ABE-FL: Efficient and secure federated learning based on CP-ABE with high-security elliptic curves
Existing secure federated learning (FL) schemes suffer from three major limitations: (1) the initial global model is unprotected during distribution; (2) multi-party computation incurs high communication overhead; and (3) the use of homomorphic encryption (HE) for parameter protection results in computational inefficiency. To address these challenges, we propose ABE-FL, a novel FL framework that incorporates Ciphertext-Policy Attribute-Based Encryption (CP-ABE) with high-security elliptic curves (a 512-bit prime-order subgroup over a 1024-bit base field, which places the construction at the 112-bit security level). ABE-FL protects both the initial model and blinding factors during distribution using CP-ABE encryption. It reduces communication costs by enabling the parameter server to centrally distribute splitting and blinding factors, and it improves aggregation efficiency by integrating a tailored key distribution scheme and a lightweight homomorphic encryption method designed atop CP-ABE. Under an explicitly stated threat model, security analysis shows that ABE-FL keeps local and aggregated model parameters confidential against an honest-but-curious parameter server, that this guarantee remains tight up to a coalition of the server and 𝑡 − 1 credentialed clients, and that entities without valid attributes can neither recover the initial model nor inject updates that are accepted for aggregation. We also delimit the scope of these guarantees: ABE-FL is a confidentiality and access-control mechanism, and does not by itself provide robustness against poisoning or Byzantine updates submitted by credentialed clients. Experiments conducted on MNIST, CIFAR-10, and Shakespeare datasets show that ABE-FL achieves significantly faster encryption, decryption, and aggregation performance compared to schemes based on the Paillier cryptosystem, while maintaining strong privacy guarantees at a comparable security level.
Authors
- Rong Wang (ORCID: https://orcid.org/0000-0001-9251-3775)
- C. Feng
- Maoli Tang
- Shixun Li (ORCID: https://orcid.org/0009-0005-6117-9846)
- Shuainan Liu (ORCID: https://orcid.org/0009-0000-9477-2922)
- Hongjie Zhang
Institutions
- Texas Tech University (US)
- Sichuan Normal University (CN)
Publication Details
- Journal
- Journal of Information Security and Applications
- Published
- 2026-09-18
- DOI
- https://doi.org/10.1016/j.jisa.2026.104636
- Primary Topic
- Cryptography and Data Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00
Funders
- Sichuan Province Science and Technology Support Program