DisT-FL: Enhancing Security for TEE-based Aggregation in Federated Learning

Abstract

Trusted Execution Environments (TEEs)-aided federated learning protocols emerge as promising solutions to counter server-side adversaries and ensure the trustworthiness of the server. In this paper, we dissect existing protocols and demonstrate that server-side adversaries can still manipulate client selection and replay aggregation to compromise system robustness and privacy, by exploiting TEE limitations, i.e., state rollback and I/O manipulation. To this end, we present DIS-TFL, a distributed system of servers guarded by multiple TEEs forming an append-only ledger for privacy-preserved, robust FL aggregation. Specifically, DisT-FL ensures operation linearizability to thwart state rollback attacks and incorporates inputs from reliable servers to mitigate I/O manipulation threats. We implement DisT-FL and conduct evaluations in WAN settings. Experimental results demonstrate that DisT-FL can effectively counter the proposed attacks and match the single-TEE’s performance while offering a 6x throughput boost over its counterparts, leveraging TEE’s computational advantages.

Type
Publication
In IEEE Transactions on Information Forensics and Security
Click the Cite button above to demo the feature to enable visitors to import publication metadata into their reference management software.