Return
Encoder-decoder based watermarking for federated learning models
DOI:10.1016/j.future.2025.108175.png)
Abstract
En 中文
Federated learning, as a significant branch of deep learning, addresses issues related to data silos, data privacy, security, and communication bandwidth. In terms of intellectual property, it faces similar challenges as deep neural networks, namely vulnerabilities in protecting model ownership. Currently, some protection schemes are available, but existing federated learning protection schemes lack concealment in embedded watermark information, failing to ensure high robustness and security. Moreover, after embedding a large amount of watermark information, the impact on model performance cannot be guaranteed. Therefore, this paper proposes a novel federated learning protection framework consisting of three steps: watermark information generation, embedding, and ownership detection. In the generation of watermark information, an encoder-decoder structure is used for embedding. For embedding watermark information, a threshold processing method is employed to embed watermarks simultaneously in convolutional layers and BN layers. Experimental results show that the use of an encoder-decoder structure ensures high robustness, security, and concealment. It also allows for embedding a large amount of watermark information with minimal impact on the model’s original task, as the accuracy only decreases by 1.16% after embedding watermark information in four types of models. In addition, it exhibits high robustness against various common attacks, including fine-tuning, pruning, and equivalent attacks.
Journal
F
IF:
0
Papers:
642
Citations:
0

