Adversarial Latency Watermarking: Covertly Encoding Zero Bit Keys in Federated Learning Model Updates

Authors

  • Barakat Saad Ibrahim College of Medicine, Al Muthanna University, Samawah, Iraq
  • Ahmed Hameed Shakir College of Medicine, Al Muthanna University, Samawah, Iraq
  • Hasan Jameel Azooz College of Medicine, Al Muthanna University, Samawah, Iraq

DOI:

https://doi.org/10.71229/v37bk664

Keywords:

Federated learning ,Latency Watermarking ,differential privacy, secure aggregation Spread spectrum coding

Abstract

Federated learning (FL) protects client data by sharing only model updates, yet current defences ignore timing metadata. We show that a single malicious client can embed a 128 bit cryptographic key into the final global model by modulating update latency alone, bypassing gradient-value inspections, differential privacy (DP), and secure aggregation (SecAgg). We model the latency-to-weight channel as an additive white Gaussian noise (AWGN) process with CPU jitter and derive its information-theoretic capacity, demonstrating that 134 rounds suffice to transmit 128 bits at ε=500 μs. We design Jitter Deconv, a spread-spectrum encoder/decoder that maps Gold-code delays to weight-space imprints and recovers keys with bit-error rate (BER) 1.02×10⁻³ under DP-SGD (σ=10⁻²) and SecAgg. To detect the covert channel, we introduce Latency Print, a lightweight autocovariance-based statistic achieving AUC=0.98 and ≤0.7 % false-positive rate with <0.1 % CPU overhead. Experiments on CIFAR-10, FEMNIST, and Stack Overflow under realistic FL hyperparameters and hardware time-stamping (PTP, ±1 μs) confirm that our attack incurs ≤0.18 % accuracy degradation and survives network congestion. We further compare Latency Print to an SVM-based arrival-pattern classifier, demonstrating superior detection speed and reliability. Our findings expose time as a first class security primitive in FL systems and recommend integrating timing randomization, lightweight monitoring, and scheduler level defenses into frameworks such as Tensor Flow Federated. 

References

[1] H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication efficient learning of deep networks from decentralized data,” in Proc. Int. Conf. Artificial Intelligence and Statistics (AISTATS), 2017, pp. 1273–1282.

[2] M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proc. ACM Conf. Computer and Communications Security (CCS), 2016, pp. 308–318.

[3] K. Bonawitz, V. Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy preserving machine learning,” in Proc. ACM Conf. Computer and Communications Security (CCS), 2017, pp. 1175–1191.

[4] P. Kairouz et al., “Advances and open problems in federated learning,” Foundations and Trends in Machine Learning, vol. 14, no. 1–2, pp. 1–210, 2021.

[5] E. Bagdasaryan et al., "How to backdoor federated learning," in Proc. Int. Conf. Artificial Intelligence and Statistics (AISTATS), 2020, pp. 2938–2948.

[6] L. Zhu, Z. Liu, and S. Han, “Deep leakage from gradients,” in Advances in Neural Information Processing Systems (NeurIPS), vol. 32, 2019.

[7] P. Kairouz et al., “Advances and Open Problems in Federated Learning,” Foundations and Trends in Machine Learning, vol. 14, no. 1–2, 2021, pp. 1–210.

[8] Pillutla, Krishna, Sham M. Kakade, and Zaid Harchaoui. "Robust aggregation for federated learning." IEEE Transactions on Signal Processing 70 (2022): 1142-1154.

[9] Fumiyuki Kato et al., Olive: Oblivious Federated Learning on Trusted Execution Environment against the Risk of Sparsification, VLDB 2023

[10] L. Cao, M. Li, and J. Liu, “FLTrust: Byzantine robust federated learning via trust bootstrapping,” in Proc. Network and Distributed System Security Symp. (NDSS), 2021.

[11] S. J. Murdoch and S. Lewis, “Embedding covert channels into TCP/IP,” in Proc. Int. Workshop Information Hiding, 2005, pp. 247–261.

[12] Lipp, Moritz, et al. "PLATYPUS: Software-based power side-channel attacks on x86." 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 2021.

[13] Giechaskiel, Ilias, Shanquan Tian, and Jakub Szefer. "Cross-VM covert-and side-channel attacks in cloud FPGAs." ACM Transactions on Reconfigurable Technology and Systems 16.1 (2022): 1-29.

[14] Kosasih, William, et al. "SoK: Can we really detect cache side-channel attacks by monitoring performance counters?." Proceedings of the 19th ACM Asia Conference on Computer and Communications Security. 2024.

[15] J. Hayes, L. Melis, G. Danezis, and E. De Cristofaro, “LOGAN: Membership inference attacks against generative models,” in Proc. Privacy Enhancing Technologies Symp. (PETS), 2019, pp. 133–152.

[16] Li, B., Fan, L., Gu, H., Li, J., & Yang, Q. (2022). FedIPR: Ownership verification for federated deep neural network models. IEEE Transactions on Pattern Analysis and Machine Intelligence, 45(4), 4521-4536.

[17] Yang, Wenyuan, et al. "Watermarking in secure federated learning: A verification framework based on client-side backdooring." ACM Transactions on Intelligent Systems and Technology 15.1 (2023): 1-25.

[18] Bansal, Arpit, et al. "Certified neural network watermarks with randomized smoothing." International Conference on Machine Learning. PMLR, 2022.

[19] S. Rajput, H. Wang, Z. Charles, and D. Papailiopoulos, “DETOX: A redundancy based framework for faster and more robust gradient aggregation,” in Proc. Advances in Neural Information Processing Systems (NeurIPS), vol. 32, 2019.

[20] C. Xie, O. Koyejo, and I. Gupta, “Fall of empires: Breaking Byzantine tolerant SGD by inner product manipulation,” in Proc. Conf. Uncertainty in Artificial Intelligence (UAI), 2020, pp. 83–92.

[21] J. Pineau et al., “Improving reproducibility in machine learning research: A report from the NeurIPS 2019 reproducibility program,” J. Mach. Learn. Res., vol. 22, no. 164, pp. 1–20, 2021.

fig 1

Downloads

Published

2026-08-15

Issue

Section

Original Articles

How to Cite

Adversarial Latency Watermarking: Covertly Encoding Zero Bit Keys in Federated Learning Model Updates. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(3), 202-213. https://doi.org/10.71229/v37bk664