Backend-agnostic via the decrypt() generic, but part of the
frozen Paillier-era legacy surface: the random-offset chain idiom
compensated for Paillier-era trust assumptions, and it encrypts each
site's value at the master, which the supported topology
deliberately does not. The supported pattern is master_aggregate().
Arguments
- master
a Master, wired to a chain via
round_robin_chain().- theta
the current parameter value (passed through to each worker's
contribution_fn).
Details
The master generates a random real offset, encrypts it under its public key, and sends it around the chain. Each worker site adds its encrypted local summary to the running total and forwards. On return, the master decrypts the running total, subtracts the offset in the clear, and returns the resulting scalar.
If any worker's contribution_fn returns NA, the chain stops and this
function returns NA_real_.
