Previous Article in Journal
Adaptive Federated Baseline K-Means for Lightweight IoT Intrusion Detection: Auto-Thresholding and Robust Statistics Aggregation
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Defense Against Information Integrity Attacks in Federated IoT Systems Using Inertial Momentum-Aware IALM-RPCA

1
Department of Computer Science and Engineering, Rajshahi University of Engineering & Technology, Rajshahi 6204, Bangladesh
2
School of Mathematics and Data Science, Adelaide University, Adelaide, SA 5005, Australia
3
School of IT, Geelong Waurn Ponds Campus, Deakin University, Burwood, VIC 3216, Australia
4
Information Technology and Systems, Australian Institute of Higher Education, Melbourne, VIC 3000, Australia
5
Information Technology and Systems, Australian Institute of Higher Education, Sydney, NSW 2000, Australia
6
School of Science, Technology and Engineering, University of the Sunshine Coast, Sippy Downs, QLD 4556, Australia
*
Authors to whom correspondence should be addressed.
These authors contributed equally to this work.
IoT 2026, 7(3), 68; https://doi.org/10.3390/iot7030068 (registering DOI)
Submission received: 8 July 2026 / Revised: 18 August 2026 / Accepted: 21 August 2026 / Published: 26 August 2026

Abstract

While federated learning offers a decentralized approach to model training, ensuring the integrity of the information from each IoT client remains a challenge. This work delves into the dynamics of multi-stage federated learning, its susceptibility to information integrity attacks, and how to defend against such threats. A comprehensive understanding of data uncertainty and the challenges of poisoning attacks is discussed, laying a solid groundwork for the proposed defense mechanisms. At its core, this paper introduces a novel multi-stage federated learning model that segments the federated learning process into distinct phases with a novel approach of inertial momentum-aware Inexact Augmented Lagrange Multiplier Robust PCA with constant momentum factor and unaltered norm of the traditional one, each tailored to optimize for both efficiency and security. This robust framework is then tested against data injection-based poisoning attacks, using sparse noise, and demonstrates the effectiveness of the proposed recovery techniques like Robust PCA. Performance results highlight the resilience and efficiency of the introduced model with novel reconstruction algorithm, emphasizing the importance of this approach in real-world IoT settings. Data analysis, model summaries, and impacts of adversarial attacks further reinforce the findings, which are evaluated using rigorous statistical metrics and machine learning algorithms. The paper concludes by acknowledging its efficiency in detection and recovery from data poisoning attacks, improving robustness and data reconstruction in IoT environments while highlighting opportunities for further security enhancements.

1. Introduction

The era of the Internet of Things (IoT) has seen an increase in the connectivity of everyday devices, establishing a network that spans personal, public, and industrial domains. This interconnection has generated a massive flow of data, with devices continuously communicating, collecting, and transmitting information. While the increase in IoT devices represents an advancement in technology into the future, it has also presented a number of new challenges, particularly in the areas of data processing and learning methodologies [1].
These devices, despite their limited processing power, have strengthened the demand for advanced computational models capable of handling large datasets with minimal latency. Federated learning (FL) has emerged as an advanced paradigm that takes advantage of the distributed nature of IoT networks. By enabling collaborative model training while maintaining data localized, FL enhances privacy and optimizes the computational load on individual devices [2].
However, the decentralization that defines FL also introduces new vulnerabilities. The integrity of data is of utmost importance, as it is the fundamental basis that ensures the reliability and success of federated learning. Attacks that involve the injection of corrupted data by malicious actors represent a significant danger to the integrity of federated learning systems [3]. These attacks can hamper the learning process, lead to incorrect model updates, and ultimately compromise the entire learning infrastructure [4].
In light of the ever-increasing number of IoT devices and the ever-increasing dependence on FL, it is vital not only to address the issues that lie ahead but also to come up with effective countermeasures [5]. Recognizing the growing deployment of IoT devices and the reliance on FL for data processing and machine learning tasks, our study seeks to strengthen the FL framework against such threats. We propose to explore and refine methodologies that can enhance the robustness of FL against data uncertainties and information integrity attacks, particularly those that originate from the client side.
The goals of this work are designed to enhance the stability and security of the federated learning approach. By doing so, we aim to protect the cooperative nature of the learning process, particularly in the context of the rapidly expanding realm of IoT technologies. This effort is crucial to ensure that as more devices connect and communicate, they do so on a platform that’s resistant to disruptions and compromises.
The primary objectives of our research are threefold: firstly, to tackle the immediate challenges arising within the rapidly evolving domains of the IoT and federated learning; secondly, proposing a novel momentum-aware Inexact Augmented Lagrange Multiplier Robust PCA algorithm which is more efficient than the existing one; and, thirdly, to establish a benchmark for future innovation in secure and dependable decentralized learning ecosystems.
The key contributions of this research are as follows:
  • We developed a multi-stage federated learning model in order to strengthen the robustness and efficiency of decentralized learning against client-side data poisoning attacks.
  • We have proposed a novel approach to the Inexact Augmented Lagrange Multiplier (IALM)-RPCA [6] method by integrating the inertial momentum with an average constant momentum factor ( β = 0.5) without any tuning of the β value persisting the trait of the traditional IALM -RPCA algorithm.
  • As a countermeasure against information integrity attacks, specifically client-side data poisoning attacks, we developed a sophisticated defense strategy using the Augmented Lagrange Multiplication method. Our proposed method ensures the successful recovery of data after being corrupted which results in detecting client-side data integrity attacks in an efficient and effective manner by hybrid Inception–Transformer used as a global model in FL setting.
  • The novel approach of IALM-RPCA has been validated through a set of extensive experiments considering a benchmark dataset known as N-BaIoT [7]. The novel approach of IALM RPCA exhibits a positive outcome over existing IALM RPCA method for reconstruction.
The remainder of the paper is organized as follows: Section 2 provides a review of related work, focusing on foundational studies on federated learning and the security vulnerabilities it faces. Section 3 outlines our methodology, including the proposed multi-stage model and defense mechanisms against poisoning attacks and a novel approach by introducing inertial momentum-aware IALM-RPCA method with constant momentum factor. Section 4 presents the results, offering insights into the dataset, confusion matrix analysis, impact of adversarial attacks, accuracy trajectories over epochs, performance metrics under varying scenarios, comparative analysis between conventional and novel process and overall observations. Section 5 discusses the relevance of federated learning, the significance of data reconstruction, comparison with previous works, and future research directions. Section 6 concludes the paper.

2. Related Work

This section is focused on federated learning, more specifically highlighting the inherent vulnerabilities of federated learning as well as its potential defense mechanisms against threats, with a particular emphasis on poisoning attacks. The covered area can be roughly divided into two categories: the preliminary studies on federated learning and the security challenges that are associated with it.

2.1. Foundational Work on Federated Learning

In recent years, federated learning has experienced considerable developments, which has resulted in the opening up of a wide variety of strategies and approaches that can be utilized to take advantage of this decentralized training paradigm. In the meantime, it has been leading the way in advancing the field of machine learning. McMahan et al. [8] established a benchmark for future research when they proposed a revolutionary method for training machine learning models without the use of centralized data repositories. This mechanism emphasized effective communication and paved the way for further investigations. This study was further developed by Konečný et al. [9], who investigated the communication challenges associated with federated learning and developed architectures that reduce those difficulties.
Yang et al. [10] explored the challenges and future directions in the area of federated learning, presenting a more comprehensive perspective on its potential. Also, Smith et al. [11] have presented a multi-task learning technique in federated settings, addressing the problems and potential solutions connected to ensuring privacy in such decentralized systems. Additionally, recent work by Lim et al. [12] on federated learning in mobile and edge computing environments has shed light on new challenges and opportunities in this domain. Bonawitz et al. [13] have made significant contributions to scalable federated learning, focusing on practical applications in large-scale systems. By sharing an additional model with each client, Tanmoy et al. [14] show an increase in the accuracy and fast convergence of the global model in FL setting in some cases compared to the existing FedAVG method. Later on, Tanmoy et al. [15] have evaluated accuracy and weight divergence of global model in FL setting for both model sharing and data sharing process.
The decentralization of data, despite its obvious challenge, comes with complications. Predicting data patterns across multiple nodes, each of which has its unique characteristics, has been a primary focus of the investigation. Bhagoji et al. provided a discussion on the challenges faced by poisoning attacks inside federated environments. Ref. [16], which is helpful. Further insights into optimizing federated learning algorithms are offered by Li et al. [17], focusing on enhancing model performance and efficiency.

2.2. Security Vulnerabilities in Federated Learning

The escalating use of federated learning has notably increased security concerns, particularly in the face of poisoning attacks. These attacks, aimed at disrupting the learning process through data manipulation, have been extensively analyzed by Biggio et al. [18]. Their work provides a deep dive into the systemic vulnerabilities of federated learning systems and the potential consequences of malicious activities. Recent developments in poisoning attacks, especially in IoT, have introduced new challenges, as discussed by Liu et al. [19]. They emphasized the complexity of security in IoT implementations of federated learning.
Recent advancements in the landscape of poisoning attacks, especially the emergence of “bi-level poisoning attacks,” have added a new layer of complexity, especially in IoT domains. Billah et al. [20] conducted an in-depth exploration of the implications of these sophisticated attacks on regression models, explaining their significant impact. Moreover, Zhang et al. [21] have brought to light various threats within the federated learning framework, emphasizing the urgent need for effective and robust security measures to counteract these challenges.
In response to the evolving security threats in federated learning, particularly in the context of IoT, researchers have proposed advanced defensive strategies. Wang et al. [22] and Wei et al. [23] have introduced comprehensive approaches to safeguard against data poisoning and model tampering. These strategies are crucial in maintaining the integrity and reliability of federated learning systems in increasingly complex and interconnected environments. The foundational work on Robust Principal Component Analysis (RPCA) by Candès et al. [24] has demonstrated that a corrupted data matrix can be decomposed into its underlying low rank structure and a sparse corruption component using Principal Component Pursuit. This work provided one of the fundamental formulations for recovering low-rank matrices with sparse and possibly arbitrarily large corruptions.
Moreover, to tackle the problem of corrupted matrices, the first paper that paves the way to use of ALM RPCA instead of traditional Robust PCA to mitigate the corrupted matrix was authored by Lin et al. [6]. Later, various optimization methods have made ALM RPCA more precise. Lin et al. [25] developed the Linearized Alternating Direction Method with Adaptive Penalty (LADMAP) algorithm, which successfully overcomes the structural constraints of traditional alternating direction method (ADM) algorithms by introducing a proximal term and an adaptive penalty rule. Zhu et al. [26] proposed a momentum-enhanced proximal ADMM framework for RPCA that improves convergence and robustness in nonconvex image- and video-processing applications. The paper authored by Wang et al. [27] introduced an inertial momentum-based optimization algorithm for SVD-free RPCA to improve computational efficiency and convergence for large-scale noisy data problems. Wu et al. [28] acquainted inertial proximal gradient methods with Bregman regularization for a class of nonconvex optimization problems. Xia et al. [29] showed that an inertial constraint term in RPCA optimization accelerates convergence and improves matrix recovery performance under mixed-noise environments by using a fractional function to approximate the L 0 norm and dynamic, non-linear thresholding. In the recent literature, Thamilarasu et al. [30] proposed a defense mechanism based on a recurrent neural network, called SpaceTime–Deep Similarity Defense (ST-DSD), which leverages spatial and temporal information to detect and prevent poisoning attacks in federated learning models. Ovi et al. [31] introduced confident federated learning, a defense framework against data poisoning attacks, that identifies and removes mislabeled training samples and detects malicious workers using neuron activation-based clustering. Olapojoye et al. [32] put forward FedECPA, a defense strategy based on scaling in blockchain-based federated learning to mitigate model poisoning attacks. The approach filters out clients with outlier model weights when aggregating and showed improved robustness.
Despite considerable academic research dedicated to unraveling the complexities of federated learning, a pronounced knowledge gap persists, especially concerning its inherent security vulnerabilities, like client-side poisoning attacks. This research endeavor is committed to addressing these vulnerabilities, aiming to illuminate the inherent weaknesses of federated learning systems. By doing so, it lays a foundational framework for future advancements designed to secure these systems against the nature of evolving threats.
This work highlights the critical need for ongoing vigilance and proactive innovation in security strategies. It underscores the importance of developing robust and adaptable defenses to safeguard federated learning models, particularly against sophisticated and dynamically changing threats. In doing so, this research not only seeks to bridge the current knowledge gap but also to pave the way for the creation of more robust and secure federated learning architectures, ensuring their efficiency and reliability in diverse and challenging environments.

3. Methodology

During this study, we have employed a wide range of distinct approaches to the implementation of investigations, all of which are described in further depth in the accompanying breakdown for this section. Detailed information regarding the procedures for multi-stage federated learning is supplied to protect the clients’ data from attacks on their information integrity. Clarification is then provided on the countermeasure technique we utilized to recover the poisoned data. This was done to remove any ambiguity that may have been caused. Discussion is also taking on regarding the amount of data uncertainty for the training data.

3.1. Overview of the Workflow

The methodology that we provide is founded on several essential steps, including data collection, the incorporation of federated learning, adding sparse noise, the processing of the data, the training of a federated model following the processing, and the subsequent strategies for data evaluation. Every one of these primary steps is capable of being broken down even further into deeper components. Figure 1 depicts the core process that we followed consistently to provide a greater understanding of our methodology. The next parts will go into greater depth regarding the complexities of each component.
A paradigm in the field of machine learning known as federated learning makes it possible to train algorithms across a large number of decentralized devices or servers, each of which stores its local data samples. When the goal is to construct machine learning models using data scattered across various devices, such as smartphones, without centralizing the data on a single server, it is crucially important that this strategy ignores the need to transfer data samples directly. This is essential when the purpose is to develop these models.

3.2. Operation of Federated Learning

The typical operation of the federated learning algorithm is described below. Here in Figure 2, a visual representation of FL process has been added.
  • The initial model is trained on a central server, which may be initialized randomly or based on some previous knowledge.
  • The most recent model is communicated to all of the devices (clients) that are actively participating in the federation.
  • Every device generates an updated model by using the data from its local environment.
  • The changes that were made locally are sent to the server. Users’ privacy can be protected by making these changes anonymous, random, or otherwise hard to understand.
  • The server aggregates all of these modifications and creates a new global model, often by taking an average of them. To balance the contribution of each device, the updates can be weighted, for example by the number of local samples on each device.
  • Steps 2 through 5 are carried out multiple times throughout several rounds until the performance of the model satisfies the specified requirements.
Federated learning is a very active research area and there are many different variants of the basic federated learning algorithm that are designed to address its various challenges. Some examples include the Federated Averaging (FedAvg) model that was proposed by McMahan et al., 2016 [9] and the SCAFFOLD model [33] that was proposed by Karimireddy et al., 2020.
It is important to highlight that even though federated learning can help protect privacy because it does not exchange raw data, it does not automatically assure full privacy or security. This is something that should be kept in mind. There is a chance that additional security measures, such as differential privacy [34] or secure multiparty computation, might be implemented to provide more robust assurances regarding the confidentiality of user information.

3.3. Poisoning Attack on Federated Learning and Recovery

Particularly in federated learning environments, poisoning attacks provide significant threats to machine learning models. They introduce inaccuracies into the training data, leading to incorrect pattern learning and inaccurate performance from the model. The nature of these attacks might be harmful. A successful recovery from such attacks requires attack detection, separation of affected data, data reconstruction, model re-training, and post-recovery analysis. In addition, an effective understanding of the potential strategies for attacks and the system architecture to enhance robustness is required.

3.3.1. Sparse Noise Introduction

During our research, we looked into a particular form of poisoning attack known as sparse noise, which is distinguished by the fact that it corrupts only a portion of the data and the magnitude is significantly high or low compared with the normal data distribution, and instances are sparse in nature. This allowed the structure of the dataset to be preserved while allowing the integration of the intended disruptions. This effectively simulated potential attacks in the real world on IoT client data.
In the considered threat model, an adversary is assumed to gain unauthorized access to the training data before it is distributed among the participating IoT clients. The attacker can modify a sparse subset of entries in the dataset while leaving the majority of the data unchanged. The objective of the attacker is to introduce corrupted information into the training process and consequently degrade the reliability and performance of the federated learning model.
In our experimental setup, the attack is implemented by adding sparse Gaussian noise into randomly selected entries of the full dataset. Then the corrupted dataset is fed to the proposed IALM-RPCA-based reconstruction method to separate the underlying low-rank information from the sparse corruption and recover the original data structure. The reconstructed dataset is then divided and distributed to the federated learning clients that participate in the federated learning process.
We assume the attacker does not have control over the federated aggregation server and the federated learning algorithm itself. The attack is conducted at the data level, prior to the dataset distribution to the involved clients. Therefore, the proposed defense is a pre-training data integrity tool instead of a client- or server-side model update defense.
The provided algorithm, termed as Sparse Noise Introduction—Poisoning Attack, is described in Algorithm 1.
The algorithm begins with an initialization phase where a sparsity level is set, for example 0.05 shown in Algorithm 1, indicating the proportion of the dataset’s entries that will be targeted with noise. Based on this sparsity level, it calculates the number of noisy entries by multiplying the dataset’s total size by the sparsity factor. Next, it randomly selects indices from the data set equal to the number of noisy entries identified.
For each of these indices, Gaussian noise is generated, following a normal distribution with a mean of zero and a standard deviation of five. Here in Figure 3 the probability density function is shown. The algorithm then applies this noise to the dataset, altering the original entries at the chosen indices to simulate the effect of an information integrity attack.
The outcome is the data set with the the noise introduced in a sparse manner, indicating a poisoning attack. To pursue the effect of attack irrespective of the different type of feature magnitude, so that for any later comparison of the two algorithms the real insight could be reflected, we have used the standard calling method after mixing raw noise with the data set. So, keeping the shape of the noisy dataset similar, all features were equally weighted so that, later on, RPCA could treat the value of all features fairly.
Figure 4 presents the distributions of several representative features. Although Gaussian noise was added randomly to entries throughout the entire feature matrix, rather than to each feature individually, the resulting distributions of the selected features in Figure 5 become bell-shaped and approximately Gaussian. This demonstrates the impact of the corruption process on the underlying data distribution.
Now, to enable effective low-rank and sparse decomposition by RPCA, we have scaled the data. In standardization, the usefulness of scaling is evident as it ensures equal feature contribution to the nuclear norm minimization and allows the regularization parameter to work uniformly across all features, leading to unbiased recovery of the low-rank structure and consistent sparse anomaly detection with efficient IALM convergence.
Here in Figure 6 only the feature values have been rescaled without changing the shape and noise structure. The standardization merely shifts each feature to zero mean and unit variance by a linear transformation, preserving the underlying data distribution and the additive Gaussian noise pattern. This is important in order for the noise characteristics to remain consistent and the low-rank and sparse structures required by RPCA to be preserved for faithful reconstruction and anomaly detection.
Algorithm 1: Sparse Noise Introduction—Poisoning Attack
Iot 07 00068 i001
It is essential to recognize that this method alters quite a few of the entries in the dataset with noise based on the Gaussian distribution. The subsequent analyses or performances of machine learning models may be dramatically impacted as a result of this.

3.3.2. Reconstruction of Noisy Data Using RPCA

The following section will provide a more in-depth breakdown of the procedures that are utilized for Robust Principal Component Analysis (RPCA) [35] and matrix completion. The large variety of RPCA approaches include methods like Accelerated Proximal Gradient, Dual Method, Singular Value Thresholding, Alternating Direction Method, and ALM (Augmented Lagrange Multiplier), among others. The Inexact ALM [35] approach has emerged as the leading choice among them, demonstrating speed and accuracy that are superior to any other method. As a result, its position as the favored alternative for data reconstruction in our research has been enhanced as a result of this development. As can be deduced from the names of the procedures, certain strategies, such as the Augmented Lagrange Multiplier and the Singular Value Thresholding, have been shown to be effective at completing matrices.

3.3.3. Inexact ALM RPCA Algorithm

Consider a matrix M R m × n . The Inexact ALM RPCA algorithm addresses the optimization problem:
min L , S L * + λ S 1 subject to L + S = M ,
where · * represents the nuclear norm (i.e., the sum of singular values) and · 1 denotes the 1 norm (i.e., the sum of absolute values). Here, L and S are low-rank and sparse matrices, respectively.
The algorithm procedure is
  • Initialize: Y = 0 , S = 0 , and L = 0 . Set μ = 1.25 M 2 , ρ = 1.5 , and max μ = 10 10 .
  • Repeat until convergence:
    (a)
    Update S using the shrinkage operator: S = shrink ( M L + Y / μ , λ / μ ) .
    (b)
    Update L with the Singular Value Thresholding (SVT) operator:
    L = SVT ( M S + Y / μ , 1 / μ ) , where U Σ V T = svd ( X ) , Σ = diag ( shrink ( σ , τ ) ) .
    (c)
    Update Y: Y = Y + μ ( M L S ) .
    (d)
    Update μ : μ = min ( ρ μ , max μ ) .
  • Convergence is achieved when M L S F / M F < tol , with ’tol’ as a pre-defined threshold.

3.3.4. Inertial Momentum-Aware Inexact ALM RPCA Algorithm

In the case of inertial momentum-aware IALM RPCA, all the steps of traditional IALM RPCA are consistent except for the addition of constant momentum factor ( β = 0.5) and extrapolation step of finding L k using L k 1 and L k 2 of the previous step for each kth iteration until convergence. We have taken into consideration that beta should be an average value because, if β = 1; the full difference affects the current value of the denoised, sparse matrix which will make the current result backward and, in the case of a negative momentum parameter β < 0, results in the opposite of momentum, which is of no use. And if β = 0, that leads to traditional IALM RPCA.
Here is the algorithm procedure:
  • Initialize: Y = 0 , S = 0 , and L = 0 . Set μ = 1.25 M 2 , ρ = 1.5 , max μ = 10 10 and β = 0.5.
  • Repeat until convergence:
    (a)
    L ¯ = L k 1 + β *( L k 1 - L k 2 ) ← addition of inertial momentum
    (b)
    Update S k using the shrinkage operator: S k = shrink ( M L ¯ + Y / μ , λ / μ ) .
    (c)
    Update L k with the Singular Value Thresholding (SVT) operator:
    L k = SVT ( M S k + Y / μ , 1 / μ ) , where U Σ V T = svd ( X ) , Σ = diag ( shrink ( σ , τ ) ) .
    (d)
    Update Y: Y = Y + μ ( M L k S k ) .
    (e)
    Update μ : μ = min ( ρ μ , max μ ) .
  • Convergence is achieved when M L k S k F / M F < tol , with ’tol’ as a pre-defined threshold.
We have used the traditional IALM RPCA algorithm with inertial momentum factor. We have not changed the 1 norm and thresholding process, rather we preserve the norm type. Keeping all traits of IALM RPCA unaltered, we have used the extrapolation method to introduce the inertial momentum factor. Moreover, we have assumed an average momentum factor β = 0.5 whereas a paper authored by Xia et al. [29] have used grid search to find beta and other parameters. Grid search can become very time-consuming, especially when many parameters exist, datasets are large, and each training or optimization run is expensive.

3.4. Overview of Used Multi-Stage Federated Learning Model

Within the scope of this study, the application of the Federated Averaging (FedAvg) algorithm was applied. The FedAvg algorithm [9], which was proposed by McMahan et al. in 2016, has now developed into a standard method in federated learning.
The following is an outline of the primary processes that make up the FedAvg algorithm:
  • Initialization: The server initializes a global model w 0 .
    w 0 Initialization of the global model
  • Model Distribution: The server sends the global model w t to each of the K clients.
    Send w t to each of the K clients
  • Local Training: Each client k computes an updated model based on its own local data D k . Each client performs E epochs of SGD with batch size B on its local dataset to compute the update.
    w t + 1 k SGD ( w t ; D k )
  • Local Model Upload: Each client sends its model updates back to the server.
    Send w t + 1 k to the server
  • Global Aggregation: The server aggregates these updates to form a new global model. This is done by taking a weighted average of the clients’ updates, where the weights could be proportional to the number of data points each client has.
    w t + 1 1 k = 1 K n k k = 1 K n k w t + 1 k
  • Repeat Steps 2–5: This process is repeated for several rounds until the model performance meets the desired criteria.
In this part, a detailed description of the research methodologies that were used in this investigation was provided. The mathematical foundations of the robust variation of Principal Component Analysis (PCA), which is referred to as Robust PCA, has been investigated and evaluated by this study. The Principal Component Analysis (PCA) is subject to severe erroneous points or outliers in the data, which is why many people choose the robust form of the Principal Component Analysis (PCA) [6]. In order to solve this problem, a number of different procedures for doing robust PCA were outlined [6]. In terms of the rank of the estimate, the relative error, and the amount of processing time that was necessary, each of these algorithms had its own unique set of benefits and drawbacks.
A lot of effort and consideration has already been given to various kinds of RPCA algorithm to make them more precise and robust. We have tried to make the IALM RPCA method more robust and efficient without changing it’s core methodology which displayed a high level of efficiency and performance over the traditional one. Following the breakdown of the algorithm into its component parts and subsequent expression using mathematical notation, the readability of the algorithm was improved significantly.
In order to correctly reconstruct the data, both traditional IALM RPCA and inertial momentum-aware IALM RPCA were applied, resulting in revealing the robustness of a novel approach of IALM RPCA, and, after that, the research endeavored to investigate federated learning. This cutting-edge method of machine learning allowed for the protection of users’ privacy concerns while simultaneously facilitating the creation of models that were founded on reconstructed data. Due to the fact that it enables the construction of models without the prerequisite of having to provide raw data, this method is significant when dealing with sensitive data.
The methodologies and algorithms that have been discussed up to this point served as the basis for the tests and results that will be discussed in the following section. The performance of each method on the dataset under consideration will offer us insights into the method for dealing with outliers in PCA that is the most effective and efficient based on those findings. In conjunction with federated learning, the objective of this research is to develop a method of data analysis that is robust, efficient, and protective of users’ privacy even when dealing with erroneous or infected data. This will be accomplished by developing a technique for data analysis that is robust, efficient, and protective of users’ privacy.

3.5. Global Model Architecture

The global model, a hybrid Inception–Transformer architecture intended for network traffic categorization, was cooperatively trained by multiple clients without exchanging raw data. Figure 7 shows the detailed model architecture and Figure 8 demonstrates the process flow diagram. The goal is to learn discriminative patterns from network flow data in order to differentiate benign traffic and various attack types.
The model uses a Transformer encoder with a Multi-Head Self-Attention (MHSA) layer to extract long-range dependencies in traffic features, which consists of three attention heads, each of dimension 64. We use residual connections and layer normalization to keep the feature representations and to stabilize the training. Instead of a conventional feed-forward sublayer, we replace the feed-forward component in the Transformer block with three stacked Inception blocks that extract multi-scale local patterns. Each Inception block consists of four parallel branches: (i) a convolutional branch with kernel size 10, (ii) a two-stage convolutional branch with kernel sizes 10 and 30, (iii) a two-stage convolutional branch with kernel sizes 10 and 50, and (iv) a max-pooling branch followed by a convolutional layer. The four branches use 16, 24, 12, and 8 filters, respectively.
The outputs of the parallel branches are concatenated and then passed through batch normalization and ReLU. Then we use a dropout with rate 0.1 for regularization and a 1 × 1 convolutional layer to project the output features to the required dimensionality. The output of the attention is added to the result of layer normalization with a residual connection. Then Global Average Pooling is used to get a fixed length feature representation. This representation is fed to a full connected layer of 32 neurons with ReLU activation, followed by dropout regularization. Finally, a softmax layer outputs the class probabilities for benign traffic and the attack classes considered.
This architecture effectively learns both contextual and local discriminative patterns by fusing the multi-scale extraction capability of Inception modules with the global dependency modeling capability of Transformer attention. This makes it appropriate for multi-class attack classification and federated network intrusion detection.

3.6. Feature Selection Process

The aim of the feature selection process was to decrease the input dimensionality without losing the most informative features. To assess the importance of each feature, an Extra Trees classifier consisting of 50 trees was trained on the training data, and the importance scores obtained were then used to rank the features, keeping only those whose importance was greater than the average importance. The feature selection procedure was constructed using only the training data and then applied to both the training and the test datasets to ensure consistency and prevent data leakage. The resulting feature sets were reshaped into a three-dimensional format, (N, F, 1), where N stands for the number of samples and F for the number of selected features, before being given as input to the neural network.

3.7. Global Model Training and Update

For federated training, the dataset is distributed across 10 simulated clients with the IID (random balanced) sampling strategy and each client is trained on mini-batches of size 64. Each client trains a local copy of the global model for one epoch per communication round with the Adam optimizer (default learning rate) and categorical cross-entropy as the loss function; class-weighted loss is used during local training. Then, the locally trained client models are uploaded to the server and their updates are scaled and aggregated by a weighted aggregation strategy similar to FedAvg to obtain the updated global model in each round. Hence, the global model is updated by aggregating locally trained models.

4. Results

The findings of our research shed insight into the discovery of the novel approach of adding a momentum term to IALM RPCA using the extrapolation method and combining with federated learning; it shows the efficiency as well as the robustness across a wide variety of circumstances. These findings demonstrate both the limitations and strengths that are inherent in federated learning models, and they also indicate the critical role that data reconstruction plays in reducing the vulnerabilities that are emphasized. In addition, these findings highlight the crucial role that data reconstruction plays in reducing the vulnerabilities that are highlighted using less computation and time.

4.1. Datasets

In our research, we utilized the ‘N-BaIoT Dataset’ [7] available in the UCI Machine Learning Repository. This dataset was developed in response to the notable absence of publicly accessible botnet datasets specifically tailored for the IoT domain. It encompasses real traffic data extracted from nine commercial IoT devices that were genuinely compromised by renowned malware, such as Mirai and BASHLITE. Figure 9 illustrates the dataset’s classes along with their respective value counts, including ten ’attack’ types and one ‘benign’ class.
Table 1 provides a detailed overview of the key attributes of the dataset employed in our study. It is structured into two columns: ‘Characteristic’ and ‘Detail’, offering a clear distinction between the attributes and their specifics. The dataset is categorized as ‘Multivariate, Sequential’, suggesting its complexity and sequential nature. It encompasses an extensive collection of 7,062,606 instances, each described by 115 real-number attributes. This dataset is versatile, as indicated by its applicability in both ‘Classification’ and ‘Clustering’ tasks. The inclusion of the ‘Date Donated’ offers insight into the dataset with a donation date of 19 March 2018.
Although the primary purpose of this dataset was to differentiate between benign and malicious traffic through the use of anomaly-detection techniques, the multifaceted nature of the malicious data enables it to also be used for multi-class classification. This is due to the fact that the malicious data consists of 10 different attacks that were initiated by two different botnets. The full N-BaIoT dataset contains traffic from nine devices, but we only use samples corresponding to device 5. In particular, we use the 5.benign.csv file with the available 5.gafgyt.* and 5.mirai.* files. This resulted in the numerical results presented in this work being obtained from the selected Device-5 subset instead of the entire nine-device dataset.
For further insights and dataset access, consult the UCI Machine Learning Repository at the following URL: http://archive.ics.uci.edu/ml/datasets/detection_of_IoT_botnet_attacks_N_BaIoT (accessed on 12 February 2024). A deeper exploration of the dataset and related research can be undertaken on Kaggle at https://www.kaggle.com/datasets/mkashifn/nbaiot-dataset (accessed on 10 February 2024).

4.2. Confusion Matrix Insights

Figure 10 visualizes the classification capabilities of our model. A noticeable trend is the high true positives under a “No Attack” context. However, adversarial interventions significantly lowered true classifications. A marked improvement in true positives was observed post-reconstruction.

4.3. Impact of Adversarial Attacks

Different levels of poisoning were tested in order to determine how well our federated learning strategy performed in a variety of information integrity attacks. The following Table 2 presents a comprehensive summary of the performance of the federated learning model when subjected to a variety of information integrity attack scenarios.
Table 2 provides a comprehensive evaluation of the federated learning approach under varying information integrity attack scenarios. The scenarios are determined based on different poisoning rates ranging from 0%, signifying no attack, to 15%, indicating that 15% clients’ data were subjected to poisoning.
Each scenario comprises:
  • The number of clients, uniformly represented as K = 10.
  • The accuracies observed during ten distinct training rounds: the initial (1st round) to the last stage (10th round).
For each of these rounds, the performance metrics are split into three categories:
  • B (Best Client Accuracy): This depicts the highest accuracy achieved by any single client.
  • W (Worst Client Accuracy): This represents the lowest accuracy across all clients.
  • G (Global Model Accuracy): This metric illustrates the accuracy of the federated global model after aggregating updates from all clients.
One may see how the integrity attacks affect the performance of the federated learning model by looking at Table 2. For instance, when there is no client attack present (the poisoning rate is set to 0%), the global model reaches an accuracy of 73.11% in the first round and significantly improves to 82.74% by the tenth round. It is important to note the model’s robustness and its flexibility to adversarial strategies as the poisoning rate increases. This is clear from the variances in accuracy across different poisoning rates.
According to Table 2, it is clear that the federated learning model maintains a noteworthy performance even when adversarial attacks are taken into consideration, and this is especially true when measured against the global accuracy metric.

4.4. Accuracy Trajectory over Epochs

As is clear in Figure 11, the model’s learning trajectory is central to comprehending its adaptability. Notably, even in the context of adversarial challenges, the rate of convergence remained noteworthy, particularly after the introduction of the data reconstruction mechanism. In Figure 11 above, it is clearly seen that the dotted line representing the IALM RPCA with inertial momentum approach outperforms the traditional IALM RPCA approach in all levels of attack, and the with no attack the model performance is undoubtedly the best one.

4.5. Performance Metrics Under Varying Scenarios

The model’s performance metrics across different scenarios, no attack, post-attack, and post-reconstruction by two approaches, are consolidated in Figure 12. It’s clear that adversarial attacks notably impaired the performance, but the data reconstruction process played a pivotal role in increasing the model’s efficiency and the inertial momentum-aware IALM RPCA with constant momentum factor is giving a better performance than existing IALM RPCA.

4.6. Comparative Analysis of Performance Metrics

The comparisons of different evaluation metrics for noisy data reconstruction are demonstrated here in Table 3, Table 4, Table 5 and Table 6. Here, different types of attack scenario have been taken into consideration to measure the robustness of each algorithm. The improvement column of each table states that.
This comparative evaluation shows that the post-reconstruction performance came close to approaching the no-attack baseline, which highlights the efficiency of the data reconstruction method that we employed. Surprisingly, even in the presence of a threat condition, the reconstructed model displayed a strong recovery, reaching an accuracy of near to 80% that outperformed the accuracy of the traditional IALM approach, which was only a bit behind the 83.34% that was seen in the case where there was no attack.

4.7. Comparative Analysis of Reconstruction Time

To compare time, reconstruction has been done under different attack scenarios 20 times and the average, median, max time and min time are recorded.
The IALM with Momentum methodology consistently needs more computing time than the normal IALM method across all attack percentages, as shown by the reconstruction time analysis in Table 7. For example, the average reconstruction time went from 524.35 s for IALM to 557.34 s for IALM with Momentum under the 25% attack scenario. The momentum-based variation exhibits increased minimum, maximum, average, and median reconstruction durations for 50%, 75%, and 100% attack settings.
The momentum mechanism, which adds an extra update component during optimization, is responsible for this rise in computing cost. This approach helps to increase optimization stability and refine low-rank reconstruction even if it slows down the reconstruction process. As a result, although IALM with Momentum takes longer to execute, it achieves better reconstruction quality, which improves classification performance over normal IALM in terms of accuracy, precision, recall, and F1-score.
As a result, there is a trade-off between reconstruction efficiency and computational efficiency. While IALM with Momentum compromises more computing time to obtain higher overall prediction performance and robustness against attacks, standard IALM delivers quicker execution. But in the case of good Cyber-Physical System (CPS) attack, removing is much more important than time efficiency, because if the attack remains it can result in rigorous loss in the long run.

4.8. Performance Assessment of Various β Values at Different Poisoning Attack Intensities

For each attack level, comparison of the different β values and identification of the best performer has been performed here.
Regarding the impact of the inertial momentum parameter β , a distinct pattern becomes apparent. The optimal balance between robustness and convergence speed is consistently achieved with moderate values of β (0.5) in most cases (highlighted in Table 8, Table 9, Table 10 and Table 11). In particular, β = 0.7 exhibits higher resistance in the most severe 100% assault scenario, achieving an F1-score of 77.22%, whereas β = 0.3 performs best under a 50% poisoning attack. Although β = 0.5 does not always achieve the highest score, it maintains stable performance across all attack intensities, indicating strong generalization. In general, extremely tiny momentum ( β = 0.1) and very large momentum ( β = 0.9) result in worse performance, indicating that the quality of RPCA reconstruction may be adversely affected by either insufficient or excessive inertial effect. We also evaluated the performance using negative values of β . The experimental results indicate that values of β greater than 1 lead to a gradual degradation in performance, while negative values of β also fail to outperform the stable performance achieved with β = 0.5 in all types of poisoning scenario. Moreover, as a small amount of carefully prepared poisoned data can have disproportionately large negative consequences for large language models, with recent experiments showing that a near-constant number of poisoned documents can compromise models of significantly different model and dataset sizes [36], efficient reconstruction of sparsely poisoned data is crucial for enabling effective detection and mitigation of such attacks. In this context, the findings show that the strongest resistance against data poisoning attempts in most cases is offered by the β value 0.5, particularly under low-sparsity poisoning conditions.

5. Discussion

The results of our study highlight the inherent potential of federated learning (FL) in assuring model robustness, particularly when it is set to the test in adversarial situations. The adaptability of the FL approach is further shown by the introduction and subsequent effectiveness of data reconstruction techniques, which is highlighted by the findings.

5.1. Relevance of Federated Learning

The findings of our study provide strong evidence on the efficiency of federated learning, demonstrating its robustness not only in typical scenarios but also in the face of adversarial conditions. This may be observed from the model’s persistent effort to maintain an outstanding level of performance, as illustrated in Table 2. The model demonstrated its flexibility and adaptation in the face of increasing rates of adverse poisoning. This was obvious from the relatively steady global accuracy metrics, even in situations where the integrity of client data was corrupted.

5.2. Significance of Data Reconstruction

The impact of adversarial attacks on the federated learning paradigm, specifically in relation to model accuracy and classification abilities, is unquestionable. This is demonstrated in Figure 10. Nevertheless, a major turn occurs with the implementation of data reconstruction approaches. The observed increase in the number of true positive results after the reconstruction process indicates that the implementation of strategic data restoration techniques has the potential to mitigate the harmful impacts of adversarial attacks. The robustness of the model, including its ability to recover from losses as shown in Figure 11, emphasizes the significant impact of effective data reconstruction methods.

5.3. Comparison with Previous Work

The findings of our study can be situated within the broader framework of the N-BaIoT dataset study, which focused on the detection of IoT botnet attacks [7]. The dataset was aimed to enable the distinction between benign and malicious network traffic. However, our research expanded its applicability by investigating its potential inside a federated learning framework with the novel IALM RPCA approach, particularly in the presence of adversarial circumstances. The expansion of the dataset’s application scope is not only enhanced, but it also highlights the practicality of employing federated learning models in real-world situations that may involve limitations.

5.4. Future Research Directions

Although our work provides a full overview of the federated learning landscape with momentum-based IALM RPCA in the presence of adversarial situations, there are still some areas that have not been explored:
  • This study aims to conduct a comprehensive examination of advanced data reconstruction strategies, with the potential to enhance the recovery capabilities of compromised models to a greater extent.
  • The expansion of this research to include other publically accessible datasets would serve to enhance the validation breadth, hence broadening the applicability of the findings.
  • An investigation on the extent to which these findings can be scaled, particularly in cases where the number of clients (K) is significantly increased.
  • This study is designed to investigate and evaluate advanced adversarial techniques and their corresponding responses in the context of federated learning.
In summary, our study highlights the undeniable potential of federated learning in addressing adversarial challenging situations. When coupled with effective data reconstruction techniques, these models have the ability to demonstrate durability, therefore guaranteeing their potential usability in various real-world situations where data integrity may be compromised. The findings, at their essence, highlight the inherent robustness of the federated learning paradigm, which is especially evident when the paradigm is further strengthened by capable data reconstruction approaches. Even while threatening activities can in fact affect performance, our research has shown that strategic countermeasures with novel approach can guarantee model robustness and capabilities.

6. Conclusions

In this paper, we present an in-depth investigation of the complexities of a multi-stage federated learning model, with an emphasis on the model’s defense against information integrity attacks in IoT contexts. The core focus of the study focuses on the integration of attack detection and data recovery, which constitutes a novel technique. This is demonstrated by the comprehensive examination of poisoning attacks, namely those arising from the presence of sparse noise inside the environment of the IoT. The results, which were emphasized by the utilization of the IALM RPCA algorithm, depict a promising outlook on the robustness of federated learning in handling reconstructed data following an attack. The results obtained from this research provide a significant basis for the evolving IoT environment and the increasing significance of decentralized learning approaches like federated learning. Moreover, a novel approach has been detected which outperforms traditional IALM RPCA in case of reconstruction. Nevertheless, the fact that this journey has been informative makes it evident that the continuously developing domain of IoT security and training needs further investigation, hence demonstrating the potential for ongoing advancements and enhancements in this domain.

Author Contributions

Conceptualization, O.B.T., S.H. and A.A.; methodology, O.B.T., S.H., A.A. and M.A.M.; software, S.H., O.B.T. and A.A.; validation, S.H., O.B.T. and A.A.; formal analysis, S.H. and O.B.T.; investigation, O.B.T. and S.H.; resources, A.A., M.A.M., A.B.M.M.H. and A.R.; data curation, S.H. and O.B.T.; writing—original draft preparation, S.H. and O.B.T.; writing—review and editing, A.A., A.R. and M.A.M.; visualization, S.H. and O.B.T.; supervision, A.A., A.R., A.B.M.M.H. and M.A.M.; project administration, A.A. and M.A.M.; funding acquisition, A.A., A.R. and A.B.M.M.H.; All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

The data presented in this study are openly available in the UCI Machine Learning Repository at http://archive.ics.uci.edu/ml/datasets/detection_of_IoT_botnet_attacks_N_BaIoT (accessed on 12 February 2024).

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
FLFederated Learning
IoTInternet of Things
ALMAugmented Lagrange Multiplication
RPCARobust Principal Component Analysis
IRPCAImproved Robust Principal Component Analysis

References

  1. Koohang, A.; Sargent, C.S.; Nord, J.H.; Paliszkiewicz, J. Internet of Things (IoT): From awareness to continued use. Int. J. Inf. Manag. 2022, 62, 102442. [Google Scholar] [CrossRef] [Scilit]
  2. API Management for IoT. Available online: https://www.wallarm.com/what/api-management-for-iot (accessed on 1 May 2026).
  3. Farhan, L.; Shukur, S.T.; Alissa, A.E.; Alrweg, M.; Raza, U.; Kharel, R. A survey on the challenges and opportunities of the Internet of Things (IoT). In Proceedings of the 2017 Eleventh International Conference on Sensing Technology (ICST); IEEE: New York, NY, USA, 2017; pp. 1–5. [Google Scholar]
  4. Ding, J.; Tramel, E.; Sahu, A.K.; Wu, S.; Avestimehr, S.; Zhang, T. Federated learning challenges and opportunities: An outlook. In Proceedings of the ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP); IEEE: New York, NY, USA, 2022; pp. 8752–8756. [Google Scholar]
  5. Kumari, P.; Jain, A.K. A comprehensive study of DDoS attacks over IoT network and their countermeasures. Comput. Secur. 2023, 127, 103096. [Google Scholar] [CrossRef] [Scilit]
  6. Lin, Z.; Chen, M.; Ma, Y. The augmented lagrange multiplier method for exact recovery of corrupted low-rank matrices. arXiv 2010, arXiv:1009.5055. [Google Scholar]
  7. Meidan, Y.; Bohadana, M.; Mathov, Y.; Mirsky, Y.; Breitenbacher, D.; Shabtai, A.; Elovici, Y. Detection of IoT Botnet Attacks N-BaIoT; University of California, Irvine (UCI): Irvine, CA, USA, 2018. [Google Scholar] [CrossRef]
  8. McMahan, B.; Moore, E.; Ramage, D.; Hampson, S.; y Arcas, B.A. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the Artificial Intelligence and Statistics, Fort Lauderdale, FL, USA, 20–22 April 2017; pp. 1273–1282. [Google Scholar]
  9. Konečnỳ, J.; McMahan, H.B.; Yu, F.X.; Richtárik, P.; Suresh, A.T.; Bacon, D. Federated learning: Strategies for improving communication efficiency. arXiv 2016, arXiv:1610.05492. [Google Scholar]
  10. Yang, Q.; Liu, Y.; Chen, T.; Tong, Y. Federated machine learning: Concept and applications. ACM Trans. Intell. Syst. Technol. (TIST) 2019, 10, 1–19. [Google Scholar]
  11. Smith, V.; Chiang, C.K.; Sanjabi, M.; Talwalkar, A.S. Federated multi-task learning. Adv. Neural Inf. Process. Syst. 2017, 30. [Google Scholar]
  12. Lim, W.Y.B.; Luong, N.C.; Hoang, D.T.; Jiao, Y.; Liang, Y.C.; Yang, Q.; Niyato, D.; Miao, C. Federated learning in mobile edge networks: A comprehensive survey. IEEE Commun. Surv. Tutor. 2020, 22, 2031–2063. [Google Scholar] [CrossRef] [Scilit]
  13. Bonawitz, K.; Eichner, H.; Grieskamp, W.; Huba, D.; Ingerman, A.; Ivanov, V.; Kiddon, C.; Konečnỳ, J.; Mazzocchi, S.; McMahan, B.; et al. Towards federated learning at scale: System design. Proc. Mach. Learn. Syst. 2019, 1, 374–388. [Google Scholar]
  14. Tanmoy, O.B.; Mamun, M.A.; Hasan, S.; Anwar, A. Enhancing federated learning with Globally Shared Model: A Modified FedAVG Approach (GSM-FedAVG). In Proceedings of the 2023 6th International Conference on Electrical Information and Communication Technology (EICT), Khulna, Bangladesh, 7–9 December 2023; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
  15. Tanmoy, O.B.; Hasan, M.A.M.; Nirjhar, N.A.; Mamun, M.A. Towards an Empirical Evaluation of Model and Data Sharing Methods in federated learning: Accuracy and Weight Divergence Analysis. In Proceedings of the 2025 28th International Conference on Computer and Information Technology (ICCIT), Cox’s Bazar, Bangladesh, 19–21 December 2025; pp. 640–645. [Google Scholar] [CrossRef] [Scilit]
  16. Bhagoji, A.N.; Chakraborty, S.; Mittal, P.; Calo, S. Analyzing federated learning through an adversarial lens. In Proceedings of the International Conference on Machine Learning, Long Beach, CA, USA, 9–15 June 2019; pp. 634–643. [Google Scholar]
  17. Li, Y.; Zhou, Y.; Jolfaei, A.; Yu, D.; Xu, G.; Zheng, X. Privacy-preserving federated learning framework based on chained secure multiparty computing. IEEE Internet Things J. 2020, 8, 6178–6186. [Google Scholar] [CrossRef] [Scilit]
  18. Biggio, B.; Nelson, B.; Laskov, P. Poisoning attacks against support vector machines. arXiv 2012, arXiv:1206.6389. [Google Scholar]
  19. Liu, Y.; Kang, Y.; Xing, C.; Chen, T.; Yang, Q. A secure federated transfer learning framework. IEEE Intell. Syst. 2020, 35, 70–82. [Google Scholar] [CrossRef] [Scilit]
  20. Billah, M.; Anwar, A.; Rahman, Z.; Galib, S.M. Bi-level poisoning attack model and countermeasure for appliance consumption data of smart homes. Energies 2021, 14, 3887. [Google Scholar] [CrossRef] [Scilit]
  21. Zhang, J.; Xu, X.; Han, B.; Niu, G.; Cui, L.; Sugiyama, M.; Kankanhalli, M. Attacks which do not kill training make adversarial learning stronger. In Proceedings of the International Conference on Machine Learning, Virtual, 13–18 July 2020; pp. 11278–11287. [Google Scholar]
  22. Wang, H.; Sreenivasan, K.; Rajput, S.; Vishwakarma, H.; Agarwal, S.; Sohn, J.y.; Lee, K.; Papailiopoulos, D. Attack of the tails: Yes, you really can backdoor federated learning. Adv. Neural Inf. Process. Syst. 2020, 33, 16070–16084. [Google Scholar]
  23. Wei, W.; Liu, L.; Loper, M.; Chow, K.H.; Gursoy, M.E.; Truex, S.; Wu, Y. A framework for evaluating gradient leakage attacks in federated learning. arXiv 2020, arXiv:2004.10397. [Google Scholar]
  24. Candès, E.J.; Li, X.; Ma, Y.; Wright, J. Robust principal component analysis? J. ACM 2011, 58, 1–37. [Google Scholar] [CrossRef] [Scilit]
  25. Lin, Z.; Liu, R.; Su, Z. Linearized alternating direction method with adaptive penalty for low-rank representation. Adv. Neural Inf. Process. Syst. 2011, 24. [Google Scholar]
  26. Zhu, Z.B.; Liu, Y.; Huang, J.Q.; Ding, Y.H. Efficient image and video processing via symmetric inertial proximal ADMM with RPCA model. Neurocomputing 2025, 637, 130054. [Google Scholar] [CrossRef] [Scilit]
  27. Wang, Q.; Han, D.; Zhang, W. A customized inertial proximal alternating minimization for SVD-free robust principal component analysis. Optimization 2024, 73, 2387–2412. [Google Scholar] [CrossRef] [Scilit]
  28. Wu, Z.; Li, C.; Li, M.; Lim, A. Inertial proximal gradient methods with Bregman regularization for a class of nonconvex optimization problems. J. Glob. Optim. 2021, 79, 617–644. [Google Scholar] [CrossRef] [Scilit]
  29. Xia, X.; Gao, F. An Optimization Algorithm of Robust Principal Component Analysis and Its Application. In Proceedings of the IOP Conference Series: Materials Science and Engineering; IOP Publishing: Bristol, UK, 2019; Volume 569, p. 052099. [Google Scholar]
  30. Thamilarasu, G.; Dunham, C. SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in federated learning. Big Data Cogn. Comput. 2025, 9, 313. [Google Scholar] [CrossRef] [Scilit]
  31. Ovi, P.R.; Gangopadhyay, A. Robust federated learning Against Data Poisoning Attacks: Prevention and Detection of Attacked Nodes. Electronics 2025, 14, 2970. [Google Scholar] [CrossRef] [Scilit]
  32. Olapojoye, R.; Salman, T.; Baza, M.; Alshehri, A. FedECPA: An Efficient Countermeasure Against Scaling-Based Model Poisoning Attacks in Blockchain-Based federated learning. Sensors 2025, 25, 6343. [Google Scholar] [CrossRef] [Scilit]
  33. Karimireddy, S.P.; Kale, S.; Mohri, M.; Reddi, S.; Stich, S.; Suresh, A.T. Scaffold: Stochastic controlled averaging for federated learning. In Proceedings of the International Conference on Machine Learning, Virtual, 13–18 July 2020; pp. 5132–5143. [Google Scholar]
  34. Wei, K.; Li, J.; Ding, M.; Ma, C.; Yang, H.H.; Farokhi, F.; Jin, S.; Quek, T.Q.S.; Vincent Poor, H. federated learning With Differential Privacy: Algorithms and Performance Analysis. IEEE Trans. Inf. Forensics Secur. 2020, 15, 3454–3469. [Google Scholar] [CrossRef] [Scilit]
  35. Low-Rank Matrix Recovery and Completion via Convex Optimization. Available online: https://people.eecs.berkeley.edu/~yima/matrix-rank/sample_code.html (accessed on 10 May 2026).
  36. Souly, A.; Rando, J.; Chapman, E.; Davies, X.; Hasircioglu, B.; Shereen, E.; Mougan, C.; Mavroudis, V.; Jones, E.; Hicks, C.; et al. Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples. arXiv 2025, arXiv:2510.07192. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Schematic representation of the workflow.
Figure 1. Schematic representation of the workflow.
Iot 07 00068 g001
Figure 2. Federated learning process.
Figure 2. Federated learning process.
Iot 07 00068 g002
Figure 3. Density function of added Gaussian noise ( μ = 0 , σ 2 = 25 ).
Figure 3. Density function of added Gaussian noise ( μ = 0 , σ 2 = 25 ).
Iot 07 00068 g003
Figure 4. Primary data distribution of some selected features.
Figure 4. Primary data distribution of some selected features.
Iot 07 00068 g004
Figure 5. Noisy data distribution of some selected features.
Figure 5. Noisy data distribution of some selected features.
Iot 07 00068 g005
Figure 6. Scaled noisy data distribution of some selected features.
Figure 6. Scaled noisy data distribution of some selected features.
Iot 07 00068 g006
Figure 7. Architecture for hybrid Inception–Transformer.
Figure 7. Architecture for hybrid Inception–Transformer.
Iot 07 00068 g007
Figure 8. Flow diagram for hybrid Inception–Transformer architecture.
Figure 8. Flow diagram for hybrid Inception–Transformer architecture.
Iot 07 00068 g008
Figure 9. Dataset class counts.
Figure 9. Dataset class counts.
Iot 07 00068 g009
Figure 10. Confusion matrix under “No Attack” context.
Figure 10. Confusion matrix under “No Attack” context.
Iot 07 00068 g010
Figure 11. Epoch vs accuracy after reconstruction by IALM RPCA and inertial momentum-aware IALM RPCA.
Figure 11. Epoch vs accuracy after reconstruction by IALM RPCA and inertial momentum-aware IALM RPCA.
Iot 07 00068 g011
Figure 12. Performance metrics of the federated learning model under diverse conditions.
Figure 12. Performance metrics of the federated learning model under diverse conditions.
Iot 07 00068 g012
Table 1. Dataset characteristics.
Table 1. Dataset characteristics.
CharacteristicDetail
TypeMultivariate, Sequential
Instances7,062,606
Attributes115 (Real Number Type)
TasksClassification, Clustering
Date Donated19 March 2018
Table 2. Evaluation of the federated learning approach under various information integrity attack scenarios.
Table 2. Evaluation of the federated learning approach under various information integrity attack scenarios.
Poisoning RateClients (K)1st Round10th Round
BWGBWG
0% (No Attack)1055.2852.5873.1182.5181.6782.74
5%1027.3225.6864.0952.7551.3169.01
10%1018.1817.5055.8640.8239.5760.88
15%1014.7014.0853.3034.0332.4458.88
* B: best client accuracy. W: worst client accuracy. G: global model accuracy.
Table 3. Performance metrics of the FL model for 25% attack.
Table 3. Performance metrics of the FL model for 25% attack.
MetricNo AttackPost AttackPost-ReconstructionImprovement
IALMIALM (Mom.)IALMIALM (Mom.)
Accuracy83.34%20.00%76.73%79.54%56.73%59.54%
Precision80.89%21.10%73.37%76.81%52.27%55.71%
Recall86.16%21.45%79.51%82.19%58.06%60.74%
F1-score81.83%12.65%74.97%77.68%62.32%65.03%
Table 4. Performance metrics of the FL model for 50% attack.
Table 4. Performance metrics of the FL model for 50% attack.
MetricNo AttackPost AttackPost-ReconstructionImprovement
IALMIALM (Mom.)IALMIALM (Mom.)
Accuracy83.34%21.40%77.58%79.20%56.18%57.80%
Precision80.89%16.63%74.55%76.11%57.92%59.48%
Recall86.16%23.09%80.41%82.00%57.32%58.91%
F1-score81.83%12.74%75.73%77.45%62.99%64.71%
Table 5. Performance metrics of the FL model for 75% attack.
Table 5. Performance metrics of the FL model for 75% attack.
MetricNo AttackPost AttackPost-ReconstructionImprovement
IALMIALM (Mom.)IALMIALM (Mom.)
Accuracy83.34%18.84%77.63%79.27%58.79%60.43%
Precision80.89%11.62%74.05%76.79%62.43%65.17%
Recall86.16%17.41%80.23%81.77%62.82%64.36%
F1-score81.83%8.04%75.90%77.27%67.05%69.23%
Table 6. Performance metrics of the FL model for 100% attack.
Table 6. Performance metrics of the FL model for 100% attack.
MetricNo AttackPost AttackPost-ReconstructionImprovement
IALMIALM (Mom.)IALMIALM (Mom.)
Accuracy83.34%23.70%74.82%75.19%51.82%51.49%
Precision80.89%11.72%72.78%72.97%61.06%61.25%
Recall86.16%26.13%77.55%76.53%51.42%50.4%
F1-score81.83%15.00%73.25%72.64%58.25%57.64%
Table 7. Comparative analysis of reconstruction time (sec) under different attack percentages.
Table 7. Comparative analysis of reconstruction time (sec) under different attack percentages.
Attack (%)Min TimeMax TimeAverage TimeMedian Time
IALMIALM (Mom.)IALMIALM (Mom.)IALMIALM (Mom.)IALMIALM (Mom.)
25%508.08538.47573.27654.05524.35557.34519.13548.285
50%452.50491.08475.82514.78460.31499.12459.89496.27
75%465.23506.76512.35568.31489.59533.00494.06537.00
100%464.90506.06521.25560.12491.50535.72498.82546.14
Table 8. Performance under 25% poisoning attack.
Table 8. Performance under 25% poisoning attack.
β AccuracyPrecisionRecallF1-Score
−0.576.0172.5678.7374.14
−0.377.5374.6080.7075.90
−0.177.0874.0880.2475.65
0.178.0174.3079.9875.85
0.378.0675.3681.5076.45
0.579.5476.8182.1977.68
0.779.6276.7882.1477.72
0.978.0175.7080.5576.25
172.2066.5069.4066.89
1.223.424.4414.306.53
Table 9. Performance under 50% poisoning attack.
Table 9. Performance under 50% poisoning attack.
β AccuracyPrecisionRecallF1-Score
−0.575.8772.8178.8774.33
−0.376.5073.6479.5974.76
−0.177.5974.9480.8075.96
0.178.1875.8781.5376.67
0.379.2876.5882.1077.75
0.579.2076.1182.0077.45
0.778.2475.6981.6676.68
0.977.5574.5280.5275.78
163.3658.0060.2555.48
1.223.404.6214.296.63
Table 10. Performance under 75% poisoning attack.
Table 10. Performance under 75% poisoning attack.
β AccuracyPrecisionRecallF1-Score
−0.576.4073.4179.7274.82
−0.378.6475.1980.9076.65
−0.178.6275.7880.8876.36
0.179.2876.3481.5877.15
0.378.6675.7581.7576.97
0.579.2776.7981.7777.28
0.776.8973.8979.8174.96
0.978.5776.6881.2577.03
169.4363.1867.7762.97
1.223.434.5614.306.60
Table 11. Performance under 100% poisoning attack.
Table 11. Performance under 100% poisoning attack.
β AccuracyPrecisionRecallF1-Score
−0.574.1771.2676.0472.57
−0.374.0471.9476.6472.39
−0.173.8970.0674.8171.48
0.174.5471.2376.3272.09
0.371.5568.0871.4967.65
0.575.1972.9776.5372.64
0.779.1875.8181.7277.22
0.977.6476.0980.3475.69
169.7558.8765.4061.15
1.211.681.269.092.20
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Tanmoy, O.B.; Hasan, S.; Anwar, A.; Mamun, M.A.; Hasan, A.B.M.M.; Rahman, A. Defense Against Information Integrity Attacks in Federated IoT Systems Using Inertial Momentum-Aware IALM-RPCA. IoT 2026, 7, 68. https://doi.org/10.3390/iot7030068

AMA Style

Tanmoy OB, Hasan S, Anwar A, Mamun MA, Hasan ABMM, Rahman A. Defense Against Information Integrity Attacks in Federated IoT Systems Using Inertial Momentum-Aware IALM-RPCA. IoT. 2026; 7(3):68. https://doi.org/10.3390/iot7030068

Chicago/Turabian Style

Tanmoy, Oudarja Barman, Sakib Hasan, Adnan Anwar, Md. Al Mamun, A B M Mehedi Hasan, and Akhlaqur Rahman. 2026. "Defense Against Information Integrity Attacks in Federated IoT Systems Using Inertial Momentum-Aware IALM-RPCA" IoT 7, no. 3: 68. https://doi.org/10.3390/iot7030068

APA Style

Tanmoy, O. B., Hasan, S., Anwar, A., Mamun, M. A., Hasan, A. B. M. M., & Rahman, A. (2026). Defense Against Information Integrity Attacks in Federated IoT Systems Using Inertial Momentum-Aware IALM-RPCA. IoT, 7(3), 68. https://doi.org/10.3390/iot7030068

Article Metrics

Article metric data becomes available approximately 24 hours after publication online.
Back to TopTop