
Ali Mahdavi, Sana Aghapour, Azadeh Zamanifar, Amirfarhad Farhadi · Scientific Reports 2026 · 2026
DOI: 10.1038/s41598-026-72021-z
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Secure aggregation (SA) hides individual client updates but usually aggregates a model-sized vector. SketchSA reduces that vector through a shared-coordinate encoder designed for the algebraic interface of SA. A public pseudorandom seed selects the same 10% of model coordinates for every client in a round. Clients clip the selected deltas, encode them as bounded 16-bit fixed-point integers, and submit only the ordered code vector. The server receives their sum and applies inverse-probability decoding. Before clipping and quantization, this decoder is sampling-unbiased; the fixed-size shared mask also avoids index uploads. The raw model-path payload is \(0.1d\times 16\) bits, exactly \(20\times \) smaller than a float32 update. On CIFAR-10, three 80-round runs with 100 Dirichlet-partitioned clients, 10% participation, and a 289K-parameter CNN reached \(64.51\pm 0.81\) % final-round test accuracy at \(20\times \) . Matched FedAvg reached \(66.11\pm 1.95\) % over the same seeds, 42–44. A seed-42 sweep reached 65.15% at \(10\times \) and 63.11% at \(40\times \) ; at a fixed \(20\times \) budget, 12-bit codes reached 64.87%. We prove the shared-coordinate estimator’s mean-squared error, give a generic convergence bound, and state how finite-ring SA security composes with the encoder. We also propose a protected path for LayerNorm deltas and pooled BatchNorm statistics. The evaluation simulates bounded integer aggregation locally in int32 ; networked SA, dropout recovery, and the protected normalization path remain systems work.
No comments yet — start the discussion below.