Search arXiv⌕ Search

arXiv subjects

Zhengchunmin Dai

Publications and source records attributed to Zhengchunmin Dai.

3 recordsLinked to original sources

Server-Enforced Watermarking in U-Shaped Split Federated Learning

U-shaped split federated learning (U-SFL) enables resource-constrained Internet of Things devices to collaboratively train models with an edge server while retaining raw data and labels locally. We consider model-service deployments in which a provider supplies proprietary models whose client-side segments reside on participating devices, creating risks of unauthorized copying and redistribution. Protecting these segments is challenging because the server cannot directly access client data, labels, or model parameters, and potentially malicious clients may refuse to perform watermark embedding. To address this challenge, we propose Sigil, a server-enforced watermarking framework for U-SFL. Sigil defines a secret watermark constraint in the server-visible activation space and embeds the watermark into client-side models by injecting a watermark gradient into the gradients returned during training. This mechanism requires neither access to clients' raw data and labels nor client-side watermarking operations. To limit interference with the main task and reduce detectability by gradient anomaly detectors, Sigil adaptively clips the watermark gradient relative to the main-task gradient. Experiments on two datasets and four model architectures demonstrate high watermark detection rates with limited impact on task accuracy, robustness against the evaluated removal attacks, and stealthiness against the evaluated gradient anomaly detector.

cs.CR↗

Stateful Agent Backdoors: Constructing Cross-Session Attack Programs

Multi-step attacks on large language model agents may depend on opportunities distributed across sessions, such as access to target information or the availability of required tools. To combine these opportunities, an attack needs to retain its state and intermediate results, and choose actions based on current conditions. In this work, we study such attacks as cross-session attack programs. We focus on their shared control structures, including sequential execution with conditional waiting, branching and merging, looping, and condition accumulation. We represent these programs as Mealy machines and construct a sub-backdoor for each transition. We build single-session training trajectories for each sub-backdoor, combine them into a training dataset, and fine-tune the model to learn the local behaviors jointly. After a single injection of the initial trigger, the agent uses persistent memory to connect local behaviors into a complete cross-session attack program. We evaluate four instantiations of these control structures across four models in a LangChain-based agent environment. The primary instantiation achieves mean complete-program success rates of 71.7\%--94.7\% in LangChain. In the official OpenClaw runtime under a controlled configuration, it achieves a complete-program success rate of 85\% for each of two evaluated models. These results demonstrate the feasibility of end-to-end execution of cross-session attack programs with different control structures.

cs.CR↗

Robust Client-Server Watermarking for Split Federated Learning

Split Federated Learning (SFL) is renowned for its privacy-preserving nature and low computational overhead among decentralized machine learning paradigms. In this framework, clients employ lightweight models to process private data locally and transmit intermediate outputs to a powerful server for further computation. However, SFL is a double-edged sword: while it enables edge computing and enhances privacy, it also introduces intellectual property ambiguity as both clients and the server jointly contribute to training. Existing watermarking techniques fail to protect both sides since no single participant possesses the complete model. To address this, we propose RISE, a Robust model Intellectual property protection scheme using client-Server watermark Embedding for SFL. Specifically, RISE adopts an asymmetric client-server watermarking design: the server embeds feature-based watermarks through a loss regularization term, while clients embed backdoor-based watermarks by injecting predefined trigger samples into private datasets. This co-embedding strategy enables both clients and the server to verify model ownership. Experimental results on standard datasets and multiple network architectures show that RISE achieves over $95\%$ watermark detection rate ($p-value \lt 0.03$) across most settings. It exhibits no mutual interference between client- and server-side watermarks and remains robust against common removal attacks.

cs.CR↗