Exploring Federated Learning Dynamics for Black-and-White-Box DNN Traitor Tracing
Elena Rodríguez-Lois, Fernando Pérez‐González
Universidade de Vigo
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
As deep learning applications become more preva-lent, the need for extensive training examples raises concerns for sensitive, personal, or proprietary data. To overcome this, Federated Learning (FL) enables collaborative model training across distributed data-owners, but it introduces challenges in safeguarding model ownership and identifying the origin in case of a leak. Building upon prior work, this paper explores the adaptation of black-and-white traitor tracing watermarking to FL classifiers, addressing the threat of collusion attacks from different data-owners. This study reveals that leak-resistant white-box fingerprints can be directly implemented without a significant impact from FL dynamics, while the black-box fingerprints are drastically affected, losing their traitor tracing capabilities. To mitigate this effect, we propose increasing the number of black-box salient neurons through dropout regularization. Though there are still some open problems to be explored, such as analyzing non-i.i.d. datasets and over-parameterized models, results show that collusion-resistant traitor tracing, identifying all data-owners involved in a suspected leak, is feasible in an FL framework, even in early stages of training.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIPrivacy-Preserving Technologies in Data
Network Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting
参考文献 20
此处列出前 3 条
引用本文 3
按被引量排序,此处列出前 3 条