Keyed Provenance Watermarking with Complementary Lattice-Based Secure Aggregation for Federated Learning

📅 2026-08-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该研究提出了一种结合密钥上下文来源水印和基于格的零知识安全聚合的联邦学习框架,以解决数据泄露、未经授权重用和恶意梯度操纵的问题。
📝 Abstract
Federated learning (FL) is vulnerable to multi-level attacks. However, existing methods address them separately, leaving FL exposed to data leakage, unauthorized reuse, and malicious gradient manipulation. In this work, we propose an FL framework that couples keyed context-provenance watermarking with verifiable lattice-based secure aggregation of Real-World Anchored Watermarking and Lattice-Based Zero-Knowledge Secure Aggregation. At the data layer, we propose a Kerckhoffs-compliant scheme that utilizes Physical Anchor Metadata (PAM) to ensure data provenance. PAM is defined as a context-provenance token derived from trusted infrastructure data (time, location, and server ID) and then subjected to a keyed HMAC-SHA-256 transformation to produce a watermark payload that cannot be generated without the client's secret key. We further design FMGAN, a GAN-based robust image watermarking framework that embeds this transformed payload using a feature fusion module and a Mamba-guided linear attention mechanism. At the computation layer, we adopt a lattice-based zero-knowledge secure aggregation (LZKSA) protocol that verifies key correctness, L2 norm bounds, and cosine similarity constraints over committed gradients without revealing private updates. The RLWE-based design guarantees post-quantum security. Extensive experiments validate the complementary protection of the two layers under composite attack scenarios. To our knowledge, no prior verification workflow has jointly evaluated both layers in a hybrid, end-to-end trustworthy FL framework.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
Data Leakage
Unauthorized Reuse
Malicious Gradient Manipulation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Keyed Provenance Watermarking
Lattice-Based Secure Aggregation
Physical Anchor Metadata (PAM)
FMGAN
LZKSA
🔎 Similar Papers
No similar papers found.
Xinyun Liu
Xinyun Liu
Google
Zhi Lu
Zhi Lu
Cobalt Fashion
Deep LearningComputer VisionExplainable AIMachine LearningMedical Image Analysis
Y
Yu Chen
Department of Electrical and Computer Engineering, Binghamton University, Binghamton, NY 13902, USA
R
Ronghua Xu
Department of Applied Computing, Michigan Technological University, Houghton, MI 49931, USA