Federated Learning (FL) enables collaborative training of models across institutions without centralizing sensitive data, making it well-suited for privacy-concerned applications, such as medical imaging. To protect FL model updates during secure aggregation, additive masking is commonly employed. However, its underlying classical key establishment is only computationally secure. On the other hand, physics-based Information-Theoretically Secure (ITS) key exchange introduces practical constraints: finite key generation rates and time-limited storage severely limit throughput and sustained training of uncompressed models. In this work, we address this bottleneck by developing an FL framework that integrates frozen backbones, knowledge distillation, and quantization. These techniques reduce communication payload and, consequently, key material consumption. Moving beyond simulation, we benchmark this framework on a real physics-based key distribution testbed involving a chest X-ray classification application. Our results show that key usage can be reduced by ∼35× while maintaining predictive accuracy. This prevents buffer depletion and key expiration, enabling sustainable FL training under physical key generation constraints.
Figures & tables
Figure 1. Overview of the proposed FL framework. Each client trains a classification head locally (backbone frozen), quantizes the updated parameters, and applies additive masks derived from quantum key material shared with ring neighbors. The server sums all masked updates (pairwise masks cancel exactly) and updates the global model via FedAvg. Overview of the proposed FL framework.
Model
Frozen
Quant.
Partition
Payload
AUROC
Teacher (No masking)
No
32-bit
IID
3.2MB
0.762
Teacher (No masking)
Yes
32-bit
IID
916kB
0.745
Teacher
Yes
32-bit
IID
916kB
0.745
Teacher
Yes
32-bit
non-IID
916kB
0.736
Student
Yes
32-bit
IID
360kB
0.748
Student
Yes
16-bit
IID
180kB
0.738
Table 1. Macro-averaged AUROC on the NIH ChestX-ray14 test set after 50 FL rounds. The teacher is ImageNet-pretrained, and the student is CheXpert-distilled.
Model
Frozen
Quant.
Consumed
Net
Tmin
Rounds
Teacher
No
32-bit
3.2MB
−3.05MB
∼ 85
∼ 33
Teacher
Yes
32-bit
916kB
−766kB
∼ 24
∼ 130
Student
Yes
32-bit
360kB
−210kB
∼ 9.6
∼ 480
Student
Yes
16-bit
180kB
−30kB
∼ 4.8
∼ 3,300
Student
Yes
8-bit
90kB
+60kB
2.4
Indefinite
Table 2. Per-link key budget per round at average key rate Rˉ≈5\text{,}\mathrm{kbit}\text{,}{\mathrm{s}}^{-1} and round duration $T\approx$4\text{\,}\mathrm{min} : consumption, net balance per round, minimum sustainable round duration Tmin=P/Rˉ (in minutes), and rounds sustained by a full ∼100MB link buffer. For the non-frozen teacher, it shows the key consumption it would incur if masked; consumption is identical under IID and non-IID partitioning.
On-device federated learning (FL) enables privacy-preserving and personalized model training on resource-constrained devices such as smartphones and IoT nodes. To reduce communication cost, sign-based methods (e.g., signSGD) transmit one-bit gradients. However, exposing gradient signs makes them vulnerable to inference attacks, while existing secure aggregation schemes are often incompatible with such methods or incur significant computational and communication overhead. We propose a lightweight and information-theoretically secure aggregation framework tailored for sign-based FL. The framework securely computes the majority vote (MV) polynomial through single-round secure multiplication, ensuring end-to-end information-theoretic security under the honest-majority assumption while revealing only the final aggregated sign to the server. To enhance efficiency and scalability, we introduce two key techniques. First, inverse-form exponent reduction halves the effective MV polynomial degree, reducing both communication and computation costs. Second, we propose single-round secure multiplication, achieving linear offline complexity and storage with only a single online communication. Together, these techniques reduce online communication by up to 99.5% and latency by up to 85.7% compared to conventional approaches. Also, by leveraging inherent MDS-code-based decoding, the framework achieves robustness against both dropouts and adversarial behaviors, yielding accuracy gains of up to 20.65% and 10.74%, respectively. Overall, the proposed framework establishes a practical foundation for large-scale, low-latency, and information-theoretically secure aggregation in sign-based FL.
Hyeong-Gun Joo, Songnam Hong, Dong-Joon Shin
Department of Electronic Engineering, Hanyang University, Seoul, South Korea
Secure aggregation allows a server to aggregate users' local updates while preserving update privacy. Existing information-theoretic problems typically assume that correlated random keys are provided by a trusted third party (TTP) or generated via prescribed groupwise structures, while the communication cost for establishing such correlated keys is often ignored. Consequently, the fundamental limits under general key-distribution mechanisms remain unknown. In this paper, we study the T-colluding information-theoretic secure aggregation problem with N users under a general two-phase framework consisting of a key distribution phase and an update aggregation phase. Unlike prior work, we model key distribution through user-to-user communication and allow arbitrary user-generated key-distribution mechanisms, eliminating TTP or prescribed structures. This enables a joint characterization of three resources: randomness for security, key-distribution communication, and aggregation communication. We completely characterize the capacity region among these three resources by constructing a novel secure aggregation scheme together with a matching information-theoretic converse. In particular, we develop an explicit deterministic capacity-achieving construction over any finite field of size at least N, whereas most existing schemes either rely on TTP or employ randomized or existential constructions over sufficiently large finite fields. We further show that the optimal performance can be achieved using only pairwise shared keys, enabling implementation via Diffie--Hellman key exchange. Compared with Google's seminal secure aggregation scheme, the proposed scheme requires fewer random masking keys while preserving the same aggregation communication overhead.
Lanxin Yi, Jinbao Zhu, Kai Wan +1
Information Coding and Transmission (ICT) Key Laboratory of Sichuan Province, Southwest Jiaotong University, Chengdu 611756, China · School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan 430074, China
Federated learning (FL) has become a foundational paradigm for multi-institutional medical AI, allowing hospitals and research centers to jointly train diagnostic models without exchanging patient records. This privacy promise, however, is increasingly contested: a malicious or honest-but-curious server can launch model inversion attacks (MIAs) that reconstruct private patient images directly from shared model updates, and recent scalable, closed-form attacks penetrate even secure aggregation at clinically realistic batch sizes. Existing defenses face an unsatisfactory dilemma. Gradient-perturbation methods such as differential privacy and pruning trade away the diagnostic accuracy on which clinical reliability depends, while cryptographic protocols add system complexity yet still leave updates exposed to these scalable attacks. We propose Aegis, a principled client-side defense that breaks this dilemma without perturbing patient data or modifying the FL protocol. Our key insight is that the success of every known MIA is fundamentally bounded by the local batch size relative to the model's leakage capacity; once this limit is exceeded, distinct samples collide and reconstructions collapse into indistinguishable mixtures. Aegis turns this universal bottleneck into a defense: each client superimposes onto its real update a masking gradient computed on locally synthesized, task-relevant data, deliberately pushing the effective batch beyond the attack's recovery capacity. We complement the design with theoretical convergence guarantees under standard convex assumptions and evaluate Aegis on MNIST, CIFAR-10, and three MedMNIST modalities (chest X-ray, abdominal CT, colon pathology). Aegis neutralizes three state-of-the-art MIAs while preserving model utility and incurring only modest overhead, offering a practical privacy primitive for medical FL.
Chaoyu Zhang, Shanghao Shi, Heng Jin +3
Virginia Tech · Washington University in St. Louis · University of South Florida