Skip to content
#federated learning Open access

Trustworthy and privacy-preserving decentralized federated learning with multi-layer defense for secure collaborative AI

Sep 2026 · Discover Artificial Intelligence · Vol 6 · 0 citations · 24 references
Privacy-Preserving Technologies in Data

TL;DR

These findings demonstrate that the proposed framework provides an effective balance between privacy preservation, adversarial robustness, and trustworthy decentralized collaborative learning for secure AI-driven systems.

Abstract

Decentralized Federated Learning (DFL) enables collaborative artificial intelligence model training without centralizing sensitive data, making it suitable for privacy-critical and distributed intelligent systems such as healthcare, Industrial IoT, and smart digital infrastructure. Despite its advantages, DFL remains vulnerable to privacy leakage through shared model updates and to model poisoning and backdoor attacks that compromise system reliability, robustness, and trustworthiness. Existing defense mechanisms primarily address either privacy preservation or poisoning robustness independently and often exhibit limited effectiveness under adaptive or high-ratio adversarial settings. This work proposes a trustworthy and privacy-preserving decentralized federated learning framework that jointly addresses these challenges through two integrated components: (i) a hybrid privacy mechanism based on public dataset pretraining followed by differentially private fine-tuning, and (ii) a multi-layer model defense architecture designed to mitigate poisoning and backdoor attacks across decentralized peer-to-peer environments. The framework integrates local data sanitization, peer-side model verification, robust trimmed-mean aggregation, and runtime inference protection to provide defense-in-depth across both training-time and inference-time attack surfaces. An adversary model and operational assumptions are formally defined, and the framework is evaluated under strong adversarial conditions, including a 20% poisoning ratio. Experimental results demonstrate consistent robustness improvements over a vanilla DFL baseline. While the baseline model achieves a clean accuracy of 83.10%, the proposed framework improves clean performance to 86.12%. Under adversarial conditions, accuracy improves from 37.71% to 53.88% for Fast Gradient Sign Method (FGSM) attacks, from 21.75% to 46.40% for Projected Gradient Descent (PGD) attacks, and from 40.62% to 67.35% for Carlini–Wagner (CW) attacks. For backdoor-based poisoning attacks such as BadNets and Blended attacks, the defense pipeline restores model accuracy to above 86% while maintaining stable benign performance. These findings demonstrate that the proposed framework provides an effective balance between privacy preservation, adversarial robustness, and trustworthy decentralized collaborative learning for secure AI-driven systems.

Read PDF

Similar papers

#federated learning Open access Sep 2026

RetFL: a privacy-preserving and traceable framework for robust federated learning

Federated learning (FL) enables multiple clients to jointly train a model without sharing raw data. Decentralized federated learning (DFL) further removes the need for a trusted central coordinator in the aggregation process. However, in decentralized settings, model aggregation is vulnerable to inference and poisoning...

Yi-Cheng Huang, Zhou Zhou, You-Liang Tian et al. · 0 citations
Open access 2026

Privacy-Preserving and Byzantine-Robust Federated Learning With Mean-Constrained Secret Sharing

Federated learning faces three critical challenges in enabling cross-institutional collaboration: privacy leakage, poisoning by malicious clients, and unverifiable aggregation results. To address these issues in a unified manner, we propose PVeriFL—a federated learning framework that integrates privacy preservation, By...

Guang-Ye Zhu, Liqiang Wu, Ke-Qian Liu · 0 citations
Sep 2026

SHFL-EI: Secure Hierarchical Federated Learning with Edge Intelligence for Robust IoT Security

The rapid proliferation of Internet of Things (IoT) systems has significantly increased the attack surface of modern cyber-physical infrastructures, creating the need for scalable, intelligent, and privacy-preserving security solutions. Traditional centralized intrusion detection approaches are limited by high communic...

Afef Slimani, K. Karoui · 0 citations
Conference Aug 2026

Big data privacy protection and data security based on deep learning

A federated deep learning framework that systematically integrates adaptive privacy noise mechanisms and trust-weighted aggregation within a distributed architecture that ensures the protection of sensitive data during collaborative analysis through precise differential privacy control and advanced neural network model...

Chang-Wen Xu, Yanqing Ding, Rui Ding · 0 citations
2026

Differential Privacy Enabled Cascaded Filter for Efficient and Privacy-Preserving Federated Learning

Federated learning (FL) enables collaborative model training across multiple clients in a privacy-preserving manner. However, the employment of homomorphic encryption algorithms might lead to high computational cost while the application of differential privacy (DP) methods would sacrifice model performance. To establi...

Zhiqiang Chen, Yuchen Jiang, Ray Y. Zhong et al. · 0 citations

Related blog posts

Microsoft Research Blog Sep 30, 2026

Forecasting space weather risks on power grids

Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.