跳到正文
arXiv:cs.LG· Halil \.Ibrahim Kanpak, Sinem Sav, Alptekin K\"up\c{c}\"u·· 4 小时前AI 评分45

HE-OFT:同态加密下隐私保护的一次性联邦微调

HE-OFT: Privacy-Preserving One-Shot Federated Fine-Tuning under Homomorphic Encryption

AI 导读

研究者提出 HE-OFT,首个加密安全的一次性联邦微调协议,任何参与方都不会拿到训练后的模型。客户端在冻结的公共骨干上微调低秩适配器和分类头,只上传一次加密的头部位移,服务器在多方 CKKS 下合并且从不解密。在四个文本分类任务和一个视觉任务上,HE-OFT 达到 61% 至 79% 准确率,单客户端单独训练为 20% 至 48%,并保留了公开模型 85% 至 96% 的准确率。

正文

View PDF HTML (experimental)

Abstract:Many organizations adapt large pretrained models to their own tasks by fine-tuning on private data. Several of these parties often hold data for the same task and wish to fine-tune a model together without pooling that data. Federated learning (FL) enables joint fine-tuning, but reconstruction attacks on shared intermediate values (the model or its gradients) remain a privacy risk. A one-shot protocol that exchanges one encrypted contribution exposes no intermediate value. Such a protocol still gives the trained model to every participant, which is not permitted where the model is a regulated or proprietary asset. We present HE-OFT, the first cryptographically secure one-shot federated fine-tuning protocol in which no party receives the trained model. Each client fine-tunes a low-rank adapter and a classifier head on a frozen public backbone and keeps the adapter. The client uploads one encrypted head displacement, which the server combines under multiparty CKKS and never decrypts. A quorum of clients returns only the predicted label to the querier. On four text classification tasks and one vision task, HE-OFT reaches 61 to 79 per cent accuracy, against 20 to 48 per cent for a client training alone. HE-OFT keeps 85 to 96 per cent of the accuracy of a disclosed model. A test-time query takes 443.1 to 1713.1 s on one core, or 56.1 to 255.1 s with level restoration on a GPU. Restoring levels at the server cuts the traffic per query from up to 1.6 GiB to 13.5 MiB.
Comments: Technical report. 32 pages, 7 figures, 12 tables. Code: this https URL
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
ACM classes: E.3; I.2.6
Cite as: arXiv:2610.08255 [cs.CR]
  (or arXiv:2610.08255v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.08255

arXiv-issued DOI via DataCite

Submission history

From: Halil İbrahim Kanpak [view email]
[v1] Tue, 6 Oct 2026 12:35:08 UTC (487 KB)

来源:arXiv:cs.LG · arxiv.org