Skip to main navigation Skip to search Skip to main content

Robust federated learning frameworks against data flipping threats in autonomous vehicles

  • Riadh Ben Chaabene

Student thesis: Master's thesisMaster in Engineering: Information Technology Engineering

Abstract

Federated Learning (FL) has emerged as a promising paradigm for privacy-preserving col laborative training across distributed clients. Its ability to enable large-scale learning while maintaining data confidentiality makes it particularly suitable for autonomous vehicles (AVs), where data is sensitive and decentralized. However, the distributed nature of FL introduces new security challenges, notably label-flipping (LF) attacks, in which malicious participants intentionally corrupt local datasets to degrade the global model’s performance. This thesis addresses these vulnerabilities by proposing a comprehensive framework that ensures both scalability and robustness in FL-based AV systems. The methodology is structured into three key parts. Part One – Development of the FL Framework: We designed and implemented a real-world FL environment integrating Convolutional Neural Networks (CNN) and Reinforcement Learning (RL) models on the SunFounder PiCar platform. This setup enabled collaborative training between vehicles while preserving data privacy. Part Two – The Attack Process: We simulated label-flipping attacks under different adversarial availability levels to analyze the system’s behavior under hostile conditions. A single malicious participant with high availability ( α = 0.9 reduced the source class recall by over 25% and caused a 20% global accuracy drop, highlighting the severity of LF threats. Part Three – Defense Mechanism (FALCON): We introduced FALCON (Federated Anomaly Learning and COllaborative Network), a multi-layer defense architecture integrating Federated Anomaly Detection (FAD), Principal Component Analysis (PCA), and Multi-Class Support Vector Machines (MCSVM). FALCON applies local anomaly detection, peer-to-peer anomaly voting, and server-level graph-based detection using Graph Neural Networks (GNN) to identify and neutralize persistent adversaries. Experimental evaluations demonstrated that the CNN achieved a 94.2% classification accuracy with a latency of 42 ms per frame, while the RL model reached a 91.8% navigation success rate and an average cumulative reward of 1365. Under LF attacks, model performance degraded significantly; however, FALCON restored global accuracy and recall to near-optimal levels, identifying over 90% of adversarial updates and reducing attack success rates to below 5%. Overall, this thesis demonstrates the feasibility of integrating FL into AV systems while effectively addressing adversarial vulnerabilities and scalability constraints. The proposed FALCON architecture represents a major step toward secure, scalable, and resilient federated learning for real-world autonomous driving and beyond.
Date7 Jan 2026
Original languageAmerican English
Awarding Institution
  • École de technologie supérieure
SupervisorMohamed Cheriet (Supervisor) & Darine Ameyed (Co-supervisor)

Cite this

'