arrow
Return

Encoder-decoder based watermarking for federated learning models

delete2025-10-01
delete0
PRE
AI
Y
Yuling Luo
Y
Y.C. Li
X
Xue Ouyang
S
Siyuan Zu
Z
Zhaohui Chen
Q
Qiang Fu
S
Sheng Qin
J
Junxiu Liu
DOI:10.1016/j.future.2025.108175delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Federated learning, as a significant branch of deep learning, addresses issues related to data silos, data privacy, security, and communication bandwidth. In terms of intellectual property, it faces similar challenges as deep neural networks, namely vulnerabilities in protecting model ownership. Currently, some protection schemes are available, but existing federated learning protection schemes lack concealment in embedded watermark information, failing to ensure high robustness and security. Moreover, after embedding a large amount of watermark information, the impact on model performance cannot be guaranteed. Therefore, this paper proposes a novel federated learning protection framework consisting of three steps: watermark information generation, embedding, and ownership detection. In the generation of watermark information, an encoder-decoder structure is used for embedding. For embedding watermark information, a threshold processing method is employed to embed watermarks simultaneously in convolutional layers and BN layers. Experimental results show that the use of an encoder-decoder structure ensures high robustness, security, and concealment. It also allows for embedding a large amount of watermark information with minimal impact on the model’s original task, as the accuracy only decreases by 1.16% after embedding watermark information in four types of models. In addition, it exhibits high robustness against various common attacks, including fine-tuning, pruning, and equivalent attacks.

Journal

F
Future Generation Computer Systems
IF:
0
Papers:
642
Citations:
0

Organization

E
electronic and information engineering
Scholars:
341
Papers: 127
Citations: 1