Federated Learning (FL) enables collaborative model training across distributed clients without sharing raw data but remains highly vulnerable to poisoning attacks, especially under non-Independent and Identically Distributed (non-IID) settings. To address this challenge, we propose DAARA: Divergence-Aware Attention for Robust Aggregation, a novel aggregation mechanism designed to defend against label flipping attacks in FL. Unlike existing defenses that rely on fixed thresholds or assume knowledge of attacker behavior, DAARA is client-agnostic and adaptively assigns attention weights to client updates based on their statistical divergence and class-wise consistency. We provide the theoretical convergence analysis of our DAARA approach. Additionally, we conduct extensive experiments on the NSL-KDD and UNSW-NB15 cybersecurity datasets, demonstrating that DAARA significantly outperforms state-of-the-art baselines, including Krum, Trimmed Mean, FoolsGold, and RFed, achieving up to a 40 4× faster convergence under both untargeted and targeted label flipping attacks. Furthermore, DAARA exhibits remarkable stability across varying attack intensities, maintaining consistently low gradient divergence even under extreme non-IID conditions. The results confirm that DAARA provides a lightweight, effective, and generalizable solution for secure FL in adversarial and heterogeneous environments.
Federated learning (FL) offers a privacy-preserving paradigm for distributed machine learning, but its application to intrusion detection systems (IDSs) in Internet of Things (IoT) networks is hindered by severe class imbalance, highly non-IID data, and high communication overhead. These challenges severely degrade the performance of conventional FL methods in real-world network traffic classification. To overcome these limitations, we propose Sentinel, a personalized federated IDS (pFed-IDS) framework that incorporates a dual-model architecture on each client, consisting of a high-capacity personalized teacher and a lightweight globally shared student model. This design balances deep local adaptation with efficient global aggregation while preserving privacy and reducing communication overhead by transmitting only the compact student model. Sentinel integrates three key mechanisms to ensure robust performance: bidirectional knowledge distillation with adaptive temperature scheduling, lightweight multilevel feature alignment between teacher and student representations, and a class-balanced loss to handle highly skewed traffic. On the server side, normalized gradient aggregation with equal client weighting mitigates client drift and improves fairness across clients. Extensive experiments on the IoTID20 and 5GNIDD benchmark datasets demonstrate that Sentinel significantly outperforms state-of-the-art federated baselines under extreme data heterogeneity, while lowering communication overhead.
Federated learning (FL) enables collaborative model training without centralized data sharing, yet its practical deployment is often hindered by slow convergence and excessive communication overhead, particularly under non-Independent and non-Identically Distributed (non-IID) data distributions. To address these challenges, this paper proposes Federated Fractional Order Gradient Descent with Adaptive Momentum (FedFOGDAM), a novel client-side optimization framework that integrates fractional-order gradients with adaptive momentum and bias correction to accelerate convergence and reduce the number of communication rounds (CRs) required for model convergence. By leveraging the memory effect of fractional-order calculus, FedFOGDAM stabilizes local updates and mitigates client drift, while adaptive momentum enhances update consistency across heterogeneous clients. We provide a rigorous convergence analysis under non-convex objectives, demonstrating improved convergence behavior compared to conventional integer-order optimizers. Extensive experiments on benchmark datasets under both IID and non-IID settings show that FedFOGDAM consistently achieves communication-efficient convergence and competitive accuracy.
Achieving simultaneous robustness against geometric distortions and signal-domain attacks remains a formidable challenge in blind image watermarking. Conventional template-based schemes typically rely on pseudo-random patterns for synchronization, which not only limit their geometric robustness due to the lack of structural optimization but also exhibit inferior resilience against signal-processing attacks compared to frequency-domain and deep-learning methods. This paper proposes an enhanced template-based color image watermarking framework by optimizing template design with a dual-channel embedding strategy. First, we develop a multi-objective template optimization framework utilizing a Genetic Algorithm to construct templates with superior peak dominance and background suppression capabilities. Then we propose a novel watermarking scheme in which the optimized template is tiled in the chrominance component as a pilot signal, while the payload is embedded in the luminance component via Perceptual Carrier Modulation. On the extraction side, we introduce a hierarchical geometric restoration (HGR) process and a novel amplitude-weighted aggregation extraction strategy to enhance extraction accuracy under hybrid distortions. Experiments demonstrate that the proposed scheme outperforms state-of-the-art methods in terms of robustness against signal-processing, geometric distortions and combined attacks. In addition, our proposed template optimization principle demonstrates generality and achieves significant improvements in robustness against geometric attacks across three distinct watermarking methods.
Federated Learning (FL), a groundbreaking approach for collaborative model training across decentralized devices, maintains data privacy while constructing a decent global machine learning model. Conventional FL methods typically demand more communication rounds to achieve convergence in non-Independent and non-Identically Distributed (non-IID) data scenarios due to their reliance on fixed Stochastic Gradient Descent (SGD) updates at each Communication Round (CR). In this paper, we introduce a novel strategy to expedite the convergence of FL models, inspired by the insights from McMahan etal.'s seminal work. We focus on FL convergence via traditional SGD decay by introducing a dynamic adjusting mechanism for local epochs and local batch size. Our method adapts the decay of SGD updates during the training process, akin to decaying learning rates in classical optimization. Particularly, by adaptively reducing local epochs and increasing local batch size using their ongoing values and the CR as the model progresses, our method enhances convergence speed without compromising accuracy, specifically by effectively addressing challenges posed by non-IID data. We provide theoretical results of the benefits of the dynamic decay of SGD updates in FL scenarios. We demonstrate our method's consistent outperformance regarding the global model's communication speedup and convergence behavior through comprehensive experiments.
Edge computing enables real-time Internet of Things data processing by bringing computation closer to data sources, but its distributed architecture creates cybersecurity vulnerabilities requiring privacy-preserving attack detection mechanisms capable of handling heterogeneous data distributions. This article proposes federated generative adversarial divergence (FedGAD), a plug-and-play modular framework that enhances existing federated learning methods through Jacobian-based regularization and dynamic complexity-aware weighting to address cyber-attack detection in non-independent and identically distributed (IID) and unlabeled edge data environments. Unlike existing approaches suffering from mode collapse and training instability, FedGAD maintains statistical consistency across distributed nodes through gradient-based stability mechanisms, supported by rigorous theoretical analysis establishing convergence guarantees and mode coverage properties. We conduct comprehensive experiments comparing FedGAD against four federated generative learning baselines federated trustworthy (FedTrust), anomaly detection generative adversarial network (ADGAN), federated generative adversarial network for intrusion detection system (FedGAN-IDS), and federated temporal sequential recurrent generative network (FedTSRGNet) and four regularization-based methods federated averaging (FedAvg), federated proximal (FedProx), learning with collaborative aggregation method (LeCam), and Jensen Shannon (JS) Divergence on telemetry data of networks - internet of things (ToN_IoT) and Communications Security Establishment in Canadian Institute for Cybersecurity - Intrusion Detection System (CSE_CIC_IDS) datasets, demonstrating FedGAD's superiority with accuracy improvements up to 3.5%, achieving 100% mode coverage compared to 25% for baseline methods while maintaining computational efficiency for resource-constrained edge deployments.
With the rapid development of 6 G communication technology and the Internet of Things (IoT), mobile edge computing (MEC) is regarded as an effective paradigm of providing low-delay, high-quality services to mobile users. In the IoT device-edge-cloud network, the optimal deployment of MEC servers is a prerequisite for a better task offloading, while the improved performance of mobile users task offloading also indicates the deployment scheme is optimal. Most of current MEC servers deployment studies focus on reducing delay and deployment costs, but ignore the offloading requirements of mobile users with similar task type and cooperative relationship arriving at the same community. In this paper, we study the MEC servers deployment driven by the task offloading requirements of community mobile users in current period by utilizing the stability of their social cooperative relationships to maximize the service satisfaction of all community mobile users in the future task offloading. First, the cooperative relationship strength between mobile users is measured to form a group of resource requesters based on interaction probability, movement trajectory and credit strength. Then, we implement the optimal search of base stations (BSs) using spatial index, followed by the one-to-many matching theory between BSs and community group resource requesters, to balance the load of BSs and reduce the communication delay between them. Finally, we use TD(lambda) algorithm and task similarity between cooperative users to deploy MEC servers with suitable resources around BSs so that the deployment scheme can significantly improve the future task offloading performance of all community mobile users. Based on the real data set provided by Shanghai Telecom, it is confirmed that the proposed scheme has significant advantages in improving all community mobile users service satisfaction, with an average improvement of 18.49% compared with the baselines.
The rapid expansion of Edge Computing (EC) and Internet of Things devices has introduced significant cybersecurity challenges, necessitating advanced and privacy-preserving attack detection strategies. Traditional cyber-attack detection methods and centralized machine learning solutions face critical limitations in addressing privacy concerns, resource constraints, and the evolving nature of cyber threats in edge environments. Federated Learning (FL) offers a transformative solution by enabling distributed model training across edge devices while preserving data privacy. This systematic literature review investigates FL for cyber-attack detection in EC environments using the PRISMA methodology, analyzing 131 primary studies from 2020–2025 across five major databases. Our contributions include: (1) a comprehensive PRISMA-compliant framework encompassing seven thematic areas with detailed comparative analysis, (2) an in-depth gap analysis with actionable recommendations for privacy-performance trade-offs, scalability, and standardization challenges, and (3) a forward-looking research agenda addressing generative models, collaborative defense, 6G-enabled intelligence, and zero-trust architectures. Unlike existing surveys, this work provides the most comprehensive scope with bibliometric analysis, multi-perspective evaluation, and practical deployment guidelines, serving as a foundational reference for advancing federated cyber-attack detection in edge computing environments.
Federated Learning (FL) has emerged as a promising paradigm for collaborative model training without centralizing client data. However, most existing methods rely on single-objective optimization and heuristic aggregation strategies that neglect client-specific characteristics, resulting in performance degradation, unfair model behavior, and inefficient convergence under heterogeneous client settings. In this work, we propose FedMOAR, a Multi-Objective Adaptive Regularization strategy that jointly optimizes global model accuracy, client-level fairness, and communication efficiency. Unlike conventional FL approaches that apply uniform regularization or focus solely on minimizing global loss, FedMOAR dynamically adjusts its regularization coefficients based on model divergence, fairness penalties, and accuracy compensation. We evaluate FedMOAR on MNIST and NSL-KDD datasets using Dirichlet-based heterogeneous (non-IID) data partitions ( α = 0.1, 0.5, 1.0) that induce variability in data volume and class distributions under both partial and full client participation. Experimental results show that FedMOAR consistently outperforms baselines such as FedAvg, FedProx, FairFed, and FedVal. Specifically, it achieves higher F1-scores, lower min-max accuracy gap (MMAG), and improved Jain’s Fairness Index (JFI), while demonstrating up to 2.4 × speedup. Even in scenarios with comparable test accuracy, FedMOAR yields significantly better F1 and JFI values, and lower MMAG, confirming its effectiveness as a fair and efficient FL solution. These results highlight FedMOAR’s practical value in real-world deployments characterized by heterogeneous data and client diversity.
Watermarking has been widely used for copyright protection of digital images. Deep learning-based watermarking systems have recently emerged as more robust and effective than traditional methods, offering improved fidelity and resilience against attacks. Among the various threats to deep learning-based watermarking systems, self-re-watermarking attacks represent a critical and underexplored challenge. In such attacks, the same encoder is maliciously reused to embed a new message into an already watermarked image. This process effectively prevents the original decoder from retrieving the original watermark without introducing perceptual artifacts. In this work, we make two key contributions. First, we introduce the self-re-watermarking threat model as a novel attack vector and demonstrate that existing state-of-the-art watermarking methods consistently fail under such attacks. Second, we develop a self-aware deep watermarking framework to defend against this threat. Our key insight for mitigating the risk of self-re-watermarking is to limit the sensitivity of the watermarking models to the inputs, thereby resisting re-embedding of new watermarks. To achieve this, we propose a self-aware deep watermarking framework that extends Lipschitz constraints to the watermarking process, regulating encoder–decoder sensitivity in a principled manner. In addition, the framework incorporates re-watermarking adversarial training, which further constrains sensitivity to distortions arising from re-embedding. The proposed method provides theoretical bounds on message recoverability under malicious encoder based re-watermarking and demonstrates strong empirical robustness against diverse scenarios of re-watermarking attempts. In addition, it maintains high visual fidelity and demonstrates competitive robustness against common image processing distortions compared to state-of-the-art watermarking methods. This work establishes a robust defense against both standard distortions and self-re-watermarking attacks. The implementation will be made publicly available in GitHub.
Laryngeal cancer imaging research lacks standardised public datasets to enable reproducible deep learning (DL) model development. We present LaryngealCT, a curated benchmark of 1,029 computed tomography (CT) scans aggregated from six collections from The Cancer Imaging Archive (TCIA). Uniform 1 mm isotropic volumes of interest encompassing the larynx were extracted using a weakly supervised parameter search framework validated by clinical experts. Six 3D DL architectures (custom 3D CNN, ResNet18/50/101, DenseNet121 and MedicalNet-pretrained ResNet50) were benchmarked on (i) early (Tis-T2) vs. advanced (T3-T4) and (ii) T4 vs. non-T4 classification tasks. On the independent test set, the 3D CNN achieved the strongest overall performance across global and per-class metrics (Accuracy = 0.854, F1-macro = 0.841) in early vs. advanced classification. In the T4 task, AU-ROC values exceeded 0.82 for most models, but sensitivity for T4 disease remained limited (≤ 0.412), with ResNet101 showing the most promising calibrated T4 recall (0.706). Model explainability assessed using GradCAM ++ with thyroid cartilage overlays for the T4 classification task revealed anatomically plausible peri-cartilage activations although spatial overlap remained modest. Through open-source data, pretrained models, and integrated explainability tools, LaryngealCT offers a reproducible foundation for AI-driven research to support future clinical decision-making in laryngeal oncology.
Biometric systems using physiological signals have shown high identification accuracy (IA) and low Equal Error Rate (EER). However, existing research largely emphasizes performance metrics alone, overlooking the characteristics of models. In contrast, this work shifts the focus toward a deeper understanding of biometric system behavior. Particularly, how signal features, population size, and sample availability influence performance and reliability. To achieve this, we propose a unified framework to analyze ECG, EEG, and PPG signals. Identification performance was assessed experimentally using machine learning models for interpretability. Further, the framework quantifies the importance of individual features using SHapley Additive exPlanations (SHAP). Additionally, sensitivity analyses are performed to study the effects of varying population size and sample availability. All classifiers using the selected feature sets from feature analysis demonstrated strong performance across various evaluation metrics. IA consistently exceeded 96% on the majority of datasets, demonstrating competitiveness with well-established deep models. They notably achieved a lower EER than all other compared deep learning-based machine learning studies. SHAP analysis revealed that wavelet coefficients, especially from the first and sixth decomposition levels, and systolic features in PPG are the most discriminative. By shifting the focus toward these underexplored dimensions, our work enables more informed decisions in biometric system development and deployment under variable conditions. These insights directly support the application and development of secure and privacy-aware biometric systems suitable for real-world deployment, including medical edge learning environments where resource constraints and data sensitivity are critical.
Nowadays IoT devices in Mobile Edge Computing (MEC) networks have been deployed in large-scale quantities to guarantee sensing data collection for anomalous event detection as full as possible even if some devices are in fault. Some techniques, such as clustering and dimensionality reduction, are adopted to eliminate redundant sensing data collection in this large-scale deployment. However, they not only have high computational complexity and easily cause the loss of information on the primary sensing attributes for detection, but also bring certain errors to the detection because of their low sensitivity to data processed. In addition, insufficient collection of primary attribute data samples often results from physical or human factors, and mindless imputation of large-scale data gaps without basis may lead to greater irreparable losses. To address the above challenges, we first complete the selection of optimal primary attribute device collection and aggregation (PADCA) path based on minimum spanning tree, reducing data communication cost for redundant primary attributes collection. Then, we propose an anomalous impact correlation search strategy to quickly locate all MEC servers whose management regions have cascading anomalous event and help determine the transferable source MEC servers. Leveraging this, we use transfer learning to help detect anomalous events in the management regions of the MEC servers with insufficient primary attribute data samples, where a particle swarm optimization based back-propagation (PSO-BP) neural network model is used to infer the fusion weight of each primary attribute. Experimental results show that our method achieves higher detection performance in terms of detection time, energy consumption, accuracy, and receiver operating characteristic (ROC) curve compared to the benchmarks by at least 24%, 34%, 0.5 and 0.05.
Intelligent physical systems, such as smart vehicles and robotic arms, are increasingly integrated into both industrial and everyday applications. However, the systems typically face hardware limitations that constrain their computational capacities. Digital twin systems offer a solution by creating real-time digital replicas of physical systems that enhance computational efficiency, overcoming physical limitations. Moreover, multiple digital twins that hold complementary knowledge can conveniently collaborate to share information and computational resources, further improving the performance of physical systems by forming an Internet of Digital Twin (IoDT). This paper presents a comprehensive investigation of the digital twin network, tracing the evolution of digital twins and providing a classification of the key technologies, functional frameworks, and application domains of IoDT. This paper delves into the IoDT communication framework by studying the fundamental communication modes of IoDT, exploring its integration with advanced technologies such as edge computing, blockchain, 5G/6G networks, and machine learning to facilitate data transmission, interaction, and omni-directional sensing. By offering a broad perspective, the paper aims to deepen stakeholders’ understanding of current research and potential future developments, encouraging further exploration of IoDT technologies and their evolution.
With the popularity of personal devices, there are abundant valuable face image datasets in the industry, which provides opportunities for the development of visual models. However, privacy concerns related to identity sensitive information hinder face datasets sharing. Despite existing works dedicated to removing identity sensitive information from images, they either lack provable privacy guarantees or compromise crucial face dataset utilities, e.g., identity correlation and image naturalness. To overcome these weaknesses, we propose a novel face dataset publication scheme that protects face images by obfuscating face features. The obfuscated features still retain a certain level of correlation, allowing the protected dataset to be used for training. In the process of obfuscating the features, we design a novel metric differential privacy mechanism, which can enhance the correlation between features while ensuring privacy. Furthermore, we construct a latent diffusion model with identity and attribute as inputs to improve the naturalness of generated images. Extensive experimental results and theoretical analysis demonstrate our scheme significantly outperforms existing works in providing privacy protection while maintaining high dataset utility for downstream tasks.
Within the domain of Industry 4.0, encompassing diverse sectors like the music industry, intellectual property violation poses a significant concern. Digital watermarking shows great promise as a technique to enforce intellectual property rights for audio signals. However, ensuring robustness against de-synchronization attacks remains a significant problem in audio watermarking. In this paper, we introduce a new and robust audio watermarking scheme that utilizes the time domain fragment energy relationship (TDFER) feature to resist both common and de-synchronization attacks. During the embedding process, the audio signal is first split into numerous segments, each of which will be subsequently further split into two fragments. Each watermark bit will be embedded into a pair of fragments by adjusting the energy relationship between the fragments. The specially designed adaptive modification window functions (AMWFs) are used to modify the audio signal smoothly without causing perceptible distortion at the fragment boundaries. In the decoding process, the embedded watermark will be retrieved by comparing the energies of the paired fragments in each segment. Theoretical analysis and empirical findings provide compelling evidence for the exceptional performance of our proposed scheme. In particular, under +/- 20% time-scale modification (TSM), our proposed scheme achieves a bit error rate of 0%, demonstrating its strong robustness in practical scenarios.
Mobile Edge Computing (MEC) has incentivized App vendors to outsource various services and applications to distributed edge nodes for low access latency. However, the data cached on these nodes is vulnerable to both intentional and accidental corruption, necessitating periodic audits of Edge Data Integrity (EDI). Existing solutions either rely on a "fully trustworthy" Third Party Auditor (TPA) or leverage blockchain to enhance trust. However, they overlook the security risks brought by the use of blockchain, particularly collusion attacks. Furthermore, while they employ a challenge-response challenge-response mechanism to enhance efficiency by batch verification, they fail to account for the heterogeneity of edge nodes. To address these challenges, we propose $\mathtt {CTCV}$CTCV, a Collusion-resistant and Time-aware Collaborative Verification framework. $\mathtt {CTCV}$CTCV aims to accommodate edge node heterogeneity while enabling public audits and batch verification without introducing additional security risks. Specifically, it incorporates blockchain to allow edge nodes to collaboratively verify EDI without trust dependencies, while mitigating collusion attacks through a carefully designed proof generation and verification approach. Considering the resource and state heterogeneity of edge nodes, $\mathtt {CTCV}$CTCV employs a time-constrained challenge-response mechanism that sets a time threshold $\mathcal {T}$T between the verification request issuance and the integrity proof inspection to avoid excessive delays. The selection guideline of $\mathcal {T}$T, along with the correctness, efficiency, and collusion resistance of $\mathtt {CTCV}$CTCV, are rigorously analyzed. Extensive experiments validate that $\mathtt {CTCV}$CTCV is computationally and communicationally efficient compared to three baselines: EdgeWatch, EDI-S, and EDI-V.
Edge Data Integrity Verification (EDIV) plays a crucial role in maintaining the authenticity of cached data replicas in decentralized and resource-constrained edge computing environments. However, existing EDIV methods prioritize generating cryptographic proofs while overlooking the need to ensure robustness against localized data tampering and neglecting the inherent security risks involved in transmitting these proofs over untrusted backhaul communication networks. These gaps leave the EDIV process vulnerable to both the manipulation of integrity proofs and their interception during transmission, ultimately undermining the reliability of EDIV. To address these gaps, we propose RAMTStego-EDIV, a novel framework that ensures both the robustness of integrity proofs and their secure transmission. In particular, RAMTStego-EDIV first introduces the Robust Aggregated Merkle Tree (RAMT)—a ternary hash tree that combines real and auxiliary nodes to produce tamper-evident cryptographic proofs, ensuring that even partial manipulation of the data can be reliably detected. Then, it develops a dual-parity transmission control protocol (TCP) steganography technique to protect the transmission of the RAMT-driven cryptographic proofs that covertly embed the proof bits into two TCP header fields: the parity of the payload length and the least significant bit of the TCP window size. This embedding allows proofs to travel invisibly within normal traffic, avoiding detection and interference by adversaries monitoring the network. Both theoretical analysis and experimental results demonstrate that RAMTStego-EDIV prevents proof tampering and interception, confirming its resilience and suitability for deployment in adversarial mobile edge computing environments.
Remote sensing imagery is essential for environmental monitoring but often suffers from large gaps due to clouds, sensor failure, or acquisition gaps. Existing interpolation and generative methods struggle to maintain spatial, spectral, and temporal coherence. We present AlignDiff, a diffusion-based framework that formulates reconstruction as a spatiotemporal alignment problem. It employs a three-way strategy: (1) spatial alignment via DEM conditioning, (2) semantic alignment through prompt-based modulation, and (3) distributional alignment with a VGG-Adapter enforcing feature-level consistency. Experiments on Landsat-8 and EarthNet2021 show that AlignDiff surpasses state-of-the-art baselines on spatial and temporal completion, enabling scalable, reliable satellite image recovery.