Server-Enforced Watermarking in U-Shaped Split Federated Learning
U-shaped split federated learning (U-SFL) enables resource-constrained Internet of Things devices to collaboratively train models with an edge server while retaining raw data and labels locally. We consider model-service deployments in which a provider supplies proprietary models whose client-side segments reside on participating devices, creating risks of unauthorized copying and redistribution. Protecting these segments is challenging because the server cannot directly access client data, labels, or model parameters, and potentially malicious clients may refuse to perform watermark embedding. To address this challenge, we propose Sigil, a server-enforced watermarking framework for U-SFL. Sigil defines a secret watermark constraint in the server-visible activation space and embeds the watermark into client-side models by injecting a watermark gradient into the gradients returned during training. This mechanism requires neither access to clients' raw data and labels nor client-side watermarking operations. To limit interference with the main task and reduce detectability by gradient anomaly detectors, Sigil adaptively clips the watermark gradient relative to the main-task gradient. Experiments on two datasets and four model architectures demonstrate high watermark detection rates with limited impact on task accuracy, robustness against the evaluated removal attacks, and stealthiness against the evaluated gradient anomaly detector.