Explainability-Aware Adversarial Threats and Mitigation in Federated Learning Based Anomaly Detection for Cooperative Smart Farming
Lopamudra Praharaj, Maanak Gupta, Deepti Gupta · 2025
Cooperative Smart Farming (CSF) provides an effective solution to address the evolving needs of smart farming, making precision agriculture more accessible to small-scale farmers. These cooperatives are formal enterprises collectively financed, managed, and operated by member farms, working together for shared benefits. However, CSFs face increased security risks, since a cyberattack on one farm can disrupt the entire network, threatening data integrity and decision-making. Federated Learning (FL) offers a robust solution that enables distributed learning by maintaining a global model across the cloud server and multiple client farms on each edge node, where the global model is trained on the client's model parameter without accessing the client's private data. This paper demonstrates that FL-based network anomaly detection systems in CSF are vulnerable to data poisoning adversarial attacks. We present a novel poisoning attack strategy in which an adversary identifies and exploits the most essential features of the dataset using Explainable AI techniques. Using the Explainability-informed features, the adversary can perform targeted data poisoning attacks using the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks against the trained Convolutional Neural Network (CNN) classifier. Our experimental results indicate that the accuracy of the FL model declines significantly when adversaries poison data by manipulating essential features compared to random perturbations. We also propose a defense mechanism leveraging DistilBERT, a lightweight language model deployed on each local client to mitigate this adversarial attack. Our defense approach effectively filters out poisoned data using cosine similarity, restoring model robustness and accuracy.