Back to feed
Open access

SURGE: Sparse Updates With Randomized Guarding and Selective Encryption for Secure Federated Learning

2026 · IEEE Access · Vol 14, pp. 115878-115897 · 0 citations · 27 references

Abstract

Model updates in federated learning can expose sensitive information, while existing defenses often trade off privacy protection, communication efficiency, and training stability. This paper presents SURGE, which stands for Sparse Updates with Randomized Guarding and Selective Encryption. SURGE targets empirical attack resistance under the honest-but-curious server model, rather than a formal privacy guarantee. SURGE builds a unified sparse coordinate set from Top-k accumulated updates and uses Layered Risk-guided Mask Selection (LRMS) to allocate a limited homomorphic-encryption budget according to leakage risk, plaintext exposure history, and residual cost. It then applies random sign flipping to the remaining plaintext coordinates and uses residual feedback to compensate for sparsification and perturbation errors across rounds. Experiments cover IID and label-skew non-IID partitions on MNIST and CIFAR-10, as well as a natural-split FEMNIST benchmark. On MNIST and CIFAR-10, SURGE reduces communication overhead by 87% to 88% relative to FedPHE and MaskCrypt, averaged over the two datasets and the two selective-encryption baselines, and reaches high accuracy sooner under the same simulated wall-clock budget. SURGE also drives membership inference performance close to random guessing and substantially degrades the quality of gradient inversion reconstructions.

Read PDF