Zero-trust architecture for secure aggregation in federated learning
One example method includes receiving a request for communication between a client node and a server node of a federated learning system. The request is made according to a protocol related to updating a global model by the federated learning system. The protocol defines a first transmission step that should be made during the update of the global model. The request for communication between the client node and the server node is analyzed based in part on credential information and communication information related to the client node and the server node. A secure communication channel is established between the client node and the server node when it is determined that the client node and the server node are to be given access to communicate with each other.
1 . A method, comprising:
receiving a request for communication between a client node and a server node of a federated learning system at a policy enforcement point, the federated learning system including client nodes and the server node, the request being made according to a protocol related to updating a global model by the federated learning system, the protocol defining a first transmission step that should be made during the update of the global model, wherein the first transmission step corresponds to a specific round of a Secure Aggregation protocol and to a specific data transmission within that Secure Aggregation round;
based on receiving the request, determining, by the policy enforcement point, if the client node is given access to communicate with the server node and the server node is to be given access to communicate with the client node based on credential information and communication information that includes behavioral analytics data and historical communication analytics related to communications between the client node and the server node, wherein subsequent communications require a separate request to the policy enforcement point; and
establishing a secure communication channel between the client node and the server node when it is determined that the client node and the server node are to be given access to communicate with each other, the secure communication channel being exclusively used by the client node and the server node, being established for the specific round of the Secure Aggregation protocol corresponding to the first transmission step, being established only for the specific data transmission corresponding to the first transmission step and independently of other data transmissions occurring within the same Secure Aggregation round;
allowing transmission of protocol-defined data between the client node and the server node over the secure communication channel during the first transmission step;
terminating the secure communication channel upon completion of the first transmission step;
detecting a trust violation or anomaly in the communications between the client node and the server node during the secure communication channel, wherein detecting the trust violation or anomaly comprises analyzing protocol-semantic data exchanged during the first transmission step, including at least one of cryptographic key material, masked model updates, signature data, or consistency-check data defined by the Secure Aggregation protocol, and, in response to the detected trust violation or anomaly, updating the credential information of at least one of the client node and the server node,
wherein the policy enforcement point receives a credential list, the credential list specifying whether the client nodes and the server node have permission to be in the federated learning system,
wherein the public key and private keys pairs are distributed to the client nodes and the server node identified as having permission to be in the federated learning system,
wherein communication information includes analytical data for communications between each of the client nodes and the server node that includes an indication of a data type communicated between the client nodes and the server node.
2 . The method according to claim 1 , further comprising:
allowing the client node and the server node to transmit data to each other using the secure communication channel during the first transmission step; and
terminating the secure communication channel upon completion of the first transmission step.
3 . The method according to claim 1 , further comprising:
receiving a second request for communication between the client node and the server node, the second request being made according to the protocol related to updating a global model by, the protocol defining a second transmission step that should be made during the update of the global model;
based on receiving the second request, determining if the client node and the server node are to be given access to communicate with each other based at least in part on the credential information and the communication information; and
establishing a second secure communication channel between the client node and the server node.
4 . The method according to claim 3 , further comprising:
allowing the client node and the server node to transmit data to each other using the second secure communication channel during the second transmission step; and
terminating the second secure communication channel upon completion of the second transmission step.
5 . The method of claim 1 , wherein the client node and the server node are not able to communicate with any other entity of the federated learning system using the secure communication channel.
6 . The method of claim 1 , wherein the communication information comprises global analytical information based on historical data related to the communication between the client node and the server node.
7 . The method of claim 1 , wherein the credential information includes an identity index for the client node and the server node and one or more permissions that specify that the client node and the server node are to be part of the federated learning system.
8 . The method of claim 1 , further comprising:
updating the credential information when it is determined that the client node and the server node are not to be given access to communicate with each other to specify that one of the client node and the server is no longer a trusted entity.
9 . The method of claim 1 , where the method is performed for all transmission steps defined by the protocol.
10 . The method of claim 9 , wherein the protocol is Secure Aggregation protocol.
11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:
receiving a request for communication between a client node and a server node of a federated learning system at a policy enforcement point, the federated learning system including client nodes and the server node, the request being made according to a protocol related to updating a global model by the federated learning system, the protocol defining a first transmission step that should be made during the update of the global model, wherein the first transmission step corresponds to a specific round of a Secure Aggregation protocol and to a specific data transmission within that Secure Aggregation round;
based on receiving the request, determining, by the policy enforcement point, if the client node is given access to communicate with the server node and the server node is to be given access to communicate with the client node based on credential information and communication information that includes behavioral analytics data and historical communication analytics related to communications between the client node and the server node, wherein subsequent communications require a separate request to the policy enforcement point; and
establishing a secure communication channel between the client node and the server node when it is determined that the client node and the server node are to be given access to communicate with each other, the secure communication channel being exclusively used by the client node and the server node, being established for the specific round of the Secure Aggregation protocol corresponding to the first transmission step, being established only for the specific data transmission corresponding to the first transmission step and independently of other data transmissions occurring within the same Secure Aggregation round;
allowing transmission of protocol-defined data between the client node and the server node over the secure communication channel during the first transmission step;
terminating the secure communication channel upon completion of the first transmission step;
detecting a trust violation or anomaly in the communications between the client node and the server node during the secure communication channel, wherein detecting the trust violation or anomaly comprises analyzing protocol-semantic data exchanged during the first transmission step, including at least one of cryptographic key material, masked model updates, signature data, or consistency-check data defined by the Secure Aggregation protocol, and, in response to the detected trust violation or anomaly, updating the credential information of at least one of the client node and the server node,
wherein the policy enforcement point receives a credential list, the credential list specifying whether the client nodes and the server node have permission to be in the federated learning system,
wherein the public key and private keys pairs are distributed to the client nodes and the server node identified as having permission to be in the federated learning system,
wherein communication information includes analytical data for communications between each of the client nodes and the server node that includes an indication of a data type communicated between the client nodes and the server node.
12 . The non-transitory storage medium of claim 11 , further comprising:
allowing the client node and the server node to transmit data to each other using the secure communication channel during the first transmission step; and
terminating the secure communication channel upon completion of the first transmission step.
13 . The non-transitory storage medium of claim 11 , further comprising:
receiving a second request for communication between the client node and the server node, the second request being made according to the protocol related to updating a global model by, the protocol defining a second transmission step that should be made during the update of the global model;
based on receiving the second request, determining if the client node and the server node are to be given access to communicate with each other based at least in part on the credential information and the communication information; and
establishing a second secure communication channel between the client node and the server node.
14 . The non-transitory storage medium of claim 13 , further comprising:
allowing the client node and the server node to transmit data to each other using the second secure communication channel during the second transmission step; and
terminating the second secure communication channel upon completion of the second transmission step.
15 . The non-transitory storage medium of claim 11 , wherein the client node and the server node are not able to communicate with any other entity of the federated learning system using the secure communication channel.
16 . The non-transitory storage medium of claim 11 , wherein the communication information comprises global analytical information based on historical data related to the communication between the client node and the server node.
17 . The non-transitory storage medium of claim 11 , wherein the credential information includes an identity index for the client node and the server node and one or more permissions that specify that the client node and the server node are to be part of the federated learning system.
18 . The non-transitory storage medium of claim 11 , further comprising:
updating the credential information when it is determined that the client node and the server node are not to be given access to communicate with each other to specify that one of the client node and the server is no longer a trusted entity.
19 . The non-transitory storage medium of claim 11 , wherein the operations are performed for all transmission steps defined by the protocol.
20 . The non-transitory storage medium of claim 11 , wherein the protocol is Secure Aggregation protocol.