{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:22:47Z","timestamp":1783614167748,"version":"3.55.0"},"reference-count":47,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,12,19]],"date-time":"2023-12-19T00:00:00Z","timestamp":1702944000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2022YFB2703303"],"award-info":[{"award-number":["2022YFB2703303"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["61602527"],"award-info":[{"award-number":["61602527"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Science and Technology Innovation Program of Hunan Province","award":["2022GK5002"],"award-info":[{"award-number":["2022GK5002"]}]},{"name":"Special Foundation for Distinguished Young Scientists of Changsha","award":["kq2209003"],"award-info":[{"award-number":["kq2209003"]}]},{"DOI":"10.13039\/501100013314","name":"111 Project","doi-asserted-by":"crossref","award":["D23006"],"award-info":[{"award-number":["D23006"]}],"id":[{"id":"10.13039\/501100013314","id-type":"DOI","asserted-by":"crossref"}]},{"name":"High Performance Computing Center of Central South University"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Intell. Syst. Technol."],"published-print":{"date-parts":[[2024,2,29]]},"abstract":"<jats:p>Federated learning (FL) allows multiple participants to collaboratively build deep learning (DL) models without directly sharing data. Consequently, the issue of copyright protection in FL becomes important since unreliable participants may gain access to the jointly trained model. Application of homomorphic encryption (HE) in a secure FL framework prevents the central server from accessing plaintext models. Thus, it is no longer feasible to embed the watermark at the central server using existing watermarking schemes. In this article, we propose a novel client-side FL watermarking scheme to tackle the copyright protection issue in secure FL with HE. To the best of our knowledge, it is the first scheme to embed the watermark to models under a secure FL environment. We design a black-box watermarking scheme based on client-side backdooring to embed a pre-designed trigger set into an FL model by a gradient-enhanced embedding method. Additionally, we propose a trigger set construction mechanism to ensure that the watermark cannot be forged. Experimental results demonstrate that our proposed scheme delivers outstanding protection performance and robustness against various watermark removal attacks and ambiguity attack.<\/jats:p>","DOI":"10.1145\/3630636","type":"journal-article","created":{"date-parts":[[2023,10,30]],"date-time":"2023-10-30T21:55:56Z","timestamp":1698702956000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":32,"title":["Watermarking in Secure Federated Learning: A Verification Framework Based on Client-Side Backdooring"],"prefix":"10.1145","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0046-5994","authenticated-orcid":false,"given":"Wenyuan","family":"Yang","sequence":"first","affiliation":[{"name":"Sun Yat-sen University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3482-4975","authenticated-orcid":false,"given":"Shuo","family":"Shao","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5641-2899","authenticated-orcid":false,"given":"Yue","family":"Yang","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2718-659X","authenticated-orcid":false,"given":"Xiyao","family":"Liu","sequence":"additional","affiliation":[{"name":"Central South University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4238-3295","authenticated-orcid":false,"given":"Ximeng","family":"Liu","sequence":"additional","affiliation":[{"name":"Fuzhou University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6860-647X","authenticated-orcid":false,"given":"Zhihua","family":"Xia","sequence":"additional","affiliation":[{"name":"Jinan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1292-7674","authenticated-orcid":false,"given":"Gerald","family":"Schaefer","sequence":"additional","affiliation":[{"name":"Loughborough University, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9365-7420","authenticated-orcid":false,"given":"Hui","family":"Fang","sequence":"additional","affiliation":[{"name":"Loughborough University, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,12,19]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1615","volume-title":"Proceedings of 2018 USENIX Security Symposium","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In Proceedings of 2018 USENIX Security Symposium. 1615\u20131631."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-022-05539-7"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3501813"},{"issue":"5","key":"e_1_3_1_5_2","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et\u00a0al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security 13, 5 (2017), 1333\u20131345.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_1_6_2","first-page":"2938","volume-title":"Proceedings of 2020 International Conference on Artificial Intelligence and Statistics","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In Proceedings of 2020 International Conference on Artificial Intelligence and Statistics. 2938\u20132948."},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3514500"},{"key":"e_1_3_1_9_2","first-page":"1","article-title":"Copyright protection of deep neural network models using digital watermarking: A comparative study","author":"Fkirin Alaa","year":"2022","unstructured":"Alaa Fkirin, Gamal Attiya, Ayman El-Sayed, and Marwa A. Shouman. 2022. Copyright protection of deep neural network models using digital watermarking: A comparative study. Multimedia Tools and Applications (2022), 1\u201315.","journal-title":"Multimedia Tools and Applications"},{"key":"e_1_3_1_10_2","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017).","journal-title":"arXiv preprint arXiv:1708.06733"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/500"},{"key":"e_1_3_1_13_2","volume-title":"Advances in Neural Information Processing Systems","author":"Han Song","year":"2015","unstructured":"Song Han, Jeff Pool, John Tran, and William Dally. 2015. Learning both weights and connections for efficient neural network. In Advances in Neural Information Processing Systems, Vol. 28."},{"key":"e_1_3_1_14_2","article-title":"Federated learning for mobile keyboard prediction","author":"Hard Andrew","year":"2018","unstructured":"Andrew Hard, Kanishka Rao, Rajiv Mathews, Swaroop Ramaswamy, Fran\u00e7oise Beaufays, Sean Augenstein, Hubert Eichner, Chlo\u00e9 Kiddon, and Daniel Ramage. 2018. Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604 (2018).","journal-title":"arXiv preprint arXiv:1811.03604"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"e_1_3_1_16_2","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky, Geoffrey Hinton, et\u00a0al. 2009. Learning multiple layers of features from tiny images. Tech. Rep. (2009).","journal-title":"Tech. Rep."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_1_18_2","article-title":"Federated learning on non-IID data silos: An experimental study","author":"Li Qinbin","year":"2021","unstructured":"Qinbin Li, Yiqun Diao, Quan Chen, and Bingsheng He. 2021. Federated learning on non-IID data silos: An experimental study. arXiv preprint arXiv:2102.02079 (2021).","journal-title":"arXiv preprint arXiv:2102.02079"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS54860.2022.00051"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45855.2022.9839218"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1002\/int.22818"},{"key":"e_1_3_1_24_2","volume-title":"Proceedings of 2021 International Conference on Learning Representations","author":"Maini Pratyush","year":"2021","unstructured":"Pratyush Maini, Mohammad Yaghini, and Nicolas Papernot. 2021. Dataset inference: Ownership resolution in machine learning. In Proceedings of 2021 International Conference on Learning Representations."},{"key":"e_1_3_1_25_2","first-page":"1273","volume-title":"Proceedings of 2017 International Conference Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of 2017 International Conference Artificial Intelligence and Statistics. 1273\u20131282."},{"key":"e_1_3_1_26_2","volume-title":"International Conference on Learning Representations","author":"Mehta Sachin","year":"2021","unstructured":"Sachin Mehta and Mohammad Rastegari. 2021. MobileViT: Light-weight, general-purpose, and mobile-friendly vision transformer. In International Conference on Learning Representations."},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403176"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48910-X_16"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.3390\/app12020734"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12029"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"issue":"11","key":"e_1_3_1_33_2","first-page":"169","article-title":"On data banks and privacy homomorphisms","volume":"4","author":"Rivest Ronald L.","year":"1978","unstructured":"Ronald L. Rivest, Len Adleman, Michael L. Dertouzos, et\u00a0al. 1978. On data banks and privacy homomorphisms. Foundations of Secure Computation 4, 11 (1978), 169\u2013180.","journal-title":"Foundations of Secure Computation"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3437880.3460401"},{"key":"e_1_3_1_35_2","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014).","journal-title":"arXiv preprint arXiv:1409.1556"},{"key":"e_1_3_1_36_2","article-title":"Federated reconstruction: Partially local federated learning","volume":"34","author":"Singhal Karan","year":"2021","unstructured":"Karan Singhal, Hakim Sidahmed, Zachary Garrett, Shanshan Wu, John Rush, and Sushant Prakash. 2021. Federated reconstruction: Partially local federated learning. Advances in Neural Information Processing Systems 34 (2021).","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475591"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS53918.2021.00038"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450000"},{"key":"e_1_3_1_41_2","first-page":"1","article-title":"Active intellectual property protection for deep neural networks through stealthy backdoor and users\u2019 identities authentication","author":"Xue Mingfu","year":"2022","unstructured":"Mingfu Xue, Shichang Sun, Yushu Zhang, Jian Wang, and Weiqiang Liu. 2022. Active intellectual property protection for deep neural networks through stealthy backdoor and users\u2019 identities authentication. Applied Intelligence (2022), 1\u201315.","journal-title":"Applied Intelligence"},{"key":"e_1_3_1_42_2","unstructured":"Y. LeCun C. Cortes and C. Burges. 2010. MNIST Handwritten Digit Database. (2010). http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_16"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-01585-4"},{"key":"e_1_3_1_46_2","first-page":"7252","volume-title":"Proceedings of 2019 International Conference on Machine Learning","author":"Yurochkin Mikhail","year":"2019","unstructured":"Mikhail Yurochkin, Mayank Agarwal, Soumya Ghosh, Kristjan Greenewald, Nghia Hoang, and Yasaman Khazaeni. 2019. Bayesian nonparametric federated learning of neural networks. In Proceedings of 2019 International Conference on Machine Learning. 7252\u20137261."},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.55"}],"container-title":["ACM Transactions on Intelligent Systems and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3630636","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3630636","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:32Z","timestamp":1750178192000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3630636"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,19]]},"references-count":47,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,2,29]]}},"alternative-id":["10.1145\/3630636"],"URL":"https:\/\/doi.org\/10.1145\/3630636","relation":{},"ISSN":["2157-6904","2157-6912"],"issn-type":[{"value":"2157-6904","type":"print"},{"value":"2157-6912","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,19]]},"assertion":[{"value":"2022-12-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-09-25","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-12-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}