Towards Efficient and Reliable Training Assurance of Untrusted Federated Learning Participants Under Hardware Non-Determinism
Rattachement africain : cn, us. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Federated learning (FL) is a popular privacy-preserving machine learning paradigm, enabling collaborative training across participants without exposing local data. Since FL loses direct control over participants' training executions, a fundamental requirement is to verify that participants faithfully perform the assigned training tasks. In this paper, we present TrustFL+, an efficient, scalable, and reliable verification scheme that ensures the training correctness of federated learning participants by leveraging both Trusted Execution Environments (TEEs) and GPUs. Essentially, it pushes all local training on high-performance but untrusted GPUs, while the TEE replicates the random parts for tunable levels of assurance. A key challenge is that hardware non-determinism can cause the same floating-point operations to yield different results between GPUs and TEEs, leading to false positives when participants behave honestly. TrustFL+ builds on deterministic training by recording rounding directions of intermediate operations during GPU-side model training and reusing them in TEE-based verification. It especially introduces adaptive rounding precisions to practically control non-determinism while maintaining global model performance in federated learning systems with lots of heterogeneous GPUs and iterative training. We prototype TrustFL+ using a range of NVIDIA GPUs covering multiple hardware architectures, along with Intel SGX, and evaluate its performance across convolutional neural networks and transformer-based networks. The experimental results demonstrate that TrustFL+ delivers up to an order of magnitude speedup compared to naive SGX-based training. Furthermore, all models trained with TrustFL+ on different GPU architectures successfully pass verification within SGX, resulting in 0 false positives.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Towards Efficient and Reliable Training Assurance of Untrusted Federated Learning Participants Under Hardware Non-Determinism
- Date Crossref
- 01/07/2026
- Éditeur
- Institute of Electrical and Electronics Engineers (IEEE)
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Les institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.