Netinfo Security ›› 2024, Vol. 24 ›› Issue (10): 1553-1561.doi: 10.3969/j.issn.1671-1122.2024.10.009

Previous Articles     Next Articles

A Survey of Ownership Protection Schemes for Federated Learning Models

SA Qirui1, YOU Weijing2(), ZHANG Yifei1, QIU Weiyang2, MA Cunqing1   

  1. 1. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100085, China
    2. College of Computer and Cyber Security, Fujian Normal University, Fuzhou 350108, China
  • Received:2024-06-08 Online:2024-10-10 Published:2024-09-27

Abstract:

In recent years, machine learning has emerged as a key technology driving development across various industries. Federated learning has achieved enhancements in both model generalization and data privacy protection in distributed secure multi-party machine learning by integrating local data training with online gradient iteration. Due to the high training costs associated with federated learning models, including computational power and datasets, protecting the ownership of these economically valuable models has become particularly important. This article surveyed existing ownership protection schemes for federated learning models. The researchers examined two fingerprinting schemes, eight black-box watermarking schemes, and five white-box watermarking schemes to analyze the current state of research on model ownership protection. Additionally, this article combined methods for protecting the ownership of deep neural network models and provided insights into the current research directions for protecting the ownership of federated learning models.

Key words: machine learning, federated learning, deep neural networks, ownership protection

CLC Number: