A Secure, Privacy-Preserving Federated Learning Framework for Smart Agricultural Supply Chains against Adversarial Data Poisoning in Supply Chain 5.0

Authors

  • Muhammad Irfan Student, Institute of Computing (IoC) Author
  • Dr. Amir Hussain Associate Professor, Institute of Computing (IoC) Author
  • Dr. Salman Qadri Professor, Institute of Computing (IoC) Author
  • Muhammad Yasir Khan Lecturer, Institute of Computing (IoC) Author
  • Dr. Kashif Razzaq Professor, Department of Horticulture Author

DOI:

https://doi.org/10.71317/kjard.2.6.2026.280

Keywords:

Federated Learning, Data Poisoning, Robust Aggregation, Smart Agriculture, Supply Chain 5.0, Internet of Things, Privacy Preservation, Edge Computing

Abstract

Modern farming supply chains rely more and more on distributed IoT sensing technologies to enable prediction analytics across the entire supply chain for crop monitoring, harvest planning and logistics downstream. However, if machine learning pipelines are centralized, sensitive telemetry data collected in the field must constantly be funneled to remote cloud servers, posing significant confidentiality concerns while using up significant bandwidth and placing all of the risk in a single point of failure. Federated Learning (FL) alleviates the data-governance issue through edge model training and only sending global model parameter updates, but also makes the global model vulnerable to adversarial data-poisoning attacks from compromised farm gateways. In this paper, a secure and privacy-preserving FL framework is proposed that is tailored for decentralized precision agriculture under Supply Chain 5.0 paradigm. The framework combines localized training on the farm with a robust aggregation mechanism that filters out anomaly data by reviewing the pair-wise geometric variance of the data from the different clients before data is synthesized globally. The system was tested on a real multi-sensor data set from agriculture consisting of 16,411 IoT telemetry instances from soil moisture, ambient temperature, and atmospheric humidity, with each node collected from a different farm and all non-IID. The evaluation specifically targets a severe threat regime in which 40% of the network (two of the five nodes) is attacking the network with a coordinated attack using data poisoning. Under this attack, an undefended FedAvg baseline struggles to remain above 77.8% accuracy; on the other hand, the proposed centroid-filtered framework gradually increases its accuracy up to around 92.6% over 20 communication rounds, which is almost the level of the benign reference accuracy and makes the security premium about 1%. 4-way ablation (with respect to coordinate-wise median, Krum, proposed filter) reveals that the proposed filter is the only filter which maintains a stable trajectory and achieves the highest terminal accuracy, while Krum is oscillating randomly in the presence of colluding minority. Stress testing with different adversarial fractions (0% to 60%) shows that the accuracy of the defended model is close to benign up to 40% adversarial fraction, at which point the adversarial fraction becomes the majority, after which the accuracy drops significantly. The held-out set consists of 3,283 samples and the protected model achieves 96.5% classification accuracy and macro-average ROC AUC of 0.993 on this set. The framework provides an evidence-based platform to deploy trusted distributed intelligence in the agriculture edge network.

Downloads

Published

2026-06-04

How to Cite

Muhammad Irfan, Dr. Amir Hussain, Dr. Salman Qadri, Muhammad Yasir Khan, & Dr. Kashif Razzaq. (2026). A Secure, Privacy-Preserving Federated Learning Framework for Smart Agricultural Supply Chains against Adversarial Data Poisoning in Supply Chain 5.0. Kashmir Journal of Academic Research and Development, 2(6), 41-62. https://doi.org/10.71317/kjard.2.6.2026.280