arXiv:2511.14422cs.CRcs.AI2025-11

为隐私保护的联邦学习设计强制水印,防止模型被盗。

Sigil: Server-Enforced Watermarking in U-Shaped Split Federated Learning via Gradient Injection

  • 用梯度注入在客户端嵌入水印,无需数据知识。
  • 水印通过激活空间统计约束实现,服务器可验证且不可移除。
  • 对抗检测和攻击,适合资源受限但需防窃的服务器场景。

在去中心化机器学习范式如分片联邦学习(SFL)及其变体U型SFL中,服务器能力严重受限。尽管这增强了客户端隐私,但也使服务器极易遭受恶意客户端的模型盗用。对这类能力受限的服务器而言,确保知识产权保护面临双重挑战:依赖客户端合作的水印方案在对抗性环境下不可靠;而传统服务器端水印方案因服务器无法访问模型参数或标签等关键元素而技术上不可行。为此,本文提出Sigil,一种专为能力受限服务器设计的强制水印框架。Sigil将水印定义为服务器可见激活空间上的统计约束,并通过梯度注入将水印嵌入客户端模型,无需任何数据知识。此外,我们设计了一种自适应梯度裁剪机制,确保水印过程兼具强制性与隐蔽性,有效抵御现有的梯度异常检测方法及专门设计的自适应子空间移除攻击。在多个数据集和模型上的大量实验表明,Sigil具有高保真度、强鲁棒性和良好隐蔽性。

原文摘要 · Abstract (English)

In decentralized machine learning paradigms such as Split Federated Learning (SFL) and its variant U-shaped SFL, the server's capabilities are severely restricted. Although this enhances client-side privacy, it also leaves the server highly vulnerable to model theft by malicious clients. Ensuring intellectual property protection for such capability-limited servers presents a dual challenge: watermarking schemes that depend on client cooperation are unreliable in adversarial settings, whereas traditional server-side watermarking schemes are technically infeasible because the server lacks access to critical elements such as model parameters or labels. To address this challenge, this paper proposes Sigil, a mandatory watermarking framework designed specifically for capability-limited servers. Sigil defines the watermark as a statistical constraint on the server-visible activation space and embeds the watermark into the client model via gradient injection, without requiring any knowledge of the data. Besides, we design an adaptive gradient clipping mechanism to ensure that our watermarking process remains both mandatory and stealthy, effectively countering existing gradient anomaly detection methods and a specifically designed adaptive subspace removal attack. Extensive experiments on multiple datasets and models demonstrate Sigil's fidelity, robustness, and stealthiness.

联邦学习水印隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。