cs.CRSep 29, 2026

OPFL: Optimistic Verification of Federated Learning via Empirical Boundary

Authors: Hongxu Su, Jianzhu Yao, Xuechao Wang, Pramod Viswanath

Abstract

Federated learning enables multiple clients to collaboratively train models without sharing their private data. However, the lack of visibility into local training makes it difficult to verify whether clients follow the prescribed training procedure or submit malicious updates, such as model poisoning. A natural approach is to replay client training for verification. However, privacy-preserving replay produces numerical results that cannot be directly matched with local client execution because the two run in different environments. We present OPFL, an optimistic verification framework for privacy-preserving federated learning. To protect data privacy, OPFL performs replay inside secure multi-party computation (MPC). Although gradients computed on MPC and local GPUs are not bitwise identical, we observe that their absolute differences are stable and bounded. OPFL therefore calibrates an empirical boundary offline and uses it to distinguish benign numerical deviations from malicious manipulation. To reduce the cost of expensive MPC replay, OPFL adopts optimistic verification by post auditing only sampled training steps. Experiments on LeNet, BERT, and Qwen show that the boundary generalizes across datasets, input lengths, and GPUs, while achieving 00% ASR against model poisoning and PGD-based attacks. On a LeNet workload, at p=0.01p=0.01, OPFL is approximately 98.6×98.6\times faster than full MPC-based FL and 625.5×625.5\times faster than ZK-based approach.

Figures & tables

Appendix figures & tables6 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning

    Jul 7, 2026Harsh Kasyap, Anil Kumar Pradhan, Ugur Ilker Atmaca +2Federated LearningHomomorphic Encryption

  2. End-to-End Verifiable and Robust Federated Learning

    Sep 14, 2026Doryan Lesaignoux, Enrique Mármol Campos, Gabriele Spini +2Federated LearningZero-Knowledge Proofs

  3. FedReview: Review and Dispose Poisoned Updates without Validation Datasets or Historic Knowledge

    Feb 26, 2024Tianhang Zheng, Yanlu Li, Bohan Deng +1Federated LearningPoisoning