FedTracker: Furnishing Ownership Verification and Traceability for Federated Learning Model.

Shuo Shao,Wenyuan Yang,Hanlin Gu,Zhan Qin,Lixin Fan,Qiang Yang,Kui Ren
DOI: https://doi.org/10.1109/tdsc.2024.3390761
2022-01-01
Abstract:Federated learning (FL) is a distributed machine learning paradigm allowingmultiple clients to collaboratively train a global model without sharing theirlocal data. However, FL entails exposing the model to various participants.This poses a risk of unauthorized model distribution or resale by the maliciousclient, compromising the intellectual property rights of the FL group. To detersuch misbehavior, it is essential to establish a mechanism for verifying theownership of the model and as well tracing its origin to the leaker among theFL participants. In this paper, we present FedTracker, the first FL modelprotection framework that provides both ownership verification andtraceability. FedTracker adopts a bi-level protection scheme consisting ofglobal watermark mechanism and local fingerprint mechanism. The formerauthenticates the ownership of the global model, while the latter identifieswhich client the model is derived from. FedTracker leverages Continual Learning(CL) principles to embed the watermark in a way that preserves the utility ofthe FL model on both primitive task and watermark task. FedTracker also devisesa novel metric to better discriminate different fingerprints. Experimentalresults show FedTracker is effective in ownership verification, traceability,and maintains good fidelity and robustness against various watermark removalattacks.
What problem does this paper attempt to address?