Detection and Mitigation of Adversarial Attacks in Federated Learning for IoT Networks

Loading...
Thumbnail Image

Date

Journal Title

Journal ISSN

Volume Title

Publisher

Setif 1 University - Ferhat ABBAS , Faculty of Sciences

Abstract

The rapid expansion of the Internet of Things (IoT) has transformed data collection across critical sectors, particularly healthcare. While Federated Learning (FL) offers a promising paradigm by enabling collaborative model training without centralizing sensitive data, its distributed architecture introduces significant security and privacy vulnerabilities. This thesis investigates the detection and mitigation of adversarial attacks in FL systems deployed over IoT networks. We focus on a realistic cross-silo medical scenario in which multiple hospitals collaboratively train a chest X-ray disease detection model based on the DenseNet-121 architecture. We first demonstrate the vulnerability of standard FL to white-box Membership Inference Attacks (MIA), revealing how data overlap between training and test sets creates exploitable structural backdoors that enable an attacker to determine whether a specific patient’s data was used during training. To counter these threats, we propose a progressive defense-in-depth strategy combining three complementary layers: (1) structural data reorganization through patient-level splitting combined with Low-Rank Adaptation (LoRA) fine-tuning, (2) Selective Differential Privacy with temperature scaling for mathematical noise injection, and (3) Homomorphic Encryption (HE) for securing the communication channel between clients and the server. Experimental results demonstrate that our integrated layered defense effectively reduces the attacker’s success rate to random chance while preserving the diagnostic performance of the model, proving that secure and privacy-preserving collaborative AI over IoT networks is practically achievable.

Description

أدّى التوسع السريع لإنترنت الأشياء إلى تحويل عملية جمع البيانات في القطاعات الحيوية، وخاصةً الرعاية الصحية. رغم أن التعلم التعلم الموحّد يُقدّم نموذجاً واعداً من خلال تمكين التدريب التعاوني للنماذج دون مركزة البيانات الحساسة، إلا أن بنيته الموزعة تُدخل ثغرات أمنية كبيرة تتعلق بالأمان والخصوصية. تبحث هذه المذكرة في كشف والتخفيف من الهجمات العدائية في أنظمة التعلم الموحّد المنشورة على شبكات إنترنت الأشياء. نركّز على سيناريو طبي واقعي من نوع حيث تتعاون عدة مستشفيات لتدريب نموذج للكشف عن الأمراض من صور الأشعة السينية للصدر باستخدام بنية . نُثبت أولاً ضعف التعلم الموحّد القياسي أمام هجمات استنتاج جموعات التنظيم الهيكلي للبيانات عبر الفصل على مستوى المريض مع التكيّف منخفض الرتبة، ثانياً الخصوصية التفاضلية الانتقائية مع تعديل درجة الحرارة لحقن الضوضاء الرياضية، وثالثاً التشفير المتجانس لتأمين قناة الاتصال بين العملاء والخادم. تُظهر النتائج التجريبية أن دفاعنا المتكامل متعدد الطبقات يُقلّل بفعالية معدل نجاح المهاجم إلى مستوى الصدفة مع الحفاظ على الأداء التشخيصي للنموذج، مما يُثبت أن الذكاء الاصطناعي التعاوني الآمن والمحافظ على الخصوصية عبر شبكات إنترنت الأشياء قابلالتدريب والاختبار أبواباً خلفية هيكلية قابلة للاستغلال تُمكّن المهاجم من تحديد ما إذا كانت بيانات مريض معيّن قد استُخدمت أثناء التدريب. لمواجهة هذه التهديدات، نقترح استراتيجية دفاع متعددة الطبقات تجمع بين ثلاث طبقات متكاملة: أولاً إعادةالعضوية من نوع الصندوق الأبيض، كاشفين كيف يُنشئ تداخل البيانات بين م للتحقيق عمليا

Citation

Endorsement

Review

Supplemented By

Referenced By