Uma Arquitetura de Aprendizado Federado Homomórfica para Treinamento de LSSVM usando CKKS e Decomposição QR de Householder

  • Victor Faria Fernandes UFF
  • Luis Antonio Kowada UFF

Resumo


Este trabalho propõe uma arquitetura de Aprendizado Federado Homomórfico One-Shot para o treinamento de Máquinas de Vetores de Suporte de Mínimos Quadrados (LSSVM) usando o esquema CKKS. Ao reduzir o treinamento a um sistema linear, emprega-se a decomposição QR de Householder para resolver o sistema KKT sobre dados cifrados, evitando ramificações estruturais incompatíveis com a criptografia homomórfica. A arquitetura é avaliada via OpenFHE em dois datasets — Iris e o Breast Cancer Wisconsin Diagnostic (WDBC) — sob particionamento IID e não-IID (Dirichlet) entre clientes, com escalabilidade testada de 40 a 225 clientes. A solução FHE federada acompanha de perto sua contraparte federada em texto claro em todas as configurações (erro relativo dos parâmetros abaixo de 3 × 10−4 para o WDBC e abaixo de 3,5% para as classes de kernel polinomial do Iris), atingindo 100% de acurácia na classe linearmente separável do Iris e até 95,6% de acurácia no WDBC sob particionamento não-IID. A abordagem elimina múltiplas rodadas de comunicação, garantindo privacidade robusta de dados e estabilidade algorítmica através de diferentes escalas de dataset, números de clientes e distribuições de dados.

Referências

Badawi, A. A., Alexandru, A., Bates, J., Bergamaschi, F., Cousins, D. B., Erabelli, S., Genise, N., Halevi, S., Hunt, H., Kim, A., Lee, Y., Liu, Z., Micciancio, D., Pascoe, C., Polyakov, Y., Quah, I., R.V., S., Rohloff, K., Saylor, J., Suponitsky, D., Triplett, M., Vaikuntanathan, V., and Zucca, V. (2022). OpenFHE: Open-source fully homomorphic encryption library. Cryptology ePrint Archive, Paper 2022/915. [link]. iacr.org/2022/915.

Boyd, S. and Vandenberghe, L. (2004). Convex optimization. Cambridge university press.

Buchanan, W. J. and Ali, H. (2025). Evaluation of privacy-aware support vector machine (SVM) learning using homomorphic encryption. arXiv:2503.04652v1.

Chen, H., Gilad-Bachrach, R., Han, K., Huang, Z., Jalali, A., Laine, K., and Lauter, K. (2018). Logistic regression over encrypted data from fully homomorphic encryption. BMC Medical Genomics, 11(4):81.

Cheon, J. H., Kim, A., Kim, M., and Song, Y. (2017). Homomorphic encryption for arithmetic of approximate numbers. pages 409–437. Springer.

Fisher, R. A. (1936). The use of multiple measurements in taxonomic problems. Annals of Eugenics, 7(2):179–188.

Geyer, R. C., Klein, T., and Nabi, M. (2018). Differentially private federated learning: A client level perspective.

Golub, G. H. and Van Loan, C. F. (2013). Matrix Computations. Johns Hopkins University Press, Baltimore, 4th edition.

Graepel, T., Lauter, K., and Naehrig, M. (2012). ML confidential: Machine learning on encrypted data. In International Conference on Information Security and Cryptology (ICISC), Lecture Notes in Computer Science, pages 1–21. Springer.

Han, K. and Ki, D. (2020). Better bootstrapping for approximate homomorphic encryption. page 364–390, Berlin, Heidelberg. Springer-Verlag.

Hartebrodt, A. and Röttger, R. (2023). Privacy of federated qr decomposition using additive secure multiparty computation. IEEE Transactions on Big Data, 10(1):31–40.

Iezzi, M. (2020). Practical privacy-preserving data science with homomorphic encryption: An overview. In IEEE International Conference on Big Data, pages 3979–3988.

Lyubashevsky, V., Peikert, C., and Regev, O. (2013). On ideal lattices and learning with errors over rings. J. ACM, 60(6).

Ma, J., Naas, S.-A., Sigg, S., and Lyu, X. (2022). Privacy-preserving federated learning based on multi-key homomorphic encryption. International Journal of Intelligent Systems.

Malekzadeh, M., Borovykh, A., and Gündüz, D. (2021). Honest-but-curious nets: Sensitive attributes of private inputs can be secretly coded into the classifiers’ outputs. CCS ’21, page 825–844, New York, NY, USA. Association for Computing Machinery.

McMahan, H. B., Andrew, G., Erlingsson, U., Chien, S., Mironov, I., Papernot, N., and Kairouz, P. (2019). A general approach to adding differential privacy to iterative training procedures.

Micciancio, D. and Goldwasser, S. (2002). Complexity of Lattice Problems: A Cryptographic Perspective, volume 671.

Nocedal, J. and Wright, S. J. (2006). Numerical Optimization. Springer, New York, 2nd edition.

Park, S., Byun, J., Lee, J., Cheon, J. H., and Lee, J. (2020). HE-friendly algorithm for privacy-preserving SVM training. IEEE Access, 8:57414–57425.

Suykens, J. A. and Vandewalle, J. (1999). Least squares support vector machine classifiers. Neural processing letters, 9:293–300.

Wolberg, W. H., Mangasarian, O. L., Street, N., and Street, W. N. (1993). Breast cancer wisconsin (diagnostic). UCI Machine Learning Repository.

Zhu, L., Liu, Z., and Han, S. (2019). Deep leakage from gradients. In Advances in Neural Information Processing Systems (NeurIPS), volume 32. arXiv:1906.08935.
Publicado
01/09/2026
FERNANDES, Victor Faria; KOWADA, Luis Antonio. Uma Arquitetura de Aprendizado Federado Homomórfica para Treinamento de LSSVM usando CKKS e Decomposição QR de Householder. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1-15. DOI: https://doi.org/10.5753/sbseg.2026.27084.