Enhancing Proof-of-Learning Security Against Spoofing Attacks Using Model Watermarking

Published in Doctoral Dissertation, 2025

Doctoral dissertation, Ph.D. in Electrical Engineering and Computer Science, Embry-Riddle Aeronautical University (Daytona Beach, Florida). Advisor: Dr. Kenji Yoshigoe.

The attack it answers

Proof-of-Learning verifies the computational effort behind a trained model, but on its own it can be spoofed by attacks that manipulate its subset-verification pathways and tolerance parameters. The dissertation first shows how an adversary can replicate the computational trajectory of a legitimate model and, under surrogate-training conditions, even approximate an embedded watermark.

The framework

The proposed framework, SecurePoL, closes that gap by coupling PoL’s training logs with three orthogonal watermarking strategies: feature-based embedding, parameter perturbation, and non-intrusive auxiliary heads. Verification then becomes a joint condition, so a forger has to reproduce both an authentic training log and a watermark-consistent ownership signal, rather than either one alone.

What it costs, measured

On CIFAR-10 with ResNet-20:

  • The computational effort required for successful blindfold Top-Q and infinitesimal-update attacks rises by more than an order of magnitude.
  • Ownership verification costs almost no utility: baseline accuracy changes by +0.00 pp with feature-based watermarking, 0.03 pp with non-intrusive heads, and 0.58 pp with parameter perturbation.

Read the full dissertation in ERAU Scholarly Commons. The watermarking-plus-PoL construction is also published as SecurePoL in IEEE Access (2025), and there is an animated explainer in the Research Lab.

Recommended citation: Ural, O. (2025). Enhancing Proof-of-Learning Security Against Spoofing Attacks Using Model Watermarking. Doctoral dissertation, Embry-Riddle Aeronautical University.
Read paper