PP-FedTrust: Securing Federated Learning Against Adaptive Poisoning Attacks

Document Type

Conference Proceeding

Source of Publication

2026 IEEE Wireless Communications and Networking Conference Workshops Wcncw 2026

Publication Date

4-13-2026

Abstract

Federated Learning (FL) is increasingly considered for ultra-reliable low-latency communications and secure 6 G RANs where edge devices train shared models under tight latency and privacy constraints. FL operates over non IID client data with heterogeneous distributions and quality. This complicates convergence and blurs the boundary between benign irregularities and malicious behavior. Attackers can compromise clients or inject Sybil participants to submit manipulated updates that poison the global model. The impact can be untargeted with broad accuracy collapse or targeted through backdoors that misclassify trigger inputs while keeping aggregate accuracy deceptively high. Existing defenses rely mainly on robust aggregation and often assume few adversaries or clear attack evidence in every round or access to a clean validation set. They also overlook early training phases where small degradations can cause lasting harm which is critical for URLLC control loops and RAN automation. In this paper, We propose PP-FedTrust, a practical framework that combines game theoretic aggregation, incentive aware client objectives, and model side verification to improve robustness under realistic constraints. The server applies similarity penalized reweighting with online replicator dynamics to suppress collusion while retaining useful signal under non IID participation. Clients optimize an objective that penalizes deviant updates and aligns with server hints, exposing rotating adversaries without accessing client data. The model layer protects top k sensitive parameters, applies selective homomorphic encryption, and projects away misaligned drifts. A fairness regularized schedule adaptively blends Multi Krum preferences with Trimmed Mean fallback. Experiments on standard benchmarks show improved robustness, stability, and accuracy over FedAvg, Krum, Trimmed mean and Median.

ISBN

[9798331577315]

Publisher

IEEE

Disciplines

Computer Sciences

Keywords

Fairness, Federated Learning, Model Poisoning Attack, Robustness, Secure Aggregation

Scopus ID

105043406230

Indexed in Scopus

yes

Open Access

no

Share

COinS