{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T06:24:53Z","timestamp":1774419893618,"version":"3.50.1"},"reference-count":29,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T00:00:00Z","timestamp":1774137600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&amp;D Program of China","doi-asserted-by":"publisher","award":["2023YFC3305501"],"award-info":[{"award-number":["2023YFC3305501"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>We present the first secure multiplicative aggregation protocol as a variant of secure aggregation. In this case, a server can compute the component-wise product of the input vectors of users while handling the possible dropout of users during protocol execution. Using pairwise masks, threshold secret sharing and the secure aggregation protocol itself, our construction is correct and secure against semi-honest adversaries. We also consider secure aggregation protocols for the case in which fixed users can reuse their private keys to do aggregation many times, and we propose key reusable secure aggregation protocols. Our protocols have an overhead polynomial in the number of users. We conduct a comprehensive evaluation of our proposed protocols. For multiplicative aggregation protocol, experiments varying the number of users (K) from 50 to 300 (with fixed input size Xu=100 KB) demonstrate that user computation scales monotonically with K and is largely insensitive to dropout rates. In contrast, server computation is highly dropout-sensitive and exhibits a steeper growth rate with respect to K. When varying the input size (10\u2013250 KB) with a fixed K, both user and server communication overheads increase linearly, while server computation remains the primary bottleneck affected by dropouts. We compare reusable and non-reusable secure aggregation protocol over repeated interactions q\u2208{1,\u2026,10} at Xu=100 KB and K=100, showing that reusing Round 1 reduces the cumulative user computation time by about 2.5 times and reduces the cumulative server computation overhead by about 1.2 times at q=10 while leaving the server communication overhead nearly unchanged, which indicates that the overall communication overhead is dominated by the non-reused rounds.<\/jats:p>","DOI":"10.3390\/e28030358","type":"journal-article","created":{"date-parts":[[2026,3,23]],"date-time":"2026-03-23T11:59:36Z","timestamp":1774267176000},"page":"358","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Secure Multiplicative Aggregation and Key-Reuse Optimization: Achieving Dropout Resilience with Amortized Efficiency"],"prefix":"10.3390","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1226-8545","authenticated-orcid":false,"given":"Hongyuan","family":"Cai","sequence":"first","affiliation":[{"name":"Department of Mathematical Sciences, Tsinghua University, Beijing 100084, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8622-8596","authenticated-orcid":false,"given":"Bei","family":"Liang","sequence":"additional","affiliation":[{"name":"Beijing Institute of Mathematical Sciences and Applications, Beijing 101408, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3593-9902","authenticated-orcid":false,"given":"Yue","family":"Qin","sequence":"additional","affiliation":[{"name":"Beijing Institute of Mathematical Sciences and Applications, Beijing 101408, China"},{"name":"School of Cyber Science and Technology, Beihang University, Beijing 100191, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1257-7598","authenticated-orcid":false,"given":"Jintai","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Mathematics and Physics, Xi\u2019an Jiaotong-Liverpool University, Suzhou 215123, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,3,22]]},"reference":[{"key":"ref_1","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H.B., Patel, S., Ramage, D., Segal, A., and Seth, K. (2016). Practical secure aggregation for federated learning on user-held data. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Yao, A.C.C. (1986). How to generate and exchange secrets. Proceedings of the 27th Annual Symposium on Foundations of Computer Science (Sfcs 1986), IEEE.","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"612","DOI":"10.1145\/359168.359176","article-title":"How to share a secret","volume":"22","author":"Shamir","year":"1979","journal-title":"Commun. ACM"},{"key":"ref_4","unstructured":"Ben-Or, M., Goldwasser, S., and Wigderson, A. (2019). Completeness theorems for non-cryptographic fault-tolerant distributed computation. Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, ACM."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Goldreich, O., Micali, S., and Wigderson, A. (2019). How to play any mental game, or a completeness theorem for protocols with honest majority. Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, ACM.","DOI":"10.1145\/3335741.3335759"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Nielsen, J.B., Nordholt, P.S., Orlandi, C., and Burra, S.S. (2012). A new approach to practical active-secure two-party computation. Proceedings of the Annual Cryptology Conference, Springer.","DOI":"10.1007\/978-3-642-32009-5_40"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Damg\u00e5rd, I., Pastro, V., Smart, N., and Zakarias, S. (2012). Multiparty computation from somewhat homomorphic encryption. Proceedings of the Annual Cryptology Conference, Springer.","DOI":"10.1007\/978-3-642-32009-5_38"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Beaver, D., Micali, S., and Rogaway, P. (1990). The round complexity of secure protocols. Proceedings of the Twenty-Second Annual ACM Symposium on Theory of Computing, ACM.","DOI":"10.1145\/100216.100287"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Beerliov\u00e1-Trub\u00edniov\u00e1, Z., and Hirt, M. (2008). Perfectly-secure MPC with linear communication complexity. Proceedings of the Theory of Cryptography Conference, Springer.","DOI":"10.1007\/978-3-540-78524-8_13"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Joye, M., and Libert, B. (2013). A scalable scheme for privacy-preserving aggregation of time-series data. Proceedings of the International Conference on Financial Cryptography and Data Security, Springer.","DOI":"10.1007\/978-3-642-39884-1_10"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Leontiadis, I., Elkhiyaoui, K., and Molva, R. (2014). Private and dynamic time-series data aggregation with trust relaxation. Proceedings of the International Conference on Cryptology and Network Security, Springer.","DOI":"10.1007\/978-3-319-12280-9_20"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Halevi, S., Lindell, Y., and Pinkas, B. (2011). Secure computation on the web: Computing without simultaneous interaction. Proceedings of the Annual Cryptology Conference, Springer.","DOI":"10.1007\/978-3-642-22792-9_8"},{"key":"ref_13","unstructured":"Gentry, C. (2009). A Fully Homomorphic Encryption Scheme, Stanford University."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. Proceedings of the Theory of Cryptography Conference, Springer.","DOI":"10.1007\/11681878_14"},{"key":"ref_15","unstructured":"McMahan, H.B., Ramage, D., Talwar, K., and Zhang, L. (2018, January 24\u201328). Learning Differentially Private Recurrent Language Models. Proceedings of the International Conference on Learning Representations, Singapore."},{"key":"ref_16","unstructured":"Geyer, R.C., Klein, T., and Nabi, M. (2017). Differentially private federated learning: A client level perspective. arXiv."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"3454","DOI":"10.1109\/TIFS.2020.2988575","article-title":"Federated learning with differential privacy: Algorithms and performance analysis","volume":"15","author":"Wei","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_18","unstructured":"Shi, E., Chan, T.H.H., Rieffel, E., Chow, R., and Song, D. (2011). Privacy-Preserving Aggregation of Time-Series Data. Annual Network and Distributed System Security Symposium, Internet Society."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Chan, T.H.H., Shi, E., and Song, D. (2012). Privacy-preserving stream aggregation with fault tolerance. Proceedings of the International Conference on Financial Cryptography and Data Security, Springer.","DOI":"10.1007\/978-3-642-32946-3_15"},{"key":"ref_20","unstructured":"Corrigan-Gibbs, H., Wolinsky, D.I., and Ford, B. (2013). Proactively accountable anonymous messaging in verdict. Proceedings of the 22nd USENIX Security Symposium (USENIX Security 13), European Commission."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kwon, Y.H. (2015). Riffle: An efficient communication system with strong anonymity. Proceedings on Privacy Enhancing Technologies, Walter de Gruyter GmbH.","DOI":"10.1515\/popets-2016-0008"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"\u00c1cs, G., and Castelluccia, C. (2011). I have a dream!(differentially private smart metering). Proceedings of the International Workshop on Information Hiding, Springer.","DOI":"10.1007\/978-3-642-24178-9_9"},{"key":"ref_23","unstructured":"Diffie, W., and Hellman, M.E. (2019). New directions in cryptography. Secure Communications and Asymmetric Cryptosystems, Routledge."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H.B., Patel, S., Ramage, D., Segal, A., and Seth, K. (2017). Practical secure aggregation for privacy-preserving machine learning. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, ACM.","DOI":"10.1145\/3133956.3133982"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1109\/JSAIT.2021.3054610","article-title":"Turbo-aggregate: Breaking the quadratic aggregation barrier in secure federated learning","volume":"2","author":"So","year":"2021","journal-title":"IEEE J. Sel. Areas Inf. Theory"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Bell, J.H., Bonawitz, K.A., Gasc\u00f3n, A., Lepoint, T., and Raykova, M. (2020). Secure single-server aggregation with (poly) logarithmic overhead. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, ACM.","DOI":"10.1145\/3372297.3417885"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Boneh, D., and Franklin, M. (2001). Identity-based encryption from the Weil pairing. Proceedings of the Annual International Cryptology Conference, Springer.","DOI":"10.1007\/3-540-44647-8_13"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Bellare, M., and Namprempre, C. (2000). Authenticated encryption: Relations among notions and analysis of the generic composition paradigm. Proceedings of the International Conference on the Theory and Application of Cryptology and Information Security, Springer.","DOI":"10.1007\/3-540-44448-3_41"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"850","DOI":"10.1137\/0213053","article-title":"How to generate cryptographically strong sequences of pseudorandom bits","volume":"13","author":"Blum","year":"1984","journal-title":"SIAM J. Comput."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/358\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T05:25:16Z","timestamp":1774416316000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/358"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,22]]},"references-count":29,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,3]]}},"alternative-id":["e28030358"],"URL":"https:\/\/doi.org\/10.3390\/e28030358","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,22]]}}}