SearcharxivSearch

arXiv subjects

Lixia Luo

Publications and source records attributed to Lixia Luo.

8 recordsLinked to original sources

Breaking Privacy in Federated Clustering: Perfect Input Reconstruction via Temporal Correlations

Federated clustering allows multiple parties to discover patterns in distributed data without sharing raw samples. To reduce overhead, many protocols disclose intermediate centroids during training. While often treated as harmless for efficiency, whether such disclosure compromises privacy remains an open question. Prior analyses modeled the problem as a so-called Hidden Subset Sum Problem (HSSP) and argued that centroid release may be safe, since classical HSSP attacks fail to recover inputs. We revisit this question and uncover a new leakage mechanism: temporal regularities in $k$-means iterations create exploitable structure that enables perfect input reconstruction. Building on this insight, we propose Trajectory-Aware Reconstruction (TAR), an attack that combines temporal assignment information with algebraic analysis to recover exact original inputs. Our findings provide the first rigorous evidence, supported by a practical attack, that centroid disclosure in federated clustering significantly compromises privacy, exposing a fundamental tension between privacy and efficiency.

cs.LG

What is the role of human decisions in a world of artificial intelligence: an economic evaluation of human-AI collaboration in diabetic retinopathy screening

As Artificial intelligence (AI) has been increasingly integrated into the medical field, the role of humans may become vague. While numerous studies highlight AI's potential, how humans and AI collaborate to maximize the combined clinical benefits remains unexplored. In this work, we analyze 270 screening scenarios from a health-economic perspective in a national diabetic retinopathy screening program, involving eight human-AI collaborative strategies and traditional manual screening. We find that annual copilot human-AI screening in the 20-79 age group, with referral decisions made when both humans and AI agree, is the most cost-effective strategy for human-AI collaboration. The 'copilot' strategy brings health benefits equivalent to USD 4.64 million per 100,000 population compared to manual screening. These findings demonstrate that even in settings where AI is highly mature and efficient, human involvement remains essential to ensuring both health and economic benefits. Our findings highlight the need to optimize human-AI collaboration strategies for AI implementation into healthcare systems.

cs.HC

Deterministic Algorithms to Solve the $(n,k)$-Complete Hidden Subset Sum Problem

The Hidden Subset Sum Problem (HSSP) is a significant NP-complete problem in number theory and combinatorics, with applications in cryptography and AI privacy. For the $(n,k)$-complete HSSP, where a target multiset must be recovered from its all $k$-subset sums, existing algorithms face limitations due to high complexity or intractability. This paper proposes two deterministic algorithms: a brute-force approach, and a novel method leveraging symmetric polynomials and Vieta's formulas with $O\left(\sum_{u=1}^n p(u,\leq k)^3+\binom{n}{k}n\right)$ complexity, where $ p(u,\leq k)$ counts the number of partitions of a positive integer $u$ into at most $k$ parts. The latter constructs an $n$-th degree polynomial via Vieta's formulas, whose roots correspond to the hidden multiset elements. Additionally, the discussion about the homogeneous symmetric polynomial rings is of independent interest.

math.CO

Perfect Gradient Inversion in Federated Learning: A New Paradigm from the Hidden Subset Sum Problem

Federated Learning (FL) has emerged as a popular paradigm for collaborative learning among multiple parties. It is considered privacy-friendly because local data remains on personal devices, and only intermediate parameters -- such as gradients or model updates -- are shared. Although gradient inversion is widely viewed as a common attack method in FL, analytical research on reconstructing input training samples from shared gradients remains limited and is typically confined to constrained settings like small batch sizes. In this paper, we aim to overcome these limitations by addressing the problem from a cryptographic perspective. We mathematically formulate the input reconstruction problem using the gradient information shared in FL as the Hidden Subset Sum Problem (HSSP), an extension of the well-known NP-complete Subset Sum Problem (SSP). Leveraging this formulation allows us to achieve perfect input reconstruction, thereby mitigating issues such as dependence on label diversity and underperformance with large batch sizes that hinder existing empirical gradient inversion attacks. Moreover, our analysis provides insights into why empirical input reconstruction attacks degrade with larger batch sizes. By modeling the problem as HSSP, we demonstrate that the batch size \( B \) significantly affects attack complexity, with time complexity reaching \( \mathcal{O}(B^9) \). We further show that applying secure data aggregation techniques -- such as homomorphic encryption and secure multiparty computation -- provides a strong defense by increasing the time complexity to \( \mathcal{O}(N^9 B^9) \), where \( N \) is the number of local clients in FL. To the best of our knowledge, this is the first work to rigorously analyze privacy issues in FL by modeling them as HSSP, providing a concrete analytical foundation for further exploration and development of defense strategies.

cs.CR

On the privacy of federated Clustering: A Cryptographic View

The privacy concern in federated clustering has attracted considerable attention in past decades. Many privacy-preserving clustering algorithms leverage cryptographic techniques like homomorphic encryption or secure multiparty computation, to guarantee full privacy, i.e., no additional information is leaked other than the final output. However, given the iterative nature of clustering algorithms, consistently encrypting intermediate outputs, such as centroids, hampers efficiency. This paper delves into this intricate trade-off, questioning the necessity of continuous encryption in iterative algorithms. Using the federated K-means clustering as an example, we mathematically formulate the problem of reconstructing input private data from the intermediate centroids as a classical cryptographic problem called hidden subset sum problem (HSSP)-extended from an NP-complete problem called subset sum problem (SSP). Through an in-depth analysis, we show that existing lattice-based HSSP attacks fail in reconstructing the private data given the knowledge of intermediate centroids, thus it is secure to reveal them for the sake of efficiency. To the best of our knowledge, our work is the first to cast federated clustering's privacy concerns as a cryptographic problem HSSP such that a concrete and rigorous analysis can be conducted.

cs.CR

Supersingular $j$-invariants and the Class Number of $\mathbb{Q}(\sqrt{-p})$

For a prime $p>3$, let $D$ be the discriminant of an imaginary quadratic order with $|D|< \frac{4}{\sqrt{3}}\sqrt{p}$. We research the solutions of the class polynomial $H_D(X)$ mod $p$ in $\mathbb{F}_p$ if $D$ is not a quadratic residue in $\mathbb{F}_p$. We also discuss the common roots of different class polynomials in $\mathbb{F}_p$. As a result, we get a deterministic algorithm (Algorithm 3) for computing the class number of $\mathbb{Q}(\sqrt{-p})$. The time complexity of Algorithm 3 is $O(p^{3/4+ε})$.

math.NT

Constructing Cycles in Isogeny Graphs of Supersingular Elliptic Curves

Loops and cycles play an important role in computing endomorphism rings of supersingular elliptic curves and related cryptosystems. For a supersingular elliptic curve $E$ defined over $\mathbb{F}_{p^2}$, if an imaginary quadratic order $O$ can be embedded in $\text{End}(E)$ and a prime $L$ splits into two principal ideals in $O$, we construct loops or cycles in the supersingular $L$-isogeny graph at the vertices which are next to $j(E)$ in the supersingular $\ell$-isogeny graph where $\ell$ is a prime different from $L$. Next, we discuss the lengths of these cycles especially for $j(E)=1728$ and $0$. Finally, we also determine an upper bound on primes $p$ for which there are unexpected $2$-cycles if $\ell$ doesn't split in $O$.

math.NT

On two problems about isogenies of elliptic curves over finite fields

Isogenies occur throughout the theory of elliptic curves. Recently, the cryptographic protocols based on isogenies are considered as candidates of quantum-resistant cryptographic protocols. Given two elliptic curves $E_1, E_2$ defined over a finite field $k$ with the same trace, there is a nonconstant isogeny $β$ from $E_2$ to $E_1$ defined over $k$. This study gives out the index of $\rm{Hom}_{\it k}(\it E_{\rm 1},E_{\rm 2})β$ as a left ideal in $\rm{End}_{\it k}(\it E_{\rm 2})$ and figures out the correspondence between isogenies and kernel ideals. In addition, some results about the non-trivial minimal degree of isogenies between the two elliptic curves are also provided.

math.NT