Robust Client-Server Watermarking for Split Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tang, Jiaxiong, Dai, Zhengchunmin, Wu, Liantao, Sun, Peng, Chen, Honglong, Cao, Zhenfu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909908870365184
author Tang, Jiaxiong
Dai, Zhengchunmin
Wu, Liantao
Sun, Peng
Chen, Honglong
Cao, Zhenfu
author_facet Tang, Jiaxiong
Dai, Zhengchunmin
Wu, Liantao
Sun, Peng
Chen, Honglong
Cao, Zhenfu
contents Split Federated Learning (SFL) is renowned for its privacy-preserving nature and low computational overhead among decentralized machine learning paradigms. In this framework, clients employ lightweight models to process private data locally and transmit intermediate outputs to a powerful server for further computation. However, SFL is a double-edged sword: while it enables edge computing and enhances privacy, it also introduces intellectual property ambiguity as both clients and the server jointly contribute to training. Existing watermarking techniques fail to protect both sides since no single participant possesses the complete model. To address this, we propose RISE, a Robust model Intellectual property protection scheme using client-Server watermark Embedding for SFL. Specifically, RISE adopts an asymmetric client-server watermarking design: the server embeds feature-based watermarks through a loss regularization term, while clients embed backdoor-based watermarks by injecting predefined trigger samples into private datasets. This co-embedding strategy enables both clients and the server to verify model ownership. Experimental results on standard datasets and multiple network architectures show that RISE achieves over $95\%$ watermark detection rate ($p-value \lt 0.03$) across most settings. It exhibits no mutual interference between client- and server-side watermarks and remains robust against common removal attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2511_13598
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Robust Client-Server Watermarking for Split Federated Learning
Tang, Jiaxiong
Dai, Zhengchunmin
Wu, Liantao
Sun, Peng
Chen, Honglong
Cao, Zhenfu
Cryptography and Security
Artificial Intelligence
Split Federated Learning (SFL) is renowned for its privacy-preserving nature and low computational overhead among decentralized machine learning paradigms. In this framework, clients employ lightweight models to process private data locally and transmit intermediate outputs to a powerful server for further computation. However, SFL is a double-edged sword: while it enables edge computing and enhances privacy, it also introduces intellectual property ambiguity as both clients and the server jointly contribute to training. Existing watermarking techniques fail to protect both sides since no single participant possesses the complete model. To address this, we propose RISE, a Robust model Intellectual property protection scheme using client-Server watermark Embedding for SFL. Specifically, RISE adopts an asymmetric client-server watermarking design: the server embeds feature-based watermarks through a loss regularization term, while clients embed backdoor-based watermarks by injecting predefined trigger samples into private datasets. This co-embedding strategy enables both clients and the server to verify model ownership. Experimental results on standard datasets and multiple network architectures show that RISE achieves over $95\%$ watermark detection rate ($p-value \lt 0.03$) across most settings. It exhibits no mutual interference between client- and server-side watermarks and remains robust against common removal attacks.
title Robust Client-Server Watermarking for Split Federated Learning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2511.13598