网络出版日期: 2024-05-18
基金资助
广东省基础与应用基础研究重大项目 (2023B0303000010);中国航空研究院航空科学基金(2022Z0660M1001);深圳前海微众银行股份有限公司校企合作项目(SYSU-73120-20230721-0001)
版权
Federated model authorization scheme based on backdoor watermarking
Online published: 2024-05-18
Copyright
随着分布式机器学习技术在众多领域的深入应用,其模型安全性问题日益凸显。联邦学习作为一种创新的分布式机器学习方法,在保护数据隐私的同时,允许多方参与者共同训练模型。然而,训练得到的模型存在被滥用和难以实现版权保护等方面的问题,导致恶意用户可能在未经允许的情况下使用模型并谋取经济利益,侵犯参与方的模型版权和知识产权。对于分布式机器学习中存在的模型滥用及版权难以保护的问题,针对联邦学习场景,提出了一种基于后门水印的联邦模型授权方案。该方案在模型训练完成后,通过中心服务器端嵌入后门水印和发放访问令牌,实现对模型使用权的管理。在这一方案下,仅当收集到多数参与方的访问令牌,即获得他们的授权时,用户才能恢复出后门信息,获得模型的使用权;否则,用户在缺乏后门信息的情况下,不能通过模型的验证,无法正常使用模型。在多种数据集上的实验表明,嵌入后门水印的模型与原联邦学习模型相比仅存在可以忽略的精度损失,且能准确验证授权信息,高效识别用户。该方案不仅有效地解决了联邦学习模型的版权保护问题,也大幅提升了联邦学习模型应用的安全性和可靠性。
张准 , 李佳睿 , 岳鹏 , 杨文元 , 操晓春 . 基于后门水印的联邦模型授权方案[J]. 网络空间安全科学学报, 2024 , 2(1) : 113 -122 . DOI: 10.20172/j.issn.2097-3136.240110
With the deepening application of distributed machine learning techniques in various fields, issues concerning model security have become increasingly prominent. Federated learning, as an innovative method of distributed machine learning, allows multiple participants to jointly train models while protecting data privacy. However, the models trained face issues of misuse and challenges in copyright protection. Malicious users may utilize these models without authorization, seeking economic benefits and thus infringing upon the copyright and intellectual property rights of the participating entities. Addressing the problem of model misuse and difficulty in protecting copyrights in distributed machine learning, A federated model authorization scheme was proposed based on backdoor watermarking for the federated learning context. This scheme embeds backdoor watermarks and issues access tokens through a central server after model training, managing the usage rights of the model. Under this scheme, users can only recover the backdoor information and obtain the right to use the model after collecting the access tokens from the majority of the participants, signifying their authorization. Otherwise, without the backdoor information, the user cannot pass the model's verification and is unable to use the model normally. Experiments conducted on multiple datasets indicate that the accuracy of models embedded with backdoor watermarks is negligibly different from that of the original federated learning models. Moreover, these models can accurately verify authorization information and efficiently identify users. This federated model authorization scheme based on backdoor watermarking not only effectively resolves the copyright protection issues of federated learning models but also significantly enhances their overall security and reliability.
表 1 测试精度Table 1 Test accuracy |
| 模型 | 数据集 | 精度/% | ||
| 嵌入前 | 嵌入后 | 降幅 | ||
| ResNet−18 | CIFAR−10 | 86.23 | 83.13 | 3.10 |
| MNIST | 99.23 | 97.41 | 1.82 | |
| ResNet−56 | CIFAR−10 | 88.12 | 84.69 | 3.43 |
| MNIST | 99.41 | 97.25 | 2.16 | |
| 1 |
KENTON J D M W C,TOUTANOVA L K. Bert:pre-training of deep bidirectional transformers for language understanding[C]//Proceedings of NAACL-HLT,2019:2.
|
| 2 |
HE K,ZHANG X,REN S,et al. Deep residual learning for image recognition[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2016:770-778.
|
| 3 |
HINTON G, DENG L, YU D, et al. Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups[J]. IEEE Signal Processing Magazine, 2012, 29 (6): 82- 97.
|
| 4 |
王健宗, 孔令炜, 黄章成, 等. 联邦学习隐私保护研究进展[J]. 大数据, 2021, 7 (3): 130- 149.
WANG J Z, KONG L W, HUANG Z C, et al. Research advances on privacy protection of federated learning[J]. Big Data Research, 2021, 7 (3): 130- 149.
|
| 5 |
MCMAHAN B,MOORE E,RAMAGE D,et al. Communication-efficient learning of deep networks from decentralized data[C]//Artificial Intelligence and Statistics. PMLR,2017:1273-1282.
|
| 6 |
YANG Q, LIU Y, CHEN T, et al. Federated machine learning: Concept and applications[J]. ACM Transactions on Intelligent Systems and Technology (TIST), 2019, 10 (2): 1- 19.
|
| 7 |
周传鑫, 孙奕, 汪德刚, 等. 联邦学习研究综述[J]. 网络与信息安全学报, 2021, 7 (5): 77- 92.
ZHOU C X, SUN Y, WANG D G, et al. Survey of federated learning research[J]. Chinese Journal of Network and Information Security, 2021, 7 (5): 77- 92.
|
| 8 |
LI T, SAHU A K, ZAHEER M, et al. Federated optimization in heterogeneous networks[J]. Proceedings of Machine Learning and Systems, 2020, 2, 429- 450.
|
| 9 |
LIU W, CHEN L, CHEN Y, et al. Accelerating federated learning via momentum gradient descent[J]. IEEE Transactions on Parallel and Distributed Systems, 2020, 31 (8): 1754- 1766.
|
| 10 |
KIM H, PARK J, BENNIS M, et al. Blockchained on-device federated learning[J]. IEEE Communications Letters, 2019, 24 (6): 1279- 1283.
|
| 11 |
KANG J,XIONG Z,NIYATO D,et al. Incentive mechanism for reliable federated learning:A joint optimization approach to combining reputation and contract theory[J]. IEEE Internet of Things Journal,2019,6(6):10700-10714.
|
| 12 |
SZE V, CHEN Y H, YANG T J, et al. Efficient processing of deep neural networks: A tutorial and survey[J]. Proceedings of the IEEE, 2017, 105 (12): 2295- 2329.
|
| 13 |
UCHIDA Y,NAGAI Y,SAKAZAWA S,et al. Embedding watermarks into deep neural networks[C]//Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval,2017:269-277.
|
| 14 |
DARVISH R B,CHEN H,KOUSHANFAR F. Deepsigns:an end-to-end watermarking framework for ownership protection of deep neural networks[C]//Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems,2019:485-497.
|
| 15 |
CAO X,JIA J,GONG N Z. IPGuard:protecting intellectual property of deep neural networks via fingerprinting the classification boundary[C]//Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security,2021:14-25.
|
| 16 |
ALAM M, SAHA S, MUKHOPADHYAY D, et al. NN-lock: A lightweight authorization to prevent IP threats of deep learning models[J]. ACM Journal on Emerging Technologies in Computing Systems (JETC), 2022, 18 (3): 1- 19.
|
| 17 |
SONG Z,JIANG W,ZHAN J,et al. Critical-weight based locking scheme for DNN IP protection in edge computing:work-in-progress[C]//Proceedings of the 2021 International Conference on Hardware/Software Codesign and System Synthesis,2021:33-34.
|
| 18 |
ITO H,APRILPYONE M M,SHIOTA S,et al. Access control of semantic segmentation models using encrypted feature maps[J]. APSIPA Transactions on Signal and Information Processing,2022,11(1):175-178.
|
| 19 |
LI B, FAN L, GU H, et al. FedIPR: ownership verification for federated deep neural network models[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2022, 45 (4): 4521- 4536.
|
| 20 |
LIU X,SHAO S,YANG Y,et al. Secure federated learning model verification:A client-side backdoor triggered watermarking scheme[C]//2021 IEEE International Conference on Systems,Man,and Cybernetics (SMC). IEEE,2021:2414-2419.
|
| 21 |
TEKGUL B G A,XIA Y,MARCHAL S,et al. Waffle:Watermarking in federated learning[C]//2021 40th International Symposium on Reliable Distributed Systems (SRDS). IEEE,2021:310-320.
|
| 22 |
AMARI S. Backpropagation and stochastic gradient descent method[J]. Neurocomputing, 1993, 5 (4-5): 185- 196.
|
| 23 |
XUE M,WU Z,HE C,et al. Active DNN IP protection:a novel user fingerprint management and DNN authorization control technique[C]//2020 IEEE 19th International Conference on Trust,Security and Privacy in Computing and Communications (TrustCom). IEEE,2020:975-982.
|
| 24 |
KRIZHEVSKY A, HINTON G. Learning multiple layers of features from tiny images[J]. Handbook of Systemic Autoimmune Diseases, 2009, 1 (4): 1- 58.
|
| 25 |
ASMUTH C, BLOOM J. A modular approach to key safeguarding[J]. IEEE Transactions on Information Theory, 1983, 29 (2): 208- 210.
|
| 26 |
DENG L. The mnist database of handwritten digit images for machine learning research [best of the web][J]. IEEE Signal Processing Magazine, 2012, 29 (6): 141- 142.
|
| 27 |
LOSHCHILOV I, HUTTER F. SGDR: Stochastic gradient descent with warm restarts[J]. arxiv preprint arXiv:, 1608, 03983, 2016.
|
| 28 |
PITTARAS N,MARKATOPOULOU F,MEZARIS V,et al. Comparison of fine-tuning and extension strategies for deep convolutional neural networks[C]//Multimedia Modeling:23rd International Conference,2017:102-114.
|
| 29 |
HAN S,POOL J,TRAN J,et al. Learning both Weights and Connections for Efficient Neural Networks[C]//Proceedings of the 28th International Conference on Neural Information Processing Systems. MIT Press,2015:1135-1143.
|
/
| 〈 |
|
〉 |