Skip to content
Open access

A federated learning-based dual-filtering solution to combat data poisoning attacks in medical image classification

Jun 2026 · Bulletin of the National Research Centre · Vol 50 · 0 citations · 36 references

TL;DR

FedGF, an end-to-end two-stage defense scheme that combines client-side Genetic Data Selection with server-side Federated Unlearning enhanced by LOF-based anomaly detection, is proposed that consistently improves robustness and convergence stability compared with conventional aggregation defenses.

Abstract

The deep integration of artificial intelligence with the Internet of Medical Things (IoMT) has accelerated the adoption of federated learning (FL) for medical image classification. However, the decentralized training pipeline exposes FL to poisoning threats at both the data and model-update levels, potentially compromising diagnostic reliability. To address this challenge, we propose FedGF, an end-to-end two-stage defense scheme that combines client-side Genetic Data Selection (GDS) with server-side Federated Unlearning (FU) enhanced by LOF-based anomaly detection. GDS optimizes local training subsets through a fitness function that jointly considers parameter similarity, validation accuracy, and category-bias penalty, thereby filtering potentially poisoned samples before local training. During aggregation, FU further identifies and removes anomalous client updates and performs similarity-aware robust weighting. Experiments on the COVID-19 Radiography Database and the Pneumonia Chest X-ray Dataset under label-flipping attacks demonstrate that FedGF consistently improves robustness and convergence stability compared with conventional aggregation defenses.

Read PDF

Similar papers

Open access Aug 2026

Regulatory-orientedDeep federated learning framework for multi-hospital medical imaging: privacy-preserving, explainable, and generalizable diagnosis

Medical imaging has been transformed by Artificial Intelligence (AI) and Deep Learning (DL). Yet, multi-hospital deployment remains limited by patient privacy concerns, heterogeneous data distributions, and insufficient model interpretability, which affect regulatory approval and clinical trust. This study proposes a regulatory-grade Federated Learning (FL) framework for secure, interpretable, and generalizable collaborative medical imaging. The proposed framework integrates Slicing Window Adaptive Kalman Filtering (SWAKF) for image denoising, Structured Multi-Modal Autoencoder Attention Fusion (SMAAF) for feature representation, and adaptive federated aggregation to address non-IID data across hospitals. Patient privacy is preserved using secure aggregation, differential privacy, and encryption, while Grad-CAM, SHAP, and LIME provide model interpretability. The proposed framework outperformed Vision Transformer, AlexNet, FedAvg, and FedProx on Brain Tumor and Alzheimer's MRI datasets. It achieved 96.1% accuracy F1-score 96.1%, and 0.978 for Brain Tumor classification, and 94.8% accuracy and 0.968 for Alzheimer's classification. The framework also reduced calibration error, exhibited minimal encryption overhead, maintained robustness under noisy-label and non-IID conditions, and demonstrated statistically significant improvements p < 0.01 over baseline methods. The proposed FL framework provides a privacy-preserving, explainable, and computationally efficient solution for collaborative AI in medical imaging. By combining adaptive federated learning, secure privacy mechanisms, and explainable AI techniques, it improves diagnostic performance while supporting regulatory compliance and clinical trust, demonstrating strong potential for deployment in multi-hospital clinical environments.

Chandra Shakher Tyagi, Partheeban Nagappan, Tapas Bapu B R · 0 citations
Open access 2026

Detecting Data Poisoning Attacks in Medical Imaging Using Explainability-Driven Features

The integrity of training data is crucial for reliable medical image analysis; however, modern deep learning models remain vulnerable to data poisoning attacks. Such attacks can degrade diagnostic performance while remaining difficult to detect, particularly when a small fraction of the training data is poisoned. Existing defenses require access to the training data or rely on manual data sanitization techniques, which limit their applicability in medical imaging environments constrained by privacy and deployment restrictions. In this work, we propose a model-centric Explainable Artificial Intelligence (XAI)-based approach to identify data poisoning in medical imaging classifiers. The proposed approach examines the consistency between model predictions and associated relevance explanations. Discriminative features extracted from the explainability maps are used to train secondary classifiers that distinguish between models trained on clean and poisoned data. Our approach eliminates the need for data-level inspection and introduces an explainability-driven paradigm for post-training poisoning detection in medical imaging systems. The proposed framework is validated across multiple medical imaging modalities using Convolutional Neural Networks (CNNs) and Vision Transformer (ViT) architectures. Experimental results demonstrate strong data poisoning detection under low poisoning rates, achieving AUC scores of 0.88–0.94 across datasets at a 2% poisoning rate. These results highlight the potential of explainability-driven features as an effective privacy-preserving mechanism for detecting poisoned medical imaging models.

Akhila Asgar, Ahmed Saleh Bataineh, Ashika Sameem Abdul Rasheed et al. · 0 citations
Open access Jul 2026

FedHeartMRI: Decentralized Anomaly Detection and Classification in Cardiac MRI Using Federated Learning with Client-Level Differential Privacy

Timely analysis of cardiac MRI data is essential for early diagnosis and clinical intervention in cardiovascular illness, which continues to be the one world's leading causes of death. However, cross-institutional data sharing is ethically and legally problematic due to the nature of sensitive medical imaging data, which restricts the capacity to train reliable diagnosis models on the variety of the patient groups. A federated DL system for privacy-preserving anomaly detection and classification in cardiac MRI is presented in this work. It is intended to function in various simulated hospital settings without disclosing raw patient data. The suggested system, HeartMRI-FL, combines two deep learning models, an adaptive sub-client splitting mechanism, client-level differential privacy, and a Flower-based federated learning architecture— a supervised classifier for categorizing cardiac conditions and a convolutional autoencoder for unsupervised anomaly detection. Real-time training triggers, prediction queries, and result visualization are provided by a supplementary Angular-based clinical dashboard that interacts with the federated backend over a REST API. The system not only supports popular medical imaging formats like DICOM, NIfTI, and JPEG, but it also demonstrates that substantial diagnostic performance may be achieved without centralizing patient data. The federated approach provides a workable route toward privacy-compliant multi-institutional cardiac imaging analysis by achieving competitive accuracy while upholding formal differential privacy commitments, as confirmed by experimental results.

Chaithanya L, Veena K · 0 citations
Open access 2026

MAD-Based Update Filtering for Non-IID Federated Learning: Robustness Analysis Under Poisoning Attacks

Federated Learning enables collaborative model training without sharing raw client data, making it attractive for privacy-sensitive domains. However, its performance degrades when local data are non-independent and identically distributed (non-IID) and when malicious clients inject adversarial updates; robust aggregation alone can be insufficient, especially for imbalanced medical datasets where minority-class degradation is masked by overall accuracy. This paper proposes a Median Absolute Deviation (MAD)-based malicious-update filtering framework for non-IID federated learning. The server flags and excludes abnormal client updates before aggregation, using a coordinate-wise median reference and a modified Z-score over cosine distances. Unlike trust-based defenses, it requires no clean server-side dataset and provides an interpretable, per-round diagnostic. We evaluate it on CIFAR-10 and HAM10000 under noise injection and sign flipping against eight robust aggregation baselines, under a unified protocol that reports Accuracy and Macro-F1 at the same validation-selected checkpoint, averaged over three seeds. On CIFAR-10, the proposed method attains a mean Macro-F1 comparable to or better than the strongest baselines under both attacks (75.9% and 67.6%). On HAM10000 under noise injection it achieves the highest mean accuracy (74.0%) with a competitive Macro-F1, whereas under sign flipping it is only mid-ranked. An ablation indicates that removing MAD filtering substantially reduces class-balanced performance on HAM10000 under noise injection, and a diagnostic analysis shows that the cosine-distance signal separates benign and malicious updates strongly under noise injection but weakly under sign flipping. These results characterize both the robustness potential and the boundary conditions of update-level median filtering in non-IID federated learning.

Tae-Wook Kang, Ji-Woo Park, Chulyoung Park et al. · 0 citations
Open access 2026

A Hybrid Autoencoder-Random Forest Framework for Intrusion Detection in Internet of Medical Things Network

With the widespread adoption of the Internet of Medical Things (IoMT), hospitals have become prime targets for cyberattacks. To overcome the limitations of traditional defenses and computationally heavy deep learning models, a hybrid Artificial Intelligence architecture is presented. By coupling a deep Autoencoder for feature extraction with a Random Forest classifier, the input space is reduced from 44 down to 16 latent dimensions. While a standalone Random Forest achieves 98.95%accuracy, it remains too resource-intensive for constrained edge devices. The proposed hybrid approach strategically accepts a marginal sacrifice in accuracy—achieving 94.60% overall—in exchange for a drastic reduction in computational complexity. Rigorously validated on the CICIoMT2024 dataset and balanced via SMOTE-ENN, this model achieves an ultra-low inference latency of 1.05 ms on edge-grade hardware, making it highly viable for Edge Computing deployment. Furthermore, integrating the SHAP algorithm ensures decision-making transparency, addressing the “black box" challenge in medical AI. These results demonstrate the efficacy of strategic dimensionality reduction in securing critical healthcare infrastructures.

Sophia ALAMI-KAMOURI, Ridouan Lachgar, M. Afif · 0 citations