A Verifiable Momentum Federated Learning Scheme
Momentum federated learning (MFL) has attracted widespread attention in privacy-preserving data mining. However, an adversary may engage in two malicious behaviors: (1) launching gradient inversion attacks on momentum information to reconstruct training samples, and (2) tampering with momentum information during aggregation to make the model unreliable. Existing MFL approaches typically struggle to simultaneously address privacy attacks and tampering during training. To address this problem, we propose a verifiable momentum federated learning scheme (VMFL). VMFL employs a chaotic map to generate a pseudo-random sequence and embeds the sum of local momentum vectors as verification data, constructing a verifiable momentum protected by additively homomorphic encryption. We further design an aggregation verification protocol that verifies the aggregated momentum by checking vector-sum consistency in the ciphertext domain before decryption and model updating. Rigorous theoretical analysis establishes the privacy preservation and verifiability. Finally, we conduct extensive experimental simulations, comparisons, and analyses on three real-world datasets, MNIST, FMNIST, and CIFAR-10, with two deep models, LeNet5 and ResNet18, verifying the advantages of VMFL in terms of privacy attack resistance, tamper detection, and time cost.
Authors
- Hua Ren (ORCID: https://orcid.org/0000-0003-1047-2370)
- Qi Wang (ORCID: https://orcid.org/0000-0002-5728-4062)
- Dandan Lu (ORCID: https://orcid.org/0000-0003-4318-8819)
- Danjie Han (ORCID: https://orcid.org/0009-0009-2283-9089)
- Lanlan Wang
- Ming Li
Institutions
- Beijing Institute of Technology (CN)
- Henan Normal University (CN)
- Henan University of Economic and Law (CN)
Publication Details
- Journal
- Symmetry
- Published
- 2026-09-25
- DOI
- https://doi.org/10.3390/sym18101602
- Primary Topic
- Privacy-Preserving Technologies in Data
- Type
- article
- Field-Weighted Citation Impact
- 0.00