Advanced Privacy and Security Techniques in Federated Learning Against Sophisticated Attacks

Hariprasad Holla, Arun Ambika Sasikumar, Chandu Gutti, Karthik Thumula, Hemanth Gogineni · 2025

This paper addresses the growing vulner-ability of federated learning (FL) systems to sophis-ticated attacks such as model poisoning, Byzantine behavior, and privacy leaks. These threats are critical in sensitive domains (healthcare, finance), where data confidentiality and model integrity are paramount. We propose PRIVFED-AD, a privacy-preserving FL framework integrating adaptive noise injection, ro-bust aggregation, and intelligent attack detection. Our approach dynamically adjusts privacy budgets and employs real-time anomaly detection to mitigate mali-cious activity in large-scale FL deployments. Exper-iments on MNIST, CIFAR-I0, and Healthcare IoT show reductions in attack success rates: 71.7% (model poisoning), 70.6% (Byzantine), 74.7% (reconstruction), and 22.9% (membership inference). Despite height-ened security measures, PRIVFED-AD maintains up to 89.6% accuracy under moderate privacy settings, with robust performance (76.8% accuracy) at 30% malicious clients. We present (1) a unified architecture that balances differential privacy and secure aggre-gation, (2) provable convergence under adversarial conditions, (3) rigorous evaluation across heteroge-neous datasets, and (4) guidelines for large-scale, attack-resilient FL. Compared to existing frameworks, PRIVFED-AD achieves lower attack success rates yet sustains higher accuracy under adversarial settings, establishing a new benchmark for secure FL. Results highlight its potential to secure FL applications and preserve utility, offering a balance between defensive rigor and feasibility.

Read the paper · More papers on PaperTik