错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Client-Side Watermarking with Private-Class in Federated Learning

  • Weitong Chen,
  • Wei Zhang,
  • Jiale Zhang,
  • Xiaobing Sun,
  • Xiang Cheng,
  • Chengcheng Zhu

摘要

Federated learning is a privacy-focused distributed learning framework that involves sharing model updates among participants. However, this sharing of the global model increases the risk of model leakage when unreliable participants are involved. To protect model copyright and improve watermark robustness, we propose a client-side watermarking method. This method introduces an additional watermark class to the client’s model, extending it to an \(N+1\) classification model. The client’s model is trained using both the watermark dataset and the local dataset. Before sending updates to the server, the watermark class parameters are removed and stored locally. Participants enhance model personalization during aggregation by uploading amplified parameters. After server aggregation, the global model is distributed for local training. The saved watermark parameters continuously update through iterations until model convergence. Extensive experiments demonstrate minimal impact on neural network performance and strong robustness during model modifications, such as fine-tuning and pruning.