Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
119 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Watermarking in Secure Federated Learning: A Verification Framework Based on Client-Side Backdooring (2211.07138v2)

Published 14 Nov 2022 in cs.CR, cs.AI, and cs.LG

Abstract: Federated learning (FL) allows multiple participants to collaboratively build deep learning (DL) models without directly sharing data. Consequently, the issue of copyright protection in FL becomes important since unreliable participants may gain access to the jointly trained model. Application of homomorphic encryption (HE) in secure FL framework prevents the central server from accessing plaintext models. Thus, it is no longer feasible to embed the watermark at the central server using existing watermarking schemes. In this paper, we propose a novel client-side FL watermarking scheme to tackle the copyright protection issue in secure FL with HE. To our best knowledge, it is the first scheme to embed the watermark to models under the Secure FL environment. We design a black-box watermarking scheme based on client-side backdooring to embed a pre-designed trigger set into an FL model by a gradient-enhanced embedding method. Additionally, we propose a trigger set construction mechanism to ensure the watermark cannot be forged. Experimental results demonstrate that our proposed scheme delivers outstanding protection performance and robustness against various watermark removal attacks and ambiguity attack.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (8)
  1. Wenyuan Yang (35 papers)
  2. Shuo Shao (35 papers)
  3. Yue Yang (146 papers)
  4. Xiyao Liu (9 papers)
  5. Ximeng Liu (45 papers)
  6. Zhihua Xia (21 papers)
  7. Gerald Schaefer (16 papers)
  8. Hui Fang (48 papers)
Citations (15)

Summary

We haven't generated a summary for this paper yet.