PP-FedDT: Securing Digital Twin Federated Learning Against Persistent and Adaptive Poisoning Attacks
Document Type
Article
Source of Publication
IEEE Transactions on Consumer Electronics
Publication Date
1-1-2026
Abstract
Federated Learning (FL) operates over non-IID client data with heterogeneous distributions and quality, which complicates convergence and makes it hard to distinguish benign irregularities from malicious behavior. FL is increasingly adopted to train edge digital twins (DTs). Healthcare applications such as CVD risk prediction across hospital networks demand both privacy preservation and model integrity, making poisoning resilience critical. Attackers can inject or compromise clients to submit manipulated updates that poison the global model, either untargeted with widespread degradation or targeted via backdoors that misclassify trigger inputs while preserving overall accuracy. DT-FL must protect privacy, preserve integrity, and resist adaptive poisoning where attackers adjust updates after observing global models and defenses. Existing defenses rely mainly on robust aggregation and often assume few adversaries, abundant attack evidence per round, or access to a clean validation set. They also overlook the dynamics of early training phases where small degradations can cause lasting harm. We propose a Privacy-Preserving Federated Digital Twin (PP-FedDT) framework that secures federated digital twin learning using private bounded updates, verifiable update compliance, and DT-assisted participant screening. Each client clips and noise-perturbs its local update, then submits a cryptographic commitment alongside a zero-knowledge proof certifying norm boundedness, encoding validity, and commitment correctness. At the edge, digital twin metadata and update similarity graphs are analyzed to detect Sybil or colluding participants, and suspicious contributions are removed prior to aggregation. The remaining updates are aggregated robustly using parameter-level trimming and adaptive weighting to suppress abnormal coordinate values. Influence is then monitored across rounds to regulate or exclude persistently harmful clients, maintaining correctness, privacy, and resistance to adaptive poisoning. Experiments on standard benchmarks show improved robustness, stability, and accuracy over FedAvg, Krum, Trimmed mean and Median.
DOI Link
ISSN
Publisher
Institute of Electrical and Electronics Engineers (IEEE)
Disciplines
Computer Sciences
Keywords
Digital Twin, Federated Learning, Model Poisoning Attack, Robustness, Secure Aggregation
Scopus ID
Recommended Citation
Taleb, Ikbal; Tariq, Asadullah; Serhani, Mohamed Adel; Din, Irfanud; Zafar, Afia; and Ahmed, Shabir, "PP-FedDT: Securing Digital Twin Federated Learning Against Persistent and Adaptive Poisoning Attacks" (2026). All Works. 8225.
https://zuscholars.zu.ac.ae/works/8225
Indexed in Scopus
yes
Open Access
no