SearcharxivSearch

arXiv subjects

Alexandre Rapetti

Publications and source records attributed to Alexandre Rapetti.

5 recordsLinked to original sources

Privacy-Preserving Federated Averaging with Byzantine Aggregators in Asynchronous Networks

Federated Learning requires secure aggregation to prevent gradient leakage, yet existing protocols suffer from key limitations: they assume synchrony, require heavy peer-to-peer coordination, and do not tolerate aggregators that halt or omit messages. These constraints make current secure aggregation schemes impractical in large-scale, unreliable distributed settings.To overcome these limitations, we introduce a new secure aggregation protocol that operates in fully asynchronous networks, where messages may be arbitrarily delayed, and tolerates fully Byzantine aggregators that are capable of arbitrary deviations including premature halting. Our design combines several key mechanisms: clustering clients under verifiable coordinators, lightweight LWE-based masking (with masking components distributed across aggregators), and differential privacy applied to both intermediary and final aggregated models. We further propose verifiable shuffling of clients across clusters, which prevents any client from being systematically excluded by a Byzantine coordinator, and a fair inclusion mechanism that ensures the inclusion of straggling clients whose messages are late. The protocol eliminates all client-to-client communication, and its communication overhead scales only with the number of aggregators. It also ensures equal representation of clients across rounds, avoiding bias and preventing unbalanced privacy risks among clients. Overall, our protocol provides the first secure aggregation primitive that is both privacy-preserving and robust to fully Byzantine behavior in asynchronous networks, closing the gap between prior secure aggregation assumptions and real-world distributed systems.

cs.DC

Auditable Shared Objects: From Registers to Synchronization Primitives

Auditability allows to track operations performed on a shared object, recording who accessed which information. This gives data owners more control on their data. Initially studied in the context of single-writer registers, this work extends the notion of auditability to other shared objects, and studies their properties. We start by moving from single-writer to multi-writer registers, and provide an implementation of an auditable $n$-writer $m$-reader read / write register, with $O(n+m)$ step complexity. This implementation uses $(m+n)$-sliding registers, which have consensus number $m+n$. We show that this consensus number is necessary. The implementation extends naturally to support an auditable load-linked / store-conditional (LL/SC) shared object. LL/SC is a primitive that supports efficient implementation of many shared objects. Finally, we relate auditable registers to other access control objects, by implementing an anti-flickering deny list from auditable registers.

cs.DC

Auditing without Leaks Despite Curiosity

\textit{Auditing} data accesses helps preserve privacy and ensures accountability by allowing one to determine who accessed (potentially sensitive) information. A prior formal definition of register auditability was based on the values returned by read operations, \emph{without accounting for cases where a reader might learn a value without explicitly reading it or gain knowledge of data access without being an auditor}. This paper introduces a refined definition of auditability that focuses on when a read operation is \emph{effective}, rather than relying on its completion and return of a value. Furthermore, we formally specify the constraints that \textit{prevent readers from learning values they did not explicitly read or from auditing other readers' accesses.} Our primary algorithmic contribution is a wait-free implementation of a \emph{multi-writer, multi-reader register} that tracks effective reads while preventing unauthorized audits. The key challenge is ensuring that a read is auditable as soon as it becomes effective, which we achieve by combining value access and access logging into a single atomic operation. Another challenge is recording accesses without exposing them to readers, which we address using a simple encryption technique (one-time pad). We extend this implementation to an \emph{auditable max register} that tracks the largest value ever written. The implementation deals with the additional challenge posed by the max register semantics, which allows readers to learn prior values without reading them. The max register, in turn, serves as the foundation for implementing an \emph{auditable snapshot} object and, more generally, \emph{versioned types}. These extensions maintain the strengthened notion of auditability, appropriately adapted from multi-writer, multi-reader registers.

cs.DC

Preliminaries paper: Byzantine Tolerant Strong Auditable Atomic Register

An auditable register extends the classical register with an audit operation that returns information on the read operations performed on the register. In this paper, we study Byzantine resilient auditable register implementations in an asynchronous message-passing system. Existing solutions implement the auditable register on top of at least 4f+1 servers, where at most $f$ can be Byzantine. We show that 4f+1 servers are necessary to implement auditability without communication between servers, or implement does not implement strong auditability when relaxing the constraint on the servers' communication, letting them interact with each other. In this setting, it exists a solution using 3f+1 servers to implement a simple auditable atomic register. In this work, we implement strong auditable register using 3f+1 servers with server to server communication, this result reinforced that with communication between servers, auditability (event strong auditability) does not come with an additional cost in terms of the number of servers.

cs.DC

The Synchronization Power of Auditable Registers

Auditability allows to track all the read operations performed on a register. It abstracts the need of data owners to control access to their data, tracking who read which information. This work considers possible formalizations of auditing and their ramification for the possibility of providing it. The natural definition is to require a linearization of all write, read and audit operations together (atomic auditing). The paper shows that atomic auditing is a powerful tool, as it can be used to solve consensus. The number of processes that can solve consensus using atomic audit depends on the number of processes that can read or audit the register. If there is a single reader or a single auditor (the writer), then consensus can be solved among two processes. If multiple readers and auditors are possible, then consensus can be solved among the same number of processes. This means that strong synchronization primitives are needed to support atomic auditing. We give implementations of atomic audit when there are either multiple readers or multiple auditors (but not both) using primitives with consensus number 2 (swap and fetch&add). When there are multiple readers and multiple auditors, the implementation uses compare&swap. These findings motivate a weaker definition, in which audit operations are not linearized together with the write and read operations (regular auditing). We prove that regular auditing can be implemented from ordinary reads and writes on atomic registers.

cs.DC