Traceable Black-Box Watermarks For Federated Learning
Jiahao Xu, Rui Hu, Olivera Kotevska, Zikai Zhang
摘要
Due to the distributed nature of Federated Learning (FL) systems, each local client has access to the global model, which poses a critical risk of model leakage. Existing works have explored injecting watermarks into local models to enable intellectual property protection. However, these methods either focus on non-traceable watermarks or traceable but white-box watermarks. We identify a gap in the literature regarding the formal definition of traceable black-box watermarking and the formulation of the problem of injecting such watermarks into FL systems. In this work, we first formalize the problem of injecting traceable black-box watermarks into FL. Based on the problem, we propose a novel server-side watermarking method, , which creates a traceable watermarked model for each client, enabling verification of model leakage in black-box settings. To achieve this, partitions the model parameter space into two distinct regions: the main task region and the watermarking region. Subsequently, a personalized global model is constructed for each client by aggregating only the main task region while preserving the watermarking region. Each model then learns a unique watermark exclusively within the watermarking region using a distinct watermark dataset before being sent back to the local client. Extensive results across various FL systems demonstrate that ensures the traceability of all watermarked models while preserving their main task performance. The code is available at https://github.com/JiiahaoXU/TraMark.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Personalized Federated Learning with Moreau EnvelopesCanh T. Dinh, Nguyen Hoang Tran, Tuan Dung NguyenNeurIPS 2020 · 被引用 1,542 次
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas 等USENIX Security 2018 · 被引用 832 次
- Reconstructive Neuron Pruning for Backdoor DefenseYige Li, Xixiang Lyu, Xingjun Ma, Nodens Koren 等ICML 2023 · 被引用 86 次
- MFL-Owner: Ownership Protection for Multi-modal Federated Learning via Orthogonal Transform WatermarkKeke Gai, Dongjue Wang, Jing Yu, Mohan Wang 等AAAI 2025 · 被引用 6 次
相关 Paper
- Collaborative Threshold WatermarkingTameem Bakr, Anish Ambreth, Nils LukasICML 2026
- CLMTracing: Black-box User-level Watermarking for Code Language Model TracingBoyu Zhang, Ping He, Tianyu Du, Xuhong Zhang 等EMNLP 2025 · 被引用 1 次
- FedGMark: Certifiably Robust Watermarking for Federated Graph LearningYuxin Yang, Qiang Li, Yuan Hong, Binghui WangNeurIPS 2024 · 被引用 11 次
- An Efficient White-box LLM Watermarking for IP Protection on Online Market PlatformsShuguang Yuan, Xingyu Su, Peizhuo Lv, Weiji Xue 等KDD 2025
- Federated Morozov Regularization for Shortcut Learning in Privacy Preserving Learning with Watermarked Image DataTao Ling, Siping Shi, Hao Wang, Chuang Hu 等ACM MM 2024 · 被引用 1 次
