IP Library › Granted Patent US 12,541,708
Granted Patent B2
US 12,541,708 · App. 17/323,006 · Granted Feb 3, 2026

Trusted and decentralized aggregation for federated learning

Inventors: Jayaram Kallapalayam Radhakrishnan (Pleasantville, NY); Ashish Verma (Nanuet, NY); Zhongshu Gu (Ridgewood, NJ); Enriquillo Valdez (Queens, NY); Pau-Chen Cheng (Yorktown Heights, NY); Hani Talal Jamjoom (Cos Cob, CT)
Assignee: International Business Machines Corporation
G06N20/00F02D41/1401F02D41/401F02M47/027F02M61/10G06N5/043F02D2041/1431F02D2200/0602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,708
App. No.
17/323,006
Filed
May 18, 2021
Granted
Feb 3, 2026
Kind
B2
Art Unit
2146
USPC
706/12
Abstract

Techniques for distributed federated learning leverage a multi-layered defense strategy to provide for reduced information leakage. In lieu of aggregating model updates centrally, an aggregation function is decentralized into multiple independent and functionally-equivalent execution entities, each running within its own trusted executed environment (TEE). The TEEs enable confidential and remote-attestable federated aggregation. Preferably, each aggregator entity runs within an encrypted virtual machine that support runtime in-memory encryption. Each party remotely authenticates the TEE before participating in the training. By using multiple decentralized aggregators, parties are enabled to partition their respective model updates at model-parameter granularity, and can map single weights to a specific aggregator entity. Parties also can dynamically shuffle fragmentary model updates at each training iteration to further obfuscate the information dispatched to each aggregator execution entity. This architectural prevents the aggregator from being a single point-of-failure, and serves to protect the model even if all aggregators are compromised.

Claims (57)

1 . A method of providing federated learning with reduced information leakage of model aggregation, comprising:

loading each aggregator execution entity included in a set of decentralized aggregator execution entities into a separate trusted execution environment that acts as a trusted intermediary for isolating each aggregator execution entity from other aggregator execution entities in the set, where each trusted execution environment utilizes a distinct encryption key to provide runtime memory encryption protection for a respective aggregator execution entity;

registering each of multiple parties with each of the aggregator execution entities included in the set of decentralized aggregator execution entities;

establishing and maintaining a secure communication channel between the aggregator execution entities for training synchronization during the federated learning;

distributing to each aggregator execution entity included in the set of decentralized aggregator execution entities an assigned portion of a partitioned model update for a machine learning model provided by the multiple parties; and

initiating execution of the set of decentralized aggregator execution entities to train the machine learning model using the assigned portions of the partitioned model update, wherein the set of decentralized aggregator execution entities engage in a number of training iterations with the multiple parties, where at each training iteration of the machine learning model, each party of the multiple parties:

obtains a latest model update from each of the set of decentralized aggregator execution entities,

produces a next model update using local training data, and

provides the next model update to each of the set of decentralized aggregator execution entities, wherein response to receiving the next model update, the set of decentralized aggregator execution entities communicate via the secure communication channel to merge the next model updates into an aggregated machine learning model, and distribute the aggregated machine learning model to each party of the multiple parties, wherein each party of the multiple parties remotely authenticates hardware for each trusted execution environment containing a respective aggregator execution entity.

2 . The method as described in claim 1 , further including attesting to an integrity of the aggregator execution entity.

3 . The method as described in claim 1 , wherein the multiple parties partition respective model updates at model-parameter granularity and map single weights to one of the set of decentralized aggregator execution entities.

4 . The method as described in claim 3 , wherein an ordering of parameter or gradient elements in at least one partition are shuffled.

5 . The method as described in claim 1 , wherein, with respect to at least one other of the set of decentralized aggregator execution entities, the aggregator execution entity executes in one of: a different machine, a different data center, a different trusted execution environment architecture, and a different geo-location.

6 . The method as described in claim 1 , wherein loading the aggregator execution entity includes injecting a unique secret into encrypted physical memory of an encrypted virtual machine that provides the trusted execution environment and using the unique secret to authenticate the aggregator execution entity at registration of a party.

7 . An apparatus, comprising:

a hardware processor; and

a computer memory holding computer program instructions executed by the hardware processor to provide federated learning with reduced information leakage of model aggregation, the computer program instructions configured to:

load each aggregator execution entity included in a set of decentralized aggregator execution entities into a separate trusted execution environment that acts as a trusted intermediary for isolating each aggregator execution entity from other aggregator execution entities in the set, where each trusted execution environment utilizes a distinct encryption key to provide runtime memory encryption protection for a respective aggregator execution entity;

register each of multiple parties with each of the aggregator execution entities included in the set of decentralized aggregator execution entities;

establish and maintain a secure communication channel between the aggregator execution entities for training synchronization during the federated learning;

distribute to each aggregator execution entity included in the set of decentralized aggregator execution entities an assigned portion of a partitioned model update for a machine learning model provided by the multiple parties; and

initiate execution of the set of decentralized aggregator execution entities to train the machine learning model using the assigned portions of the partitioned model update, wherein the set of decentralized aggregator execution entities engage in a number of training iterations with the multiple parties, where at each training iteration of the machine learning model, each party of the multiple parties:

obtains a latest model update from each of the set of decentralized aggregator execution entities,

produces a next model update using local training data, and

provides the next model update to each of the set of decentralized aggregator execution entities, wherein response to receiving the next model update, the set of decentralized aggregator execution entities communicate via the secure communication channel to merge the next model updates into an aggregated machine learning model, and distribute the aggregated machine learning model to each party of the multiple parties, wherein each party of the multiple parties remotely authenticates hardware for each trusted execution environment containing a respective aggregator execution entity.

8 . The apparatus as described in claim 7 , wherein the computer program instructions are further configured to attest to an integrity of the aggregator execution entity.

9 . The apparatus as described in claim 7 , wherein the multiple parties partition respective model updates at model-parameter granularity and map single weights to one of the set of decentralized aggregator execution entities.

10 . The apparatus as described in claim 9 , wherein an ordering of parameter or gradient elements in at least one partition are shuffled.

11 . The apparatus as described in claim 7 , wherein, with respect to at least one other of the set of decentralized aggregator execution entities, the aggregator execution entity executes in one of: a different machine, a different data center, a different trusted execution environment architecture, and a different geo-location.

12 . The apparatus as described in claim 7 , wherein the computer program instructions configured to load the aggregator execution entity further including computer program instructions configured to receive a unique secret in the trusted execution environment and to use the unique secret to authenticate the aggregator execution entity at registration of a party.

13 . A computer program product in a non-transitory computer readable medium for use in a data processing system to provide federated learning with reduced information leakage of model aggregation, the computer program product holding computer program instructions that, when executed by the data processing system, are configured to:

load each aggregator execution entity included in a set of decentralized aggregator execution entities into a separate trusted execution environment that acts as a trusted intermediary for isolating each aggregator execution entity from other aggregator execution entities in the set, where each trusted execution environment utilizes a distinct encryption key to provide runtime memory encryption protection for a respective aggregator execution entity;

register each of multiple parties with each of the aggregator execution entities included in the set of decentralized aggregator execution entities;

establish and maintain a secure communication channel between the aggregator execution entities for training synchronization during the federated learning;

distributing to each aggregator execution entity included in the set of decentralized aggregator execution entities an assigned portion of a partitioned model update for a machine learning model provided by the multiple parties; and

initiating execution of the set of decentralized aggregator execution entities to train the machine learning model using the assigned portions of the partitioned model update, wherein the set of decentralized aggregator execution entities engage in a number of training iterations with the multiple parties, where at each training iteration of the machine learning model, each party of the multiple parties:

obtains a latest model update from each of the set of decentralized aggregator execution entities,

produces a next model update using local training data, and

provides the next model update to each of the set of decentralized aggregator execution entities, wherein response to receiving the next model update, the set of decentralized aggregator execution entities communicate via the secure communication channel to merge the next model updates into an aggregated machine learning model, and distribute the aggregated machine learning model to each party of the multiple parties, wherein each party of the multiple parties remotely authenticates hardware for each trusted execution environment containing a respective aggregator execution entity.

14 . The computer program product as described in claim 13 , wherein the computer program instructions are further configured to attest to an integrity of the aggregator execution entity.

15 . The computer program product as described in claim 13 , wherein the multiple parties partition respective model updates at model-parameter granularity and map single weights to one of the set of decentralized aggregator execution entities.

16 . The computer program product as described in claim 15 , wherein an ordering of parameter or gradient elements in at least one partition are shuffled.

17 . The computer program product as described in claim 13 , wherein, with respect to at least one other of the set of decentralized aggregator execution entities, the aggregator execution entity executes in one of: a different machine, a different data center, a different trusted execution environment architecture, and a different geo-location.

18 . The computer program instructions as described in claim 13 , wherein the computer program instructions configured to load the aggregator execution entity further including computer program instructions configured to receive a unique secret in the trusted execution environment and to use the unique secret to authenticate the aggregator execution entity at registration of a party.

19 . A federated learning system that is secure against information leakage of model aggregation, comprising:

a set of trusted execution environments; and

an aggregator partitioned into a set of decentralized aggregator execution entities, with each aggregator execution entity loaded into a respective trusted execution environment that acts as a trusted intermediary for isolating each aggregator execution entity from other aggregator execution entities in the set, and each aggregator execution entity utilizes a respective distinct encryption key to provide runtime memory encryption protection;

wherein each party of multiple parties is registered with each of the aggregator execution entities included in the set of decentralized aggregator execution entities, and wherein a secure communication channel is established between the aggregator execution entities for training synchronization during the federated learning, and wherein an assigned portion of a partitioned model update for a machine learning model provided by the multiple parties is distributed to each aggregator execution entity included in the set of decentralized aggregator execution entities; and

wherein execution of the set of decentralized aggregator execution entities is initiated to train the machine learning model using the assigned portions of the partitioned model update, wherein the set of decentralized aggregator execution entities engage in a number of training iterations with the multiple parties, where at each training iteration of the machine learning model, each party of the multiple parties:

obtains a latest model update from each of the set of decentralized aggregator execution entities,

produces a next model update using local training data, and

provides the next model update to each of the set of decentralized aggregator execution entities, wherein response to receiving the next model update, the set of decentralized aggregator execution entities communicate via the secure communication channel to merge the next model updates into an aggregated machine learning model, and distribute the aggregated machine learning model to each party of the multiple parties, wherein each party of the multiple parties remotely authenticates hardware for each trusted execution environment containing a respective aggregator execution entity.

20 . The federated learning system as described in claim 19 , wherein, with respect to at least one other of the set of decentralized aggregator execution entities, an aggregator execution entity executes in one of: a different machine, a different data center, a different trusted execution environment architecture, and a different geo-location.

21 . The federated learning system as described in claim 19 , wherein the multiple parties partition respective model updates at model-parameter granularity and map single weights to one of the set of decentralized aggregator execution entities.

22 . The method as described in claim 1 , further comprising:

partitioning a central aggregator into the set of decentralized aggregator execution entities, where each decentralized aggregator in the set is functionally-equivalent to each other; and

launching a set of encrypted virtual machines, wherein each decentralized aggregator is loaded onto a respective encrypted virtual machine that provides a respective trusted execution environment for the decentralized aggregator.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTORS' NAMES PREVIOUSLY RECORDED ON REEL 56269 FRAME 668. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT. Recorded Oct 24, 2025
From: RADHAKRISHNAN, JAYARAM KALLAPALAYAM; VERMA, ASHISH; GU, ZHONGSHU; VALDEZ, ENRIQUILLO; CHENG, PAU-CHEN; JAMJOOM, HANI TALAL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 073266/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: RADHAKRISHNAN, JAYARAM KALLAPALAYAN; VERMA, ASHISH; GU, ZHONGSHU; VALDEZ, ENRIQUILLO; CHENG, PAU-CHEN; JAMJOON, HANI TALAL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056269/0668 →
Continuity (1)
Related Publication 20220374762A1 · Nov 24, 2022
References Cited (73)
US 10504154B1 · Bonawitz · 2019 [cited by examiner]
US 10839320B2 · Augustine et al. · 2020 [cited by applicant]
US 10848974B2 · Bachmutsky · 2020 [cited by applicant]
US 10970402B2 · Verma et al. · 2021 [cited by applicant]
US 11295229B1 · Kumar · 2022 [cited by examiner]
US 11887505B1 · Aloisio · 2024 [cited by examiner]
US 20110142108A1 · Agee · 2011 [cited by examiner]
US 20180018590A1 · Szeto · 2018 [cited by examiner]
US 20190042878A1 · Sheller et al. · 2019 [cited by applicant]
US 20190042937A1 · Sheller · 2019 [cited by applicant]
US 20190213346A1 · Friedman · 2019 [cited by applicant]
US 20190373021A1 · Parthasarathy · 2019 [cited by examiner]
US 20200133898A1 · Therene · 2020 [cited by examiner]
US 20200358599A1 · Baracaldo Angel · 2020 [cited by examiner]
US 20200380326A1 · Kawaguchi · 2020 [cited by examiner]
US 20200394470A1 · Ganapavarapu · 2020 [cited by examiner]
US 20200394471A1 · Ganapavarapu · 2020 [cited by examiner]
US 20210133555A1 · Qiu et al. · 2021 [cited by applicant]
US 20210256407A1 · Therani · 2021 [cited by examiner]
US 20220327652A1 · Sankaranarayanasamy · 2022 [cited by examiner]
US 20220360450A1 · Brandenburger · 2022 [cited by examiner]
US 20240072981A1 · Zhu · 2024 [cited by examiner]
AU 2012231158B2 · 2015 [cited by examiner]
CA 2813026A1 · 2012 [cited by examiner]
CA 3060835C · 2022 [cited by examiner]
CN 112580821A · 2021 [cited by applicant]
CN 112749812A · 2021 [cited by applicant]
CN 115424085A · 2022 [cited by examiner]
CN 111966875B · 2023 [cited by examiner]
CN 117242463A · 2023 [cited by applicant]
CN 112906903B · 2024 [cited by examiner]
CN 109871702B · 2024 [cited by examiner]
DE 102005045947B4 · 2017 [cited by examiner]
DE 102020110034A1 · 2021 [cited by examiner]
DE 112022002623T5 · 2024 [cited by applicant]
EP 3370083A1 · 2018 [cited by examiner]
EP 3471367A1 · 2019 [cited by examiner]
EP 3794771B1 · 2025 [cited by examiner]
GB 2621732A · 2024 [cited by applicant]
JP 2023501335A · 2023 [cited by examiner]
JP 2024519365A · 2024 [cited by applicant]
KR 20190075449A · 2019 [cited by examiner]
KR 20220148017A · 2022 [cited by examiner]
TW I798550B · 2023 [cited by examiner]
WO 2019227208A1 · 2019 [cited by applicant]
WO WO2021056043A1 · 2021 [cited by examiner]
WO 2021082647A1 · 2021 [cited by applicant]
WO WO2021112831A1 · 2021 [cited by examiner]
WO WO2021224453A1 · 2021 [cited by examiner]
WO 2022243871A1 · 2022 [cited by applicant]
Pillutla, et al., “Robust Aggregation for Federated Learning,” arXiv:1912.13445, Dec. 31, 2019. [cited by applicant]
Anonymous, “A Decentralized Architecture for Transparent and Verifiable Knowledge Manipulation in Untrusted Networks,” IPCOM000251032D, Oct. 2, 2017. [cited by applicant]
Anonymous, “Identifying and Determining Trustworthiness of a Machine-Learned Model,” IPCOM000252359D, Jan. 5, 2018. [cited by applicant]
Anonymous, “Decentralizing Reviews in E-Commerce Using Blockchain with Federated Learning,” PCOM000264206D, Nov. 20, 2020. [cited by applicant]
Anonymous, Fully Decentralized Cloud using Generalized Trusted Execution Environments and Distributed Hash Tables (Without Blockchain), IPCOM000264923D, Feb. 5, 2021. [cited by applicant]
Wittkopp, et al., “Decentralized Federated Learning Preserves Model and Data Privacy,” arXiv:2102.00880v1 [cs.LG] Feb. 1, 2021. [cited by applicant]
Kang, et al., “Scalable and Communication-efficient Decentralized Federated Edge Learning with Multi-blockchain Framework,” arXiv:2008.04743v1 [cs.CR] Aug. 10, 2020. [cited by applicant]
Zhu et al., “Deep Leakage from Gradients,” 33rd Conference on Neural Information Processing Systems, NeurIPS 2019. [cited by applicant]
Gu, et al., “Reaching Data Confidentiality and Model Accountability on the CalTrain,” 2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) IEEE, 2019. [cited by applicant]
Melis, et al., “Exploiting unintended feature leakage in collaborative learning,” 2019 IEEE Symposium on Security and Privacy (Sp). IEEE, 2019. [cited by applicant]
Hitaj, et al., “Deep models under the GAN: Information leakage from collaborative deep learning,” in Proceedings of the 24th ACM SIGSAC Conference on Computer and Communications Security, 2017. [cited by applicant]
Jayaram, et al., MYSTIKO: Cloud-Mediated, Private, Federated Gradient Descent, IEEE Cloud 2020, arXiv:2012.00740v1 [cs.CR] Dec. 1, 2020. [cited by applicant]
Abadi, et al., “Deep Learning with Differential Privacy,” Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Oct. 24-28, 2016. [cited by applicant]
Jost et al., “Encryption Performance Improvements of the Paillier Cryptosystem”, Cryptology ePrint Archive, 2015, 11 pages. [cited by applicant]
Lecun et al., “Deep learning” Abstract Only, Nature vol. 521, pp. 436-444 (2015), 20 pages. [cited by applicant]
Mahajan et al., “Exploring the Limits of Weakly Supervised Pretraining”, arXiv:1805.00932v1 [cs.CV] May 2, 2018, 23 pages. [cited by applicant]
Patent Cooperation Treaty, International Search Report, International Application No. PCT/1B2022/054581, Jul. 28, 2022, 8 pages. [cited by applicant]
Sarwate et al., “Signal Processing and Machine Learning with Differential Privacy”, Published in final edited form as: IEEE Signal Process Mag, Sep. 1, 2013; 30(5): 86-94, doi:10.1109/MSP.2013.2259911, 17 pages. [cited by applicant]
Girgis et al., “Shuffled Model of Differential Privacy in Federated Learning”, The 24th International Conference on Artificial Intelligence and Statistics, Apr. 13-15, 2021, 12 pages. [cited by applicant]
Grace Period Disclosure Cheng et al., “Separation of Powers in Federated Learning”, Anonymous submission #220 to ACM CCS 2021, May 19, 2021, 14 pages. [cited by applicant]
Shokri et al., “Membership Inference Attacks Against Machine Learning Models”, arXiv:1610.05820v2, Mar. 31, 2017, 16 pages. [cited by applicant]
The State Intellectual Property Office of People's Republic of China, “First Office Action”, Aug. 29, 2025, 18 Pages, CN Application No. 202280032564.6. [cited by applicant]
Japan Patent Office, “Notice of Reasons for Refusal” Dec. 2, 2025, 11 Pages, JP Application No. 2023-571220. [cited by applicant]