FedSMW: Server-Side Model Watermark Framework for Model Ownership Verification in Federated Learning

Yang Cao, Hao Fang, Bin Chen, Xuan Wang, Shu‐Tao Xia · 2024

Federated Learning (FL) has recently become a promising framework for privacy-preserving distributed machine learning, particularly under edge computing scenarios. It allows geographically dispersed devices to collaboratively train a global model under the coordination of a central server, without compromising their private data. However, as every participating local device can access the FL model, the development and deployment stages of FL are susceptible to model Intellectual Property Rights (IPR) infringement issues, including unlawful theft and misuse. Previous studies have offered schemes in which devices independently inject watermarks into the model during the local training phase to protect their IPR for the FL model. Nevertheless, this strategy may cause additional problems, such as mutual interference of watermarks, increased computational burden for distributed resource-constrained devices, and degraded global model accuracy. To address these issues, we propose a novel framework to uphold IPR in federated learning. Rather than depending on device-generated watermarks, our approach utilizes injecting watermarks from the central server, permitting it to globally and intelligently embed watermarks for every device. Extensive experiments demonstrate that our methodology can enhance the watermark injection rate and preserve main task accuracy concurrently. Furthermore, our framework can seamlessly integrate with other secure federated learning methods.

Read the paper · More papers on PaperTik