Privacy-Preserving and Byzantine-Robust Federated Learning With Mean-Constrained Secret Sharing
Abstract
Federated learning faces three critical challenges in enabling cross-institutional collaboration: privacy leakage, poisoning by malicious clients, and unverifiable aggregation results. To address these issues in a unified manner, we propose PVeriFL—a federated learning framework that integrates privacy preservation, Byzantine fault tolerance, and lightweight client-side verifiability. Its core innovation is a dynamic mean-constrained secret sharing (DMCSS) mechanism. By imposing quantile-based constraints, DMCSS ensures that secret shares closely follow the directional profile of the original gradients. This enables robust gradient filtering while maintaining strong privacy guarantees. Building on DMCSS, we design an efficient two-server protocol that securely performs Top- $k$ filtering on encrypted shares. Clients can then non-interactively verify the correctness of aggregated results using homomorphic hashing. Theoretical analysis proves the security of PVeriFL and formally quantifies the inherent privacy–robustness trade-off. Comprehensive experiments on multiple datasets show that under 50% client poisoning, PVeriFL achieves accuracy comparable to the state-of-the-art scheme P2Brofl (e.g., 96.71% on MNIST) while delivering major efficiency gains: end-to-end runtime is reduced to 34.7% of P2Brofl, computational overhead drops to about 2.25%, and communication overhead is lowered by 25%. PVeriFL thus effectively unifies the three security objectives, offering a practical and trustworthy solution for real-world federated learning systems.