TAR-DT: A Trusted and Attack-Resilient Mechanism for Distributed DNN Training in Agentic Edge Intelligence †
Abstract
1. Introduction
- We propose TAR-DT, a blockchain-enabled distributed DNN training framework that seamlessly integrates data and model parallelism with verifiable poisoning defenses, ensuring both efficiency and security in heterogeneous edge environments.
- We design the Loss-aware Credit Evaluation and Shuffling-based Isolation Mechanism, enabling effective identification and isolation of malicious agents, particularly in model-parallel training scenarios.
- We leverage smart contracts and Byzantine-tolerant aggregation to provide tamper-resistant and auditable security-critical state transitions, thereby reducing the reliance on a fully trusted coordinator for loss recording, credit updating, grouping decisions, and aggregation commitments.
- Extensive experiments demonstrate that TAR-DT significantly outperforms state-of-the-art methods under diverse poisoning attack settings while maintaining practical training efficiency.
2. Preliminaries and Related Work
2.1. Distributed Machine Learning
2.1.1. Data and Model Parallelism
2.1.2. Edge Distributed DNN Training
2.2. Model Poisoning Attack
2.2.1. Attack Method
2.2.2. Defense Method
2.3. Blockchain for Incentives and Trust in Distributed Systems
3. TAR-DT
3.1. System Model
- The master agent uploads the initial model parameters to the blockchain, groups the available agents, and assigns one cell to each agent. Following the deployment-oriented perspective in [39], we explicitly identify the entities involved in model transmission and verification. Each agent retrieves the corresponding model parameters according to the information recorded on the blockchain. For large models, the parameter data can be stored and transmitted through IPFS, while only the corresponding CIDs and cryptographic digests are recorded on-chain for integrity verification.
- The training process begins. Each group of K agents collaboratively trains a group model denoted by . The loss sequence of group g is , where denotes the loss value in the q-th iteration.
- Upon completing one epoch, and are packaged into a transaction and uploaded to the blockchain.
- The master agent retrieves the loss records from the blockchain and invokes the Loss-aware Credit Evaluation (LACE) smart contract to evaluate the performance of each group and update the agents’ credits (Section 4.1).
- Subsequently, the BTA smart contract aggregates the group models to obtain the updated global model (Section 4.3).
- Simultaneously, the master agent invokes the Shuffling-based Isolation Mechanism (SBIM) smart contract to regroup the agents for the next training epoch (Section 4.2).These six steps are repeated until training is complete.
3.2. Attack Model
3.3. Reputation Mechanism Based on Blockchain
4. Attack-Resilient Agent Management and Model Aggregation
4.1. Loss-Aware Credit Evaluation
4.1.1. Preliminary Experiment
4.1.2. Group Grading
4.1.3. Credit Update
| Algorithm 1 Loss-Aware Credit Evaluation (LACE). |
| Input: the group set ; the loss vectors ; and the credits from the previous time slot, . |
| Output: the credit , the set of PGs , and the set of WGs . |
| 1: #Group Grading# |
| 2: for all g in do |
| 3: Determine and evaluate at all observed loss samples using Equations (1) and (2); |
| 4: Select and compute the half-maximum support size using Equation (3); |
| 5: Compute and the group score using Equation (5); |
| 6: end for |
| 7: Classify the groups into WGs and PGs using K-means. |
| 8: #Credit Update# |
| 9: for all agents n do |
| 10: Update the credit using Equation (6). |
| 11: end for |
4.2. Shuffling-Based Isolation Mechanism
| Algorithm 2 Shuffling-based Isolation Mechanism (SBIM). |
| Input: agent groups and , group size K, latest block hash , task identifier , epoch index t, timestamp |
| Output: Updated grouping |
| 1: Seed Initialization (Master Agent) |
| 2: |
| 3: Roulette-wheel Selection |
| 4: Initialize , , , and |
| 5: while is not empty do |
| 6: |
| 7: |
| 8: |
| 9: for each agent do |
| 10: Compute |
| 11: Assign the cumulative interval according to Equation (10) |
| 12: end for |
| 13: Select agent i satisfying |
| 14: Add agent i to and remove it from |
| 15: if then |
| 16: Add to and reset |
| 17: end if |
| 18: end while |
| 19: Verification (Blockchain Smart Contract) |
| 20: Verify each selection round using , generated , credit values, and cumulative intervals |
| 21: Store the verified grouping result on-chain |
| 22: Final Output |
| 23: |
| 24: return |
4.3. Byzantine-Tolerant Aggregation (BTA)
4.4. Theoretical Analysis
4.4.1. Complexity and Overhead Analysis
4.4.2. Qualitative Analysis of Poisoning-Group Concentration
5. Experiments
5.1. Experimental Setup
5.1.1. Datasets
5.1.2. Testbed
5.1.3. Parameter Settings
5.1.4. Baselines
- V-DT (vanilla distributed DNN training): A fundamental distributed DNN training architecture, encompassing both data parallelism and model parallelism. A detailed description can be found in [28]. V-DT randomly selects agents for computation tasks and does not include a defense mechanism against potential attacks.
- Multi-Krum [16]: An enhancement of the classic Byzantine-robust algorithm Krum. Its core principle is that gradients among benign agents are relatively similar, whereas gradients generated by malicious agents are significantly different. Through iterative computation, potential malicious gradients are filtered out, thereby improving the robustness of distributed learning.
- FLDetector [50]: Attacks are detected by examining the consistency of model updates. Specifically, the master agent predicts subsequent model updates based on historical updates. If an update deviates significantly from the prediction, the corresponding agent is regarded as malicious.
5.2. Results and Analysis
- V-DT, which lacks a defense mechanism, has difficulty converging to a reasonable value.
- TAR-DT consistently outperforms the other methods in terms of MSE. As the number of malicious agents increases, this advantage becomes more evident.
- FLDetector and Multi-Krum show suboptimal performance. The limited performance of FLDetector is primarily attributable to its reliance on consistent model updates for prediction. In practical model poisoning attacks, malicious behavior may not always lead to obvious gradient variations, which weakens its effectiveness. Multi-Krum removes potentially harmful model updates according to loss differences. Although Multi-Krum performs better than FLDetector, its lack of further malicious-agent detection leaves it inferior to TAR-DT.
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Jiang, T.; Yang, L.; Zhao, X.; Qin, Z.; Hu, Q. Less Is More: Rethinking Parameter-Efficient Fine-Tuning from a Subtractive Perspective. Proc. AAAI Conf. Artif. Intell. 2026, 40, 5432–5440. [Google Scholar] [CrossRef] [Scilit]
- Andreina, S.; Zimmer, P.; Karame, G. On the Robustness of Distributed Machine Learning Against Transfer Attacks. Proc. AAAI Conf. Artif. Intell. 2025, 39, 7219–7227. [Google Scholar] [CrossRef] [Scilit]
- Zhang, W.; Hu, Y.; Shi, J.; Bai, X. Poplar: Efficient Scaling of Distributed DNN Training on Heterogeneous GPU Clusters. Proc. AAAI Conf. Artif. Intell. 2025, 39, 22587–22595. [Google Scholar] [CrossRef] [Scilit]
- Li, J.; Wang, X.; Chen, H.; Wu, Z.; Zhu, Z.; Cao, J.; Buyya, R. DGPAS: DQN-GRU guided distributed DNN pipeline training and adjacent scheduling in edge networks. Comput. Netw. 2025, 271, 111592. [Google Scholar] [CrossRef] [Scilit]
- Zhang, M.; Abdi, M.; Ashdown, J.; Restuccia, F. Adversarial attacks to latent representations of distributed neural networks in split computing. Comput. Netw. 2025, 273, 111755. [Google Scholar] [CrossRef] [Scilit]
- Li, H.; Li, X.; Fan, Q.; He, Q.; Wang, X.; Leung, V.C.M. Distributed DNN Inference With Fine-Grained Model Partitioning in Mobile Edge Computing Networks. IEEE Trans. Mob. Comput. 2024, 23, 9060–9074. [Google Scholar] [CrossRef] [Scilit]
- Huang, Y.; Cheng, Y.; Bapna, A.; Firat, O.; Chen, D.; Chen, M.; Lee, H.; Ngiam, J.; Le, Q.V.; Wu, Y.; et al. GPipe: Efficient training of giant neural networks using pipeline parallelism. Adv. Neural Inf. Process. Syst. 2019, 32, 103–112. [Google Scholar]
- Narayanan, D.; Harlap, A.; Phanishayee, A.; Seshadri, V.; Devanur, N.R.; Ganger, G.R.; Gibbons, P.B.; Zaharia, M. PipeDream: Generalized pipeline parallelism for DNN training. In Proceedings of the 27th ACM Symposium on Operating Systems Principles; ACM: New York, NY, USA, 2019; pp. 1–15. [Google Scholar]
- Zhang, R.; Liu, G.; Liu, Y.; Zhao, C.; Wang, J.; Xu, Y.; Niyato, D.; Kang, J.; Li, Y.; Mao, S.; et al. Toward Edge General Intelligence with Agentic AI and Agentification: Concepts, Technologies, and Future Directions. IEEE Commun. Surv. Tutor. 2026, 28, 4285–4318. [Google Scholar]
- Lovén, L.; Farahani, R.; Murturi, I.; Sigg, S.; Dustdar, S. Agentic Edge Intelligence: A Research Agenda. In Proceedings of the 18th IEEE/ACM International Conference on Utility and Cloud Computing (UCC), Nantes, France, 1–4 December 2025; ACM: New York, NY, USA, 2025. [Google Scholar]
- Ling, Z.; Jiang, X.; Tan, X.; He, H.; Zhu, S.; Yang, J. Joint Dynamic Data and Model Parallelism for Distributed Training of DNNs Over Heterogeneous Infrastructure. IEEE Trans. Parallel Distrib. Syst. 2025, 36, 150–167. [Google Scholar] [CrossRef] [Scilit]
- Tian, Z.; Cui, L.; Liang, J.; Yu, S. A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv. 2022, 55, 166. [Google Scholar] [CrossRef] [Scilit]
- Fang, M.; Cao, X.; Jia, J.; Gong, N. Local model poisoning attacks to Byzantine-robust federated learning. In 29th USENIX Security Symposium (USENIX Security 20); USENIX Association: Berkeley, CA, USA, 2020; pp. 1605–1622. [Google Scholar]
- Ma, Z.; Ma, J.; Miao, Y.; Li, Y.; Deng, R.H. ShieldFL: Mitigating model poisoning attacks in privacy-preserving federated learning. IEEE Trans. Inf. Forensics Secur. 2022, 17, 1639–1654. [Google Scholar] [CrossRef] [Scilit]
- Li, L.; Xu, W.; Chen, T.; Giannakis, G.B.; Ling, Q. RSA: Byzantine-robust stochastic aggregation methods for distributed learning from heterogeneous datasets. In Proceedings of the AAAI Conference on Artificial Intelligence; AAAI Press: Palo Alto, CA, USA, 2019; Volume 33, pp. 1544–1551. [Google Scholar]
- Blanchard, P.; El Mhamdi, E.M.; Guerraoui, R.; Stainer, J. Machine learning with adversaries: Byzantine tolerant gradient descent. Adv. Neural Inf. Process. Syst. 2017, 30. [Google Scholar]
- Pan, Y.; Su, Z.; Wang, Y.; Zhou, J.; Mahmoud, M. Privacy-Preserving Byzantine-Robust Federated Learning via Deep Reinforcement Learning in Vehicular Networks. IEEE Trans. Veh. Technol. 2025, 74, 9461–9475. [Google Scholar] [CrossRef] [Scilit]
- El-Mhamdi, E.M.; Guerraoui, R.; Rouault, S. The Hidden Vulnerability of Distributed Learning in Byzantium. In Proceedings of the 35th International Conference on Machine Learning; PMLR: Stockholm, Sweden, 2018; Volume 80, pp. 3521–3530. [Google Scholar]
- Andreina, S.; Marson, G.A.; Möllering, H.; Karame, G. BaFFLe: Backdoor detection via feedback-based federated learning. In 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS); IEEE: Piscataway, NJ, USA, 2021; pp. 852–863. [Google Scholar]
- Liu, K.; Brendan, D.; Siddharth, G. Fine-pruning: Defending against backdooring attacks on deep neural networks. In International Symposium on Research in Attacks, Intrusions, and Defenses; Springer: Cham, Switzerland, 2018. [Google Scholar]
- Wu, Z.; Xu, C.; Wang, M.; Ma, Y.; Wu, Z.; Xiahou, Z.; Grieco, L.A. Patronus: Countering Model Poisoning Attacks in Edge Distributed DNN Training. In Proceedings of the 2024 IEEE Wireless Communications and Networking Conference (WCNC); IEEE: Piscataway, NJ, USA, 2024; pp. 1–6. [Google Scholar]
- Huang, W.; Ye, M.; Du, B. Learn from others and be yourself in heterogeneous federated learning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition; IEEE: Piscataway, NJ, USA, 2022; pp. 10143–10153. [Google Scholar]
- Chen, X.; Du, T.; Wang, M.; Gu, T.; Zhao, Y.; Kou, G.; Xu, C.; Wu, D.O. Towards optimal customized architecture for heterogeneous federated learning with contrastive cloud-edge model decoupling. IEEE Trans. Comput. 2024, 74, 1123–1137. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Du, T.; Xu, C.; Zhuang, F.; Zhong, L.; Muntean, G.; Wu, D.O. FedOBP: Federated Optimal Brain Personalization through Cloud-Edge Element-wise Decoupling. arXiv 2026, arXiv:2604.16574. [Google Scholar]
- Sen, T.; Shen, H. Distributed training for deep learning models on an edge computing network using shielded reinforcement learning. In 2022 IEEE 42nd International Conference on Distributed Computing Systems (ICDCS); IEEE: Piscataway, NJ, USA, 2022; pp. 581–591. [Google Scholar]
- Chen, M.; Gündüz, D.; Huang, K.; Saad, W.; Bennis, M.; Feljan, A.V.; Poor, H.V. Distributed learning in wireless networks: Recent progress and future challenges. IEEE J. Sel. Areas Commun. 2021, 39, 3579–3605. [Google Scholar] [CrossRef] [Scilit]
- Qu, Z.; Guo, S.; Wang, H.; Ye, B.; Wang, Y.; Zomaya, A.Y.; Tang, B. Partial synchronization to accelerate federated learning over relay-assisted edge networks. IEEE Trans. Mob. Comput. 2021, 21, 4502–4516. [Google Scholar] [CrossRef] [Scilit]
- Yuan, L.; He, Q.; Chen, F.; Dou, R.; Jin, H.; Yang, Y. PipeEdge: A Trusted Pipelining Collaborative Edge Training based on Blockchain. In Proceedings of the ACM Web Conference 2023; ACM: New York, NY, USA, 2023; pp. 3033–3043. [Google Scholar]
- Lyu, X.; Han, Y.; Wang, W.; Liu, J.; Wang, B.; Liu, J.; Zhang, X. Poisoning with Cerberus: Stealthy and colluded backdoor attack against federated learning. In Thirty-Seventh AAAI Conference on Artificial Intelligence; AAAI Press: Washington, DC, USA, 2023; Volume 37, pp. 9020–9028. [Google Scholar]
- Shubha, S.S.; Shen, H. Trustworthy Distributed Deep Neural Network Training in an Edge Device Network. In 2022 IEEE International Conference on Big Data (Big Data); IEEE: Piscataway, NJ, USA, 2022; pp. 1570–1575. [Google Scholar]
- Tang, M.; Peng, F.; Wong, V.W.S. A Blockchain-Empowered Incentive Mechanism for Cross-Silo Federated Learning. IEEE Trans. Mob. Comput. 2024, 23, 9240–9253. [Google Scholar] [CrossRef] [Scilit]
- Ying, C.; Xia, F.; Wei, D.S.L.; Yu, X.; Xu, Y.; Zhang, W.; Jiang, X.; Jin, H.; Luo, Y.; Zhang, T.; et al. BIT-FL: Blockchain-Enabled Incentivized and Secure Federated Learning Framework. IEEE Trans. Mob. Comput. 2025, 24, 1212–1229. [Google Scholar] [CrossRef] [Scilit]
- Chen, H.; Zhou, R.; Chan, Y.-H.; Jiang, Z.; Chen, X.; Ngai, E.C.H. LiteChain: A Lightweight Blockchain for Verifiable and Scalable Federated Learning in Massive Edge Networks. IEEE Trans. Mob. Comput. 2025, 24, 1928–1944. [Google Scholar] [CrossRef] [Scilit]
- An, J.; Tang, S.; Sun, X.; Gui, X.; He, X.; Wang, F. FREB: Participant Selection in Federated Learning With Reputation Evaluation and Blockchain. IEEE Trans. Serv. Comput. 2024, 17, 3685–3698. [Google Scholar] [CrossRef] [Scilit]
- Tang, W.; Liu, E.; Ni, W.; Qu, X.; Huang, B.; Li, K.; Niyato, D.; Jamalipour, A. Game-Theoretic Incentive Mechanism for Blockchain-Based Federated Learning. IEEE Trans. Mob. Comput. 2025, 24, 10363–10376. [Google Scholar] [CrossRef] [Scilit]
- Ying, X.; Yan, K.; Gao, X.; Huang, J. IMFLKD: An Incentive Mechanism for Decentralized Federated Learning Based on Knowledge Distillation. Sci. Rep. 2026, 16, 10567. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Wu, Z.; Xu, C.; Chen, X.; Ma, Y.; Zhong, L.; Zhang, H.; Grieco, L.A. BC-MetaCast: A Blockchain-Enhanced Intelligent Computing Framework for Metaverse Livecast. IEEE Netw. 2023, 37, 161–168. [Google Scholar] [CrossRef] [Scilit]
- Chen, Y.; Yang, Q.; He, S.; Shi, Z.; Chen, J.; Guizani, M. FTPipeHD: A Fault-Tolerant Pipeline-Parallel Distributed Training Approach for Heterogeneous Edge Devices. IEEE Trans. Mob. Comput. 2023, 23, 3200–3212. [Google Scholar] [CrossRef] [Scilit]
- Miuccio, L.; Riolo, S.; Bennis, M.; Panno, D. Design of a Feasible Wireless MAC Communication Protocol via Multi-Agent Reinforcement Learning. In Proceedings of the 2024 IEEE International Conference on Machine Learning for Communication and Networking (ICMLCN), Stockholm, Sweden, 5–8 May 2024; pp. 94–100. [Google Scholar] [CrossRef] [Scilit]
- Shejwalkar, V.; Houmansadr, A. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In Proceedings of the Network and Distributed System Security Symposium, virtual, 21–25 February 2021. [Google Scholar]
- Hu, J.S.; Kuai, T.; Waslander, S.L. Point density-aware voxels for LiDAR 3D object detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition; IEEE: Piscataway, NJ, USA, 2022; pp. 8469–8478. [Google Scholar]
- Full Width at Half Maximum. Wikipedia. Available online: https://en.wikipedia.org/wiki/Full_width_at_half_maximum (accessed on 9 August 2026).
- Ikotun, A.M.; Ezugwu, A.E.; Abualigah, L.; Abuhaija, B.; Heming, J. K-means clustering algorithms: A comprehensive review, variants analysis, and advances in the era of big data. Inf. Sci. 2022, 622, 178–210. [Google Scholar] [CrossRef] [Scilit]
- Micali, S.; Rabin, M.; Vadhan, S. Verifiable random functions. In 40th Annual Symposium on Foundations of Computer Science; Cat. No. 99CB37039; IEEE: New York, NY, USA, 1999; pp. 120–130. [Google Scholar]
- TORCH. DISTRIBUTED. Pytorch. Available online: https://pytorch.org/docs/stable/distributed.html (accessed on 9 August 2026).
- Zhou, H.; Zhang, S.; Peng, J.; Zhang, S.; Li, J.; Xiong, H.; Zhang, W. Informer: Beyond efficient transformer for long sequence time-series forecasting. Proc. AAAI Conf. Artif. Intell. 2021, 35, 11106–11115. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Yu, R.; Shahabi, C.; Liu, Y. Diffusion convolutional recurrent neural network: Data-driven traffic forecasting. arXiv 2017, arXiv:1707.01926. [Google Scholar]
- Zhou, H. ETDataset. Available online: https://github.com/zhouhaoyi/ETDataset (accessed on 9 August 2026).
- UC Irvine. ElectricityLoadDiagrams. Available online: https://archive.ics.uci.edu/dataset/321/electricityloaddiagrams20112014 (accessed on 9 August 2026).
- Zhang, Z.; Cao, X.; Jia, J.; Gong, N.Z. FLDetector: Defending federated learning against model poisoning attacks via detecting malicious clients. In Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining; ACM: New York, NY, USA, 2022; pp. 2545–2555. [Google Scholar]






| Symbol/Parameter | Value |
|---|---|
| Total number of agents N | 30 |
| Number of malicious agents | 6 |
| Number of groups G | 6 |
| Initial credit | 50 |
| Default training model | Informer |
| Default training dataset | ETTm1 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Wu, Z.; Ma, Y.; Lu, L.; Xiao, H.; Liu, C. TAR-DT: A Trusted and Attack-Resilient Mechanism for Distributed DNN Training in Agentic Edge Intelligence. Future Internet 2026, 18, 439. https://doi.org/10.3390/fi18080439
Wu Z, Ma Y, Lu L, Xiao H, Liu C. TAR-DT: A Trusted and Attack-Resilient Mechanism for Distributed DNN Training in Agentic Edge Intelligence. Future Internet. 2026; 18(8):439. https://doi.org/10.3390/fi18080439
Chicago/Turabian StyleWu, Zhonghui, Yunxiao Ma, Lu Lu, Han Xiao, and Chao Liu. 2026. "TAR-DT: A Trusted and Attack-Resilient Mechanism for Distributed DNN Training in Agentic Edge Intelligence" Future Internet 18, no. 8: 439. https://doi.org/10.3390/fi18080439
APA StyleWu, Z., Ma, Y., Lu, L., Xiao, H., & Liu, C. (2026). TAR-DT: A Trusted and Attack-Resilient Mechanism for Distributed DNN Training in Agentic Edge Intelligence. Future Internet, 18(8), 439. https://doi.org/10.3390/fi18080439

