2 ms·
In the secure aggregation paper (linked in the post: http://eprint.iacr.org/2017/281 http://eprint.iacr.org/2017/281 ) they indeed hint at the possibility of ex
by pepve 10y ago
In the secure aggregation paper (linked in the post: http://eprint.iacr.org/2017/281 http://eprint.iacr.org/2017/281 ) they indeed hint at the possibility of extracting information from the diffs. So the protocol they propose cryptographically ensures that the individual diffs can not be learned. They do this by having each pair of clients generate a secret the size of the diff, and have one add it to their diff and the other subtract it. The clients then send that result to the server where they are summed, which cancels out all the secrets. The bulk of the protocol then deals with setting up the secrets and dealing with client drop outs, which appears to be the real challenge.
Well, that's my fallible summary anyway, go read the paper. :-)