
Federated Learning (FL) enables collaborative model training without centralizing raw data and has become an important paradigm for privacy-sensitive intelligent systems. Nevertheless, its distributed architecture, heterogeneous data, and unreliable participants introduce substantial robustness and security challenges, ranging from communication noise and system failures to poisoning, privacy inference, and Byzantine attacks. In this paper, we present a structured survey of robust federated learning. We first organize the literature through a threat-oriented taxonomy that covers poisoning attacks, privacy leakage risks, Byzantine behavior, and scenario-specific robustness challenges. We explicitly analyze stronger adversaries that collude, coordinate poisoning campaigns, replace models behind secure aggregation, and adapt their optimization to defense-specific weaknesses. We then review representative defense mechanisms, including robust aggregation, backdoor defense, privacy-preserving training, secure aggregation, and personalized robustness enhancement. Particular attention is given to three recurring tensions in the literature: robustness under Non-IID data, robustness-efficiency trade-offs, and robustness-privacy trade-offs. We further discuss robust federated learning in wireless and IoT environments, where communication uncertainty and resource constraints become first-order concerns. We examine how existing robustness mechanisms translate, or fail to translate, to foundation-model-based FL, federated fine-tuning of large language models, federated reinforcement learning, agentic federated systems, and federated retrieval-augmented generation. Finally, we summarize open challenges and outline future research directions for building more reliable, efficient, and deployable federated learning systems.
The integration of multifunctional modules into ultrathin, spatially constrained flexible electronics often leads to localized heat accumulation, challenging device reliability under conformal operation. Achieving precise heat-flux manipulation, mechanical flexibility, and scalable fabrication within a unified platform remains an open challenge. Here, we report a gradient-discretized design strategy for flexible thermal metamaterials that combines multiscale topology optimization with transformation thermotics. This framework links microstructural geometry, deformation-induced effects, and macroscopic thermal functionality, including thermal cloaking and thermal concentration. Using flexible printed-circuit fabrication, we fabricate gradient arrays containing 6×6 to 20×20 unit cells, with pitches ranging from 10 to 3 mm, within a fixed 60×60 mm² footprint. We also develop a coupled thermomechanical resistance model to quantify bending-induced perturbations. In the flat state, the thermal-cloaking function suppresses the temperature gradient within the protected region to approximately 1% of the surrounding background gradient, thereby enabling thermal concealment of embedded heterogeneous structures. The thermal-concentration function enhances local heat focusing by nearly one order of magnitude, increasing the temperature difference available to a thermoelectric module. Both functions remain effective under bending at a radius of 19 mm, with only moderate performance degradation. These results establish a scalable and mechanically compliant platform for programmable heat-flux control in next-generation conformal and wearable electronics.
Predicting future cellular network traffic volume patterns is crucial for optimizing network resource management and enhancing user experience. Recently, with cellular traffic data represented as pseudo-image data, state-of-the-art frameworks based on Deep Neural Networks (DNNs) have been introduced to enable effective modeling of spatiotemporal dependencies for the prediction tasks. Nonetheless, highly parameterized DNNs require large datasets, which are often missing for cellular network traffic prediction task and thus underscore the need for effective data augmentation strategies. Our preliminary analysis shows that the augmentation methods for natural images prove ineffective in enhancing performance on this task due to its pseudo-image nature. We identify that the reason lies in image augmentations introducing missing values and misalignments, with masking and geometric alterations disrupting the real-world cellular traffic patterns. On top of this, we propose an adaptation of underlying augmentation process into a tailored strategy suitable for the spatial and temporal complexities of the data, which stem from interactions between base stations and evolving traffic patterns. Specifically, we introduce MixScale, an augmentation technique designed for pseudo-image cellular network traffic data. MixScale integrates constrained spatio-temporal data mixing with multi-scaling to better align with the unique characteristics of the dataset. Evaluation on two real-world datasets, including a 5G dataset, demonstrates promising results; MixScale consistently achieves reductions between 16% and 32% in root mean square error (RMSE) compared to the baseline.
Image privacy protection relies on effective diffusion, yet existing methods still suffer from limited cross-plane interaction and insufficient perturbation propagation. To address this issue, this paper proposes a chaotic image privacy protection method based on Layer-Coupled Co-Evolutionary Cellular Automata (LCCE-CA). A diffusion-oriented Life-like CA rule optimization method is first designed by imposing finite-step balance and temporal-correlation constraints to obtain low-correlation and near-balanced diffusion rules. Then, a reversible LCCE-CA mechanism is constructed by coupling image bit-planes with auxiliary co-evolution planes, enabling explicit cross-plane feedback at each iteration. Based on this mechanism, a chaotic image privacy protection framework is developed and validated on standard grayscale image encryption experiments. Compared with the traditional 8th-order reversible CA, LCCE-CA reduces the early-stage mean balance deviation from 0.3003 to 0.0008, corresponding to a 99.7% reduction. At the 8th iteration, the cumulative perturbation propagation ratio increases from 0.2580 to 0.5609. Experiments on nine standard grayscale images with sizes of 256 × 256 and 512 × 512 show noise-like protected images, nearly uniform histograms, and strong spatial decorrelation, with a maximum absolute adjacent-pixel correlation coefficient of 0.00857. The scheme exhibits strong plaintext and ciphertext sensitivity, with the average Number of Pixels Change Rate (NPCR) and Unified Average Changing Intensity (UACI) for plaintext sensitivity reaching 99.6075% and 33.4708%, respectively. These results indicate that LCCE-CA provides a practical reversible diffusion framework for secure image privacy protection.
Open-set recognition (OSR) of low-probability-of-interception (LPI) radar signals is challenging in non-cooperative environments. Due to parameter variations and low signal-to-noise ratios (SNRs), LPI radar features often exhibit multimodal structures. This limits conventional single-center representations, leading to loose acceptance regions and increased false acceptance of unknown samples. To address this issue, this paper devises a feature-space multi-center framework for OSR of LPI radar signals. It represents each known class with multiple local prototypes and a shared within-class covariance matrix to capture complex intra-class distributions. A consistency-driven filtering mechanism calibrates the rejection boundary using validation data, while a class-level prototype configuration strategy adapts model complexity to heterogeneous class structures. Experiments on a simulated LPI radar signal dataset across a wide SNR range show that our solution outperforms several representative baseline approaches in terms of the area under the receiver operating characteristic curve (AUROC) and the false positive rate at a 95% true positive rate (FPR@95%TPR). At an SNR of −6 dB, the proposed method achieves an FPR@95%TPR of 19.09% and an AUROC of 92.11%, indicating effective discrimination under noise-dominated conditions. These results indicate the potential of the proposed method for handling complex intra-class structures in OSR of LPI radar signals under simulated non-cooperative conditions.