Collusion-resistant Black-box Watermarking in Federated Learning through Weight Relevance Analysis
Elena Rodríguez Lois, Fernando Pérez-González
Abstract
Federated Learning (FL) is a promising solution for training machine learning models on data that may contain personal or sensitive information, allowing different data-owners to provide local training updates to a shared model while keeping their data on their own premises. To protect the model from potential misuse or leakage, previous works on FL watermarking have proposed both white-box and black-box schemes, more recently including collusion-resistant traitor tracing capabilities, providing a unique model instance to each data-owner. In case of a leak, the suspected model can be traced back to its origin, even if multiple malicious participants collude. However, there is still a large margin for improving the collusion-resistance capabilities of black-box schemes, where the watermark is embedded into the model’s input-output behavior. This work aims at shedding light on this challenging aspect and demonstrates that collusion-resistance can be improved through the identification by the embedder of the relevant weights across different model instances.
BibTeX
@inproceedings{icassp2025_collusionresista,
title = {Collusion-resistant Black-box Watermarking in Federated Learning through Weight Relevance Analysis},
author = {Elena Rodríguez Lois and Fernando Pérez-González},
booktitle = {ICASSP 2025},
year = {2025}
}