Embedding watermarks into models has been widely used to protect model ownership in federated learning (FL). However, existing methods are inadequate for protecting the ownership of personalized models acquired by clients in personalized FL (PFL). This is due to the aggregation of the global model in PFL, resulting in conflicts over clients' private watermarks. Moreover, malicious clients may tamper with embedded watermarks to facilitate model leakage and evade accountability. This paper presents a robust watermark embedding scheme, named RobWE, to protect the ownership of personalized models in PFL. We first decouple the watermark embedding of personalized models into two parts: head layer embedding and representation layer embedding. The head layer belongs to clients' private part without participating in model aggregation, while the representation layer is the shared part for aggregation. For representation layer embedding, we employ a watermark slice embedding operation, which avoids watermark embedding conflicts. Furthermore, we design a malicious watermark detection scheme enabling the server to verify the correctness of watermarks before aggregating local models. We conduct an exhaustive experimental evaluation of RobWE. The results demonstrate that RobWE significantly outperforms the state-of-the-art watermark embedding schemes in FL in terms of fidelity, reliability, and robustness.
翻译:将水印嵌入模型已广泛用于保护联邦学习(FL)中的模型所有权。然而,现有方法不足以保护个性化联邦学习(PFL)中客户端获取的个性化模型的所有权。这是因为PFL中全局模型的聚合导致客户端私有水印产生冲突。此外,恶意客户端可能篡改嵌入水印以促进模型泄露并逃避责任。本文提出一种名为RobWE的鲁棒水印嵌入方案,以保护PFL中个性化模型的所有权。我们首先将个性化模型的水印嵌入解耦为两部分:头部层嵌入和表示层嵌入。头部层属于客户端的私有部分,不参与模型聚合;而表示层是用于聚合的共享部分。对于表示层嵌入,我们采用水印切片嵌入操作,避免了水印嵌入冲突。此外,我们设计了一种恶意水印检测方案,使服务器在聚合局部模型前能够验证水印的正确性。我们对RobWE进行了详尽的实验评估。结果表明,RobWE在保真度、可靠性和鲁棒性方面显著优于FL中最先进的水印嵌入方案。