When Topology Betrays Privacy: Lattice-Based Reconstruction Attacks on Secure Aggregation in Decentralized Federated Learning
Researchers show colluding nodes in decentralized federated learning can reconstruct private updates despite secure aggregation, using lattice-based attacks tied to the Hidden Subset Sum Problem.
Secure aggregation in decentralized federated learning is widely assumed to hide individual model updates. The authors show that sparse decentralized topologies give colluding semi-honest nodes asymmetric aggregate views exposing hidden linear combinations of honest participants' private states. They establish a formal connection to the Hidden Subset Sum Problem and design a lattice-based reconstruction approach combining lattice reduction with structural filtering. Evaluations on image, tabular, and text tasks show attackers recover local updates and can reconstruct private training data.