PP-FedDT: Securing Digital Twin Federated Learning Against Persistent and Adaptive Poisoning Attacks

Document Type

Article

Source of Publication

IEEE Transactions on Consumer Electronics

Publication Date

1-1-2026

Abstract

Federated Learning (FL) operates over non-IID client data with heterogeneous distributions and quality, which complicates convergence and makes it hard to distinguish benign irregularities from malicious behavior. FL is increasingly adopted to train edge digital twins (DTs). Healthcare applications such as CVD risk prediction across hospital networks demand both privacy preservation and model integrity, making poisoning resilience critical. Attackers can inject or compromise clients to submit manipulated updates that poison the global model, either untargeted with widespread degradation or targeted via backdoors that misclassify trigger inputs while preserving overall accuracy. DT-FL must protect privacy, preserve integrity, and resist adaptive poisoning where attackers adjust updates after observing global models and defenses. Existing defenses rely mainly on robust aggregation and often assume few adversaries, abundant attack evidence per round, or access to a clean validation set. They also overlook the dynamics of early training phases where small degradations can cause lasting harm. We propose a Privacy-Preserving Federated Digital Twin (PP-FedDT) framework that secures federated digital twin learning using private bounded updates, verifiable update compliance, and DT-assisted participant screening. Each client clips and noise-perturbs its local update, then submits a cryptographic commitment alongside a zero-knowledge proof certifying norm boundedness, encoding validity, and commitment correctness. At the edge, digital twin metadata and update similarity graphs are analyzed to detect Sybil or colluding participants, and suspicious contributions are removed prior to aggregation. The remaining updates are aggregated robustly using parameter-level trimming and adaptive weighting to suppress abnormal coordinate values. Influence is then monitored across rounds to regulate or exclude persistently harmful clients, maintaining correctness, privacy, and resistance to adaptive poisoning. Experiments on standard benchmarks show improved robustness, stability, and accuracy over FedAvg, Krum, Trimmed mean and Median.

ISSN

0098-3063

Publisher

Institute of Electrical and Electronics Engineers (IEEE)

Disciplines

Computer Sciences

Keywords

Digital Twin, Federated Learning, Model Poisoning Attack, Robustness, Secure Aggregation

Scopus ID

105043578579

Indexed in Scopus

yes

Open Access

no

Share

COinS