Distributed Watermarking and Anti-attack Scheme in Federated Learning
Author:
Affiliation:

Clc Number:

TP309

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Federated learning (FL), as a distributed machine learning method, enables model training while protecting user privacy and data security. However, the involvement of multiple parties and the widespread exposure of models in FL can easily lead to copyright leakage. This study proposes a watermarking scheme with ownership verification, model leakage tracing, and lazy client detection. The proposed scheme introduces a client identity-based backdoor watermark generation mechanism and federated dynamic weight adjustment (FDWA) to ensure the uniqueness of each client’s watermark and resolve watermark conflicts. Model fidelity and watermark trigger rates are significantly improved, while also achieving better performance in detecting lazy clients. Experimental results show that the scheme provides more comprehensive protection while maintaining model performance, significantly improves watermark trigger rates, and effectively resists various attacks such as fine-tuning, pruning, quantization, and collusion attacks, thus enhancing the security and fairness of the FL environment and providing effective copyright protection for models.

    Reference
    Related
    Cited by
Get Citation

孙友欣,田有亮.联邦学习中分布式水印与抗攻击方案.软件学报,,():1-19

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:March 25,2025
  • Revised:January 20,2026
  • Adopted:
  • Online: May 27,2026
  • Published:
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063