AP3-FedFleet: Asynchronous Federated Learning With Dynamic Layer-Wise Privacy Protection for Heterogeneous IoT Systems
Abstract
Federated learning (FL) enables multiple devices to collaboratively train machine learning models without sharing raw data, making it well-suited for Internet of Things (IoT) applications. However, this approach is not fully secure, as the exchanged gradients can still leak sensitive information. Attacks such as Deep Leakage from Gradients (DLG) can reconstruct original training data, while Membership Inference Attacks (MIA) can determine whether a data sample was used during training. In addition, real-world IoT systems face significant challenges due to device heterogeneity, in which variations in computational capabilities and communication conditions lead to delays, unstable convergence, and inefficient training. To address these challenges, this paper proposes AP3-FedFleet, a unified framework that jointly handles privacy preservation and device heterogeneity. The proposed approach adopts a three-tier architecture consisting of clients, edge servers, and a central server, enabling asynchronous learning to avoid delays caused by slow devices. For privacy protection, each client applies a sequence of operations to its gradients, including gradient clipping to limit sensitivity, null-space rotation to disrupt reconstruction attacks, and selective noise injection applied only to dynamically identified high-risk layers. At the edge level, secure aggregation ensures that individual updates remain hidden, while the central server performs staleness-aware adaptive aggregation based on update freshness, accuracy trends, and model divergence to maintain stable learning. Experimental results on the MNIST dataset demonstrate that AP3-FedFleet effectively mitigates gradient reconstruction, achieving a low PSNR (7.29 dB) and reducing membership inference risk, with an area under the curve (AUC) close to random guessing (0.491), while maintaining high classification accuracy across varying levels of device heterogeneity. These results confirm that the proposed framework provides strong empirical resistance to the evaluated privacy attacks without compromising learning performance in heterogeneous IoT environments.