3 ms·
Do you have a specific technical criticism of the secure aggregation protocol? That’s what’s supposed to make it impossible to deduce the data from model update
by CyanTas 7y ago
Do you have a specific technical criticism of the secure aggregation protocol? That’s what’s supposed to make it impossible to deduce the data from model updates. Or is your concern something else?
- im3w1l 7y agoI hadn't really read it at that point. It more seemed like a too big achievement for me to believe that anyone could solve. One issue with their approach I found while causally browsing is "for the proof against active adversaries, we assume that there exists a public-key infras-tructure (PKI), which guarantees to users that messages they receive came from other users (and not the server). Without this assumption, the server can perform a Sybil attack on the users in RoundShareKeys" Basically assume there is some trustworthy entity that solves Sybil attacks. I don't think such an entity exists. So question is how they solve that in practice.