ICASSP 2025accepted0 citations

Collusion-resistant Black-box Watermarking in Federated Learning through Weight Relevance Analysis

Elena Rodríguez Lois, Fernando Pérez-González

Abstract

Federated Learning (FL) is a promising solution for training machine learning models on data that may contain personal or sensitive information, allowing different data-owners to provide local training updates to a shared model while keeping their data on their own premises. To protect the model from potential misuse or leakage, previous works on FL watermarking have proposed both white-box and black-box schemes, more recently including collusion-resistant traitor tracing capabilities, providing a unique model instance to each data-owner. In case of a leak, the suspected model can be traced back to its origin, even if multiple malicious participants collude. However, there is still a large margin for improving the collusion-resistance capabilities of black-box schemes, where the watermark is embedded into the model’s input-output behavior. This work aims at shedding light on this challenging aspect and demonstrates that collusion-resistance can be improved through the identification by the embedder of the relevant weights across different model instances.

BibTeX
@inproceedings{icassp2025_collusionresista,
  title = {Collusion-resistant Black-box Watermarking in Federated Learning through Weight Relevance Analysis},
  author = {Elena Rodríguez Lois and Fernando Pérez-González},
  booktitle = {ICASSP 2025},
  year = {2025}
}