Fed-PK-Judge: Provably Secure Intellectual-Property Protection for Federated Learning

Wafaa Kanakri, Brian King · IEEE Internet of Things Journal · 2025

Federated Learning (FL) enables collaborative model training across distributed devices but creates significant intellectual property risks, as adversaries may attempt to compromise implemented protections. This work addresses the need for a provably secure ownership verification scheme that adheres to cryptographic principles in FL’s decentralized environment. Drawing inspiration from public-key infrastructure’s transition from password-based authentication to cryptographic signatures, we propose Fed-PK-Judge, which implements a cryptographic security level authentication and eliminates reliance on watermark secrecy by decoupling verification from confidential credentials, complying with Kerckhoffs’ principle. Unlike prior threshold-based methods that degrade security via bit-error tolerance, Fed-PK-Judge retains full key entropy while binding model ownership to a cryptographic secret through asymmetric digital signatures. The protocol enables deterministic verification resistant to replay attacks, ambiguity, and parameter perturbations, resolving vulnerabilities in statistical approaches. Extensive experimental results confirm the fidelity, efficiency, and robustness of our scheme across diverse FL scenarios. By eliminating reliance on watermark confidentiality, Fed-PK-Judge establishes a foundation for legal disputes and regulatory compliance requiring unambiguous ownership attestation in distributed machine learning systems.

Read the paper · More papers on PaperTik