Dynamic Black-Box Model Watermarking for Heterogeneous Federated Learning

被引:0
作者
Liao, Yuying [1 ]
Jiang, Rong [1 ]
Zhou, Bin [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp Sci & Technol, Changsha 410073, Peoples R China
基金
中国国家自然科学基金;
关键词
federated learning; ownership demonstration; watermarking; deep learning;
D O I
10.3390/electronics13214306
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Heterogeneous federated learning, as an innovative variant of federated learning, aims to break through the constraints of vanilla federated learning on the consistency of model architectures to better accommodate the heterogeneity in mobile computing scenarios. It introduces heterogeneous and personalized local models, which effectively accommodates the heterogeneous data distributions and hardware resource constraints of individual clients, and thus improves computation and communication efficiency. However, it poses a challenge to model ownership protection, as watermarks embedded in the global model are corrupted to varying degrees when they are migrated to a user's heterogeneous model and cannot continue to provide complete ownership protection in the local models. To tackle these issues, we propose a dynamic black-box model watermarking method for heterogeneous federated learning, PWFed. Specifically, we design an innovative dynamic watermark generation method which is based on generative adversarial network technology and is capable of generating watermark samples that are virtually indistinguishable from the original carriers. This approach effectively solves the limitation of the traditional black-box watermarking technique, which only considers static watermarks, and makes the generated watermarks significantly improved in terms of stealthiness and difficult to detect by potential model thieves, thus enhancing the robustness of the watermarks. In addition, we design two watermark embedding strategies with different granularities in the heterogeneous federated learning environment. During the watermark extraction and validation phase, PWFed accesses watermark samples claiming ownership of the model through an API interface and analyzes the differences between their output and the expected labels. Our experimental results show that PWFed achieves a 99.9% watermark verification rate with only a 0.1-4.8% sacrifice of main task accuracy on the CIFAR10 dataset.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Auditing black-box models for indirect influence
    Adler, Philip
    Falk, Casey
    Friedler, Sorelle A.
    Nix, Tionney
    Rybeck, Gabriel
    Scheidegger, Carlos
    Smith, Brandon
    Venkatasubramanian, Suresh
    [J]. KNOWLEDGE AND INFORMATION SYSTEMS, 2018, 54 (01) : 95 - 122
  • [22] A Joint Client-Server Watermarking Framework for Federated Learning
    Fang, Shufen
    Gai, Keke
    Yu, Jing
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT IV, KSEM 2024, 2024, 14887 : 424 - 436
  • [23] Heterogeneous Model Fusion Federated Learning Mechanism Based on Model Mapping
    Lu, Xiaofeng
    Liao, Yuying
    Liu, Chao
    Lio, Pietro
    Hui, Pan
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (08): : 6058 - 6068
  • [24] Auditing black-box models for indirect influence
    Philip Adler
    Casey Falk
    Sorelle A. Friedler
    Tionney Nix
    Gabriel Rybeck
    Carlos Scheidegger
    Brandon Smith
    Suresh Venkatasubramanian
    [J]. Knowledge and Information Systems, 2018, 54 : 95 - 122
  • [25] Rearranging Pixels is a Powerful Black-Box Attack for RGB and Infrared Deep Learning Models
    Pomponi, Jary
    Dantoni, Daniele
    Alessandro, Nicolosi
    Scardapane, Simone
    [J]. IEEE ACCESS, 2023, 11 : 11298 - 11306
  • [26] Demystifying Black-box Learning Models of Rumor Detection from Social Media Posts
    Tafannum, Faiza
    Shopnil, Mir Nafis Sharear
    Salsabil, Anika
    Ahmed, Navid
    Alam, Md Golam Rabiul
    Reza, Md Tanzim
    [J]. 2021 IEEE 12TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2021, : 358 - 364
  • [27] Speed Up Federated Learning in Heterogeneous Environments: A Dynamic Tiering Approach
    Mahmoud Sajjadi Mohammadabadi, Seyed
    Zawad, Syed
    Yan, Feng
    Yang, Lei
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (05): : 5026 - 5035
  • [28] Dynamic Sample Selection for Federated Learning with Heterogeneous Data in Fog Computing
    Cai, Lingshuang
    Lin, Di
    Zhang, Jiale
    Yu, Shui
    [J]. ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [29] Black-Box Reward Attacks Against Deep Reinforcement Learning Based on Successor Representation
    Cai, Kanting
    Zhu, Xiangbin
    Hu, Zhao-Long
    [J]. IEEE ACCESS, 2022, 10 : 51548 - 51560
  • [30] FedEqual: Defending Model Poisoning Attacks in Heterogeneous Federated Learning
    Chen, Ling-Yuan
    Chiu, Te-Chuan
    Pang, Ai-Chun
    Cheng, Li-Chen
    [J]. 2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,