Blockchain‐Based AI Intelligent Systems in Healthcare: A Decentralized Federated Learning Framework With Zero Trust
Martin George Wynn, Sepideh Mollajafari, Joe Cox, Mah-Rukh Fida, Md. Hasibul Alam Ratul · International Journal of Intelligent Systems · 2026
Artificial intelligence (AI), blockchain (BC), and federated learning (FL) offer significant potential for strengthening data privacy, security, and decentralized decision‐making in healthcare. However, healthcare AI systems remain vulnerable to adversarial threats, including data poisoning, Byzantine behavior, Sybil attacks, and unauthorized access. This article provides an integrative review of the pertinent literature from which a conceptual framework for exploring the relationship between BC, FL, and Zero Trust (ZT) is developed in the context of AI in healthcare. An experimental framework for a ZT approach based on BC and FL is then designed, tested, and evaluated. The framework combines strict identity verification, permissioned BC access control, immutable auditability, decentralized model training, and history‐aware threat detection to enhance robustness while preserving data privacy. A series of simulations was conducted to evaluate the framework under poisoning, Byzantine, and Sybil attack scenarios, using F 1‐score as the primary model‐performance metric and latency, gas cost, and throughput as BC‐performance metrics. The results show that poisoning clients were consistently detected and excluded once adversarial behavior began, with only minor temporary performance degradation and subsequent recovery of global model performance. Under Byzantine attacks, the proposed history‐aware trust filter improved the global F 1‐score across evaluated configurations, including an increase from 0.7762 under attack to 0.9117 with defense in one configuration. BC operations remained efficient, with latency generally between approximately 19 and 39 ms and throughput of 31.65 transactions per second, although upload operations incurred the highest gas cost. Sybil attack experiments further confirmed that cryptographic identity verification and permissioned access control prevented malicious identities from affecting the FL process, while attack cost increased linearly with no operational gain. The findings demonstrate that the proposed framework can effectively balance privacy preservation, adversarial robustness, auditability, and performance, making it a promising approach for secure healthcare systems.