The proposed ResFL-UAV++ framework achieves over 98% accuracy in adversarial UAV detection while introducing less than 4% system overhead, and adversarial training using the Fast Gradient Sign Method (FGSM) enhances reliability and data confidentiality while incurring minimal computational overhead.
Abstract
Federated Learning (FL) enables privacy-preserving collaborative model training for Unmanned Aerial Vehicles (UAVs). However, its decentralized nature makes it vulnerable to adversarial attacks such as model poisoning, label flipping, and backdoor attacks. To address these challenges in resource-constrained UAV environments, this study proposes ResFL-UAV++, a lightweight and secure FL framework incorporating a multi-layer defense mechanism. The framework integrates a multi-metric anomaly detection module based on cosine similarity, L2-Norm Filtering, and Temporal Update Consistency (TUC) to identify malicious UAV updates. A hybrid robust aggregation strategy combining Trimmed Mean and Krum mitigates adversarial effects while preserving model convergence. Additionally, adversarial training using the Fast Gradient Sign Method (FGSM), together with Differential Privacy (DP), enhances reliability and data confidentiality while incurring minimal computational overhead. Experimental evaluation on the HIT-UAV Infrared Thermal dataset and the WebUAV-3M demonstrates that ResFL-UAV++ achieves 98% accuracy under adversarial conditions. The framework reduces the Backdoor Attack Success Rate (ASR) to below 20%. Furthermore, it achieves over 98% accuracy in adversarial UAV detection while introducing less than 4% system overhead. These results demonstrate the effectiveness and practicality of ResFL-UAV++ for secure FL in UAV environments.
Decentralized Federated Learning (DFL) enables collaborative artificial intelligence model training without centralizing sensitive data, making it suitable for privacy-critical and distributed intelligent systems such as healthcare, Industrial IoT, and smart digital infrastructure. Despite its advantages, DFL remains vulnerable to privacy leakage through shared model updates and to model poisoning and backdoor attacks that compromise system reliability, robustness, and trustworthiness. Existing defense mechanisms primarily address either privacy preservation or poisoning robustness independently and often exhibit limited effectiveness under adaptive or high-ratio adversarial settings. This work proposes a trustworthy and privacy-preserving decentralized federated learning framework that jointly addresses these challenges through two integrated components: (i) a hybrid privacy mechanism based on public dataset pretraining followed by differentially private fine-tuning, and (ii) a multi-layer model defense architecture designed to mitigate poisoning and backdoor attacks across decentralized peer-to-peer environments. The framework integrates local data sanitization, peer-side model verification, robust trimmed-mean aggregation, and runtime inference protection to provide defense-in-depth across both training-time and inference-time attack surfaces. An adversary model and operational assumptions are formally defined, and the framework is evaluated under strong adversarial conditions, including a 20% poisoning ratio. Experimental results demonstrate consistent robustness improvements over a vanilla DFL baseline. While the baseline model achieves a clean accuracy of 83.10%, the proposed framework improves clean performance to 86.12%. Under adversarial conditions, accuracy improves from 37.71% to 53.88% for Fast Gradient Sign Method (FGSM) attacks, from 21.75% to 46.40% for Projected Gradient Descent (PGD) attacks, and from 40.62% to 67.35% for Carlini–Wagner (CW) attacks. For backdoor-based poisoning attacks such as BadNets and Blended attacks, the defense pipeline restores model accuracy to above 86% while maintaining stable benign performance. These findings demonstrate that the proposed framework provides an effective balance between privacy preservation, adversarial robustness, and trustworthy decentralized collaborative learning for secure AI-driven systems.
Durga Sivan, Uma Maheshwari Shanmugam, Sachnev Vasily et al.· Discover Artificial Intellig...· 0 citations
As vehicular networks move toward 5G/6G edge intelligence, federated learning (FL) is widely promoted as a privacy-preserving way for vehicles and infrastructure to train shared models without exposing raw sensor data. Yet the updates clients transmit still leak enough information to identify who sent them, which threatens the anonymity that safety-critical V2X applications assume and adds to existing concerns over adversarial ML, model poisoning, and backdoor attacks. We study server-side client identity inference from transmitted weight deltas using inertial (IMU) measurements, evaluated on the UCI Human Activity Recognition (HAR) benchmark as an accessible proxy for the IMU streams produced onboard connected vehicles. Across five attack classifiers and five non-IID partitions, an honest-but-curious server recovers client identity with near-perfect accuracy (approximately 1.000) from undefended updates, confirming a concrete identifiability risk. We then quantify the privacy-utility trade-off of a lightweight clip-then-noise defense by sweeping Gaussian noise (sigma in {0.00, 0.05, 0.10, 0.20, 0.50, 1.00}) at fixed clipping (C=1.0), and report formal (epsilon, delta)-DP budgets through Renyi accounting. A practical region (sigma in [0.1, 0.2]) drives attack accuracy to near-random while costing under 5% relative FL accuracy. Ensemble FL supplies complementary structural privacy with a 1/K anonymity-set bound and no noise penalty. Results are supported by cryptographic (SHA-256) train/evaluation gradient disjointness, three seeds, and a count-normalized attacker-advantage metric. We position HAR explicitly as a proxy and discuss what validation on true vehicular telemetry would require.
Ali Akarma, Toqeer Ali Syed, Muhammad Khan et al.· 0 citations
Secure and reliable wireless communication is a major requirement for upcoming 6G mission-critical applications, such as emergency response and public safety networks. In this respect, unmanned aerial vehicle (UAV)-mounted, simultaneously transmitting and reflecting reconfigurable intelligent surface (STAR-RIS) systems are expected to play an important role in enabling secure, mission-critical 6G communications. However, practical implementations require discrete phase shifts, which can introduce performance degradation due to phase quantization effects. In this paper, we investigate phase quantization in a UAV-mounted STAR-RIS-assisted downlink non-orthogonal multiple access (NOMA) network to maximize secrecy rate. Two approaches are considered, namely, post-training quantization (PTQ) and quantization-aware training (QAT). A Twin Delayed Deep Deterministic Policy Gradient (TD3) agent is developed to jointly optimize STAR-RIS phase shifts and UAV positioning while enforcing minimum quality-of-service (QoS) requirements for users. Simulation results show that QAT consistently outperforms PTQ, particularly at low resolutions. While PTQ suffers significant performance degradation under coarse quantization, QAT maintains near-continuous performance at 3-bit resolution with less than 1% secrecy rate loss, and significantly reduces degradation at 2 bits. These results demonstrate that QAT enables efficient low-bit STAR-RIS operation, reducing hardware complexity and signaling overhead while preserving secrecy performance, thereby enhancing the practical viability of the proposed framework.
Yaser Almasri, Khaled M. Rabie, Mahmoud M. Salim et al.· IEEE Open Journal of the Com...· 0 citations
The suggested DP-FAL model is a privacy-conserving, scalable, and robust intrusion prevention system that can be used real-time V2X conditions and has the potential to be deployed safely, reliably, and sustainably in next-generation transportation systems.
S. Sonker, V. K. Raina, B. B. Sagar et al.· Discover Computing· 0 citations
This study provides among the first empirical evaluations of adversarial fragility in cooperative MARL-based intrusion detection within distributed 5G-oriented security abstractions, demonstrating that cooperative intelligence alone does not guarantee adversarial robustness.
B. Ndlovu, Kudzaishe Lawal Chizengwe· Scientific Journal of Inform...· 0 citations
Unmanned Aerial Vehicles (UAVs) serve an essential function in various civilian, commercial, and military applications, but their reliance on wireless communication, onboard sensors, and ground control systems make them vulnerable to a comprehensive set of cyber threats. Existing security measures—ranging from cryptographic protocols to traditional intrusion detection—struggle to address evolving attack vectors such as GPS spoofing, man-in-the-middle (MITM), jamming, denial-of-service/distributed-denial-of-service (DoS/DDoS), and other advanced UAV-specific intrusions. This study proposes a lightweight ensemble machine learning framework integrating Light Gradient Boosting (LightGBM), Histogram-based Gradient Boosting (HGB), and Categorical Boosting (CatBoost) to detect both sensor-based and broader cyber-attack types in UAV environments. To enhance trust and operational transparency, Explainable AI (XAI) is embedded into the framework, enabling interpretability of detection outcomes for operators and stakeholders. The proposed model is evaluated on the UAV-GCS-IDS dataset capturing diverse attacks, including DoS/DDoS, brute force, reconnaissance, scanning, MITM, replay, fake landing, and evil twin intrusions. Results from the experiments indicate that the ensemble surpasses baseline machine learning models with 99.74% accuracy, 99.87% F1-score, 99.86% precision, and 99.88% recall. In addition, the model also achieves a robust ROC-AUC of 99.85% and PR-AUC of 100.0%, while maintaining low computational overhead—making it suitable for resource-constrained UAV systems. This work strengthens UAV cybersecurity by introducing an interpretable, high-performance detection framework capable of operating effectively in realworld, mission-critical scenarios.
C. Chidimma, P. Asuquo, Ihemereze Chijioke Nnanna et al.· E3S Web of Conferences· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.