联邦学习中分布式水印与抗攻击方案
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP309

基金项目:

国家重点研发计划(2025YFB3109800); 国家自然科学基金(62272123); 贵州省高层次创新型人才项目(黔科合平台人才[2020]6008); 贵州省科技计划(黔科合平台人才[2020]5017, 黔科合支撑[2022]一般065, 黔科合支撑[2023]一般371); 贵州省基础研究计划面上项目(黔科合基础MS[2026]208); 贵州省科技创新平台科研项目(黔科合平台CXPTXM[2025]024)


Distributed Watermarking and Anti-attack Scheme in Federated Learning
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    联邦学习作为一种分布式机器学习方法, 能够在保护用户隐私和数据安全的同时进行模型训练. 然而, 联邦学习多参与方、模型大范围暴露的特点容易造成模型版权泄露问题. 提出一种具有所有权验证、模型泄露追溯和懒惰客户端检测功能的水印方案, 引入了客户端身份标识生成后门水印机制和动态调整聚合权重(federated dynamic weight adjustment , FDWA)算法, 确保每个客户端的水印具有唯一性, 并解决了水印冲突问题, 在显著提高模型保真度和水印触发率的同时具备更好的懒惰客户端检测性能. 实验结果表明, 该方案在提供更完善的保护功能的同时, 能保持模型性能, 显著提高水印触发率, 并有效抵御微调、剪枝、量化和共谋攻击等多种攻击手段, 提高了联邦学习环境的安全性和公平性, 为模型提供有效版权保护.

    Abstract:

    Federated learning (FL), as a distributed machine learning method, enables model training while protecting user privacy and data security. However, the involvement of multiple parties and the widespread exposure of models in FL can easily lead to copyright leakage. This study proposes a watermarking scheme with ownership verification, model leakage tracing, and lazy client detection. The proposed scheme introduces a client identity-based backdoor watermark generation mechanism and federated dynamic weight adjustment (FDWA) to ensure the uniqueness of each client’s watermark and resolve watermark conflicts. Model fidelity and watermark trigger rates are significantly improved, while also achieving better performance in detecting lazy clients. Experimental results show that the scheme provides more comprehensive protection while maintaining model performance, significantly improves watermark trigger rates, and effectively resists various attacks such as fine-tuning, pruning, quantization, and collusion attacks, thus enhancing the security and fairness of the FL environment and providing effective copyright protection for models.

    参考文献
    相似文献
    引证文献
引用本文

孙友欣,田有亮.联邦学习中分布式水印与抗攻击方案.软件学报,,():1-19

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-03-25
  • 最后修改日期:2026-01-20
  • 录用日期:
  • 在线发布日期: 2026-05-27
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号