Back to results

Embry Riddle Aeronautical University

Enhancing Proof-of-Learning Security Against Spoofing Attacks Using Model Watermarking

Abstract

dc:description.abstract

<p>With the rapid expansion of machine learning (ML) technologies across diverse domains such as healthcare, finance, and autonomous systems, ensuring secure and trustworthy training methodologies has become more critical than ever. Proof-of-Learning (PoL) has recently emerged as a foundational mechanism for verifying the computational effort invested in training ML models, thereby certifying the authenticity and reproducibility of the training process. Yet PoL, when deployed in isolation, remains vulnerable to sophisticated spoofing attacks that manipulate its subset-verification pathways and tolerance parameters. In parallel, model watermarking has become indispensable for safeguarding intellectual property and detecting unauthorized model usage. Motivated by these complementary strengths, this dissertation proposes a robust dual-layer verification framework that integrates Proof-of-Learning (PoL) with three distinct watermarking strategies: feature-based embedding, parameter perturbation, and non-intrusive auxiliary heads, to provide comprehensive end-to-end security and integrity. We first systematically analyze existing PoL schemes and reveal how adversaries can replicate the computational trajectories of legitimate models and, under surrogate-training conditions, even approximate embedded watermarks. The enhanced PoL mechanism introduced here mitigates these vulnerabilities by coupling robust watermarking techniques with PoL's immutable training logs, thereby requiring attackers, even if they possess the watermark key, to reproduce both authentic logs and watermark-consistent ownership signals at a computational cost comparable to honest fine-tuning. Comprehensive experiments on the CIFAR-10 benchmark with ResNet-20 demonstrate that the integrated approach increases the computational effort required for successful blindfold Top-Q and infinitesimal-update attacks by more than an order of magnitude. Empirical results confirm the practical viability of the framework: feature-based watermarking preserved baseline accuracy with a change of +0.00 % pp, non-intrusive methods yielded a change of -0.03 % pp, and parameter perturbation incurred a change of -0.58 % pp, showcasing a clear fidelity-robustness trade-off. The computational overhead relative to standard PoL ranged from 0.6 % runtime for parameter perturbation to approximately 11–17 % runtime for the non-intrusive and feature-based schemes. In comparison, proof-log storage overhead remained below 12 MB. Extensive empirical analyses across watermark strengths, adversarial scenarios, and performance metrics substantiate that augmenting PoL with a flexible, multi-technique watermarking layer yields heightened security and robust resilience to spoofing attacks. While each watermarking strategy introduces distinct trade-offs in stealth, complexity, and fidelity, their integration achieves a practical balance between security hardening and deployment efficiency. By exposing critical weaknesses in prior PoL frameworks and providing cost-amplifying countermeasures, this dissertation positions the integrated PoL-watermarking framework as a blueprint for advancing secure, accountable, and tamper-evident ML systems. These findings guide future verification mechanisms safeguarding computational integrity and model ownership in next-generation ML deployments.</p>

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy in Electrical Engineering & Computer Science
Level thesis:degree_level
Dissertation - Open Access
Discipline thesis:degree_discipline
Electrical Engineering and Computer Science
Year
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Ural, Ozgur

Subjects

dc:subject × 10

Identifiers

dc:identifier.*
Repository record dc:identifier
https://commons.erau.edu/edt/905
OAI identifier oai:identifier
oai:commons.erau.edu:edt-1944

Chain of custody

source
Harvested from
Embry Riddle Aeronautical University
Base URL
commons.erau.edu/do/oai/
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Ural, Ozgur. Enhancing Proof-of-Learning Security Against Spoofing Attacks Using Model Watermarking. Dissertation - Open Access thesis, 2025. https://commons.erau.edu/edt/905