数字水印
计算机科学
稳健性(进化)
计算机安全
人工智能
图像(数学)
生物化学
化学
基因
作者
Lan Zhang,Chen Tang,Huiqi Liu,Haikuo Yu,Xirong Zhuang,Qi Zhao,Lei Wang,Wenjing Fang,Xiang-Yang Li
标识
DOI:10.1109/icdcs60910.2024.00081
摘要
Machine learning models are increasingly recognized as valuable intellectual property (IP), prompting the development of a range of watermarking techniques aimed at safeguarding the IP of these models. However, in the context of federated learning (FL) models involving multiple owners, such as the participants in FL model training, conventional techniques designed for single-owner models prove ineffective due to limitations in their capacity and robustness. Few work has explored how to effectively embed watermarks to FL models for multiple-owners, which is non-trivial, especially when the number of owners is large. To fill this gap, we first analyze the capacity of existing watermarking methods. Second, we propose FedMark, a general large-capacity watermarking mechanism for FL, which leverages the Bloom Filter to achieve conflict-free watermarking of a large number of participants. Moreover, we propose a secret-sharing-based verification method to improve the watermarking robustness against false positives caused by Bloom Filter. Finally, comprehensive experiments show that our design can support over 150 participants to embed watermarks while the model accuracy varies within 1 %, and is robust to non-independent identical distributed data, different participant selection rates, model modifications, permutation attacks, scaling attacks and forging attacks.
科研通智能强力驱动
Strongly Powered by AbleSci AI