Blockchain-Enabled Federated Learning for Healthcare: An Empirical Evaluation of the Integrity Boundary, Byzantine Robustness, and Ledger Overhead
Abstract
Federated learning enables healthcare institutions to train shared models without pooling patient records, but it does not by itself authenticate participants, verify that model updates arrive unaltered, or provide an auditable record of contributions. Permissioned blockchains are often proposed to address these gaps, yet existing studies commonly evaluate the ledger alongside other defenses, leaving its independent predictive effect, security boundary, and system overhead unclear. This study isolates the ledger through a paired experimental design. Federated logistic regression and a multilayer perceptron were trained on three clinical datasets (WDBC, ACTG 175, and GBSG-2) under IID and Dirichlet label-skewed partitions across ten partition seeds. SHA-256 digests and ECDSA-signed transactions were validated using an instrumented single-host reference implementation of the Hyperledger Fabric execute–order–validate architecture. Alteration in transit, unauthorized submission, replay, harmful but validly signed updates, and label poisoning were evaluated with ledger verification and three Byzantine-robust aggregators. Four findings emerged. First, verified and unverified training produced bitwise-identical parameters in all 180 paired runs with valid updates; thus, verification did not affect predictive performance, whereas data heterogeneity did. Second, verification rejected every tested altered, unauthorized, and replayed submission but provided no recovery of balanced accuracy against harmful updates that were correctly hashed and signed. Third, coordinate-wise median aggregation recovered a small portion of the accuracy lost to such updates, generally within partition variability, at a small cost without attacks, indicating that verification and robust aggregation address different attack surfaces. Fourth, orderer batch waiting accounted for about 91% of measured end-to-end ledger latency, while cryptographic operations represented an estimated upper bound of about 1%; aligning block size with the per-round transaction structure removed most of the wait. These results indicate that ledger verification preserves model integrity but cannot detect value-level malicious updates and should therefore be paired with value-based defenses and configured for the federation’s round structure. The study uses small tabular models, one malicious client, and a single-host reference implementation; it is not a production Fabric benchmark and does not evaluate privacy leakage.