GRASP-FL: A Closed-Loop Defence Framework Against Adaptive Backdoor Attacks in Federated Learning
Ahmed Soliman, Khalid M. Amin, Noura A. Semary, Hayam Mousa · IEEE Access · 2026
Federated Learning (FL) enables decentralised model training without sharing raw data, but remains highly vulnerable to adaptive backdoor attacks that embed hidden triggers while maintaining high accuracy on clean data. This paper presents GRASP-FL, a robust closed-loop defence framework that addresses evolving threats in realistic non-IID FL environments. GRASP-FL integrates four coordinated modules: (1)anchor-free geometric screeningvia principal angle divergence; (2)reputation-aware aggregationwith adaptive trimming; (3)layer-wise sanitisation combiningadversarial pruning and differential privacy; and (4)GAN-guided feedback adaptationfor dynamic reconfiguration. Crucially, GRASP-FL operates without access to client data, trusted infrastructure, or ground-truth labels, ensuring privacy-preserving operation. Comprehensive evaluations on CIFAR-10, FEMNIST, and MNIST including intermittent attacks and varying adversarial strengths (10%–30% malicious clients) demonstrate clean accuracy up to 97.25%, suppression of attack success rates to below 10%, and false positive rates under 5%, outperforming state-of-the-art baselines. Theoretical analysis establishes formal guarantees on convergence under poisoning, geometric separability of malicious activations, and stability of the closed-loop adaptation. These results position GRASP-FL as a practical, scalable, and privacy-preserving defence for federated learning deployments in security-critical domains such as healthcare, finance, and autonomous systems.