arXiv:2511.12663cs.LGcs.AI2025-11

为联邦学习设计可视觉验证的防冲突水印框架,保护多方模型产权。

FLClear: Visually Verifiable Multi-Client Watermarking for Federated Learning

  • 通过对比学习联合优化反向模型实现无冲突水印聚合。
  • 水印可视觉还原并用相似度量化验证,支持直观所有权认定。
  • 在多种攻击场景下优于现有方法,适合多客户端协作场景。

联邦学习允许多个客户端在不共享本地数据的前提下协同训练全局模型,但中央服务器可能恶意篡改模型以抹除客户端贡献或窃取知识产权。水印技术成为保护模型产权的重要手段,但现有方法存在水印冲突、安全性不足和验证不直观等问题。本文提出FLClear框架,实现无冲突水印聚合、增强水印安全性和可视觉验证的产权确认。该框架引入与主任务联合优化的反向模型,通过对比学习融合水印与任务目标;验证时从反向模型重构水印,结合视觉检查与结构相似性指标,实现定性与定量双重验证。在多种数据集、聚合策略和攻击场景下的实验表明,FLClear显著优于当前最优方法。

原文摘要 · Abstract (English)

Federated learning (FL) enables multiple clients to collaboratively train a shared global model while preserving the privacy of their local data. Within this paradigm, the intellectual property rights (IPR) of client models are critical assets that must be protected. In practice, the central server responsible for maintaining the global model may maliciously manipulate the global model to erase client contributions or falsely claim sole ownership, thereby infringing on clients' IPR. Watermarking has emerged as a promising technique for asserting model ownership and protecting intellectual property. However, existing FL watermarking approaches remain limited, suffering from potential watermark collisions among clients, insufficient watermark security, and non-intuitive verification mechanisms. In this paper, we propose FLClear, a novel framework that simultaneously achieves collision-free watermark aggregation, enhanced watermark security, and visually interpretable ownership verification. Specifically, FLClear introduces a transposed model jointly optimized with contrastive learning to integrate the watermarking and main task objectives. During verification, the watermark is reconstructed from the transposed model and evaluated through both visual inspection and structural similarity metrics, enabling intuitive and quantitative ownership verification. Comprehensive experiments conducted over various datasets, aggregation schemes, and attack scenarios demonstrate the effectiveness of FLClear and confirm that it consistently outperforms state-of-the-art FL watermarking methods.

联邦学习模型水印产权保护视觉验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。