Secflh- Defending Federated Learning-Based IoT Health Prediction Systems Against Poisoning Attacks
Sanoj Liyanage, Venuranga Weerawardhane, Jalitha Kheminda, Yushan Siriwardhana, Thilina N. Weerasinghe, Madhusanka Liyanage · 2025
Poisoning attacks in Federated Learning (FL) train the model to learn towards a malicious objective. While existing defenses against poisoning attacks are effective, their performance substantially degrades with the presence of non-IID (Independent and Identically Distributed) data. This paper introduces SecFLH, a novel defense mechanism for FL systems designed to counter targeted model poisoning attacks, particularly in non-IID data environments often encountered in healthcare IoT applications. Unlike traditional aggregation defenses, SecFLH employs a multi-step approach, incorporating cosine distance analysis, HDBSCAN clustering, centroid selection, and adaptive clipping to effectively isolate and exclude malicious client updates. Experimental results on benchmark datasets, including MNIST, CIFAR-10, and real-world healthcare data, validate SecFLH's robustness in maintaining model accuracy even with a high percentage of malicious clients. The proposed algorithm demonstrates resilience across varying non-IID scenarios, highlighting its practical potential for secure FL applications in dynamic, distributed environments.