详细信息
Guard Against Infringement: An Anti-Distillation Federated Learning Watermarking Framework ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:Guard Against Infringement: An Anti-Distillation Federated Learning Watermarking Framework
作者:Yi, Xiao[1];Zhang, Hengrun[1];Yu, Huiqun[1,2];Fan, Guisheng[1,2];Zhu, Haojin[3]
机构:[1]East China Univ Sci & Technol, Dept Comp Sci & Engn, Shanghai 200237, Peoples R China;[2]Shanghai Engn Res Ctr Smart Energy, Shanghai 201103, Peoples R China;[3]Shanghai Jiao Tong Univ, Comp Sci Sch, Shanghai 200240, Peoples R China
年份:2026
卷号:23
期号:1
起止页码:49
外文期刊名:IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING
收录:;EI(收录号:20253519091217);WOS:【SCI-EXPANDED(收录号:WOS:001663382300045)】;
基金:This work was supported by the National Natural Science Foundation of Chinaunder Grant 62372174, Grant 62276097, Grant 62325207, and Grant 62132013,in part by the Science Foundation of Shanghai Key Laboratory of ComputerSoftware Evaluating and Testing under Grant SSTL2024_02, in part by thethe Computational Biology Program of Shanghai Science and TechnologyCommission under Grant 23JS1400600, and in part by the the Research ProjectFunding of Shanghai Data Exchange Corporation.
语种:英文
外文关键词:Watermarking; Biological system modeling; Training; Intellectual property; Artificial neural networks; Protection; Model compression; Federated learning; Security; Data privacy; Federated learning (FL); intellectual property protection; model watermark
摘要:To balance the gap between data privacy and the need for data fusion, federated learning (FL) has been proposed and has become a hot-point method to address data silos and privacy issues. However, AI models exchanged in FL face risks such as illegal copying, redistribution and/or free-riding. To address these risks, FL watermarking frameworks have been proposed to assert and protect the intellectual property (IP) of models, which are resistant to popular watermark removal attacks. Knowledge distillation has recently been of significant contribution to FL convergence performance optimization but brings vulnerability to FL watermark robustness with distillation attack, which enables attackers to maintain high performance on the main task while erasing the watermarks. In response, we introduce a new FL watermarking framework called FedRW, which focuses specifically on anti-distillation. FedRW employs model regularization techniques to bind the main task parameters with the watermark task parameters, thereby enhancing resistance to distillation attacks. Extensive experiments confirm the threat of distillation attacks in FL and demonstrate that FedRW is more resistant to distillation compared to existing FL watermarking frameworks.
参考文献:
正在载入数据...
