<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">65887</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.065887</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>VPAFL: Verifiable Privacy-Preserving Aggregation for Federated Learning Based on Single Server</article-title>
<alt-title alt-title-type="left-running-head">VPAFL: Verifiable Privacy-Preserving Aggregation for Federated Learning based on Single Server</alt-title>
<alt-title alt-title-type="right-running-head">VPAFL: Verifiable Privacy-Preserving Aggregation for Federated Learning based on Single Server</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Lai</surname><given-names>Peizheng</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Zhang</surname><given-names>Minqing</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref><email>api_zmq@126.com</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Tang</surname><given-names>Yixin</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Yue</surname><given-names>Ya</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Di</surname><given-names>Fuqiang</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<aff id="aff-1"><label>1</label><institution>College of Cryptography Engineering, Engineering University of PAP</institution>, <addr-line>Xi&#x2019;an, 710086</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Key Laboratory of PAP for Cryptology and Information Security</institution>, <addr-line>Xi&#x2019;an, 710086</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Minqing Zhang. Email: <email>api_zmq@126.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>03</day><month>07</month><year>2025</year>
</pub-date>
<volume>84</volume>
<issue>2</issue>
<fpage>2935</fpage>
<lpage>2957</lpage>
<history>
<date date-type="received">
<day>24</day>
<month>3</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>08</day>
<month>5</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_65887.pdf"></self-uri>
<abstract>
<p>Federated Learning (FL) has emerged as a promising distributed machine learning paradigm that enables multi-party collaborative training while eliminating the need for raw data sharing. However, its reliance on a server introduces critical security vulnerabilities: malicious servers can infer private information from received local model updates or deliberately manipulate aggregation results. Consequently, achieving verifiable aggregation without compromising client privacy remains a critical challenge. To address these problem, we propose a reversible data hiding in encrypted domains (RDHED) scheme, which designs joint secret message embedding and extraction mechanism. This approach enables clients to embed secret messages into ciphertext redundancy spaces generated during model encryption. During the server aggregation process, the embedded messages from all clients fuse within the ciphertext space to form a joint embedding message. Subsequently, clients can decrypt the aggregated results and extract this joint embedding message for verification purposes. Building upon this foundation, we integrate the proposed RDHED scheme with linear homomorphic hash and digital signatures to design a verifiable privacy-preserving aggregation protocol for single-server architectures (VPAFL). Theoretical proofs and experimental analyses show that VPAFL can effectively protect user privacy, achieve lightweight computational and communication overhead of users for verification, and present significant advantages with increasing model dimension.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Verifiable federated learning</kwd>
<kwd>privacy-preserving</kwd>
<kwd>homomorphic encryption</kwd>
<kwd>reversible data hiding in encrypted domain</kwd>
<kwd>secret sharing</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Natural Science Foundation of China</funding-source>
<award-id>62102450</award-id>
<award-id>62272478</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Independent Research Project of a Certain Unit</funding-source>
<award-id>ZZKY20243127</award-id>
</award-group></funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<sec id="s1_1">
<label>1.1</label>
<title>Motivation</title>
<p>With the widespread adoption of cloud computing technologies [<xref ref-type="bibr" rid="ref-1">1</xref>], the migration of large amounts of user data to the cloud has become an irreversible trend. To address the risks of privacy breaches, encrypting data for storage has become essential. However, this measure introduces new challenges, particularly in performing operations such as metadata embedding and identity authentication while ensuring data confidentiality.</p>
<p>To address these challenges, the technique of reversible data hiding in the encrypted domain (RDHED) [<xref ref-type="bibr" rid="ref-2">2</xref>&#x2013;<xref ref-type="bibr" rid="ref-4">4</xref>] has emerged as a promising solution. This technology enables the reversible embedding of data, such as identity markers and integrity labels, within encrypted data [<xref ref-type="bibr" rid="ref-5">5</xref>,<xref ref-type="bibr" rid="ref-6">6</xref>]. Upon decryption, both the original data and the embedded data can be completely recovered, providing an innovative approach to managing encrypted data. Despite significant advancements in traditional RDHED methods, most existing schemes rely on stream cipher encryption mechanisms, which do not support ciphertext operations [<xref ref-type="bibr" rid="ref-2">2</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>&#x2013;<xref ref-type="bibr" rid="ref-6">6</xref>]. This limitation makes them unsuitable for emerging privacy-preserving computing scenarios, such as federated learning (FL) [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
<p>In recent years, homomorphic encryption (HE)-based RDHED schemes have gained attention as a potential solution [<xref ref-type="bibr" rid="ref-8">8</xref>&#x2013;<xref ref-type="bibr" rid="ref-10">10</xref>]. However, these approaches face two major technical challenges. First, their applicability is often limited because most existing research focuses on image data processing, while FL predominantly involves model parameters. Second, compatibility issues arise: existing methods do not adequately address the destructive effects of homomorphic processing on embedded data [<xref ref-type="bibr" rid="ref-11">11</xref>]. For instance, when encrypted data undergo homomorphic processing, such as ciphertext aggregation, embedded data may suffer irreversible distortion, resulting in extraction failures [<xref ref-type="bibr" rid="ref-12">12</xref>&#x2013;<xref ref-type="bibr" rid="ref-14">14</xref>]. Furthermore, FL usually involves multiple participants, yet enabling each user to independently perform data embedding and extraction independently in decentralized scenarios remains a great challenge.</p>
<p>In a typical FL architecture, users upload their local models to the server, which aggregates the received local models to generate the global model and distributes it back to users. However, this collaborative training mechanism raises concerns about privacy leakage. In particular, a semi-honest server can infer user privacy by analyzing local or global gradients [<xref ref-type="bibr" rid="ref-15">15</xref>&#x2013;<xref ref-type="bibr" rid="ref-17">17</xref>], while a malicious server could manipulate the aggregation results, thereby compromising the usability of the global model [<xref ref-type="bibr" rid="ref-18">18</xref>]. Existing privacy protection solutions, such as HE [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-20">20</xref>], differential privacy [<xref ref-type="bibr" rid="ref-21">21</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>], and secure multiparty computation [<xref ref-type="bibr" rid="ref-23">23</xref>], can mitigate some privacy risks. However, they fail to address a critical issue: verifying the correctness of model aggregation.</p>
<p>To address these challenges, several verifiable federated learning (VFL) schemes have been successively proposed [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-27">27</xref>]. These solutions primarily utilize linear homomorphic hash (LHH) [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>] or dual-aggregation techniques [<xref ref-type="bibr" rid="ref-27">27</xref>] to achieve verifiability. However, they exhibit limitations: the former incurs computational overhead that scales with the model dimension, while the latter suffers from the inflation of communication costs and requires auxiliary protocols for full verifiability [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>].</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Our Contributions</title>
<p>This study addresses existing challenges by focusing on two core issues: (1) designing a RDHED scheme compatible with homomorphic processing, and (2) integrating this RDHED scheme with cryptographic tools to develop an efficient verifiable privacy-preserving aggregation protocol under a single-server architecture.</p>
<p>To achieve these goals, we propose a joint embedding-extraction mechanism (JEEM). Using the additive homomorphic property of the Paillier encryption algorithm [<xref ref-type="bibr" rid="ref-19">19</xref>], JEEM enables multiple users to collaboratively embed and extract secret messages without altering the original plaintext. Building on JEEM, we further integrate LHH [<xref ref-type="bibr" rid="ref-30">30</xref>] and digital signatures to design a verifiable privacy-preserving aggregation protocol based on a single server (VPAFL).</p>
<p>The contributions of this study can be summarized as follows:</p>
<p>1) RDHED Scheme for Joint Secret Message Embedding and Extraction: This study resolves the compatibility limitations of existing RDHED schemes with homomorphic processing. Each user independently exploits ciphertext redundancy during encryption to embed secret messages. After the server aggregates the ciphertexts, homomorphic properties enable the fusion of all user-embedded messages within the ciphertext space, yielding a joint embedded message. Users can then extract this joint embedded message after decrypting the aggregation result.</p>
<p>2) Efficient Verifiable Aggregation Protocol: Compared to existing LHH-based VFL schemes, VPAFL enhances efficiency by integrating the proposed RDHED scheme. Specifically, VPAFL utilizes the secret message embedded by the users in each communication round as input for the hash value computation. This design decouples hash generation computational overhead from the model dimension, thereby significantly reducing the computational overhead of users for verification. Furthermore, VPAFL maintains minimal communication overhead of users for verification (below 0.2 KB) and achieves verification of aggregation results within only two interaction rounds under a single-server framework, significantly enhancing practical deployability.</p>
</sec>
<sec id="s1_3">
<label>1.3</label>
<title>Organization</title>
<p>The rest of this article is organized as follows: <xref ref-type="sec" rid="s2">Section 2</xref> reviews related works, while <xref ref-type="sec" rid="s3">Section 3</xref> introduces preliminary concepts. <xref ref-type="sec" rid="s4">Section 4</xref> provides an overview of the system and the threat <xref ref-type="sec" rid="s5">Section 5</xref> presents the proposed RDHED scheme and details the VPAFL protocol. <xref ref-type="sec" rid="s6">Sections 6</xref> and <xref ref-type="sec" rid="s7">7</xref> offer theoretical analyses and experimental results, respectively. Finally, <xref ref-type="sec" rid="s8">Section 8</xref> concludes this study.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Works</title>
<p>In this section, we provide a brief review of the work related to RDHED schemes in the homomorphic encrypted domain and VFL.</p>
<sec id="s2_1">
<label>2.1</label>
<title>RDHED Schemes in the Homomorphic Encrypted Domain</title>
<p>With the widespread application of HE in privacy computing, HE-based RDHED methods have emerged as a research hotspot [<xref ref-type="bibr" rid="ref-12">12</xref>]. These schemes are categorized into two types based on their impact on plaintext: plaintext modification schemes (Type I) and lossless data hiding schemes (Type II). Specifically, Type I methods involve embedding operations that result in changes to plaintext [<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>,<xref ref-type="bibr" rid="ref-14">14</xref>]. For example, a typical method modifies the ciphertext value <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>c</mml:mi></mml:math></inline-formula> to produce a decrypted plaintext of the form <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mn>2</mml:mn><mml:mi>m</mml:mi><mml:mo>+</mml:mo><mml:mi>b</mml:mi></mml:math></inline-formula>, where <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mi>m</mml:mi></mml:math></inline-formula> is the original plaintext, and <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> denotes the embedded 1 bit message. During data extraction, the embedded bit <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>b</mml:mi></mml:math></inline-formula> is extracted by computing <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>m</mml:mi><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mn>2</mml:mn></mml:math></inline-formula>, while <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>m</mml:mi></mml:math></inline-formula> is recovered by integer division <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mo fence="false" stretchy="false">&#x230A;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>m</mml:mi><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo fence="false" stretchy="false">&#x230B;</mml:mo></mml:math></inline-formula>. However, a critical limitation of Type I schemes is that they are not well suited for directly processing ciphertexts containing embedded messages. As a result, employing Type I methods may limit the processing of ciphertexts.</p>
<p>In contrast, Type II schemes aim to achieve lossless data hiding in ciphertexts (LDH-CT) without altering plaintexts or increasing ciphertext size [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-11">11</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>]. For example, Zheng et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] proposed a LDH-CT scheme based on numerical interval mapping: the data hider modifies the ciphertext to fall into specific subintervals corresponding to embedded bits. Using the homomorphic and probabilistic properties of cryptosystems to ensure invariance of plaintext. Wu et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] proposed a RDHED scheme using random number substitution (RS). In this scheme, binary secret messages are first converted into decimal numbers that then replace the random numbers used during the encryption process to embed the data. However, this method constrains the bit length of embedded messages, as exceeding predefined limits disrupts both encryption and decryption processes.</p>
<p>Despite advances in existing research, two critical challenges hinder the application of RDHED schemes to FL: First, existing RDHED schemes primarily target image data carriers, whereas FL predominantly processes model parameters. Second, existing schemes do not adequately address compatibility with homomorphic processing [<xref ref-type="bibr" rid="ref-12">12</xref>&#x2013;<xref ref-type="bibr" rid="ref-14">14</xref>]. In particular, when encrypted data containing embedded information undergoes homomorphic computations, such as ciphertext aggregation, the embedded data may suffer irreversible distortion, thereby leading to extraction failure.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Verifiable Federated Learning</title>
<p>In FL, the trustworthiness of the servers cannot be absolutely guaranteed as malicious servers can return incorrect aggregation results [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>]. Models derived from such compromised servers inevitably underperform in prediction or classification tasks, necessitating VFL schemes to mitigate these risks.</p>
<p>Existing VFL research follows mainly two technical paths: LHH-based schemes [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>] and dual-aggregation frameworks [<xref ref-type="bibr" rid="ref-27">27</xref>]. Xu et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed the first VFL framework, integrating a double-masking protocol [<xref ref-type="bibr" rid="ref-23">23</xref>] for privacy protection with LHH and pseudorandom techniques to achieve verifiable aggregation. However, this scheme suffers from two critical drawbacks: First, communication overheads scale with the model dimension. Second, computationally intensive bilinear pairing operations. To optimize communication efficiency, Guo et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] proposed VeriFL, which decouples communication overhead for verification from model dimensions via LHH combined with equivocal commitments. Recent advances include VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>], where VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] designs a novel aggregation protocol to minimize performance degradation caused by heterogeneous client data quality, while PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>] employs a blockwise encryption strategy to alleviate computational bottlenecks of HE, reducing resource demands without compromising security.</p>
<p>However, LHH-based VFL schemes remain plagued by high computational overhead, as the complexity of hash value calculation increases with model dimensions [<xref ref-type="bibr" rid="ref-26">26</xref>]. To enable lightweight verification, Hahn et al. proposed VERSA [<xref ref-type="bibr" rid="ref-27">27</xref>], a dual-aggregation verification framework that eliminates the need for trusted setups and uses a lightweight pseudorandom generator (PRG) to enable efficient verification of the aggregation result. However, recent studies have identified vulnerabilities that compromise its verifiability [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>].</p>
<p>In summary, neither LHH-based VFL nor dual-aggregate verification-based schemes achieve high efficiency. As shown in <xref ref-type="table" rid="table-2">Table 2</xref> (detailed in <xref ref-type="sec" rid="s7_4_1">Section 7.4.1</xref>), the LHH-based approach incurs significant computational overhead during verification as the model dimension grows, requiring approximately 12,490 s to compute the LHH values for models with dimensions reaching 10,000,000. In contrast, dual-aggregate verification-based schemes face substantial communication overhead: Users must submit both local model updates and validation codes derived from these parameters, which doubles their communication expenditure. Furthermore, as the model dimensionality increases, the communication overhead introduced by validation becomes impractical for real-world applications. Crucially, given the resource constraints of end-user devices, the designed VFL framework should maintain lightweight communication and computational overheads for verification to facilitate practical deployment.</p>

</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Preliminaries</title>
<p>In this section, we provide the foundational concepts necessary to understand our VPAFL scheme.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Federated Learning</title>
<p>Deep learning has attracted significant attention for its remarkable achievements in various fields, though high-performance deep neural networks (DNNs) typically rely on extensive datasets. However, the data used to train DNNs often contain sensitive information. For example, location-based services [<xref ref-type="bibr" rid="ref-31">31</xref>] could expose personal whereabouts, while goods purchase records can be exploited for targeted advertising. More critically, the leakage of health information or facial data poses serious privacy risks. To address these challenges, FL has emerged as a promising solution [<xref ref-type="bibr" rid="ref-7">7</xref>]. Since its inception, FL has been widely adopted in various applications such as the Internet of Things (IoT), smart healthcare [<xref ref-type="bibr" rid="ref-32">32</xref>], and smart cities [<xref ref-type="bibr" rid="ref-33">33</xref>]. FL is a distributed machine learning paradigm that collaboratively trains a global model by coordinating multiple participants without compromising data privacy. In this architecture, the server does not directly access user data; instead, it iteratively aggregates parameters to optimize the global model. Let <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:math></inline-formula> denote the set of participating users, where <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula> represents the total number of users, and each user <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:math></inline-formula> has a private dataset <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The FL training process proceeds iteratively through the following stages per communication round:</p>
<p>a) Global Model Distribution: The server broadcasts the current global model <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">M</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msup></mml:math></inline-formula> to all users, where <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>k</mml:mi></mml:math></inline-formula> denotes the current communication round.</p>
<p>b) Local Model Training: Each user <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> initializes their local model with <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">M</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msup></mml:math></inline-formula> and trains on <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">D</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> using the stochastic gradient descent (SGD) algorithm [<xref ref-type="bibr" rid="ref-34">34</xref>].</p>
<p>c) Model Aggregation: The server aggregates the received local models via the Federated Averaging (FedAvg) algorithm [<xref ref-type="bibr" rid="ref-7">7</xref>] to generate the updated global model <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">M</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p>Formally, during the <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>k</mml:mi></mml:math></inline-formula>-th communication round, each user <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> updates its local model parameters using the SGD algorithm [<xref ref-type="bibr" rid="ref-34">34</xref>]:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msub><mml:mi>l</mml:mi><mml:mi>r</mml:mi></mml:msub></mml:mrow><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:msub><mml:mi>l</mml:mi><mml:mi>r</mml:mi></mml:msub></mml:math></inline-formula> denotes the local learning rate, <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:msubsup></mml:math></inline-formula> denotes the parameters of the local model for user <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> during the <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mi>k</mml:mi></mml:math></inline-formula>-th communication round, and <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the loss function. Subsequently, the server aggregates the received local models using the FedAvg algorithm [<xref ref-type="bibr" rid="ref-7">7</xref>] as follows:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>k</mml:mi></mml:msup><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Linear Homomorphic Hash</title>
<p>LHH [<xref ref-type="bibr" rid="ref-30">30</xref>] is a one-way and collision-resistant homomorphic hash function that can calculate the hash of a composite data block based on the hash of a single data block. The LHH scheme is formally defined by three algorithms LHH &#x003D; (<bold>LHH.Gen</bold>, <bold>LHH.Hash</bold>, <bold>LHH.Eval</bold>):</p>
<p>a) <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:mtext mathvariant="bold">LHH.Gen</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BA;</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: Given the security parameters <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>&#x03BA;</mml:mi></mml:math></inline-formula> and a <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mi>d</mml:mi></mml:math></inline-formula>-dimensional vector <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mi>v</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>d</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, this algorithm outputs public parameters <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>q</mml:mi><mml:mo>,</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mi>d</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> is a cyclic group of prime order <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>q</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>g</mml:mi></mml:math></inline-formula> is a generator of <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:msub><mml:mi>g</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mi>d</mml:mi></mml:msub></mml:math></inline-formula> are distinct elements in <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>.</p>
<p>b) <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mrow><mml:mtext mathvariant="bold">LHH.Hash</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: For a <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>d</mml:mi></mml:math></inline-formula>-dimensional vector <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>v</mml:mi></mml:math></inline-formula>, this algorithm computes its LHH value of <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>v</mml:mi></mml:math></inline-formula>: <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:msub><mml:mi>h</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msubsup><mml:mi>g</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>.</p>
<p>c) <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>l</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mi>l</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: Given <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mi>l</mml:mi></mml:math></inline-formula> hash values <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>l</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mi>l</mml:mi></mml:math></inline-formula> coefficients <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mi>l</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi></mml:msub></mml:math></inline-formula>, this algorithm outputs the linear combination of the <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>l</mml:mi></mml:math></inline-formula> hash values: <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>h</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>l</mml:mi></mml:mrow></mml:munderover><mml:msubsup><mml:mi>h</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mi>l</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></inline-formula></p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Overview of the System and the Threat Model</title>
<sec id="s4_1">
<label>4.1</label>
<title>System Model</title>
<p>As illustrated in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, the system model of the VPAFL protocol comprises three entities, consistent with previous works [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>]: The trusted authority (TA), the server, and the users.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>System model of VPAFL</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-1.tif"/>
</fig>
<p><list list-type="bullet">
<list-item>
<p><bold>TA:</bold> The TA initializes the system by generating cryptographic parameters (public/private keys) and distributing the initial global model to all participants. It is considered trustworthy and remains offline after initialization.</p></list-item>
<list-item>
<p><bold>Server:</bold> The server aggregates encrypted local models received from users, updates the global model, and broadcasts the aggregated result to the user for verification.</p></list-item>
<list-item>
<p><bold>Users:</bold> In each communication round (except for the first), users download the latest global model from the server as their local mode. During the first communication round, the TA initializes the global model. Each user trains the local model on their private dataset, encrypts the local model parameters with their private key, and uploads the ciphertext to the server. Upon receiving the aggregated result, users verify its correctness. Training continues only if verification succeeds; otherwise, training is aborted.</p></list-item>
</list></p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Threat Model</title>
<p>Our threat model is defined as follows:
<list list-type="bullet">
<list-item>
<p><bold>Semi-honest users:</bold> Users follow the FL protocol faithfully, but may attempt to infer sensitive information from the data of honest users. Additionally, a subset of users may collude with the server to manipulate the aggregation results.</p></list-item>
<list-item>
<p><bold>Server:</bold> The server may attempt to infer user privacy or forge verifiable aggregation results. In particular, the server can collude with up to <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> users, where <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>t</mml:mi></mml:math></inline-formula> denotes the threshold parameter in Shamir&#x2019;s Secret Sharing (<inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mrow><mml:mtext mathvariant="bold">SS</mml:mtext></mml:mrow></mml:math></inline-formula>) protocol [<xref ref-type="bibr" rid="ref-35">35</xref>].</p></list-item>
<list-item>
<p><bold>Out-of-Scope attacks:</bold> In FL systems, not all participants are trustworthy, as malicious users can launch poisoning attacks [<xref ref-type="bibr" rid="ref-36">36</xref>] aimed at manipulating local models to compromise the performance of the global model. However, this paper does not consider poisoning attacks, as our primary objective focuses on ensuring the correctness of the aggregation results while maintaining user privacy protection.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Proposed Scheme</title>
<p>In this section, we first propose a RDHED scheme designed for compatibility with homomorphic processing. In particular, we design a JEEM by utilizing the additive homomorphic properties of the Paillier cryptosystem [<xref ref-type="bibr" rid="ref-19">19</xref>]. Subsequently, we further construct the VPAFL protocol by integrating the proposed RDHED scheme with the LHH [<xref ref-type="bibr" rid="ref-30">30</xref>] and digital signature algorithms.</p>
<sec id="s5_1">
<label>5.1</label>
<title>Joint Embedding-Extraction Mechanism</title>
<p>Extending the drop-tolerant secure aggregation algorithm (<bold>DTSA</bold>) proposed by Zhao et al. [<xref ref-type="bibr" rid="ref-20">20</xref>], we propose a novel secure aggregation-data hiding (<bold>SADH</bold>) hybrid algorithm that is compatible with homomorphic processing. The core innovation of <bold>SADH</bold> lies in its JEEM, which enables users to collaboratively embed secret messages in ciphertext and extract them after aggregation. For simplicity, we assume that no user dropout occurs during training. The scheme operates as follows:
<list list-type="bullet">
<list-item>
<p><inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mrow><mml:mtext mathvariant="bold">SADH.Gen</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BA;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: This algorithm initializes cryptographic parameters. The inputs include the security parameter <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mi>&#x03BA;</mml:mi></mml:math></inline-formula>, the threshold <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>t</mml:mi></mml:math></inline-formula> for the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>] and the user set <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:math></inline-formula> with <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>. First, generate the public key <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>n</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> shared among all users, along with the private key <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> assigned to each user <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and the public parameter <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula> for the server. In particular, two large prime numbers <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>q</mml:mi></mml:math></inline-formula> are selected such that <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>p</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>q</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:math></inline-formula>. Then, compute <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>N</mml:mi><mml:mo>=</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>q</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mi>&#x03BB;</mml:mi><mml:mo>=</mml:mo><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mi>m</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>q</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mi>m</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the least common multiple of <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mi>a</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>b</mml:mi></mml:math></inline-formula>. Next, choose a random integer <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mi>g</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> that satisfies <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>g</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>&#x03BB;</mml:mi></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, where <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>N</mml:mi></mml:math></inline-formula>. Subsequently, compute <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>, where <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mi>&#x03C3;</mml:mi></mml:math></inline-formula> is a large prime satisfying <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:math></inline-formula>. Finally, construct the polynomial <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as follows:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>+</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mo>,</mml:mo></mml:math></disp-formula>
where the private key is denoted as <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>, the coefficients <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:msub><mml:mi>a</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mi>s</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are randomly chosen.</p></list-item>
<list-item>
<p><inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mrow><mml:mtext mathvariant="bold">SADH.Ence</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: This encryption-embedding hybrid algorithm processes the plaintext <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and messages <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> as input, encrypts <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> using <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and outputs the ciphertext <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:msubsup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula>
The core mechanism lies in embedding secret messages through redundant ciphertext values without changing the plaintext, as demonstrated in <xref ref-type="sec" rid="s6_1">Section 6.1</xref>. The key parameters are defined as follows:
<list list-type="simple">
<list-item><label>&#x2013;</label><p>The embedded message <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> serves two purposes: (1) to carry a secret message and (2) to allow collaborative generation of joint embedded messages. Where <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mi>l</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> denotes a binary sequence of length <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mi>l</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> denotes its decimal value.</p></list-item>
<list-item><label>&#x2013;</label><p>The random number <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula> is used to ensure the confidentiality of the message and <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:mi>&#x03BA;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula>.</p></list-item>
<list-item><label>&#x2013;</label><p>The user set <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:math></inline-formula> contains <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>n</mml:mi></mml:math></inline-formula> users (<inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>).</p></list-item>
</list></p></list-item>
<list-item>
<p><inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mrow><mml:mtext mathvariant="bold">SADH.Agg</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: The server aggregates the received ciphertexts as follows:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>.</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:msubsup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
where <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> denotes the joint embedded message <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mi>d</mml:mi></mml:math></inline-formula>, formed by fusing the user-embedded secret messages within the ciphertext domain.</p></list-item>
<list-item>
<p><inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mrow><mml:mtext mathvariant="bold">SADH.Dece</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: After receiving the aggregated ciphertext <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, the user decrypts it with the private key <italic>SK</italic> and extracts the joint embedded message <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mi>d</mml:mi></mml:math></inline-formula> through the following steps:
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>w</mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:msup><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mi>&#x03BB;</mml:mi></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>&#x03BB;</mml:mi></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>N</mml:mi><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>&#x03C3;</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>&#x03C3;</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
Define <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:msup><mml:mi>w</mml:mi><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:msup><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>N</mml:mi></mml:math></inline-formula>. Because <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mi>&#x03C3;</mml:mi></mml:math></inline-formula> are known parameters, the user can derive <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi mathvariant="bold-italic">o</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, which corresponds to the joint embedded message <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>d</mml:mi></mml:math></inline-formula>.</p></list-item>
</list></p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Verifiable Privacy-Preserving Aggregation for Federated Learning</title>
<p>In the proposed protocol, users first utilize <bold>SADH</bold> to encrypt their local models and embed secret messages, subsequently uploading both the hash and the signature to the server. Following this, the server aggregates the received ciphertexts and returns the aggregation results along with the collected hashes and signatures to the users. Finally, after receiving these, each user decrypts the aggregation result to obtain the global model, extracts the joint embedded message, and performs verification to confirm the correctness of the aggregation result. The specific details of VPAFL (Algorithm 1) is illustrated in protocol in particular, the proposed protocol requires two rounds of interaction, with the specific processes for processes for each round described below:</p>
<fig id="fig-10">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-10.tif"/>
</fig>
<p>In <bold>Round 0</bold>, TA initializes the system, distributes the public parameters <italic>PP</italic>, <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mi>p</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula>, the global model <inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mrow><mml:mi mathvariant="double-struck">M</mml:mi></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>&#x2026;</mml:mo><mml:mtext>&#x00A0;</mml:mtext><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:msub></mml:math></inline-formula>, assigns private keys <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> to each user, and transmits the public parameter <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula> to the servers.</p>
<p>In <bold>Round 1</bold>, each user <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> encrypts their local model <inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula> while embedding a secret message <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, obtaining the ciphertext <inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">SADH.Ence</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mi>k</mml:mi></mml:math></inline-formula> denotes the current communication round. To optimize efficiency, for models with multiple parameters, the user embeds <inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> solely during the encryption of the first parameter, and subsequent parameters replace the embedded message with a random number <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula>. As demonstrated in <xref ref-type="sec" rid="s6_3">Section 6.3</xref>, embedding the message in even one parameter suffices to verify the aggregation results. Subsequently, the user <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> computes the LHH value <inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> of the embedded message <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and generates a digital signature <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> for <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. These values will later be used to verify the aggregated result. Finally, the user <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> sends <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> to the server. Upon receiving the ciphertexts, the server aggregates them and returns <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> to each user <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>.</p>
<p>In <bold>Round 2</bold>, each user <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> first checks the validity of the received digital signature <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to ensure the integrity of the associated hash values <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. If valid, the user decrypts the aggregation result to obtain the global model and the joint embedded message <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">SADH.Dece</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Next, the user verifies the aggregation result by checking whether <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:mrow><mml:mtext mathvariant="bold">LHH.Hash</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mo>?</mml:mo></mml:mrow></mml:mover></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula> denotes the total number of participating users. If equality holds, the verification succeeds and the user accepts the aggregation result as valid.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Theoretical and Comparative Analysis</title>
<sec id="s6_1">
<label>6.1</label>
<title>Correctness</title>
<p>We define correctness as the ability to ensure that the user gets the correct aggregation result to update the local model when all entities involved in the FL honestly perform the predetermined operations in the protocol.</p>
<p><bold>Theorem 1.</bold> <italic>The user can obtain the correct aggregation result if at least <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:mi>t</mml:mi></mml:math></inline-formula> users participate in FL and the server performs the aggregation operation honestly, where <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mi>t</mml:mi></mml:math></inline-formula> is the threshold of the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>]</italic>.</p>
<p><bold>Proof of Theorem 1:</bold> Assume <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. From <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>, the user <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> applies the encryption-embedding hybrid algorithm <inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:mrow><mml:mtext mathvariant="bold">SADH.Ence</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to encrypt the local model <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and embed the message <inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> as follows:
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:msubsup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Then, as shown in Protocol 1, the ciphertext received by server aggregation in <bold>Round 1</bold> is as follows:
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msubsup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:math></inline-formula>, and <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>. Based on <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>] and Lagrange interpolation formula, we can define a polynomial as follows:
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi></mml:math></disp-formula></p>
<p>From <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>, <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>. When <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula>, there is <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>p</mml:mi></mml:math></inline-formula>, where <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:mi>a</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula>, thus <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref> can be modified as follows:
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>N</mml:mi></mml:mrow></mml:msup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>N</mml:mi></mml:mrow></mml:msup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula>. Finally. users decrypt <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> as:
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:msup><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:mi>&#x03BB;</mml:mi></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>&#x03BB;</mml:mi></mml:mrow></mml:msup><mml:mspace width="0.667em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>N</mml:mi><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>&#x03C3;</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>&#x03C3;</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>This concludes the proof. <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mi>&#x25FB;</mml:mi></mml:math></inline-formula></p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Privacy-Preserving</title>
<p>This section begins by analyzing the security of <bold>SADH</bold> and subsequently evaluates the security of VPAFL under two adversarial scenarios: (1) a malicious server operating independently and (2) a malicious server colluding with up to <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> users.</p>
<p><bold>Theorem 2.</bold> <italic>If <bold>DTSA</bold> is indistinguishability under chosen-plaintext attack (IND-CPA) security, then the <bold>SADH</bold> is IND-CPA security</italic>.</p>
<p><bold>Proof of Theorem 2:</bold> As mentioned earlier, according to <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>, the user replaces the random number used in the encryption process with the product of a decimal number and the random number <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula>. This substitution does not compromise security, as the decimal multiplier does not alter the underlying randomness of <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Therefore, the modifications introduced by <bold>SADH</bold> to <bold>DTSA</bold> [<xref ref-type="bibr" rid="ref-20">20</xref>] do not weaken the security of the scheme. Furthermore, <bold>DTSA</bold> [<xref ref-type="bibr" rid="ref-20">20</xref>] is IND-CPA security, then the security of <bold>SADH</bold> is guaranteed.</p>
<p><bold>Theorem 3.</bold> <italic>(Security Against Malicious Server) In the absence of collusion between the malicious server and semi-honest users, the privacy of all honest users is preserved</italic>.</p>
<p><bold>Proof of Theorem 3:</bold> To formally prove privacy guarantees, we employ a standard hybrid argument [<xref ref-type="bibr" rid="ref-37">37</xref>], proved as follows: Under the (<bold>SADH</bold>, <bold>LHH</bold>)-hybrid model, assuming that the security parameter of VPAFL is <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mi>&#x03BA;</mml:mi></mml:math></inline-formula>, the threshold of <bold>SS</bold> protocol is <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mi>t</mml:mi></mml:math></inline-formula>, and the total number of users is <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:mi>n</mml:mi></mml:math></inline-formula>. For simplicity, we define Server as <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mi>S</mml:mi><mml:mo>,</mml:mo><mml:mi>V</mml:mi><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:mo>&#x2229;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>,</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow></mml:math></inline-formula>. The joint view of all entities in<italic>V</italic> can be denoted as a random variable <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. There is also a probabilistic polynomial-time (PPT) simulator <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">SIM</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. In order to prove the security of VPAFL, it is necessary to prove that the outputs of <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">SIM</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> are indistinguishable, which is formally expressed as follows:
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2261;</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">SIM</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p><bold>hyb0</bold> First, we create a series of random variables, which are indistinguishable from the joint real view of <italic>V</italic> in <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> in the actual implementation of the VPAFL.</p>
<p><bold>hyb1</bold> In this hybrid, we change the behavior of the user <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> through the simulator, and replace the real local model <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> with the random vector <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Then, the user <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is invoked to encrypt the random vector <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and embed the message <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Note that in <xref ref-type="sec" rid="s5">Section 5</xref>, <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is defined as the product of two components: (1) a decimal number converted from a binary sequence, and (2) a random number <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula>. However, in the simulation phase, the simulator replaces <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> with an random value <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:msub><mml:mi>r</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula>. The encryption process is adjusted as follows:
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">SADH.Ence</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> denotes the secret key of user <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. The simulator then invokes the user <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> to calculate the hash value of <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:msub><mml:mi>r</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula>: <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">LHH.Hash</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and generates the digital signature of <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>: <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">DS.Sign</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Finally, the user <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> sends <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> to the server. Reviewing the proof of <bold>Theorem 2</bold>, <bold>SADH</bold> guarantees that <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> is computationally indistinguishable from <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. In particular, it has been proved that the output of LHH is random and indistinguishable under different inputs. Thus, VPAFL guarantees the same distribution between <bold>hyb1</bold> and <bold>hyb0</bold>.</p>
<p><bold>hyb2</bold> In this hybrid, the server aggregates the received ciphertext and returns the aggregation result, the received LHH value and the digital signature to each user:
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>v</mml:mi><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mrow><mml:mtext mathvariant="bold">SADH.Agg</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mrow><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Similarly, the security of <bold>SADH</bold> algorithm ensures the same distribution between <bold>hyb2</bold> and <bold>hyb1</bold>.</p>
<p>As mentioned above, based on the security of the <bold>SADH</bold> and <bold>LHH</bold> algorithms, we prove that the view in the PPT simulator <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">SIM</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is indistinguishable from the real view of V in the <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, i.e., that the <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">REAL</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2261;</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">SIM</mml:mtext></mml:mrow><mml:mi>V</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BA;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:mi>&#x25FB;</mml:mi></mml:math></inline-formula></p>
<p><bold>Theorem 4.</bold> <italic>(Security against Colluding Malicious Server and Users) Even if a malicious server colludes with up to <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> users, the privacy of all honest users is preserved</italic>.</p>
<p><bold>Proof of Theorem 4:</bold> According to <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>, the user <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> encrypted local model <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> as follows:
<disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>S</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:msubsup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:mi>t</mml:mi></mml:math></inline-formula><inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denote the threshold of the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>], and <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mn mathvariant="bold">1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mfrac><mml:mi>j</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:mfrac></mml:math></inline-formula>. According to the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>], if the malicious server colludes with <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:mo>&#x2265;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula> users, <xref ref-type="disp-formula" rid="eqn-15">Eq. (15)</xref> can be modified as follows:
<disp-formula id="eqn-16"><label>(16)</label><mml:math id="mml-eqn-16" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:mi>a</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula>. At this point, the encrypted local model <inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> can be decrypted using the private key <italic>SK</italic>, otherwise it cannot be decrypted. <inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:mi>&#x25FB;</mml:mi></mml:math></inline-formula></p>
<p>According to <bold>Theorem 3</bold> and <bold>Theorem 4</bold>, we further demonstrate the resistance of VPAFL to inference attacks under two threat scenarios: (1) attacks initiated solely by the server and (2) collusion between the server and malicious users.</p>
<p>Regarding the global model, since all users transmit encrypted model parameters, the server exclusively operates on ciphertexts during aggregation. This prevents the server from directly analyzing sensitive information. Even if the server colludes with a user to obtain the private key <italic>SK</italic>, the inherent lack of auxiliary training data ensures that meaningful inference remains infeasible.</p>
<p>For local updates, in the VPAFL protocol, users employ <bold>SADH</bold> to encrypt local model updates. Under the first threat model (only malicious server), <bold>Theorem 3</bold> guarantees that the server cannot decrypt the encrypted parameters of any user without access to the corresponding private key <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:mi>S</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Under the second threat model (server-user collusion), <bold>Theorem 4</bold> ensures confidentiality even if up to <inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> users conspire with the server: the colluding parties cannot decrypt the local updates of honest users. Since adversaries cannot analyze relevant sensitive information from ciphertext, VPAFL satisfies security requirements against inference attacks in both scenarios.</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Verifiability</title>
<p><bold>Theorem 5.</bold> <italic>We define verifiability as the ability of each client to independently verify the correctness of the aggregation results under the threat model defined in <xref ref-type="sec" rid="s4_2">Section 4.2</xref></italic>.</p>
<p><bold>Proof of Theorem 5:</bold> According to the operation of the malicious server on the aggregation results, we consider two scenarios to prove the effectiveness of the verification.</p>
<p>Scenario 1 (Partial Model Aggregation): Let the total number of users be <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:mi>n</mml:mi></mml:math></inline-formula>, and let <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mi>t</mml:mi></mml:math></inline-formula> denote the threshold of the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>]. Assume the server aggregates the models received from <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:mi>c</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:mi>t</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>) users. According to <xref ref-type="disp-formula" rid="eqn-7">Eqs. (7)</xref> and <xref ref-type="disp-formula" rid="eqn-8">(8)</xref>, the results obtained by the server aggregation as follows:
<disp-formula id="eqn-17"><label>(17)</label><mml:math id="mml-eqn-17" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mspace width="1em" /><mml:mi>mod</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>According to <xref ref-type="disp-formula" rid="eqn-10">Eq. (10)</xref>, the user decrypts the ciphertext using private key <italic>SK</italic> to to obtain the global model <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:math></inline-formula> and extracts the joint embedded message <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:msubsup><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. Subsequently, the user will check if the following equation is true.
<disp-formula id="eqn-18"><label>(18)</label><mml:math id="mml-eqn-18" display="block"><mml:mrow><mml:mtext mathvariant="bold">LHH.Hash</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mo>?</mml:mo></mml:mrow></mml:mover></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Based on the definitions in <xref ref-type="sec" rid="s3_2">Section 3.2</xref>, we have:
<disp-formula id="eqn-19"><label>(19)</label><mml:math id="mml-eqn-19" display="block"><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Obviously <xref ref-type="disp-formula" rid="eqn-18">Eq. (18)</xref> does not hold and therefore the aggregation result fails to pass validation.</p>
<p>Scenario 2 (Collusion Attack): The server colludes with <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:mi>c</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mi>c</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>t</mml:mi></mml:math></inline-formula>) users to forge aggregated results that pass verification, where <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:mi>t</mml:mi></mml:math></inline-formula> denote the threshold of the <bold>SS</bold> protocol [<xref ref-type="bibr" rid="ref-35">35</xref>]. Assume the total number of users is <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:mi>n</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:mi>c</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>t</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>). To forge an aggregation result that passes the validation, the server must craft a result of the following form:
<disp-formula id="eqn-20"><label>(20)</label><mml:math id="mml-eqn-20" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Let <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:math></inline-formula> denote the modified aggregation results. To forge a verified aggregation result, the server must ensure the joint embedded message <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> can be extracted from <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. However, since the server colludes with only <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x003C;</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> users, it cannot access the secret messages <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2209;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold-script">U</mml:mi></mml:mrow><mml:mi>c</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> of non-colluding users and must instead guess their values. Suppose the server attempts this forgery by manipulating the aggregation result as follows:<disp-formula id="eqn-21"><label>(21)</label><mml:math id="mml-eqn-21" display="block"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>s</mml:mi><mml:mrow><mml:mi>q</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>!</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> denotes the guess of the server of the secret messages embedded by non-colluding users. As defined in <xref ref-type="sec" rid="s5">Section 5</xref>, the user extracts the joint embedded message <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:msubsup><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> from the ciphertext <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:mo stretchy="false">[</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>. To verify the correctness of the aggregation results, the user checks if the following equation is true:
<disp-formula id="eqn-22"><label>(22)</label><mml:math id="mml-eqn-22" display="block"><mml:mrow><mml:mtext mathvariant="bold">LHH.Hash</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mo>?</mml:mo></mml:mrow></mml:mover></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:mrow><mml:mtext mathvariant="bold">LHH.Eval</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:munderover><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:math></inline-formula>, therefore the forged aggregation result cannot pass the verification. <inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:mi>&#x25FB;</mml:mi></mml:math></inline-formula></p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Comparison</title>
<p>We compare VPAFL with existing LHH-based VFL schemes, including VerifyNet [<xref ref-type="bibr" rid="ref-18">18</xref>], VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>], VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>], and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>], as shown in <xref ref-type="table" rid="table-1">Table 1</xref>. VerifyNet [<xref ref-type="bibr" rid="ref-18">18</xref>] and VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>] are based on the double-masking protocol [<xref ref-type="bibr" rid="ref-23">23</xref>], which effectively protects the local gradients of users but fails to protect the privacy of aggregation results. Moreover, these schemes require multiple rounds of interaction between users and the server, increasing communication overhead. In particular, they do not address the risk that corrupted clients colluding with a malicious server are forged to bypass verification. To mitigate collusion attacks during verification, VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>], PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>], and our proposed VPAFL employ LHH combined with digital signatures, ensuring collusion-resistant verification.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison of VFL protocols</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Protocol</th>
<th align="center">Local privacy (WITH collusion)</th>
<th align="center">Aggregation privacy (without collusion)</th>
<th align="center">Collusion-resistant verification</th>
<th align="center">Verification complexity</th>
<th align="center">Rounds of interactions</th>
</tr>
</thead>
<tbody>
<tr>
<td>VerifyNet [<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td><inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>4</td>
</tr>
<tr>
<td>VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td><inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>4</td>
</tr>
<tr>
<td>VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td><inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>3</td>
</tr>
<tr>
<td>PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td><inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>2</td>
</tr>
<tr>
<td>VPAFL (our)</td>
<td><inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-279"><mml:math id="mml-ieqn-279"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-280"><mml:math id="mml-ieqn-280"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>2</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Regarding aggregation privacy, VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] introduces a blinding factor to mask the aggregation results, while VPAFL and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>] delegate decryption authority to users. This approach prevents the server from directly decrypting the aggregation results, thus enhancing privacy protection. However, it is important to note that neither VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>], PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>], nor VPAFL can fully preserve aggregation results in privacy under collusion attacks. Since FL inherently involves collaborative training of a unified global model, the server only needs to collude with a single user to obtain the global model.</p>
<p>In terms of verification complexity, we assume that the computational complexity of each call to LHH is <inline-formula id="ieqn-281"><mml:math id="mml-ieqn-281"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-282"><mml:math id="mml-ieqn-282"><mml:mi>d</mml:mi></mml:math></inline-formula> represents the model dimension. In VerifyNet [<xref ref-type="bibr" rid="ref-18">18</xref>] and VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>], users perform LHH twice per verification: once to generate the hash value and once to verify the result. Thus, the verification complexity is <inline-formula id="ieqn-283"><mml:math id="mml-ieqn-283"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> per communication round. To optimize this, VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>] employs an amortized verification mechanism. Specifically, users sample a set of random coefficients to compute the linear combination of hash aggregations across multiple communication rounds (for example, after <inline-formula id="ieqn-284"><mml:math id="mml-ieqn-284"><mml:msub><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:msub></mml:math></inline-formula> rounds). They then verified whether the combined hash matches the hash of the linear combination (using the same coefficients) applied to the aggregation results of those rounds. Consequently, VeriFL [<xref ref-type="bibr" rid="ref-24">24</xref>] reduces the verification complexity to <inline-formula id="ieqn-285"><mml:math id="mml-ieqn-285"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. In contrast, VPAFL further optimizes the process by integrating the proposed RDHED with LHH (see <xref ref-type="sec" rid="s7_4_1">Section 7.4.1</xref> for details), thus reducing the verification complexity to <inline-formula id="ieqn-286"><mml:math id="mml-ieqn-286"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Moreover, VPAFL requires only two interaction rounds, establishing it as a more efficient protocol compared to existing solutions.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Experimental Results</title>
<p>In this section, similar to previous studies [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>], we evaluate the performance of VPAFL in terms of fidelity, computational overhead, and communication overhead.</p>
<sec id="s7_1">
<label>7.1</label>
<title>Experimental Settings</title>
<p>This subsection describes the experimental settings for VPAFL.</p>
<p><bold>Model Architectures and Datasets:</bold> We employ two deep neural network architectures: AlexNet [<xref ref-type="bibr" rid="ref-38">38</xref>] for the CIFAR-100 [<xref ref-type="bibr" rid="ref-39">39</xref>] classification task and FedCNN for the MNIST [<xref ref-type="bibr" rid="ref-40">40</xref>] and CIFAR-10 [<xref ref-type="bibr" rid="ref-39">39</xref>] classification task.</p>
<p><bold>Federated Learning Settings:</bold> Based on the open-source personalized FL framework (<ext-link ext-link-type="uri" xlink:href="https://github.com/TsingZ0/PFLlib">https://github.com/TsingZ0/PFLlib</ext-link>, accessed on 7 May 2025) [<xref ref-type="bibr" rid="ref-41">41</xref>], we simulate a horizontal FL environment where users employ the SGD algorithm [<xref ref-type="bibr" rid="ref-34">34</xref>] for local model updates during each communication round, with the server using the FedAvg algorithm [<xref ref-type="bibr" rid="ref-7">7</xref>] for model aggregation.</p>
<p>All experiments were conducted on an Ubuntu 22.04 workstation equipped with an Intel Xeon Platinum 8352V 2.10 GHz CPU, 60 GB RAM, and a single NVIDIA 4090 GPU. Our implementation uses Python 3.9 with stable libraries. The LHH is implemented using NIST P-256 curves. FedCNN is a convolutional neural network with the following architecture: <inline-formula id="ieqn-287"><mml:math id="mml-ieqn-287"><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>32</mml:mn><mml:mo>,</mml:mo><mml:mn>5</mml:mn><mml:mspace width="negativethinmathspace" /><mml:mo>&#x00D7;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mn>5</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>U</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>M</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>32</mml:mn><mml:mo>,</mml:mo><mml:mn>64</mml:mn><mml:mo>,</mml:mo><mml:mn>5</mml:mn><mml:mspace width="negativethinmathspace" /><mml:mo>&#x00D7;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:mn>5</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>U</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>M</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>F</mml:mi><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>1024</mml:mn><mml:mo>,</mml:mo><mml:mn>512</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>U</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>F</mml:mi><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>512</mml:mn><mml:mo>,</mml:mo><mml:mn>10</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-288"><mml:math id="mml-ieqn-288"><mml:mi>x</mml:mi></mml:math></inline-formula> denotes the dimension of the input, <inline-formula id="ieqn-289"><mml:math id="mml-ieqn-289"><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:math></inline-formula> denotes the convolutional layer, <inline-formula id="ieqn-290"><mml:math id="mml-ieqn-290"><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>L</mml:mi><mml:mi>U</mml:mi></mml:math></inline-formula> denotes the type of activation function, <inline-formula id="ieqn-291"><mml:math id="mml-ieqn-291"><mml:mi>M</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mi>P</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>l</mml:mi></mml:math></inline-formula> denotes the pooling layer, and <italic>FC</italic> denotes the fully connected layer.</p>
</sec>
<sec id="s7_2">
<label>7.2</label>
<title>Evaluation Metrics</title>
<p><bold>Fidelity:</bold> We measure fidelity using the accuracy of the model on the classification task, denoted by <inline-formula id="ieqn-292"><mml:math id="mml-ieqn-292"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>c</mml:mi></mml:math></inline-formula>.</p>
<p><bold>Computational and Communication Overhead:</bold> Similarly to previous studies [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>], we measure computational and communication overhead to evaluate the efficiency of the VPAFL.</p>
<p><bold>Baseline:</bold> Regarding the selection of the baseline for overhead comparison, we adopt VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] because it also uses the DTSA algorithm [<xref ref-type="bibr" rid="ref-20">20</xref>] as the privacy-preserving strategy. In particular, VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] introduces a weight aggregation protocol to mitigate the degradation of model performance caused by heterogeneous user data quality. To ensure comparability, we exclusively retain the core modules relevant to VFL during baseline reproduction.</p>
</sec>
<sec id="s7_3">
<label>7.3</label>
<title>Fidelity</title>
<p>To validate that the proposed scheme maintains aggregation accuracy without compromising privacy guarantees, we evaluate its performance on three datasets: MNIST [<xref ref-type="bibr" rid="ref-40">40</xref>], CIFAR-10, and CIFAR-100 [<xref ref-type="bibr" rid="ref-39">39</xref>], adopting identical training configurations (e.g., learning rate, batch size) for direct comparison with the FedAvg algorithm [<xref ref-type="bibr" rid="ref-7">7</xref>]. As shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, the proposed VPAFL protocol achieves an aggregation effectiveness comparable to that of FedAvg [<xref ref-type="bibr" rid="ref-7">7</xref>], with a stable convergence behavior observed across all datasets. This consistency originates from the mathematically lossless encryption and decryption of the plaintext model parameters, thereby preserving data integrity throughout the FL process.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>The task accuracy (<inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>c</mml:mi></mml:math></inline-formula>) on MNIST, CIFAR-10 and CIFAR-100</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-2.tif"/>
</fig>
</sec>
<sec id="s7_4">
<label>7.4</label>
<title>Computational and Communication Overhead</title>
<p>To systematically analyze system efficiency, we define <inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:mi>n</mml:mi></mml:math></inline-formula> as the number of participating users, <inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:mi>&#x03BA;</mml:mi><mml:mo>=</mml:mo><mml:mn>512</mml:mn></mml:math></inline-formula> as the security parameter and <inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:mi>d</mml:mi></mml:math></inline-formula> as the model dimension. To isolate variable impacts, we evaluate computational and communication overhead under two scenarios: (1) Different number of users (<inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:mi>n</mml:mi></mml:math></inline-formula> from 100 to 1000) with fixed model dimension <inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:mi>d</mml:mi><mml:mo>=</mml:mo><mml:mn>5000</mml:mn></mml:math></inline-formula>. (2) Different model dimension (<inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:mi>d</mml:mi></mml:math></inline-formula> from 1000 to 10,000) with fixed number of users <inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>500</mml:mn></mml:math></inline-formula>.</p>
<sec id="s7_4_1">
<label>7.4.1</label>
<title>Computational Overhead</title>
<p>The computational overhead of the user in VPAFL is primarily determined from modular arithmetic operations in <inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:msub></mml:math></inline-formula>. Let <inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> denote the time costs of single modular multiplications in <inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:msub></mml:math></inline-formula>, respectively, and <inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub></mml:math></inline-formula> for modular exponentiation in <inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi>N</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mrow></mml:msub></mml:math></inline-formula>. Based on <xref ref-type="disp-formula" rid="eqn-4">Eqs. (4)</xref> and <xref ref-type="disp-formula" rid="eqn-6">(6)</xref>, the encryption overhead per user is theoretically <inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:mi>d</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, while decryption requires <inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:mi>d</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Thus, the total computational overhead per user becomes <inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:mi>d</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates the computational overhead of a single user per communication round. The computational overhead exhibits a positive correlation with both the number of participating users <inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mi>n</mml:mi></mml:math></inline-formula> and the model dimension <inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:mi>d</mml:mi></mml:math></inline-formula>. This growth comes from increasing computational demands in both the model encryption and the decryption phases. Mathematically, as the user count <inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:mi>n</mml:mi></mml:math></inline-formula> grows, the exponent of the <italic>SK</italic> term in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref> increases, resulting in more computationally intensive operations. The higher model dimension <inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mi>d</mml:mi></mml:math></inline-formula> not only expands the set of encryption parameters, but also prolongs the decryption time. In particular, the VPAFL protocol shows superior operational efficiency compared to VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>], achieving an average reduction in computational overhead of 10 s.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Computational overheads of the users [<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-3.tif"/>
</fig>
<p>To further evaluate the efficiency of the verification process, <xref ref-type="fig" rid="fig-4">Fig. 4</xref> quantifies the computational overhead for a single user to verify aggregated results. The experimental results show that verification overhead increases with the number of users <inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:mi>n</mml:mi></mml:math></inline-formula>, due to the increasing computational demands required to validate a growing number of signatures. Specifically, the verification overhead reaches a maximum of 152.73 ms at <inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula>. In contrast, variations in model dimension <inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:mi>d</mml:mi></mml:math></inline-formula> exhibit negligible influence on verification overhead, with the results stabilizing at approximately 80 ms in all tested configurations. In particular, VPAFL achieves substantially lower verification overhead than VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>], reducing the average computational costs by approximately 8 s under identical conditions.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Computational overheads of the users for verification [<xref ref-type="bibr" rid="ref-24">24</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-4.tif"/>
</fig>
<p>In addition, we further investigate the performance of VPAFL in large-scale user scenarios. To evaluate scalability, we measure the computational overhead per user during validation under a fixed model dimension <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:mi>d</mml:mi><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula> while varying the number of participating users from 1000 to 5000 in increments of 1000 and compared it with VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p>As illustrated in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, the results demonstrate that the computational overhead of the users for verification in all three schemes increases with the number of participating users. This growth pattern originates mainly from the cost of <bold>LHH.Eval</bold>, whose computational complexity scales with the number of participating users. While the verification process requires checking more digital signatures as user numbers expand, this component contributes minimal overhead, approximately 0.3 ms even at 5000 users. Note that although VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>] employ distinct cryptographic algorithms, they share the same verification mechanism. Therefore, the computational overheads of the users for verification remain identical in both schemes.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Computational overheads of the users for verification with large user scenarios [<xref ref-type="bibr" rid="ref-25">25</xref>,<xref ref-type="bibr" rid="ref-26">26</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-5.tif"/>
</fig>
<p>In particular, VPAFL maintains significantly lower overhead than both VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] and PriVeriFL [<xref ref-type="bibr" rid="ref-26">26</xref>]. This advantage arises from differences in LHH implementation, and we elucidate the precise reasons for this disparity in the following analysis.</p>
<p>The performance superiority of VPAFL originates from a fundamental distinction in hash computation mechanisms between the two schemes. Although VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] employs LHH to decouple communication overhead from model dimension <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mi>d</mml:mi></mml:math></inline-formula>, its hash calculation operates directly on the model parameters themselves, resulting in computational demands proportional to <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:mi>d</mml:mi></mml:math></inline-formula>. In contrast, VPAFL integrates RDHED with LHH, restricting the hash computation to the lightweight secret messages embedded by users during each communication round. This strategic change in computational input&#x2014;from high-dimensional model parameters to compact secret messages&#x2014;decouples hash-related costs from <inline-formula id="ieqn-322"><mml:math id="mml-ieqn-322"><mml:mi>d</mml:mi></mml:math></inline-formula>, addressing a critical efficiency bottleneck in existing LHH-based VFL schemes [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>]. The benefits of this innovation are significantly amplified in high-dimensional model scenarios, as evidenced by the quantitative comparisons in <xref ref-type="table" rid="table-2">Table 2</xref>. For model sizes of 10,000, 100,000, 1,000,000 and parameters, the hash computation time of VPAFL remains consistently below 4 ms, while the LHH-based VFL [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>] requires up to 12,490 s when <inline-formula id="ieqn-323"><mml:math id="mml-ieqn-323"><mml:mi>d</mml:mi><mml:mo>=</mml:mo></mml:math></inline-formula> 10,000,000, a disparity that strikingly validates the efficiency gains enabled by RDHED integration.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>The time cost of calculating the hash value</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Dimensions of the model</th>
<th colspan="2">Scheme</th>
</tr>
<tr>
<th></th>
<th>Proposed scheme</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>]</th>
</tr>
</thead>
<tbody>
<tr>
<td>10,000</td>
<td>2.3 ms</td>
<td>9568.51 ms</td>
</tr>
<tr>
<td>100,000</td>
<td>2.89 ms</td>
<td>91,861.36 ms</td>
</tr>
<tr>
<td>1,000,000</td>
<td>2.9 ms</td>
<td>895,392.4 ms</td>
</tr>
<tr>
<td>10,000,000</td>
<td>3.85 ms</td>
<td>12,490,847.49 ms</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In summary, the computational overhead of the users for verification in VPAFL is lightweight, making it more conducive to practical deployment, particularly in scenarios involving large-scale models or numerous participating users.</p>
<p>In VPAFL, the server is responsible for aggregating the encrypted local models received and its computational overhead is <inline-formula id="ieqn-324"><mml:math id="mml-ieqn-324"><mml:mi>d</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> clearly shows that the calculation overhead of the server increases when the number <inline-formula id="ieqn-325"><mml:math id="mml-ieqn-325"><mml:mi>n</mml:mi></mml:math></inline-formula> of users and the model dimension <inline-formula id="ieqn-326"><mml:math id="mml-ieqn-326"><mml:mi>d</mml:mi></mml:math></inline-formula> increase. Among them, the computational overhead of the server in VPAFL is slightly lower than that of the server in VPFLI, because the server in VPAFL only involves aggregating local models and does not decrypt the ciphertext.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Computational overheads of the server [<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-6.tif"/>
</fig>
</sec>
<sec id="s7_4_2">
<label>7.4.2</label>
<title>Communication Overhead</title>
<p>In the experiment, we measure the communication overhead by the size of the uploaded information. As shown in <xref ref-type="fig" rid="fig-7">Fig. 7</xref>, the communication overhead of the users is not related to the number of users, but related to the model dimension <inline-formula id="ieqn-327"><mml:math id="mml-ieqn-327"><mml:mi>d</mml:mi></mml:math></inline-formula>. With increasing model dimension <inline-formula id="ieqn-328"><mml:math id="mml-ieqn-328"><mml:mi>d</mml:mi></mml:math></inline-formula>, the size of the ciphertext generated by users becomes larger, leading to greater communication overhead. For the server, as shown in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, its communication overhead is positively correlated with the number of users <inline-formula id="ieqn-329"><mml:math id="mml-ieqn-329"><mml:mi>n</mml:mi></mml:math></inline-formula> and the model dimension <inline-formula id="ieqn-330"><mml:math id="mml-ieqn-330"><mml:mi>d</mml:mi></mml:math></inline-formula>. The larger the number of users <inline-formula id="ieqn-331"><mml:math id="mml-ieqn-331"><mml:mi>n</mml:mi></mml:math></inline-formula>, the more messages need to be transmitted, and the larger the model dimension <inline-formula id="ieqn-332"><mml:math id="mml-ieqn-332"><mml:mi>d</mml:mi></mml:math></inline-formula>, the larger the ciphertext size generated by server aggregation.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Communication overheads of the users [<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-7.tif"/>
</fig><fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Communication overheads of the server [<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-8.tif"/>
</fig>
<p>Finally, we evaluate the communication overhead associated with the verification. Since our implementation reproduces only the verifiable module of VPFLI [<xref ref-type="bibr" rid="ref-25">25</xref>] while maintaining consistency with the proposed scheme in other components, both schemes exhibit identical communication overhead under identical experimental configurations. For the user, LHH and digital signature algorithms transform variable length messages into fixed size outputs, thus decoupling verification-related communication overhead from both the number of users <inline-formula id="ieqn-333"><mml:math id="mml-ieqn-333"><mml:mi>n</mml:mi></mml:math></inline-formula> and the model dimension <inline-formula id="ieqn-334"><mml:math id="mml-ieqn-334"><mml:mi>d</mml:mi></mml:math></inline-formula>. Conversely, the verification-related communication overhead of the server is determined by the cost of broadcasting the received hash values and signatures to all users, causing the communication costs of the server to scale linearly with the number of users <inline-formula id="ieqn-335"><mml:math id="mml-ieqn-335"><mml:mi>n</mml:mi></mml:math></inline-formula>.</p>
<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> shows the communication overhead for individual users and servers under fixed model dimensions <inline-formula id="ieqn-336"><mml:math id="mml-ieqn-336"><mml:mi>d</mml:mi></mml:math></inline-formula> &#x003D; 5000 and varying numbers of participating users <inline-formula id="ieqn-337"><mml:math id="mml-ieqn-337"><mml:mi>n</mml:mi></mml:math></inline-formula>. The results show that the communication overhead for verification per user remains below 0.2 KB regardless of <inline-formula id="ieqn-338"><mml:math id="mml-ieqn-338"><mml:mi>n</mml:mi></mml:math></inline-formula>, while the server overhead increases linearly with <inline-formula id="ieqn-339"><mml:math id="mml-ieqn-339"><mml:mi>n</mml:mi></mml:math></inline-formula> due to the increasing volume of hash values and signatures broadcast. Importantly, since user devices typically face stringent computational and storage resource constraints compared to servers, the low verification-related communication overhead for users (0.2 KB) in VPAFL enhances its practicality for real-world deployment.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Communication overheads for verification when <inline-formula id="ieqn-340"><mml:math id="mml-ieqn-340"><mml:mi>d</mml:mi></mml:math></inline-formula> &#x003D; 5000 with different number of users [<xref ref-type="bibr" rid="ref-25">25</xref>]</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_65887-fig-9.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s8">
<label>8</label>
<title>Conclusion</title>
<p>In this paper, we propose a reversible data hiding in encrypted domains (RDHED) scheme that designs a joint message embedding and extraction mechanism. Building on this RDHED scheme, we further design VPAFL, a verifiable privacy-preserving aggregation protocol for single-server architectures, by combining linear homomorphic hash and digital signature algorithms. Unlike prior verifiable federated learning schemes based on linear homomorphic hash, VPAFL computes hash values using secret messages embedded by users during each communication round, thereby decoupling the computational overhead of hash generation from the model dimension. Theoretical analysis demonstrates the security and feasibility of VPAFL, while the experiment results confirm that the computational and communication overheads of the users for verification are lightweight.</p>
</sec>
</body>
<back>
<ack>
<p>The authors appreciate the valuable comments from the reviewers and editors.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported in part by the National Natural Science Foundation of China under Grants 62102450, 62272478 and the Independent Research Project of a Certain Unit under Grant ZZKY20243127.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Conceptualization: Peizheng Lai, Minqing Zhang; Experimental operation and data proofreading: Peizheng Lai, Yixin Tang, Ya Yue; Analysis and interpretation of results: Peizheng Lai, Minqing Zhang, Fuqiang Di; Draft manuscript preparation: Peizheng Lai, Ya Yue; Figure design and drawing: Peizheng Lai, Yixin Tang. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The datasets used to support the findings of this study are publicly available on Internet as follows: MNIST: <ext-link ext-link-type="uri" xlink:href="http://yann.lecun.com/exdb/mnist/">http://yann.lecun.com/exdb/mnist/</ext-link> (accessed on 24 March 2025); CIFAR-10 and CIFAR-100: <ext-link ext-link-type="uri" xlink:href="https://www.cs.toronto.edu/kriz/cifar.html">https://www.cs.toronto.edu/kriz/cifar.html</ext-link> (accessed on 24 March 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tari</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yi</surname> <given-names>X</given-names></string-name>, <string-name><surname>Premarathne</surname> <given-names>US</given-names></string-name>, <string-name><surname>Bertok</surname> <given-names>P</given-names></string-name>, <string-name><surname>Khalil</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Security and privacy in cloud computing: vision, trends, and challenges</article-title>. <source>IEEE Cloud Computing</source>. <year>2015</year>;<volume>2</volume>(<issue>2</issue>):<fpage>30</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MCC.2015.45</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Du</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wei</surname> <given-names>X</given-names></string-name>, <string-name><surname>Meng</surname> <given-names>D</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>X</given-names></string-name></person-group>. <article-title>High capacity reversible data hiding in encrypted images by patch-level sparse representation</article-title>. <source>IEEE Trans Cybern</source>. <year>2015</year>;<volume>46</volume>(<issue>5</issue>):<fpage>1132</fpage>&#x2013;<lpage>43</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCYB.2015.2423678</pub-id>; <pub-id pub-id-type="pmid">25955861</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shi</surname> <given-names>YQ</given-names></string-name>, <string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>HT</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Reversible data hiding: advances in the past two decades</article-title>. <source>IEEE Access</source>. <year>2016</year>;<volume>4</volume>:<fpage>3210</fpage>&#x2013;<lpage>37</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2016.2573308</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Qian</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Separable reversible data hiding in encrypted JPEG bitstreams</article-title>. <source>IEEE Trans Depend Secure Comput</source>. <year>2016</year>;<volume>15</volume>(<issue>6</issue>):<fpage>1055</fpage>&#x2013;<lpage>67</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2016.2634161</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>S</given-names></string-name>, <string-name><surname>Li</surname> <given-names>D</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>D</given-names></string-name>, <string-name><surname>Ye</surname> <given-names>D</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Lossless data hiding algorithm for encrypted images with high capacity</article-title>. <source>Multimed Tools Appl</source>. <year>2016</year>;<volume>75</volume>(<issue>21</issue>):<fpage>13765</fpage>&#x2013;<lpage>78</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11042-015-2920-y</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Puteaux</surname> <given-names>P</given-names></string-name>, <string-name><surname>Puech</surname> <given-names>W</given-names></string-name></person-group>. <article-title>An efficient MSB prediction-based method for high-capacity reversible data hiding in encrypted images</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2018</year>;<volume>13</volume>(<issue>7</issue>):<fpage>1670</fpage>&#x2013;<lpage>81</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2018.2799381</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>McMahan</surname> <given-names>B</given-names></string-name>, <string-name><surname>Moore</surname> <given-names>E</given-names></string-name>, <string-name><surname>Ramage</surname> <given-names>D</given-names></string-name>, <string-name><surname>Hampson</surname> <given-names>S</given-names></string-name>, <string-name><surname>Arcas</surname> <given-names>BA</given-names></string-name></person-group>. <chapter-title>Communication-efficient learning of deep networks from decentralized data</chapter-title>. In: <source>Artificial intelligence and statistics</source>; <year>2017</year>; <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>PMLR</publisher-name>. p. <fpage>1273</fpage>&#x2013;<lpage>82</lpage></mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>HT</given-names></string-name>, <string-name><surname>Cheung</surname> <given-names>YM</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>D</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Lossless data hiding in NTRU cryptosystem by polynomial encoding and modulation</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2024</year>;<volume>19</volume>(<issue>11</issue>):<fpage>3719</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2024.3362592</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Anushiadevi</surname> <given-names>R</given-names></string-name>, <string-name><surname>Amirtharajan</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Design and development of reversible data hiding-homomorphic encryption &#x0026; rhombus pattern prediction approach</article-title>. <source>Multimedia Tools Appl</source>. <year>2023</year>;<volume>82</volume>(<issue>30</issue>):<fpage>46269</fpage>&#x2013;<lpage>92</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11042-023-15455-1</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>N</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ke</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Di</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Separable reversible data hiding scheme in homomorphic encrypted domain based on NTRU</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>81412</fpage>&#x2013;<lpage>24</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.2990903</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>HT</given-names></string-name>, <string-name><surname>Cheung</surname> <given-names>YM</given-names></string-name>, <string-name><surname>Zhuang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Lossless data hiding in encrypted images compatible with homomorphic processing</article-title>. <source>IEEE Trans Cybern</source>. <year>2022</year>;<volume>53</volume>(<issue>6</issue>):<fpage>3688</fpage>&#x2013;<lpage>701</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCYB.2022.3163245</pub-id>; <pub-id pub-id-type="pmid">35427226</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Lossless data hiding based on homomorphic cryptosystem</article-title>. <source>IEEE Trans Depend Secure Comput</source>. <year>2019</year>;<volume>18</volume>(<issue>2</issue>):<fpage>692</fpage>&#x2013;<lpage>705</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TDSC.2019.2913422</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Reversible data hiding in homomorphic encrypted domain by mirroring ciphertext group</article-title>. <source>IEEE Trans Circuits Syst Video Technol</source>. <year>2018</year>;<volume>28</volume>(<issue>11</issue>):<fpage>3099</fpage>&#x2013;<lpage>110</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCSVT.2017.2742023</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ke</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>MQ</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Su</surname> <given-names>TT</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>XY</given-names></string-name></person-group>. <article-title>Fully homomorphic encryption encapsulated difference expansion for reversible data hiding in encrypted domain</article-title>. <source>IEEE Trans Circuits Syst Video Technol</source>. <year>2020</year>;<volume>30</volume>(<issue>8</issue>):<fpage>2353</fpage>&#x2013;<lpage>65</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCSVT.2019.2963393</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hitaj</surname> <given-names>B</given-names></string-name>, <string-name><surname>Ateniese</surname> <given-names>G</given-names></string-name>, <string-name><surname>Perez-Cruz</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Deep models under the GAN: information leakage from collaborative deep learning</article-title>. In: <conf-name>Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security</conf-name>; <year>2017</year>; <publisher-loc>New York, NY, USA</publisher-loc>. p. <fpage>603</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Han</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Deep leakage from gradients</article-title>. <source>Adv Neural Inf Process Syst</source>. <year>2019</year>;<volume>32</volume>:<fpage>14747</fpage>&#x2013;<lpage>56</lpage>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>C</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>M</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>HH</given-names></string-name>, <string-name><surname>Shu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Quek</surname> <given-names>TQ</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>On safeguarding privacy and security in the framework of federated learning</article-title>. <source>IEEE Network</source>. <year>2020</year>;<volume>34</volume>(<issue>4</issue>):<fpage>242</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MNET.001.1900506</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>G</given-names></string-name>, <string-name><surname>Li</surname> <given-names>H</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>X</given-names></string-name></person-group>. <article-title>VerifyNet: secure and verifiable federated learning</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2019</year>;<volume>15</volume>:<fpage>911</fpage>&#x2013;<lpage>26</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2019.2929409</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Paillier</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Public-key cryptosystems based on composite degree residuosity classes</article-title>. In: <conf-name>International Conference on the Theory and Applications of Cryptographic Techniques</conf-name>; <year>1999</year>; <publisher-loc>Berlin/Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>. p. <fpage>223</fpage>&#x2013;<lpage>38</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Li</surname> <given-names>H</given-names></string-name>, <string-name><surname>Tu</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>CORK: a privacy-preserving and lossless federated learning scheme for deep neural network</article-title>. <source>Inform Sciences</source>. <year>2022</year>;<volume>603</volume>(<issue>3</issue>):<fpage>190</fpage>&#x2013;<lpage>209</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ins.2022.04.052</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wei</surname> <given-names>K</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>HH</given-names></string-name>, <string-name><surname>Farokhi</surname> <given-names>F</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated learning with differential privacy: algorithms and performance analysis</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2020</year>;<volume>15</volume>:<fpage>3454</fpage>&#x2013;<lpage>69</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2020.2988575</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wei</surname> <given-names>K</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>C</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Personalized federated learning with differential privacy and convergence guarantee</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2023</year>;<volume>18</volume>:<fpage>4488</fpage>&#x2013;<lpage>503</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2023.3293417</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bonawitz</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ivanov</surname> <given-names>V</given-names></string-name>, <string-name><surname>Kreuter</surname> <given-names>B</given-names></string-name>, <string-name><surname>Marcedone</surname> <given-names>A</given-names></string-name>, <string-name><surname>McMahan</surname> <given-names>HB</given-names></string-name>, <string-name><surname>Patel</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Practical secure aggregation for privacy-preserving machine learning</article-title>. In: <conf-name>Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security</conf-name>; <year>2017</year>; <publisher-loc>New York, NY, USA</publisher-loc>. p. <fpage>1175</fpage>&#x2013;<lpage>91</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>B</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>VeriFL: communication-efficient and fast verifiable aggregation for federated learning</article-title>. <source>IEEE Trans Inf Forensics Security</source>. <year>2020</year>;<volume>16</volume>:<fpage>1736</fpage>&#x2013;<lpage>51</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TIFS.2020.3043139</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ren</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>G</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name></person-group>. <article-title>VPFLI: verifiable privacy-preserving federated learning with irregular users based on single server</article-title>. <source>IEEE Trans Services Computing</source>. <year>2024</year>;<volume>18</volume>(<issue>2</issue>):<fpage>1124</fpage>&#x2013;<lpage>36</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TSC.2024.3520867</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Polato</surname> <given-names>M</given-names></string-name>, <string-name><surname>Brighente</surname> <given-names>A</given-names></string-name>, <string-name><surname>Conti</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>PriVeriFL: privacy-preserving and aggregation-verifiable federated learning</article-title>. <source>IEEE Trans Services Computing</source>. <year>2024</year>;<volume>18</volume>(<issue>2</issue>):<fpage>998</fpage>&#x2013;<lpage>1011</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TSC.2024.3451183</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hahn</surname> <given-names>C</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>H</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hur</surname> <given-names>J</given-names></string-name></person-group>. <article-title>VERSA: verifiable secure aggregation for cross-device federated learning</article-title>. <source>IEEE Trans Depend Secure Comput</source>. <year>2021</year>;<volume>20</volume>(<issue>1</issue>):<fpage>36</fpage>&#x2013;<lpage>52</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TSC.2024.3451183</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Li</surname> <given-names>W</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>F</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Comments on &#x201C;VERSA: verifiable secure aggregation for cross-device federated learning&#x201D;</article-title>. <source>IEEE Trans Depend Secure Comput</source>. <year>2024</year>;<volume>21</volume>(<issue>4</issue>):<fpage>4297</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TDSC.2023.3272338</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Luo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Comments on &#x201C;VERSA: verifiable secure aggregation for cross-device federated learning&#x201D;</article-title>. <source>IEEE Trans Depend Secure Comput</source>. <year>2024</year>;<volume>21</volume>(<issue>1</issue>):<fpage>499</fpage>&#x2013;<lpage>500</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TDSC.2023.3253082</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bellare</surname> <given-names>M</given-names></string-name>, <string-name><surname>Goldreich</surname> <given-names>O</given-names></string-name>, <string-name><surname>Goldwasser</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Incremental cryptography: the case of hashing and signing</article-title>. In: <conf-name>Advances in Cryptology-CRYPTO&#x2019;94: 14th Annual International Cryptology Conference</conf-name>; <year>1994 Aug 21&#x2013;25</year>; <publisher-loc>Santa Barbara, CA, USA</publisher-loc>: <publisher-name>Springer</publisher-name>. p. <fpage>21</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>T</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Federated learning and convex hull enhancement for privacy preserving WiFi-based device-free localization</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2024</year>;<volume>70</volume>(<issue>1</issue>):<fpage>2577</fpage>&#x2013;<lpage>85</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCE.2023.3342834</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tian</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xiong</surname> <given-names>J</given-names></string-name>, <string-name><surname>Bi</surname> <given-names>R</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Bhuiyan</surname> <given-names>MZA</given-names></string-name></person-group>. <article-title>Robust and privacy-preserving decentralized deep federated learning training: focusing on digital healthcare applications</article-title>. <source>IEEE/ACM Trans Comput Bi</source>. <year>2024</year>;<volume>21</volume>(<issue>4</issue>):<fpage>890</fpage>&#x2013;<lpage>901</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCBB.2023.3243932</pub-id>; <pub-id pub-id-type="pmid">37028039</pub-id></mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wehbi</surname> <given-names>O</given-names></string-name>, <string-name><surname>Arisdakessian</surname> <given-names>S</given-names></string-name>, <string-name><surname>Guizani</surname> <given-names>M</given-names></string-name>, <string-name><surname>Wahab</surname> <given-names>OA</given-names></string-name>, <string-name><surname>Mourad</surname> <given-names>A</given-names></string-name>, <string-name><surname>Otrok</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Enhancing mutual trustworthiness in federated learning for data-rich smart cities</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>;<volume>12</volume>(<issue>3</issue>):<fpage>3105</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2024.3476950</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bottou</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Large-scale machine learning with stochastic gradient descent</article-title>. In: <conf-name>Proceedings of COMPSTAT&#x2019;2010: 19th International Conference on Computational Statistics</conf-name>; <year>2010 Aug 22&#x2013;27</year>; <publisher-loc>Paris, France</publisher-loc>: <publisher-name>Springer</publisher-name>. p. <fpage>177</fpage>&#x2013;<lpage>86</lpage>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shamir</surname> <given-names>A</given-names></string-name></person-group>. <article-title>How to share a secret</article-title>. <source>Commun ACM</source>. <year>1979</year>;<volume>22</volume>(<issue>11</issue>):<fpage>612</fpage>&#x2013;<lpage>3</lpage>. doi:<pub-id pub-id-type="doi">10.1145/359168.359176</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Jagielski</surname> <given-names>M</given-names></string-name>, <string-name><surname>Oprea</surname> <given-names>A</given-names></string-name>, <string-name><surname>Biggio</surname> <given-names>B</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Nita-Rotaru</surname> <given-names>C</given-names></string-name>, <string-name><surname>Li</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Manipulating machine learning: poisoning attacks and countermeasures for regression learning</article-title>. In: <conf-name>2018 IEEE Symposium on Security and Privacy (SP)</conf-name>; <year>2018</year>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>19</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gentry</surname> <given-names>C</given-names></string-name>, <string-name><surname>Groth</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ishai</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Peikert</surname> <given-names>C</given-names></string-name>, <string-name><surname>Sahai</surname> <given-names>A</given-names></string-name>, <string-name><surname>Smith</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Using fully homomorphic hybrid encryption to minimize non-interative zero-knowledge proofs</article-title>. <source>J Cryptol</source>. <year>2015</year>;<volume>28</volume>(<issue>4</issue>):<fpage>820</fpage>&#x2013;<lpage>43</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00145-014-9184-y</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Krizhevsky</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sutskever</surname> <given-names>I</given-names></string-name>, <string-name><surname>Hinton</surname> <given-names>GE</given-names></string-name></person-group>. <article-title>Imagenet classification with deep convolutional neural networks</article-title>. <source>Adv Neural Inf Process Syst</source>. <year>2012</year>;<volume>25</volume>:<fpage>1097</fpage>&#x2013;<lpage>105</lpage>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Krizhevsky</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hinton</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Learning multiple layers of features from tiny images</article-title>. <source>Handb Systemic Autoimmune Dis</source>. <year>2009</year>;<volume>1</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>60</lpage>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>LeCun</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>The MNIST database of handwritten digits</article-title>; <year>1998</year>. <comment>[cited 2025 May 7]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="http://yann.lecun.com/exdb/mnist/">http://yann.lecun.com/exdb/mnist/</ext-link>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Hua</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Song</surname> <given-names>T</given-names></string-name>, <string-name><surname>Xue</surname> <given-names>Z</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>PFLlib: personalized federated learning algorithm library</article-title>. <comment>arXiv:231204992. 2023</comment>.</mixed-citation></ref>
</ref-list>
</back></article>