AP-PPFL: An Anti-poisoning Privacy-preserving Federated Learning Method

preprint OA: closed
Full text JSON View at publisher

Abstract

Abstract Federated Learning (FL) has been widely used in Internet of Things (IoT) environments as a promising decentralized framework capable of collaborative model training without exposing local data. Despite its advantages, FL still encounters significant security challenges. In particular, semi-honest servers can potentially infer private information from the gradients shared by clients. Additionally, FL’s distributed nature opens up vulnerabilities to adversarial behavior, where malicious clients may submit manipulated gradients to degrade the global model's accuracy or hinder its convergence. Addressing privacy and robustness simultaneously is an enormous challenge, as most privacy-preserving approaches focus on securing gradients through encryption or noise injection, which obstructs the identification of malicious clients—an essential step in poisoning defense. To resolve this conflict, this work introduces AP-PPFL, a federated learning framework that integrates both privacy protection and poisoning defense. The proposed approach incorporates a voting-based parameter importance evaluation strategy and a cosine similarity-based mechanism to filter out harmful gradients. Furthermore, it leverages Paillier homomorphic encryption within a dual-server setup to maintain gradient confidentiality while enabling secure computation directly over encrypted data. Compared with conventional methods, AP-PPFL achieves a balanced improvement in both privacy-preserving and attack resilience, with comprehensive security analysis provided.
Full text 18,142 characters · extracted from preprint-html · click to expand
AP-PPFL: An Anti-poisoning Privacy-preserving Federated Learning Method | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article AP-PPFL: An Anti-poisoning Privacy-preserving Federated Learning Method Yongfei Li, Chen Fang, Chaowen Chang, Yuanbo Guo, Haodong Sun, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6821919/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Federated Learning (FL) has been widely used in Internet of Things (IoT) environments as a promising decentralized framework capable of collaborative model training without exposing local data. Despite its advantages, FL still encounters significant security challenges. In particular, semi-honest servers can potentially infer private information from the gradients shared by clients. Additionally, FL’s distributed nature opens up vulnerabilities to adversarial behavior, where malicious clients may submit manipulated gradients to degrade the global model's accuracy or hinder its convergence. Addressing privacy and robustness simultaneously is an enormous challenge, as most privacy-preserving approaches focus on securing gradients through encryption or noise injection, which obstructs the identification of malicious clients—an essential step in poisoning defense. To resolve this conflict, this work introduces AP-PPFL, a federated learning framework that integrates both privacy protection and poisoning defense. The proposed approach incorporates a voting-based parameter importance evaluation strategy and a cosine similarity-based mechanism to filter out harmful gradients. Furthermore, it leverages Paillier homomorphic encryption within a dual-server setup to maintain gradient confidentiality while enabling secure computation directly over encrypted data. Compared with conventional methods, AP-PPFL achieves a balanced improvement in both privacy-preserving and attack resilience, with comprehensive security analysis provided. Federated learning Poisoning defense Privacy-preserving Homomorphic encryption Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6821919","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":518733743,"identity":"5fe2143c-7b5e-4198-8cf3-9ee9e0141a8e","order_by":0,"name":"Yongfei Li","email":"","orcid":"","institution":"Information Engineering University","correspondingAuthor":false,"prefix":"","firstName":"Yongfei","middleName":"","lastName":"Li","suffix":""},{"id":518733744,"identity":"0429a9f8-1fda-484b-8536-56b8dbc4ee90","order_by":1,"name":"Chen Fang","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA6klEQVRIie3RMWvCQBTA8RdOXhEeZj2JJF8hItznuUPoZMGpZMgQUXRQ9/sYmWy7KYXrct0dU/wA1alOYjq3JHFzuN98f7j3HoDj3CGMvn+OxyQl/2G6K2SS1icdkMLT1oTdlRnGhTX1SVgmrD1ng1iPRPdrxhp8DLaPB0BUOYxEojIEf7GU1YmXfQzG1FMvYJ736rUH3H7m1QnzskBzVG+T6WavLELMn2oSZBBQzFT+DmKs5qxBQogByXJ80xLQLOHE+nr7u2QccmkN1c4SafKK06U8ZXTYnc5JGvqLdXXyB9323HEcx/nXFZBWR9iYSgeSAAAAAElFTkSuQmCC","orcid":"","institution":"Information Engineering University","correspondingAuthor":true,"prefix":"","firstName":"Chen","middleName":"","lastName":"Fang","suffix":""},{"id":518733745,"identity":"c23a7036-dad0-4bde-9260-5df0d1b51bf5","order_by":2,"name":"Chaowen Chang","email":"","orcid":"","institution":"Information Engineering University","correspondingAuthor":false,"prefix":"","firstName":"Chaowen","middleName":"","lastName":"Chang","suffix":""},{"id":518733746,"identity":"2477c5bf-07a9-43ae-92a6-bc53faa7ad79","order_by":3,"name":"Yuanbo Guo","email":"","orcid":"","institution":"Hainan University","correspondingAuthor":false,"prefix":"","firstName":"Yuanbo","middleName":"","lastName":"Guo","suffix":""},{"id":518733747,"identity":"dca10a8c-e385-4748-a845-d9134f1131fc","order_by":4,"name":"Haodong Sun","email":"","orcid":"","institution":"Information Engineering University","correspondingAuthor":false,"prefix":"","firstName":"Haodong","middleName":"","lastName":"Sun","suffix":""},{"id":518733748,"identity":"cbba0f52-7e26-4103-b314-754e3dd702be","order_by":5,"name":"Yaohui Hao","email":"","orcid":"","institution":"Information Engineering University","correspondingAuthor":false,"prefix":"","firstName":"Yaohui","middleName":"","lastName":"Hao","suffix":""}],"badges":[],"createdAt":"2025-06-04 15:23:12","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6821919/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6821919/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":92137151,"identity":"6f3f41ff-aed6-45f3-bd4f-41a472d3c5cb","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"json","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":7279,"visible":true,"origin":"","legend":"","description":"","filename":"5eae3131334a438d9e52ccc74977ca30.json","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/56b464f8054f7aa80bb8795d.json"},{"id":92137152,"identity":"91019def-080e-49ed-bfcf-51d400196a72","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"xml","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":108602,"visible":true,"origin":"","legend":"","description":"","filename":"5eae3131334a438d9e52ccc74977ca301enriched.xml","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/4b376bc3d8a9096d5f5f8e60.xml"},{"id":92139071,"identity":"106dfc48-b18b-4cdc-9eed-ad2bb2a18064","added_by":"auto","created_at":"2025-09-25 05:11:07","extension":"pdf","order_by":2,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":2122083,"visible":true,"origin":"","legend":"","description":"","filename":"APPPFLSpringer.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/4975aa649265b26196f8eedc.pdf"},{"id":92137669,"identity":"e8caeedc-f2f5-4101-a10c-d87fbfb43739","added_by":"auto","created_at":"2025-09-25 05:03:07","extension":"png","order_by":5,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":775950,"visible":true,"origin":"","legend":"","description":"","filename":"sfresultsIID.png","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/88f223e719cca81de098c91f.png"},{"id":92137157,"identity":"00cd02ed-7e10-45be-9951-b0fa36102921","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"png","order_by":6,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":772320,"visible":true,"origin":"","legend":"","description":"","filename":"sfresultsNonIID.png","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/ac40db4797a60f1956e17a25.png"},{"id":92137671,"identity":"2c6c70ec-ee89-4125-824f-c4e098f4875f","added_by":"auto","created_at":"2025-09-25 05:03:07","extension":"bst","order_by":7,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":147148,"visible":true,"origin":"","legend":"","description":"","filename":"snapacite.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/3bf203b7a87f02d7d060fe07.bst"},{"id":92137156,"identity":"c8ac434f-c947-4462-8b7b-6afc6e22b5e4","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"bst","order_by":8,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":30423,"visible":true,"origin":"","legend":"","description":"","filename":"snaps.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/c9cf4eb149c8e26f48f33584.bst"},{"id":92137153,"identity":"1a13e95b-87b2-494b-8db8-424babecea9e","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"bst","order_by":9,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":35733,"visible":true,"origin":"","legend":"","description":"","filename":"snbasic.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/f13d2aad21575939cd6af518.bst"},{"id":92137160,"identity":"87a72e3c-18cc-4940-b489-9e065a9a79a4","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"bst","order_by":10,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":40398,"visible":true,"origin":"","legend":"","description":"","filename":"snchicago.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/b7871c6dcab246f96377d80c.bst"},{"id":92137159,"identity":"a8625a1a-d761-4bb2-918f-dbd6d202e736","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"cls","order_by":11,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":55331,"visible":true,"origin":"","legend":"","description":"","filename":"snjnl.cls","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/74ead4711131415304d847af.cls"},{"id":92137161,"identity":"3d437537-10e8-45ff-b081-3591edd0ca96","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"bst","order_by":12,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":64140,"visible":true,"origin":"","legend":"","description":"","filename":"snmathphysay.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/cd40204ec8f65ec3dcd56709.bst"},{"id":92137163,"identity":"79844020-bde0-464f-8370-cc6e12327869","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"bst","order_by":13,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":64141,"visible":true,"origin":"","legend":"","description":"","filename":"snmathphysnum.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/d447719e5760ef5f47ca858a.bst"},{"id":92137673,"identity":"be690023-53f0-461b-9156-3057985c38ff","added_by":"auto","created_at":"2025-09-25 05:03:07","extension":"bst","order_by":14,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":38349,"visible":true,"origin":"","legend":"","description":"","filename":"snnature.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/fb80c3b1c79ae552abc79b51.bst"},{"id":92137672,"identity":"b11e06da-5987-4029-8914-97b4b39f202b","added_by":"auto","created_at":"2025-09-25 05:03:07","extension":"bst","order_by":15,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":41304,"visible":true,"origin":"","legend":"","description":"","filename":"snvancouver.bst","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/cdb730a81df2e9eadbe91bd4.bst"},{"id":92137166,"identity":"0dd981e6-d649-4c57-8cc8-94622120e78d","added_by":"auto","created_at":"2025-09-25 04:55:07","extension":"xml","order_by":18,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":118328,"visible":true,"origin":"","legend":"","description":"","filename":"5eae3131334a438d9e52ccc74977ca301structuring.xml","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/ee16bc6b0dd2e3833e2a4fbc.xml"},{"id":92139072,"identity":"44bdde01-e1e8-4baa-b336-8130bcfde913","added_by":"auto","created_at":"2025-09-25 05:11:07","extension":"html","order_by":19,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":130894,"visible":true,"origin":"","legend":"","description":"","filename":"earlyproof.html","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1/668db3e58f1df2dfef7faadb.html"},{"id":93375523,"identity":"f381cf0c-7e97-45d7-b39f-655576a76aa1","added_by":"auto","created_at":"2025-10-13 08:09:50","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":2674084,"visible":true,"origin":"","legend":"","description":"","filename":"APPPFLSpringer.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6821919/v1_covered_0e689f27-751d-4eaf-9fa2-e10a888c7c41.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"AP-PPFL: An Anti-poisoning Privacy-preserving Federated Learning Method","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Federated learning, Poisoning defense, Privacy-preserving, Homomorphic encryption","lastPublishedDoi":"10.21203/rs.3.rs-6821919/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6821919/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eFederated Learning (FL) has been widely used in Internet of Things (IoT) environments as a promising decentralized framework capable of collaborative model training without exposing local data. Despite its advantages, FL still encounters significant security challenges. In particular, semi-honest servers can potentially infer private information from the gradients shared by clients. Additionally, FL\u0026rsquo;s distributed nature opens up vulnerabilities to adversarial behavior, where malicious clients may submit manipulated gradients to degrade the global model's accuracy or hinder its convergence. Addressing privacy and robustness simultaneously is an enormous challenge, as most privacy-preserving approaches focus on securing gradients through encryption or noise injection, which obstructs the identification of malicious clients\u0026mdash;an essential step in poisoning defense. To resolve this conflict, this work introduces AP-PPFL, a federated learning framework that integrates both privacy protection and poisoning defense. The proposed approach incorporates a voting-based parameter importance evaluation strategy and a cosine similarity-based mechanism to filter out harmful gradients. Furthermore, it leverages Paillier homomorphic encryption within a dual-server setup to maintain gradient confidentiality while enabling secure computation directly over encrypted data. Compared with conventional methods, AP-PPFL achieves a balanced improvement in both privacy-preserving and attack resilience, with comprehensive security analysis provided.\u003c/p\u003e","manuscriptTitle":"AP-PPFL: An Anti-poisoning Privacy-preserving Federated Learning Method","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-09-25 04:55:02","doi":"10.21203/rs.3.rs-6821919/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"0e43b7ea-3f21-4999-a1b2-6d53eb3ec1d7","owner":[],"postedDate":"September 25th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-10-10T19:08:21+00:00","versionOfRecord":[],"versionCreatedAt":"2025-09-25 04:55:02","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-6821919","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6821919","identity":"rs-6821919","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00