FedCIPP: A Novel Full-Lifecycle Intellectual Property Protection Framework for Federated Learning
摘要
The protection of Intellectual Property (IP) in Federated Learning (FL) has emerged as a critical issue due to the vulnerability of valuable models to theft or unauthorized distribution within the distributed architecture. However, existing IP protection mechanisms for FL models often significantly increase the difficulty of convergence and typically only protect specific procedures. This paper proposes a novel FL watermarking scheme that minimally impacts the FL model’s accuracy and training computational overhead by mapping the watermark into the model parameters. This approach ensures the watermark persists throughout the entire life cycle of FL models, enabling IP verification during each training iteration. Experimental results demonstrate that the proposed scheme is effective in terms of the fidelity, reliability and robustness. Even after fine-tuning, pruning and noisy injection attacks, the watermark detection accuracy remains over 96%.