Kuscia: A Decentralized Framework to Alleviate User Burden and Security Concerns in Secure Collaborative Computing

Zhengyan Zhou , Mingyang Jia , Xiaolong Hu , Shilei Guo , Yue Zhao , HaoLin Huang , Zhiming Xu , Linchuan Li , Jin Tan , Dongwen Hu , Lei Wang , Lingfei Cheng , Haifeng Zhou , Chunming Wu

Engineering ›› : 202608014

PDF (2335KB)
Engineering ›› :202608014 DOI: 10.1016/j.eng.2026.08.014
research-article
Kuscia: A Decentralized Framework to Alleviate User Burden and Security Concerns in Secure Collaborative Computing
Author information +
History +
PDF (2335KB)

Abstract

Secure collaborative computing (SCC) enables the sharing of sensitive data across untrusted domains while preserving privacy. However, developing or deploying an SCC system poses significant challenges. First, users face substantial burdens due to infrastructure heterogeneity, domain-specific programming, and cross-domain interconnection. Second, users lose control over the cooperation process between untrusted domains, raising security concerns. In this paper, we propose Kuscia, a decentralized framework that does not rely on any centralized entity, to alleviate these burdens and concerns through the swift orchestration of SCC and readily available security guarantees. The main characteristics of Kuscia are as follows: ① Kuscia is a decentralized architecture that allows each domain to maintain its administrative boundaries during cross-domain cooperation. ② It decentralizes the components, computation, and networking with unified abstractions, thereby enabling seamless deployment, cooperation, and interconnection across domains. ③ It designs a universal cross-domain protocol, which safeguards against domain impersonation, data misuse, and computation misbehaviors. Deployed in over 40 companies and 600 institutions, Kuscia has demonstrated its ability to reduce user efforts to develop an SCC program from months to just a few days and to alleviate security concerns, with an average additional execution time overhead of only 8.4%.

Keywords

Secure collaborative computing / Decentralized framework / Privacy-preserving machine learning / Cross-domain security

Cite this article

Download citation ▾
Zhengyan Zhou, Mingyang Jia, Xiaolong Hu, Shilei Guo, Yue Zhao, HaoLin Huang, Zhiming Xu, Linchuan Li, Jin Tan, Dongwen Hu, Lei Wang, Lingfei Cheng, Haifeng Zhou, Chunming Wu. Kuscia: A Decentralized Framework to Alleviate User Burden and Security Concerns in Secure Collaborative Computing. Engineering 202608014 DOI:10.1016/j.eng.2026.08.014

登录浏览全文

4963

注册一个新账户 忘记密码

References

[1]

Lécuyer M, Duquesne S, Henry R, Mocanu R, Pierre S, Pratt F, et al. Privacy accounting and quality control in the sage differentially private ml platform. In: Proceedings of the 2019 ACM SIGOPS International Symposium on Operating Systems Principles; 2019 Oct 27—30; Huntsville, AL, USA. New York City: ACM; 2019. p. 187-203.

[2]

Luo T, Chen Y, Li P, Wang C, Zhang H, Liu X . Privacy budget scheduling. In: Proceedings of the 15th USENIX Symposium on Operating Systems Design and Implementation; 2021 Jul 14—16; online. Berkeley: USENIX Association; 2021. p. 1121—38.

[3]

Zhou J, Li Z, Zhao H, Wang J, Zheng B, Xu X, et al. Kunpeng: parameter server based distributed learning systems and its applications in Alibaba and ant financial. In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining; 2017 Aug 13—17; Halifax, QC, Canada. New York City: ACM; 2017. p. 1693-702.

[4]

Goldman E. An introduction to the California consumer privacy act (CCPA). In: Santa Clara University legal studies research paper series 2020. Santa Clara: Santa Clara University; 2020.

[5]

Goddard M . The EU general data protection regulation (GDPR): European regulation that has a global impact. Int J Mark Res 2017; 59(6):703—5.

[6]

Al—Rubaie M, Chang JM . Privacy—preserving machine learning: threats and solutions. IEEE Secur Priv 2019; 17(2):49-58.

[7]

Huang Z, Ju L, Li J, Wang H, Zhang X . Cheetah: lean and fast secure two—party deep neural network inference. In: Proceedings of the 31st USENIX Security Symposium; 2022 Aug 10—12; Boston, MA, USA. Berkeley: USENIX Association; 2022. p. 809-26.

[8]

Juvekar C, Vaikuntanathan V, Chandrakasan A . Gazelle: a low latency framework for secure neural network inference. In: Proceedings of the 27th USENIX Security Symposium; 2018 Aug 15—17; Baltimore, MD, USA. Berkeley: USENIX Association; 2018. p. 1651—69.

[9]

Kumar N, Rathee M, Chandran N, Gupta D, Rastogi A, Sharma R . Cryptflow: secure tensorflow inference. In: Proceedings of the 2020 IEEE Symposium on Security and Privacy; 2020 May 18—21; San Francisco, CA, USA. New York City: IEEE; 2020. p. 336-53.

[10]

Mohassel P, Rindal P . Aby3: a mixed protocol framework for machine learning. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security; 2018 Oct 15—19; Toronto, ON, Canada. New York City: ACM;2018. p. 35-52.

[11]

Mohassel P, Zhang Y . Secureml: a system for scalable privacy—preserving machine learning. In: Proceedings of the 2017 IEEE Symposium on Security and Privacy; 2017 May 22—24; San Jose, CA, USA. New York City: IEEE; 2017. p. 19-38.

[12]

Quoc DL, Schindler P, Schubotz R, May T, Beck M . Securetf: a secure tensorflow framework. In: Proceedings of the 21st International Middleware Conference; 2020 Dec 7—11; online. New York City: ACM; 2020. p. 44-59.

[13]

Riazi MS, Weinstein O, Horst F, Sadeghi AR, Koushanfar F . Chameleon: a hybrid secure computation framework for machine learning applications. In: Proceedings of the 13th ACM Asia Conference on Computer and Communications Security; 2018 May 29—Jun 1; Incheon, Republic of Korea. New York City: ACM; 2018. p. 707—21.

[14]

Wagh S, Gupta D, Chandran N . SecureNN: 3—party secure computation for neural network training. Proc Priv Enhancing Technol 2019; 2019(3):26-49.

[15]

Wagh S, Rathee M, Gupta D, Chandran N . Falcon: honest—majority maliciously secure framework for private deep learning. 2020. arXiv:2004.02229.

[16]

Lindell Y. Secure multiparty computation. Commun ACM 2021; 64(1):86-96.

[17]

Liu Y, Fan T, Chen T, Xu Q, Yang C, Zou L, et al. Fate: an industrial grade platform for collaborative learning with data protection. J Mach Learn Res 2021; 22(226):1-6.

[18]

Chandran N, Gupta D, Rastogi A, Sharma R, Rathee M . Ezpc: programmable and efficient secure two—party computation for machine learning. In: Proceedings of the 2019 IEEE European Symposium on Security and Privacy; 2019 Jun 17—19; Stockholm, Sweden. New York City: IEEE; 2019. p. 496-511.

[19]

Dahl M, Riazi MS, Kantarcioglu M, Koushanfar F, Sadeghi AR . Private machine learning in TensorFlow using secure computation. 2018. arXiv:1810.08130.

[20]

Demmler D, Schneider T, Zohner M . Aby—a framework for efficient mixed—protocol secure two—party computation. In: Proceedings of the 22nd Network and Distributed System Security Symposium; 2015 Feb 8—11; San Diego, CA, USA. Reston: Internet Society; 2015. p. 1-15.

[21]

Hastings M, Hemenway B, Noble D, Zdancewic S . Sok: general purpose compilers for secure multi—party computation. In: Proceedings of the 2019 IEEE Symposium on Security and Privacy; 2019 May 13—15; San Francisco, CA, USA. New York City: IEEE; 2019. p. 1220-37.

[22]

Keller M. Mp—spdz: a versatile framework for multi—party computation. In: Proceedings of the 27th ACM SIGSAC Conference on Computer and Communications Security; 2020 Nov 9—13; Orlando, FL, USA. New York City: ACM; 2020. p. 1575-90.

[23]

Knott B, Venkatraman S, Hannun A, Srinivasan M, Ng A, Shoeb A, Puri R . Crypten: secure multi—party computation meets machine learning. Adv Neural Inf Process Syst 2021; 34:4961-73.

[24]

Ma J, Zhang K, Wang L, Yu Y, Fang W, Cao S, Hua G . Secretflow—spu: a performant and user—friendly framework for privacy—preserving machine learning. In: Proceedings of the 2023 USENIX Annual Technical Conference; 2023 Jul 10—14; Boston, MA, USA. Berkeley: USENIX Association; 2023. p. 17-33.

[25]

Abadi M, Agarwal A, Barham P, Brevdo E, Chen Z, Citro C, et al. Tensorflow: a system for large—scale machine learning. In: Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation; 2016 Nov 2—4; Savannah, GA, USA. Berkeley: USENIX Association; 2016. p. 265-83.

[26]

Paszke A, Gross S, Massa F, Lerer A, Bradbury J, Chanan G, et al. Automatic differentiation in PyTorch. In: Proceedings of the 31st Conference on Neural Information Processing Systems; 2017 Dec 4—9; Long Beach, CA, USA. Red Hook: Curran Associates; 2017. p. 8024—35.

[27]

Fang W, Cao S, Hua G, Ma J, Yu Y, Huang Q, et al. SecretFlow—SCQL: a secure collaborative query platform. Proc VLDB Endow 2024; 17(12):3987-4000.

[28]

SecretFlow Development Team . SecretFlow—serving is a serving system for privacy—preserving machine learning models [Internet]. Undated:Secretflow; [cited 2026 Jul 19]. Available from:https://github.com/secretflow/serving.

[29]

Kaviani D, Naseer M, Zhang Y, Zhou T, Chen L . Flock: a framework for deploying on—demand distributed trust. In: Proceedings of the 18th USENIX Symposium on Operating Systems Design and Implementation; 2024 Jul 10—12; Santa Clara, CA, USA. Berkeley: USENIX Association; 2024. p. 743-59.

[30]

Baudet M, Ching A, Chursin A, Danezis G, Garillot F, Ghosh S, et al. State machine replication in the libra blockchain. Report. Geneva: The Diem Association; 2019.

[31]

Proton Mail . Proton mail official website [Internet]. Geneva: Proton AG; [cited2026 Jul 19]. Available from:https://proton.me/.

[32]

Telegram FZ—LLC. Telegram official website [Internet]. Dubai:Telegram FZ—LLC ; [cited 2026 Jul 19]. Available from:https://telegram.org/.

[33]

WhatsApp LLC . WhatsApp official website [Internet]. Menlo Park: Meta Platforms, Inc.; [cited2026 Jul 19]. Available from:https://www.whatsapp.com/.

[34]

Zoom Video Communications, Inc. Zoom official website [Internet]. San Jose:Zoom Video Communications, Inc. ; [cited 2026 Jul 19]. Available from:https://zoom.us/.

[35]

Buterin V . A next—generation smart contract and decentralized application platform [Internet]. Zeughausgasse: ethereum.org;2016 Jul 16 [cited 2026 Jul 19]. Available from:https://ethereum.org/whitepaper/.

[36]

Nakamoto S. Bitcoin: a peer—to—peer electronic cash system [Internet].Metzdowd: Satoshi Nakamoto; 2008 Nov 1 [cited 2026 Jul 19]. Available from:https://bitcoin.org/en/bitcoin—paper.

[37]

Google LLC. A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp—bpf syscall filters [Internet]. Mountain View:Google LLC ; 2025 May [cited 2026 Jul 19]. Available from:https://github.com/google/nsjail.

[38]

Kata Containers Community . Kata containers is an open source project and community working to build a standard implementation of lightweight virtual machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs [Internet]. Austin: OpenStack Foundation; [cited2026 Jul 19]. Available from:https://github.com/kata—containers/kata—containers.

[39]

Kairouz P, McMahan HB, Avent B, Bellet A, Bennis M, Bhagoji AN, et al. Advances and open problems in federated learning. Found Trends Mach Learn 2021; 14(1—2):1—210.

[40]

Skupper Project Team . Skupper is an implementation of a virtual application network, enabling rich hybrid cloud communication [Internet]. Raleigh: Red Hat, Inc.; [cited2026 Jul 19]. Available from:https://github.com/skupperproject/skupper.

[41]

Cloud Native Computing Foundation (CNCF) . Kubernetes native edge computing framework (project under CNCF) [Internet]. San Francisco: Cloud Native Computing Foundation; [cited2026 Jul 19]. Available from:https://github.com/kubeedge/kubeedge.

[42]

Brooker M, Cook R, Li T, Miller C, Ruan J, Voss A . On—demand container loading in AWS lambda. In: Proceedings of the 2023 USENIX Annual Technical Conference; 2023 Jul 10—14; Boston, MA, USA. Berkeley: USENIX Association; 2023. p. 315—28.

[43]

Manco F, Costa C, Munez F, Tulip J, Schiavoni V, Santos J, et al. My VM is lighter (and safer) than your container. In: Proceedings of the 26th ACM SIGOPS International Symposium on Operating Systems Principles; 2017 Oct 27—30; Huntsville, AL, USA. New York City: ACM; 2017. p. 218-33.

[44]

Khalid J, Rozner E, Sauer J, Waechtler A, Mogul J, Vahdat A . Iron: isolating network—based CPU in container environments. In: Proceedings of the 15th USENIX Symposium on Networked Systems Design and Implementation; 2018 Apr 16—18; Renton, WA, USA. Berkeley: USENIX Association; 2018. p. 313—28.

[45]

Shen Z, Sun Z, Huang H, Li Z, Jin H, Zhang X . X—containers: breaking down barriers to improve performance and isolation of cloud—native containers. In: Proceedings of the 24th International Conference on Architectural Support for Programming Languages and Operating Systems; 2019 Apr 13—17; Providence, RI, USA. New York City: ACM; 2019. p. 121—35.

[46]

Chen JL, Zhang Y, Chen H, Wang L, Xu M . Starlight: fast container provisioning on the edge and over the WAN. In: Proceedings of the 19th USENIX Symposium on Networked Systems Design and Implementation; 2022 Apr 4—6; Renton, WA, USA. Berkeley: USENIX Association; 2022. p. 35-50.

[47]

Qiao A, Yu H, Li M, Zhang H, Wu J, Zhang W . Pollux: co—adaptive cluster scheduling for goodput—optimized deep learning. In: Proceedings of the 15th USENIX Symposium on Operating Systems Design and Implementation; 2021 Jul 14—16; held virtually. Berkeley: USENIX Association; 2021. p. 301-6.

[48]

Zhao Y, Li J, Li Z, Zhang Y, Liu X, Yang G . Multi—resource interleaving for deep learning training. In: Proceedings of the 2022 ACM SIGCOMM Conference; 2022 Aug 22—26; Amsterdam, The Netherlands. New York City: ACM; 2022. p. 428—40.

[49]

Mohan J, Phanishayee A, Kulkarni S, Thekkath C . Looking beyond GPUS for DNN scheduling on multi—tenant clusters. In: Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation; 2022 Jul 11—13; Carlsbad, CA, USA. Berkeley: USENIX Association; 2022. p. 579-96.

[50]

Xiao W, Bhardwaj R, Ramjee R, Shin M, Srivatsa M, Wang L, et al. Gandiva: introspective cluster scheduling for deep learning. In: Proceedings of the 13th USENIX Symposium on Operating Systems Design and Implementation; 2018 Jul 10—12; Carlsbad, CA, USA. Berkeley: USENIX Association; 2018. p. 595-610.

[51]

Mahajan K, Prakash D, Thakkar A, Choudhary V, Sahu S . Themis: fair and efficient GPU cluster scheduling. In: Proceedings of the 17th USENIX Symposium on Networked Systems Design and Implementation; 2020 Feb 25—26; Santa Clara, CA, USA. Berkeley: USENIX Association; 2020. p. 289-304.

[52]

Bhardwaj R, Ghosh T, Tandon A, Choudhary V, Srivatsa M . Cilantro: performance—aware resource allocation for general objectives via online feedback. In: Proceedings of the 17th USENIX Symposium on Operating Systems Design and Implementation; 2023 Jul 10—14; Boston, MA, USA. Berkeley: USENIX Association; 2023. p. 623-43.

[53]

Grandl R, Kandula S, Rao S, Akella A . Altruistic scheduling in multi—resource clusters. In: Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation; 2016 Nov 2—4; Savannah, GA, USA. Berkeley: USENIX Association; 2016. p. 65-80.

[54]

Ghodsi A, Zaharia M, Hindman B, Konwinski A, Shenker S, Stoica I . Dominant resource fairness: fair allocation of multiple resource types. In: Proceedings of the 8th USENIX Symposium on Networked Systems Design and Implementation; 2011 Mar 30—Apr 1; Boston, MA, USA. Berkeley: USENIX Association; 2011. p. 29-42.

[55]

Vuppalapati M, Suresh L, Venkataraman S, Ghodsi A . Karma: resource allocation for dynamic demands. In: Proceedings of the 17th USENIX Symposium on Operating Systems Design and Implementation; 2023 Jul 10—14; Boston, MA, USA. Berkeley: USENIX Association; 2023. p. 645—62.

[56]

Poddar R, Tiwari R, Shah A, Srinivasan S, Chandra R . SafeBricks: shielding network functions in the cloud. In: Proceedings of the 15th USENIX Symposium on Networked Systems Design and Implementation; 2018 Apr 16—18; Renton, WA, USA. Berkeley: USENIX Association; 2018. p. 201-16.

[57]

Trach B, Krohmer A, Frassetto T, Jauernig P, Sasse R, Strufe T . ShieldBox: secure middleboxes using shielded execution. In: Proceedings of the ACM Symposium on Software Defined Networking Research; 2018 Aug 24; Budapest, Hungary. New York City: ACM; 2018. p. 1-14.

[58]

Wang H, Li X, Wang Y, Zhao Y, Yu Y, Yang H, et al. SICS: secure and dynamic middlebox outsourcing. IEEE/ACM Trans Netw 2020; 28(6):2713—26.

[59]

Schwarz F, Rossow C . Seng, the SGX—enforcing network gateway: authorizing communication from shielded clients. In: Proceedings of the 29th USENIX Security Symposium; 2020 Aug 12—14; online. Berkeley: USENIX Association; 2020. p. 753—70.

[60]

Lai S, Zhang Y, Li Z, Chen X, Ren K . OblivSketch: oblivious network measurement as a cloud service. In: Proceedings of the 28th Network and Distributed System Security Symposium; 2021 Feb 21—25; online. Reston: Internet Society; 2021. p. 1-18.

[61]

Rancher Labs. K3s: lightweight kubernetes [Internet]. Austin:Rancher Labs ; [cited 2026 Jul 19]. Available from:https://k3s.io.

[62]

Cloud Native Computing Foundation. Kubernetes: production—grade container orchestration [Internet]. San Francisco:Cloud Native Computing Foundation ; [cited 2026 Jul 19]. Available from:https://kubernetes.io/.

[63]

Lyft Inc. Envoy, an open source edge and service proxy, designed for cloud—native applications [Internet]. San Francisco:Cloud Native Computing Foundation; [cited 2026 Jul 19]. Available from:https://www.envoyproxy.io.

PDF (2335KB)

0

Accesses

0

Citation

Detail

Sections
Recommended

/