Dnyanesh Khedekar, Tanmaya Mahapatra, Amitesh Singh Rajput · Journal of Information Security and Applications 2026 · 2026
DOI: 10.1016/j.jisa.2026.104660
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Hierarchical Federated Learning (HFL) addresses scalability in distributed machine learning by organizing clients into geographically sparse clusters managed by edge servers. However, this architecture introduces vulnerabilities to sophisticated adversarial coordination, where traditional defences designed for federated learning fail to detect attacks spanning multiple clusters. In this work, we propose adaptive Coordinated Data Poisoning (aCDP), a novel attack where sybil adversaries distributed across edge servers collude by sharing local model updates with each other in an external sybil environment and strategically update their model parameters to bypass existing detection mechanisms. Unlike prior poisoning strategies, aCDP exploits the geographic isolation of clients and partial coordination among sybils to mimic benign behaviour at the edge level while collectively degrading global model performance. We demonstrate that aCDP increases the attack success rate to around 60% and reduces target-class accuracy on MNIST dataset under state-of-the-art defences. To counter this threat, we design HFL-Deflect, a lightweight defence framework that identifies sybil coordination through cross-cluster analysis of gradient similarities and dynamic pattern behaviour. By correlating update patterns across clusters using a similarity history vector, HFL-Deflect detects subtle adversarial collusion without assuming a prior knowledge of attack timing or participant ratios. Experiments conducted with multiple CNN architectures and FL aggregation strategies show that the HFL-Deflect limits attack success rate within 20% and with very low accuracy degradation under aCDP, outperforming existing defences. Our work explores critical blind spots in HFL security and offers a robust, scalable solution for real-world deployments in IoT and healthcare, where client sparsity and resource constraints are inherent.
No comments yet — start the discussion below.