Federated Learning With Security Authentication and Traceability of Poisoning by Embedded Message Authentication Code

Yan Ke, Minqing Zhang, Jia Liu, Yiliang Han, Wenchao Liu · IEEE Transactions on Dependable and Secure Computing · 2025

Federated learning (FL) allows for collaborative training without centralizing data, but concerns regarding model privacy leakage, intellectual property theft and poisoning attacks have hindered its development. To mitigate such risks, this paper proposes embedded message authentication code technology (EMAC) to integrate encryption, digital signatures, and watermark functions for model security. In EMAC, the authentication data is embedded into the model ciphertext using reversible data hiding after encryption. The marked ciphertext supports data extraction for subsequent authentication and lossless decryption for testing and training simultaneously. Based on EMAC, a novel FL with security authentication and traceability of poisoning (FL-SATP) is proposed, which integrates privacy protection, identity authentication and poisoning traceability into FL. The poisoner tracing is designed to detect and identify poisoners retrospectively based on the practical performance of trained or aggregated models, thus removing the malicious users' model and deterring poisoning behaviors. Theoretical analysis and experimental results demonstrate that FL-SATP could ensure the confidentiality of the model content, the availability of model function, and that when more than half of the users are benign, the proposed method can accurately and efficiently pinpoint all malicious poisoners in FL.

Read the paper · More papers on PaperTik