Ensuring Federated Ownership Verification with FedBack: A Trigger-Based Watermarking Approach
Yue Wang, Yan Liu, Xingyu Chen · Research Square · 2023
Abstract Federated learning (FL) has become an emerging distributed framework to build deep learning models through the collaborative efforts from multiple participants without sharing training data across the engaged parties. However, during the whole life cycle of FL models, many unreliable participants may gain access and expose risks to them. Therefore, from the perspective of copyright protection, FedBack, a backdoor watermarking method based on trigger pre-processing is proposed to verify federated ownership on client side. First, clients embed their backdoor watermark information to the global model naturally at model training stage. Subsequently, federated ownership can be preliminarily verified through client detection and gain an outpouring of support through server mediation, without disclosing model privacy. Moreover, Trigger Pre-processing Algorithm is innovatively proposed to study watermark performance by changing watermark levels. Experimental results show that watermark detection rate of any level is high enough to credibly prove ownership verification result, with p-value providing more statistical evidence. This protection mechanism is deployed under two DNN architectures to prove watermark fidelity, significance and robustness. Overall, FedBack can credibly support the ownership verification result, with negligible impact on primitive classification tasks. It is also applicable to various federated training settings and robust to various model attacks.