Skip to content
Conference Open access

TrusTEE: Storage-Centric Secure Federated Learning with Trusted Execution and Policy Enforcement

2026 · International Conference on Security and Cryptography · pp. 677-688 · 0 citations · 29 references
Computer Science

TL;DR

TrusTEE is introduced, an end-to-end hardware-backed confidential federated learning system that combines cloud Trusted Execution Environments (TEEs) with user-controlled, policy-enforced object storage and evaluates TrusTEE using the FLAIR dataset to show that confidential aggregation can be achieved while preserving standard federated learning dynamics.

Abstract

: Federated Learning enables collaborative model training without sharing raw user data, yet remains vulnerable to privacy threats via shared gradients, model updates, and the hardware in which aggregation runs. Users must trust that centralised servers correctly aggregate updates and enforce data access policies. This paper introduces TrusTEE, an end-to-end hardware-backed confidential federated learning system that combines cloud Trusted Execution Environments (TEEs) with user-controlled, policy-enforced object storage. Unlike prior TEE-based federated learning work, TrusTEE treats cloud object storage as the primary communication substrate and trust boundary, using a minimal TEE-based aggregator and cloud-native role-based access control (RBAC) to separate roles. The system ensures that (1) raw client updates are never visible to the coordinator, (2) aggregation occurs entirely in hardware-encrypted memory, and (3) access to updates, aggregates, and global weights is enforced via strict identity-bound storage policies. We evaluate TrusTEE using the FLAIR dataset and show that confidential aggregation can be achieved while preserving standard federated learning dynamics.

Read PDF

Similar papers

Open access Jul 2026

Secure Collaborative Decision-Making Among Distributed Cloud Brokers Using Privacy-Preserving Federated Learning

Cloud brokers play a vital role in coordinating resource-allocation decisions across a heterogeneous cloud environment. Centralised brokerage approaches are prone to single points of failure and data exposure, expose sensitive data, and have limited interoperability. There is a need for distributed cloud brokerage that enhances collaboration by enabling decision-making without exposing raw workload specifications. A shared knowledge repository in collaborative learning introduces data sovereignty and adversarial risks. This paper proposes Federated learning-based SecureBroker-FL, introducing 3 key aspects: (i) A Differential Privacy enhanced Gradient Encryption (DPGE) protocol. (ii) An Adaptive Trust scoring (ATS) mechanism, (iii) Hierarchical Secure Aggregation (HSA). The experiments are simulated and evaluated using the Google Cloud Trace 2019 and Alibaba Clustered Trace 2022 datasets, with five geographically distributed cloud brokers. It demonstrates that SecureBroker-FL achieves 94.7% decision accuracy. The framework withstands up to 40% malicious broker participation handling graceful degradation without catastrophic collapse and outperforms baseline approaches, including FedAvg, Krum, and FLTrust.

Chaitra M · 0 citations
Open access 2026

A Trust-Aware Federated Learning Framework Based on Zero Trust Architecture for Secure Cloud Intrusion Detection

Cloud computing provides scalable infrastructure but introduces critical challenges to data privacy, trust management, and intrusion detection. To address these issues, we present a trust-aware framework that integrates a Federated Learning (FL)-based distributed ensemble with Zero Trust Architecture (ZTA) for secure cloud environments. The framework enables collaborative learning while keeping data local and private. Zero Trust is implemented by periodically verifying identity and evaluating client contributions with a lightweight local trust filter before aggregation. For reliability and agreement with the local model, an ensemble of Random Forest and Decision Tree classifiers is used. Contributions are only aggregated when satisfying the predefined trust and performance thresholds, thereby reducing the influence of potentially unreliable or malicious inputs under the assumed threat model. The proposed framework is evaluated on the UNSW-NB15 dataset under non-IID client data distribution, achieving 96% accuracy, 95.1% precision, 94%recall, 0.96 AUC-ROC, and an average per-round latency of 180 ms. Comparative results demonstrate that the framework provides a better trade-off between detection accuracy, privacy preservation, and trust enforcement than several state-of-the-art baselines, positioning it as a practical solution for cloud intrusion detection.

Unknown authors · 0 citations
2026

Trust-Centric Federated Learning Using Blockchain-Enabled Smart Contracts: An Analysis of Data Privacy, Model Integrity, and Decentralized AI Governance

A trust-based federated learning framework in which a smart contract enabled by blockchain oversees client registration, model update logging, hash-based integrity verification, trust score calculation, malicious node penalization, aggregation approval, and decentralised audit logging is proposed.

Shankar Thalla · 0 citations
Open access 2026

SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents

Security analysis demonstrates that SecuAudit can effectively resist data forgery, metadata tampering, and sub-threshold collusion attacks under the defined threat model, and establishes a feasible framework for secure data circulation under the evaluated deployment assumptions.

Yufa Shi, Jiaxing Hu, Lipeng Wang et al. · 0 citations
Open access Aug 2026

Privacy-preserving secure data sharing in edge-cloud collaborative environments

A privacy-preserving, secure data-sharing framework tailored for edge-cloud collaborative architectures that minimizes the computational overhead on the terminal side while safeguarding user privacy, and effectively reduces the overhead associated with user joining and revocation within the same group.

Qikun Zhang, Zheng Cai, Jinbo Feng et al. · 0 citations
Open access Jul 2026

Robust Trust-Aware Federated Learning for Privacy-Preserving Distributed Intelligence in Resource-Constrained IoT Systems: A Blockchain-Assisted Architecture

This paper investigates a blockchain-assisted, trust-aware FL framework for privacy-aware distributed intelligence in resource-constrained IoT systems, where the blockchain layer is used to support trust coordination, auditability, traceability, and tamper-resistant metadata recording rather than to directly improve predictive performance.

M. Reis, Carlos Serôdio, Frederico Branco · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.