Return
Backdoor-Based Watermarking in Multi-Client Split Learning
DOI:10.1109/tdsc.2026.3712080.png)
Abstract
En 中文
Split learning (SL) partitions a deep neural network (DNN) into client-side and server-side models, with clients sequentially training the client-side model to reduce local computation. As SL adoption increases, protecting the model’s intellectual property to acknowledge clients’ joint contributions becomes critical. Model watermarking is a promising solution. However, existing schemes, designed for centralized training or adapted from collaborative frameworks, are not applicable to SL, especially in multi-client settings. This is because the sequential training nature of SL introduces three unique challenges: (1) server-side training can erase client-inserted watermarks; (2) shared client-side models allow later clients to overwrite earlier watermarks; and (3) malicious clients can deliberately remove legitimate watermarks. This paper presents the first study on watermarking DNNs in multi-client SL, proposing two methods: MarkSplit for benign environments and MarkSplit+ for adversarial settings with malicious clients. Both leverage a novel watermark sample generation technique named Color-Shape-ID. Specifically, MarkSplit jointly trains main-task and watermark samples within a three-tiered structure (mini-local, local, and global rounds), while MarkSplit+ enhances robustness at the cost of increased resource consumption by dynamically adjusting watermark sample counts per client based on watermark detection accuracy. Experiments demonstrate that both methods maintain high fidelity and robustness, achieving $\sim$98% watermark detection accuracy with only a $\sim$3% main-task accuracy drop on average.
Keywords:
Split learning
model watermarking
malicious manipulation
deep neural network
Journal
IF:
7.5
Papers:
2.4K
Citations:
9.6K
Organization
Cited Papers
No cited papers available

