arXiv:2608.20580cs.CRcs.LG2026-08

为联邦学习设计双层水印与安全聚合方案,防数据泄露和梯度篡改。

Keyed Provenance Watermarking with Complementary Lattice-Based Secure Aggregation for Federated Learning

论文配图:Keyed Provenance Watermarking with Complementary Lattice-Based Secure Aggregation for Federated Learning
图 1 · 摘自论文原文
  • 用物理锚点元数据生成带密钥的水印,防伪造来源
  • 在复合攻击下水印可验证且梯度聚合无隐私暴露
  • 结合后量子安全聚合,适合高安全性场景

联邦学习易受多层级攻击。现有方法各自应对,导致数据泄露、非法重用和恶意梯度篡改风险并存。本文提出融合密钥上下文溯源水印与可验证格基安全聚合的联邦学习框架。数据层采用符合柯克霍夫原则的方案,利用物理锚点元数据(时间、位置、服务器ID)生成上下文溯源令牌,并通过密钥化HMAC-SHA-256变换生成水印载荷,无客户端密钥无法复现。设计FMGAN——基于GAN的鲁棒图像水印框架,通过特征融合模块与Mamba引导的线性注意力机制嵌入该载荷。计算层采用基于RLWE的零知识安全聚合协议(LZKSA),在不暴露私有更新的前提下验证密钥正确性、梯度L2范数边界及余弦相似性约束,保障后量子安全。大量实验验证了两层协同防护在复合攻击下的有效性。据我们所知,这是首个在端到端可信框架中联合评估双层保护的验证工作。

原文摘要 · Abstract (English)

Federated learning (FL) is vulnerable to multi-level attacks. However, existing methods address them separately, leaving FL exposed to data leakage, unauthorized reuse, and malicious gradient manipulation. In this work, we propose an FL framework that couples keyed context-provenance watermarking with verifiable lattice-based secure aggregation of Real-World Anchored Watermarking and Lattice-Based Zero-Knowledge Secure Aggregation. At the data layer, we propose a Kerckhoffs-compliant scheme that utilizes Physical Anchor Metadata (PAM) to ensure data provenance. PAM is defined as a context-provenance token derived from trusted infrastructure data (time, location, and server ID) and then subjected to a keyed HMAC-SHA-256 transformation to produce a watermark payload that cannot be generated without the client's secret key. We further design FMGAN, a GAN-based robust image watermarking framework that embeds this transformed payload using a feature fusion module and a Mamba-guided linear attention mechanism. At the computation layer, we adopt a lattice-based zero-knowledge secure aggregation (LZKSA) protocol that verifies key correctness, L2 norm bounds, and cosine similarity constraints over committed gradients without revealing private updates. The RLWE-based design guarantees post-quantum security. Extensive experiments validate the complementary protection of the two layers under composite attack scenarios. To our knowledge, no prior verification workflow has jointly evaluated both layers in a hybrid, end-to-end trustworthy FL framework.

联邦学习水印技术安全聚合后量子安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。