Mitigating Model Poisoning and Tampering in Consumer IoT With HMAC in Split Federated Learning
Shahid Latif, Jawad Elsayed Ahmad, Wajdan Al Malwi, Fatima Asiri, Noha Alnazzawi, Jing Yang, Thippa Reddy Gadekallu · IEEE Transactions on Consumer Electronics · 2025
The Consumer Internet of Things (CIoT) is rapidly transforming multiple aspects of daily life. To optimize routine operations, ensure the privacy of valuable consumer data, and enhance decision-making, CIoT devices require the adaptation of distributed machine learning frameworks such as Split Federated Learning (SFL). SFL combines the key strengths of Federated Learning (FL) and Split Learning (SL) to promote resource and communication efficiency. However, SFL architectures are susceptible to several potential security threats, such as model poisoning and data tampering, which may compromise the integrity and performance of the entire CIoT network. To address these significant security issues, this article proposes a lightweight and efficient SFL architecture integrated with Hash-based Message Authentication Code (HMAC). In the proposed framework, HMAC ensures the authenticity and integrity of model updates by generating and verifying cryptographic signatures using three well-known SHA3 hash variants. To analyze the effectiveness of the designed security framework, a comprehensive evaluation model was developed to simulate and examine the behavior of the SFL architecture under model poisoning and tampering attacks. The designed model exhibited a higher attack detection accuracy of 98.19% across different client configurations. The system demonstrated good computational efficiency with an average attack detection time of 12.09 ms. Experimental outcomes confirm the improved attack detection performance, scalability, and reduced latency of our architecture, making it a promising approach to secure SFL-enabled CIoT applications.