为分割联邦学习设计双向水印方案,保护客户端与服务器的模型产权。
Robust Client-Server Watermarking for Split Federated Learning
- 服务器用特征水印,客户端用后门水印,双端协同验证所有权。
- 在多个模型和数据集上水印检测率超95%,且对移除攻击鲁棒。
- 适合需要多方协作又担心模型被窃的联邦学习场景使用。
分割联邦学习(SFL)因其隐私保护性和低计算开销,在去中心化机器学习中备受关注。在该框架下,客户端使用轻量模型本地处理私有数据,并将中间输出发送至强大服务器进行后续计算。然而,SFL是一把双刃剑:虽支持边缘计算并增强隐私,但也因客户端与服务器共同参与训练,导致知识产权归属模糊。现有水印技术无法同时保护双方,因任一参与者均不掌握完整模型。为此,我们提出RISE——一种针对SFL的鲁棒模型知识产权保护方案,采用客户端-服务器水印嵌入机制。具体而言,服务器通过损失正则项嵌入基于特征的水印,客户端则通过向私有数据集中注入预定义触发样本实现基于后门的水印嵌入。该协同嵌入策略使双方均可验证模型所有权。在标准数据集和多种网络架构上的实验表明,RISE在多数设置下水印检测率超过95%(p值 < 0.03),客户端与服务器水印无相互干扰,且对常见移除攻击具有鲁棒性。
原文摘要 · Abstract (English)
Split Federated Learning (SFL) is renowned for its privacy-preserving nature and low computational overhead among decentralized machine learning paradigms. In this framework, clients employ lightweight models to process private data locally and transmit intermediate outputs to a powerful server for further computation. However, SFL is a double-edged sword: while it enables edge computing and enhances privacy, it also introduces intellectual property ambiguity as both clients and the server jointly contribute to training. Existing watermarking techniques fail to protect both sides since no single participant possesses the complete model. To address this, we propose RISE, a Robust model Intellectual property protection scheme using client-Server watermark Embedding for SFL. Specifically, RISE adopts an asymmetric client-server watermarking design: the server embeds feature-based watermarks through a loss regularization term, while clients embed backdoor-based watermarks by injecting predefined trigger samples into private datasets. This co-embedding strategy enables both clients and the server to verify model ownership. Experimental results on standard datasets and multiple network architectures show that RISE achieves over $95\%$ watermark detection rate ($p-value \lt 0.03$) across most settings. It exhibits no mutual interference between client- and server-side watermarks and remains robust against common removal attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。