Differentially Private Federated Adversarial Learning for Robust Malware Detection in Internet of Health Things (IoHTs)
Mohamed Amjath, Shagufta Henna · 2025
The Federated Learning (FL) approach in the Internet of Health Things (IoHT) is vulnerable to membership inference attacks (MIAs) and adversarial attacks such as model poisoning, both of which threaten privacy and robustness. Model poisoning attacks compromise the global model by aggregating malicious client updates, while MIAs exploit information leakage during FL communication. Current techniques for FL robustness, such as adversarial training and differential privacy (DP) address these threats differently. DP provides the benefit of noise injection into gradients, ensuring privacy for data shared on a central aggregation server while maintaining a privacy-utility trade-off. However, it is not robust against model poisoning attacks on clients in a collaborative FL deployment within the IoHs. To address the challenges with the robustness of the DP, this work proposes a differentially private federated adversarial training (DP-FAT), integrating adversarial training with DP (DP-PGD and DP-FGSM). Using the ClaMP_Integrated-5184 dataset, proposed DP-FAT approach ensures a robust malware detection model while preserving privacy. Experimental results demonstrate that DP-FAT mitigates adversarial attacks and protects sensitive data during federated rounds, offering a scalable solution for secure IoHTs. Furthermore, privacy-utility trade-offs for DP- PGD reveal optimal Rényi Differential Privacy (RDP) guarantees, with configurations such as$(\alpha=3, \epsilon=6)$or$(\alpha=2,\ \epsilon\in[5,7])$effectively balancing robustness and privacy in IoHT malware detection systems.