Ongoing

SybilGuard-FL: Byzantine-Robust Federated Learning for V2X Sybil Detection

Research problem
Vehicle-to-Everything (V2X) communication supports cooperative mobility and safety applications, but a single Sybil adversary can emulate multiple vehicles and distort traffic perception. Centralised detection requires collecting sensitive vehicular data, while ordinary federated learning can itself be poisoned by Byzantine or colluding clients. This creates a dual-layer security problem: Sybil messages must be detected at the application layer, and federated training must stay reliable under naturally non-IID vehicular data.
Description
SybilGuard-FL is a Byzantine-robust federated learning framework for detecting Sybil attacks in V2X networks. Each vehicle/RSU client trains a compact CNN–LSTM on its own temporal V2X message sequences, so raw vehicular observations never leave the client, while the server's SybilGuard aggregation limits poisoned and colluding model updates without penalising honest clients whose data naturally differs.
Research area
Federated Learning · V2X Security
Role
Lead researcher, Ph.D. research
Methods
Local detector: a compact CNN–LSTM (two Conv1D layers with 64 filters, a 64-unit LSTM and a 32-unit dense layer; 51,137 parameters) trained on 10×16 temporal sequences built from 16 kinematic and communication features.
Server-side SybilGuard aggregation: median–MAD norm clipping, robust update-deviation scoring, historical collusion similarity between clients' update directions, adaptive MAD-based suspicion thresholds, and reliability-weighted (trust-aware) aggregation instead of hard rejection.
Evaluation: DNN, 1D-CNN, LSTM, TCN and CNN–LSTM backbones; FedAvg, FedProx, coordinate median, trimmed mean, Multi-Krum and FoolsGold baselines under 0%, 20% and 40% colluding malicious clients.
Datasets
VeReMi NextGen — InTAS Highway 2 AM Traffic Congestion Sybil scenario, using its predefined training, validation and test partitions. Messages are grouped by observer into 10×16 sequences, and complete observer streams are assigned to 20 logical vehicle/RSU clients, giving naturally non-IID clients (40–59% Sybil sequences per client) without train–test leakage.
Key contribution
Formulates V2X Sybil detection as a dual-layer federated security problem that combines application-layer Sybil detection with Byzantine-resilient training over observer-derived non-IID vehicular clients. Introduces SybilGuard, an aggregation rule that fuses update-deviation and collusion-similarity evidence with historical client reliability, down-weighting malicious updates while preserving heterogeneous honest clients. Provides an observer-preserving evaluation protocol on VeReMi NextGen against standard and Byzantine-robust baselines.
Collaborators
Haitham Y. Adarbah and Afzel Noore — AI-Based Autonomous System Research Lab, Department of EECS, Texas A&M University–Kingsville
Period
Aug 2026 – present