arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向联邦学习的结合互补格基安全聚合的密钥化来源水印

Keyed Provenance Watermarking with Complementary Lattice-Based Secure Aggregation for Federated Learning

Xinyun Liu, Zhi Lu, Yu Chen, Ronghua Xu

arXiv 2608.20580首次发表:更新:

发表机构

Michigan Technological University; National University of Singapore; Binghamton University(密歇根理工大学; 新加坡国立大学; 宾汉姆顿大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对联邦学习面临的多级攻击问题,提出结合密钥化来源水印与格基安全聚合的FL框架,经实验验证其在复合攻击下具备互补保护能力,且为端到端可信FL提供了联合评估方案。

AI 中文摘要

联邦学习(FL)易受到多级攻击,然而现有方法单独应对这些攻击,使得FL仍面临数据泄露、未授权复用及恶意梯度操纵的风险。本研究提出一种FL框架,将密钥化上下文来源水印与可验证的格基安全聚合(包含Real-World Anchored Watermarking和格基零知识安全聚合)相结合。在数据层,提出符合Kerckhoffs原则的方案,利用物理锚点元数据(PAM)确保数据来源;PAM是从可信基础设施数据(时间、位置和服务器ID)衍生的上下文来源令牌,经密钥化HMAC-SHA-256变换生成水印载荷,若无客户端密钥则无法生成。进一步设计FMGAN,这是一种基于GAN的鲁棒图像水印框架,采用特征融合模块和Mamba引导的线性注意力机制嵌入该变换后的载荷。在计算层,采用基于格的零知识安全聚合(LZKSA)协议,对承诺梯度验证密钥正确性、L2范数边界及余弦相似度约束,同时不泄露私有更新;基于RLWE的设计保证后量子安全性。大量实验验证了两层在复合攻击场景下的互补保护效果,据作者所知,此前尚无验证工作在混合端到端可信FL框架中联合评估这两层。

英文摘要

Federated learning (FL) is vulnerable to multi-level attacks. However, existing methods address them separately, leaving FL exposed to data leakage, unauthorized reuse, and malicious gradient manipulation. In this work, we propose an FL framework that couples keyed context-provenance watermarking with verifiable lattice-based secure aggregation of Real-World Anchored Watermarking and Lattice-Based Zero-Knowledge Secure Aggregation. At the data layer, we propose a Kerckhoffs-compliant scheme that utilizes Physical Anchor Metadata (PAM) to ensure data provenance. PAM is defined as a context-provenance token derived from trusted infrastructure data (time, location, and server ID) and then subjected to a keyed HMAC-SHA-256 transformation to produce a watermark payload that cannot be generated without the client's secret key. We further design FMGAN, a GAN-based robust image watermarking framework that embeds this transformed payload using a feature fusion module and a Mamba-guided linear attention mechanism. At the computation layer, we adopt a lattice-based zero-knowledge secure aggregation (LZKSA) protocol that verifies key correctness, L2 norm bounds, and cosine similarity constraints over committed gradients without revealing private updates. The RLWE-based design guarantees post-quantum security. Extensive experiments validate the complementary protection of the two layers under composite attack scenarios. To our knowledge, no prior verification workflow has jointly evaluated both layers in a hybrid, end-to-end trustworthy FL framework.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑