Guard(计算机科学)
计算机科学
数字水印
计算机安全
人工智能
图像(数学)
程序设计语言
作者
Xiao Yi,Hengrun Zhang,Huiqun Yu,Guisheng Fan,Haojin Zhu
标识
DOI:10.1109/tdsc.2025.3604013
摘要
To balance the gap between data privacy and the need for data fusion, federated learning (FL) has been proposed and has become a hot-point method to address data silos and privacy issues. However, AI models exchanged in FL face risks such as illegal copying, redistribution and/or free-riding. To address these risks, FL watermarking frameworks have been proposed to assert and protect the intellectual property (IP) of models, which are resistant to popular watermark removal attacks. Knowledge distillation has recently been of significant contribution to FL convergence performance optimization but brings vulnerability to FL watermark robustness with distillation attack, which enables attackers to maintain high performance on the main task while erasing the watermarks. In response, we introduce a new FL watermarking framework called FedRW, which focuses specifically on anti-distillation. FedRW employs model regularization techniques to bind the main task parameters with the watermark task parameters, thereby enhancing resistance to distillation attacks. Extensive experiments confirm the threat of distillation attacks in FL and demonstrate that FedRW is more resistant to distillation compared to existing FL watermarking frameworks.
科研通智能强力驱动
Strongly Powered by AbleSci AI