Protected logistic research path¶
VertiMosaic v0.3 includes one intentionally narrow, executable privacy-enhanced VFL path instead of treating independent privacy primitives as if they automatically secured the full protocol.
The path combines:
- PSI-based entity intersection through a configured
PSIBackend(the optionalOpenMinedPSIBackendis the packaged adapter); - exact ordered entity binding after the intersection, enforced by the model boundary;
- VFL logistic training with all raw feature matrices remaining party-local;
- L2 clipping + Gaussian noise on every active-to-passive residual message through
ClippedGaussianDPBackend; - zCDP composition converted to
(epsilon, delta)for those residual releases.
Example¶
from vertimosaic.privacy import OpenMinedPSIBackend, fit_protected_logistic
run = fit_protected_logistic(
active=bank_party,
active_entity_ids=bank_ids,
passive=[telecom_party, insurance_party],
passive_entity_ids=[telecom_ids, insurance_ids],
psi_backend=OpenMinedPSIBackend(),
clip_l2_norm=1.0,
noise_multiplier=2.0,
seed=42,
model_kwargs={"max_iter": 200, "learning_rate": 0.05},
)
report = run.privacy_report(delta=1e-6)
Install the optional PSI adapter with:
Exact guarantee boundary¶
This is not a generic secure=True switch and must not be described as end-to-end cryptographically secure VFL.
- PSI protects the set-intersection operation according to the selected PSI backend's threat model.
- Ordered entity digests detect accidental row-order mismatch after alignment; hashing is an integrity/correctness check, not PSI.
- Clipped Gaussian accounting covers residual messages routed through the configured backend.
- Passive-to-active logits, model parameters, timing, message sizes, and other protocol metadata are not automatically differentially private.
- The path does not provide malicious-party security, collusion resistance, Byzantine robustness, encrypted model training, or dropout-resilient secure aggregation.
Evaluation requirements¶
Any paper/report using this path should report side-by-side:
- ordinary VFL utility;
- protected-path utility;
- PSI intersection size and coverage;
- number of protected residual releases;
- clipping norm, adjacency definition, noise multiplier, epsilon and delta;
- wall-clock overhead;
- logical communication overhead;
- the same empirical privacy attacks used elsewhere in the repository;
- the exact guarantee-boundary paragraph above or equivalent wording.
The objective is to make the privacy/utility/resource trade-off measurable without expanding the claim beyond the mechanisms actually executed.