paper-with-me

홈 › Papers

FedOT: Ownership Verification and Leakage Tracing via Watermarks for Federated LDMs

2026-06-22 · Wenlong Cheng, Yuan Gan, Yunqiu Xu, Jiaxu Miao arxiv

Training Latent Diffusion Models (LDMs) within Federated Learning (FL) has attracted increasing attention due to its ability to combine the powerful generative capacity of LDMs with the privacy-preserving properties of FL. However, FL requires sharing the global model with multiple participants, which risks unauthorized model distribution or resale by malicious clients. While an intuitive approach is to adopt existing VAE-based watermarking techniques for LDMs in FL, this strategy falls short in addressing such threats due to two fundamental challenges: (1) Existing methods support ownership verification but lack the ability to trace model leakage to a specific malicious client; (2) VAE-based watermarks are vulnerable, as they can be removed simply by replacing the decoder with a clean counterpart. In this paper, we propose FedOT, the first framework for ownership verification and leakage tracing in federated LDMs. Specifically, to address the first challenge, we design a chunked watermark, where the first part is for ownership verification, and the second part is used for client identification. Furthermore, to overcome the second challenge and secure the model against VAE replacement attack, we introduce Latent Vector Transformation (LVT), which strengthens the connection between the VAE and U-Net latent spaces by modifying the original latent distribution of the VAE. Consequently, any attempt to replace the VAE for watermark removal leads to significant image quality degradation, making the LDM model unusable. Extensive experiments demonstrate that FedOT achieves superior performance in both ownership verification and traceability. Project page: https://spyzixuan.github.io/FedOT/.

📄 PDF Abstract BibTeX arXiv:2606.22875

Code (0)

등록된 구현이 없습니다.

Tasks

Federated Learning

Similar Papers 제목 키워드 기반

PoLO: Proof-of-Learning and Proof-of-Ownership at Once with Chained Watermarking

2025-05-18 · Haiyu Deng, Yanna Jiang, Guangsheng Yu, Qin Wang 외

Machine learning models are increasingly shared and outsourced, raising requirements of verifying training effort (Proof-of-Learning, PoL) to ensure claimed performance and establishing ownership (Proof-of-Ownership, PoO…

Privacy Preserving

OVLA: Neural Network Ownership Verification using Latent Watermarks

2023-06-15 · Feisi Fu, Wenchao Li

Ownership verification for neural networks is important for protecting these models from illegal copying, free-riding, re-distribution and other intellectual property misuse. We present a novel methodology for neural net…

Data Poisoning

FedIPR: Ownership Verification for Federated Deep Neural Network Models

2021-09-27 · Bowen Li, Lixin Fan, Hanlin Gu, Jie Li 외

Federated learning models are collaboratively developed upon valuable training data owned by multiple parties. During the development and deployment of federated models, they are exposed to risks including illegal copyin…

Federated Learning

DeepTracer: Tracing Stolen Model via Deep Coupled Watermarks

2025-11-12 · Yunfei Yang, Xiaojun Chen, Yuexin Xuan, Zhendong Zhao 외 arxiv

Model watermarking techniques can embed watermark information into the protected model for ownership declaration by constructing specific input-output pairs. However, existing watermarks are easily removed when facing mo…

A Novel Watermarking Framework for Ownership Verification of DNN Architectures

2021-09-29 · Xiaoxuan Lou, Shangwei Guo, Tianwei Zhang, Jiwei Li 외

We present a novel watermarking scheme to achieve the intellectual property (IP) protection and ownership verification of DNN architectures. Existing works all embedded watermarks into the model parameters while treating…

Model extractionNeural Architecture Search