Solved
Secure Aggregation (SecAgg; Bonawitz et al., 2017) resolves the fundamental privacy risk that a curious or compromised central coordinator could inspect unmasked client weight updates $\Delta w_k$.
SecAgg ensures that the central coordinator learns only the global sum:
while remaining cryptographically blinded to any individual bank's contribution $\Delta w_k$.
2. Implementation in CF-Intelligence
- Location:
backend/app/infrastructure/security/p2p_secagg_driver.py - Key Exchange: X25519 (Curve25519 Diffie-Hellman key agreement over $\mathbb{F}_{2^{255}-19}$).
- Pairwise Zero-Sum Masking:
For every pair of active banks $(i, j)$ with $i < j$:
- Bank $i$ and Bank $j$ establish a shared secret via Diffie-Hellman: $k_{i,j} = \mathrm{X25519}(\mathrm{sk}_i, \mathrm{pk}_j) = \mathrm{X25519}(\mathrm{sk}_j, \mathrm{pk}_i)$.
- A pseudorandom mask vector $s_{i,j} \in \mathbb{R}^d$ is expanded using HMAC-SHA256 seeded with $k_{i,j}$.
- Bank $i$ adds $s_{i,j}$ to its update; Bank $j$ subtracts $s_{i,j}$:
where $\mathbf{b}_i$ is Bank $i$'s local self-mask.
- Sum Cancellation: When all $K$ clients submit their masked updates to the coordinator:
- Dropout Resilience: Self-masks $\mathbf{b}_i$ and pairwise seeds are split using $(t, n)$ Shamir's Secret Sharing. If a client drops out before round completion, remaining active peers reveal shares of the dropped client's pairwise keys, enabling the coordinator to subtract orphaned masks without unblinding honest clients.
3. Threat Model & Security Assumptions
- Adversary Limit: Protects against an honest-but-curious coordinator colluding with up to $N - 2$ corrupted clients.
- Collusion Bound: Requires at least 2 honest clients $(u, v)$ to guarantee complete confidentiality of model updates; their mutual pairwise mask $s_{u,v}$ prevents the coordinator and all $N - 2$ colluding participants from unblinding individual updates.
- Information-Theoretic Barrier: In the event of $N - 1$ colluding participants, the remaining client's update is algebraically determined by subtracting known weights from the global sum $S - \sum_{i \neq u} w_i = w_u$, representing the fundamental information-theoretic limit of all additive aggregation protocols.
- Replay & Tamper Resistance: Ephemeral Curve25519 key agreements combined with round-salted HKDF-SHA256 derivation (
cfi:secagg:round:{round_id}) prevent cross-round replay and mask injection attacks.
4. Operational Limitations
- Communication Rounds: Requires 4 sequential network rounds:
- Advertise Keys (Round 0)
- Share Encrypted Seeds (Round 1)
- Masked Input Collection (Round 2)
- Unmasking Shares Verification (Round 3)
- Computational Complexity: Scale $O(K^2)$ in pairwise key negotiations, optimized for consortium sizes $K \le 50$.
5. Test Suite Verification & Scientific Proofs
- Scientific Verification Suite (53 Passing Tests):
verification/secure_aggregation/tests/test_secagg_correctness.py: 27 mathematical tests proving exact pairwise mask cancellation $\sum_{u \in U} \mathbf{m}_u \equiv \mathbf{0} \pmod{2^{32}}$ for $N \in {2, 3, 5, 8}$ and dimensions $d \in {1, 16, 256, 1024, 20000}$, with floating-point tolerance $\le 10^{-6}$ against unblinded model updates.verification/secure_aggregation/tests/test_zero_server_knowledge.py: 7 statistical and cryptographic tests verifying Pearson correlation $|r(w, y)| < 0.05$ (zero correlation), Shannon entropy $H(y) \ge 31.95\text{ bits}$, $N-2$ non-collusion protection, Shamir $(t, n)$ dropout privacy, and round isolation.verification/secure_aggregation/tests/test_secagg_hypothesis.py: 6 Hypothesis property-based tests verifying unweighted and weighted zero-sum invariants.verification/secure_aggregation/tests/test_secagg_robustness.py: 12 failure injection and protocol stress scenarios.verification/secure_aggregation/tests/test_fhe_homomorphic_sum.py: TenSEAL CKKS homomorphic linearity verification.
- Unit & Integration Tests:
backend/tests/unit/test_p2p_secagg_driver.py: 16 unit tests covering Curve25519 ECDH key exchange, HMAC bundle signing, PRNG counter expansion, and modular arithmetic.backend/tests/unit/test_p2p_secagg_dropout_recovery.py: Dropout reconstruction using Shamir $(t, n)$ shares.backend/tests/unit/test_shamir_engine.py: Polynomial secret sharing primitives over Galois fields.backend/tests/unit/test_compression_engine.py: 22 unit tests verifying wire transfer measurements, Top-K gradient sparsification, FP16/INT8 quantization, and SecAgg protocol overhead bounds.
6. Communication Cost, Bandwidth Overhead & Wire Size Profiling
6.1 Cryptographic Coordination Payload Breakdown
Across the 4-round Curve25519 SecAgg lifecycle, the wire payload exchanged between $K$ client banks and the central coordinator consists of:
- Round 0 (Advertise Keys): Each client broadcasts its ephemeral Curve25519 public key ($32\text{ bytes}$) signed with an Ed25519 identity signature ($64\text{ bytes}$):
- Round 1 (Share Encrypted Seeds): Each client transmits $(K - 1)$ encrypted seed shares wrapped with recipient public keys ($\approx 48\text{ bytes}$ ciphertext per peer):
- Round 2 (Masked Input Collection): Each client transmits its blinded parameter vector $\widetilde{\Delta w}_i \in \mathbb{R}^d$ along with an HMAC-SHA256 message authentication code ($32\text{ bytes}$):
- Round 3 (Unmasking Shares): Clients reveal Shamir shares of the blinding seeds for dropped participants or self-masks ($\approx 32\text{ bytes}$ per peer):
6.2 Total Wire Volume vs Baseline Protocols ($d = 1{,}969$ parameters, $K=3$ banks, $R=5$ rounds)
| Protocol | Payload per Round | 5-Round Total Volume | Relative Overhead vs FedAvg | Security & Privacy Guarantee |
|---|---|---|---|---|
FED_AVG |
31,504 B | 0.1502 MB | 1.00Γ | No cryptographic blinding (plaintext parameters) |
FED_PROX |
31,504 B | 0.1502 MB | 1.00Γ | Identical wire footprint; local proximal loss penalty |
CURVE25519_SECAGG |
32,752 B | 0.1562 MB | 1.04Γ | Information-theoretic zero-knowledge server privacy ($+4.0%$ overhead) |
SCAFFOLD |
63,008 B | 0.3004 MB | 2.00Γ | Dual parameter + control variate exchange |
TENSEAL_CKKS |
330,792 B | 1.5773 MB | 10.50Γ | Fully homomorphic ciphertext expansion ($10.5\times$ bandwidth) |
The complete empirical benchmark analysis and 4-panel bandwidth visualization figure are documented in docs/enterprise_benchmark_report.md#24-federated-communication-cost--bandwidth-profiling-benchmark and docs/figures/benchmark_communication.png.