Secure and Accountable Collaborative Learning
Abstract
Secure machine learning paradigms have emerged as compelling solutions to address growing concerns of large-scale data collection in modern Machine Learning (ML) systems. These paradigms leverage secure computation techniques to enable the execution of ML applications without the necessity to share raw data, models or predictions to be shared between parties, offering strong, formal privacy guarantees. Recent advances have significantly enhanced both the scalability and expressiveness of these secure paradigms, facilitating their deployment in real-world scenarios across a variety of privacy-sensitive domains. However, the very mechanisms that provide these privacy guarantees also introduce new challenges to robustness, trust, and accountability. To ensure secrecy, secure ML systems conceal the processes of training and inference, making them difficult to inspect, validate, or audit. This intrinsic opacity creates a fundamental tension between privacy and accountability: hiding data and models to protect users’ privacy can also obscure failures and enable undetectable manipulation. Furthermore, in many secure ML frameworks, multiple, potentially untrusted parties collaboratively contribute to computations, thereby amplifying risks. Traditional threat models in adversarial ML often depend on transparent access to data, models, or outputs—assumptions that do not hold in secure settings. As a result, these systems become vulnerable to new and sometimes more potent attack vectors. Without dedicated integrity mechanisms, these privacy-preserving systems cannot be safely deployed in high-stakes domains such as healthcare, finance, or critical infrastructure. Realizing the full potential of secure ML requires a comprehensive understanding of the unique threats these systems face, the development of new integrity mechanisms, and their integration into these systems in a way that is efficient and preserves the privacy guarantees they provide. This dissertation advances accountability in secure ML through two complementary directions. First, it develops an understanding of the robustness challenges that arise in secure settings. We investigate the role of memorization and system-level dynamics in exposing secure systems to targeted manipulation. Based on these insights, we then introduce new cryptographic building blocks to strengthen the robustness and transparency of secure ML. We present RoFL, a system for privacy-preserving input validation in secure Federated Learning; Arc, the first framework for end-to-end auditing of secure ML pipelines; and Artemis, a new construction for generating efficient zero-knowledge proofs for real-world ML models. Together, these contributions lay the foundation for secure ML systems that are not only private, but also accountable and trustworthy in practice.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.