MARATTO

article · IET Software

Blockchain‐Audited Federated Learning: Securing Data and Model Updates With On‐Chain Provenance

20257 citationsOpen accessWoldia University

In plain language

This research outlines an engineering and architectural framework that uses a permissioned blockchain to audit federated learning systems. The system enhances data provenance and protects model update integrity by using a modular two-channel structure that separates provenance tracking from update auditing. Lightweight validation takes place directly on the blockchain, while complex analytics are processed off-chain. Tested in a prototype combining TensorFlow Federated and Hyperledger Fabric across ten clients, the framework detected anomalies approximately 18% faster under attack compared to a baseline federated learning configuration. It also achieved a slight accuracy improvement of 0.4 percentage points, accompanied by modest overheads of around 6% for communication and 8% for energy. Additionally, the architecture incorporates a proof-of-concept zero-knowledge argument flow to verify client summary properties off-chain while anchoring results on the blockchain.

Key takeaways

  • A two-channel architecture separates data provenance from model-update auditing across permissioned blockchains.
  • A working prototype built on TensorFlow Federated and Hyperledger Fabric achieved about 18% faster anomaly detection under attack.
  • The framework delivered a 0.4 percentage point gain in model accuracy alongside overheads of roughly 6% in communication and 8% in energy.
  • A proof-of-concept zero-knowledge proof mechanism allows off-chain validation of client summaries with on-chain anchoring.

Why it matters

Federated learning lets multiple parties train shared artificial intelligence models without exposing their raw data, but it remains vulnerable to malicious updates. By introducing a blockchain-based audit trail, this approach provides verifiable tracking of data and model changes, helping organisations catch attacks more swiftly without paying a heavy price in network bandwidth or power consumption.

Commercialisation angle

This work demonstrates an applied, tested prototype that could enable organisations collaborating on sensitive distributed machine learning to secure their training pipelines against tampering. Potential adopters include enterprises running consortium networks that require strict compliance and auditability. Having been evaluated on a ten-client laboratory testbed, the technology sits at an applied proof-of-concept stage and would require further testing at commercial scale before production deployment.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

We present a permissioned blockchain–audited federated learning (FL) framework that strengthens data provenance and model‐update integrity. Our contribution is primarily engineering and architectural: a modular two‐channel design (provenance vs. update‐audit), lightweight on‐chain validation with off‐chain analytics, and a practical mapping to the 1 + 5 architectural views. In a TensorFlow Federated + Hyperledger Fabric prototype with 10 clients, we observe ≈18% faster anomaly detection under attack and a + 0.4 pp accuracy delta versus a baseline FL setup, with ~6% communication and ~8% energy overhead. We also provide a proof‐of‐concept zero‐knowledge succinct noninteractive argument of knowledge (zk‐SNARK) flow to validate per‐client summary properties off‐chain while anchoring results on‐chain. These contributions collectively advance the practical deployment of secure, auditable FL systems.

Research topics

  • Scientific Computing and Data Management
  • Privacy-Preserving Technologies in Data
  • Blockchain Technology Applications and Security

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1049/sfw2/6670439

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.