Federated Morozov Regularization for Shortcut Learning in Privacy Preserving Learning with Watermarked Image Data
Tao Ling, Siping Shi, Hao Wang, Chuang Hu, Dan Wang
摘要
Federated learning is a promising privacy-preserving learning paradigm in which multiple clients can collaboratively learn a model with their image data kept local. For protecting data ownership, personalized watermarks are usually added to the image data by each client. However, the introduced watermarks can lead to a shortcut learning problem, where the learned model performs predictions over-rely on the simple watermark-related features and represents a low accuracy on real-world data. Existing works assume the central server can directly access the predefined shortcut features during the training process. However, these may fail in the federated learning setting as the shortcut features of the heterogeneous watermarked data are difficult to obtain.
In this paper, we propose a federated Morozov regularization technique, where the regularization parameter can be adaptively determined based on the watermark knowledge of all the clients in a privacy-preserving way, to eliminate the shortcut learning problem caused by the watermarked data. Specifically, federated Morozov regularization firstly performs lightweight local watermark mask estimation in each client to obtain the locations and intensities knowledge of local watermarks. Then, it aggregates the estimated local watermark masks to generate the global watermark knowledge with a weighted averaging. Finally, federated Morozov regularization determines the regularization parameter for each client by combining the local and global watermark knowledge. With the regularization parameter determined, the model is trained as normal federated learning. We implement and evaluate federated Morozov regularization based on a real-world deployment of federated learning on 40 Jetson devices with real-world datasets. The results show that federated Morozov regularization improves model accuracy by 11.22% compared to existing baselines.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- Federated Learning on Non-IID Data Silos: An Experimental StudyQinbin Li, Yiqun Diao, Quan Chen, Bingsheng HeICDE 2022 · 被引用 1,110 次
- The Origins and Prevalence of Texture Bias in Convolutional Neural NetworksKatherine L. Hermann, Ting Chen, Simon KornblithNeurIPS 2020 · 被引用 369 次
- MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG CompressionZhaoyang Jia, Han Fang, Weiming ZhangACM MM 2021 · 被引用 251 次
- Rectifying the Shortcut Learning of Background for Few-Shot LearningXu Luo, Longhui Wei, Liangjian Wen, Jinrong Yang 等NeurIPS 2021 · 被引用 110 次
- Automatic Shortcut Removal for Self-Supervised Representation LearningMatthias Minderer, Olivier Bachem, Neil Houlsby, Michael TschannenICML 2020 · 被引用 78 次
相关 Paper
- Acceleration of Federated Learning with Alleviated Forgetting in Local TrainingChencheng Xu, Zhiwei Hong, Minlie Huang, Tao JiangICLR 2022 · 被引用 61 次
- Personalized Federated Learning with Parameter PropagationJun Wu, Wenxuan Bao, Elizabeth A. Ainsworth, Jingrui HeKDD 2023 · 被引用 17 次
- FedCorr: Multi-Stage Federated Learning for Label Noise CorrectionJingyi Xu, Zihan Chen, Tony Q. S. Quek, Kai Fong Ernest ChongCVPR 2022 · 被引用 101 次
- Class-Wise Federated Averaging for Efficient PersonalizationGyuejeong Lee, Daeyoung ChoiICCV 2025 · 被引用 3 次
- MFL-Owner: Ownership Protection for Multi-modal Federated Learning via Orthogonal Transform WatermarkKeke Gai, Dongjue Wang, Jing Yu, Mohan Wang 等AAAI 2025 · 被引用 6 次
