引用本文:孙友欣,田有亮.联邦学习中分布式水印与抗攻击方案.软件学报,,():1-19
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 272次   下载 155 本文二维码信息
码上扫一扫!
分享到: 微信 更多
联邦学习中分布式水印与抗攻击方案
孙友欣1, 田有亮1,2
1.贵州大学 计算机科学与技术学院(贵州保密学院), 贵州 贵阳 550025;2.贵州大学 大数据与信息工程学院, 贵州 贵阳 550025
摘要:
联邦学习作为一种分布式机器学习方法, 能够在保护用户隐私和数据安全的同时进行模型训练. 然而, 联邦学习多参与方、模型大范围暴露的特点容易造成模型版权泄露问题. 提出一种具有所有权验证、模型泄露追溯和懒惰客户端检测功能的水印方案, 引入了客户端身份标识生成后门水印机制和动态调整聚合权重(federated dynamic weight adjustment , FDWA)算法, 确保每个客户端的水印具有唯一性, 并解决了水印冲突问题, 在显著提高模型保真度和水印触发率的同时具备更好的懒惰客户端检测性能. 实验结果表明, 该方案在提供更完善的保护功能的同时, 能保持模型性能, 显著提高水印触发率, 并有效抵御微调、剪枝、量化和共谋攻击等多种攻击手段, 提高了联邦学习环境的安全性和公平性, 为模型提供有效版权保护.
关键词:  联邦学习  产权保护  后门水印  参数水印  模型聚合
DOI:10.13328/j.cnki.jos.007665
分类号:TP309
基金项目:国家重点研发计划(2025YFB3109800); 国家自然科学基金(62272123); 贵州省高层次创新型人才项目(黔科合平台人才[2020]6008); 贵州省科技计划(黔科合平台人才[2020]5017, 黔科合支撑[2022]一般065, 黔科合支撑[2023]一般371); 贵州省基础研究计划面上项目(黔科合基础MS[2026]208); 贵州省科技创新平台科研项目(黔科合平台CXPTXM[2025]024)
Distributed Watermarking and Anti-attack Scheme in Federated Learning
SUN You-Xin1, TIAN You-Liang1,2
1.College of Computer Science and Technology (Guizhou Confidentiality College), Guizhou University, Guiyang 550025, China;2.College of Big Data and Information Engineering, Guizhou University, Guiyang 550025, China
Abstract:
Federated learning (FL), as a distributed machine learning method, enables model training while protecting user privacy and data security. However, the involvement of multiple parties and the widespread exposure of models in FL can easily lead to copyright leakage. This study proposes a watermarking scheme with ownership verification, model leakage tracing, and lazy client detection. The proposed scheme introduces a client identity-based backdoor watermark generation mechanism and federated dynamic weight adjustment (FDWA) to ensure the uniqueness of each client’s watermark and resolve watermark conflicts. Model fidelity and watermark trigger rates are significantly improved, while also achieving better performance in detecting lazy clients. Experimental results show that the scheme provides more comprehensive protection while maintaining model performance, significantly improves watermark trigger rates, and effectively resists various attacks such as fine-tuning, pruning, quantization, and collusion attacks, thus enhancing the security and fairness of the FL environment and providing effective copyright protection for models.
Key words:  federated learning (FL)  property rights protection  backdoor-based watermark  parameter-based watermark  model aggregation

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: