PP-FedTrust: Securing Federated Learning Against Adaptive Poisoning Attacks
Document Type
Conference Proceeding
Source of Publication
2026 IEEE Wireless Communications and Networking Conference Workshops Wcncw 2026
Publication Date
4-13-2026
Abstract
Federated Learning (FL) is increasingly considered for ultra-reliable low-latency communications and secure 6 G RANs where edge devices train shared models under tight latency and privacy constraints. FL operates over non IID client data with heterogeneous distributions and quality. This complicates convergence and blurs the boundary between benign irregularities and malicious behavior. Attackers can compromise clients or inject Sybil participants to submit manipulated updates that poison the global model. The impact can be untargeted with broad accuracy collapse or targeted through backdoors that misclassify trigger inputs while keeping aggregate accuracy deceptively high. Existing defenses rely mainly on robust aggregation and often assume few adversaries or clear attack evidence in every round or access to a clean validation set. They also overlook early training phases where small degradations can cause lasting harm which is critical for URLLC control loops and RAN automation. In this paper, We propose PP-FedTrust, a practical framework that combines game theoretic aggregation, incentive aware client objectives, and model side verification to improve robustness under realistic constraints. The server applies similarity penalized reweighting with online replicator dynamics to suppress collusion while retaining useful signal under non IID participation. Clients optimize an objective that penalizes deviant updates and aligns with server hints, exposing rotating adversaries without accessing client data. The model layer protects top k sensitive parameters, applies selective homomorphic encryption, and projects away misaligned drifts. A fairness regularized schedule adaptively blends Multi Krum preferences with Trimmed Mean fallback. Experiments on standard benchmarks show improved robustness, stability, and accuracy over FedAvg, Krum, Trimmed mean and Median.
DOI Link
ISBN
[9798331577315]
Publisher
IEEE
Disciplines
Computer Sciences
Keywords
Fairness, Federated Learning, Model Poisoning Attack, Robustness, Secure Aggregation
Scopus ID
Recommended Citation
Tariq, Asadullah; Sallabi, Farag M.; Serhani, Mohamed Adel; Qayyum, Tariq; Barka, Ezedin S.; and Taleb, Ikbal, "PP-FedTrust: Securing Federated Learning Against Adaptive Poisoning Attacks" (2026). All Works. 8233.
https://zuscholars.zu.ac.ae/works/8233
Indexed in Scopus
yes
Open Access
no