论文标题

FedTracker:为联合学习模型提供所有权验证和可追溯性

FedTracker: Furnishing Ownership Verification and Traceability for Federated Learning Model

论文作者

Shao, Shuo, Yang, Wenyuan, Gu, Hanlin, Qin, Zhan, Fan, Lixin, Yang, Qiang, Ren, Kui

论文摘要

联合学习(FL)是一种分布式的机器学习范式,允许多个客户在不共享本地数据的情况下协作训练全球模型。但是,FL需要将模型暴露给各种参与者。这构成了恶意客户未经授权的模型分配或转售的风险,损害了FL集团的知识产权。为了阻止这种不当行为,必须建立一种机制来验证该模型的所有权,并将其起源追溯到FL参与者中的泄漏者。在本文中,我们介绍了FedTracker,这是第一个提供所有权验证和可追溯性的FL模型保护框架。 FedTracker采用了由全球水印机制和局部指纹机制组成的双层保护计划。前者对全球模型的所有权进行了身份验证,而后者则标识了该模型来自哪些客户。 FedTracker利用持续学习(CL)原则以将FL模型的实用性保留在原始任务和水印任务上的方式。 FedTracker还设计了一个新颖的指标,以更好地区分不同的指纹。实验结果表明,FedTracker在所有权验证,可追溯性方面有效,并保持良好的保真度和鲁棒性,以防止各种水印去除攻击。

Federated learning (FL) is a distributed machine learning paradigm allowing multiple clients to collaboratively train a global model without sharing their local data. However, FL entails exposing the model to various participants. This poses a risk of unauthorized model distribution or resale by the malicious client, compromising the intellectual property rights of the FL group. To deter such misbehavior, it is essential to establish a mechanism for verifying the ownership of the model and as well tracing its origin to the leaker among the FL participants. In this paper, we present FedTracker, the first FL model protection framework that provides both ownership verification and traceability. FedTracker adopts a bi-level protection scheme consisting of global watermark mechanism and local fingerprint mechanism. The former authenticates the ownership of the global model, while the latter identifies which client the model is derived from. FedTracker leverages Continual Learning (CL) principles to embed the watermark in a way that preserves the utility of the FL model on both primitive task and watermark task. FedTracker also devises a novel metric to better discriminate different fingerprints. Experimental results show FedTracker is effective in ownership verification, traceability, and maintains good fidelity and robustness against various watermark removal attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源