SafeRec-FL: Robust Federated Recommendation Learning Against Data Poisoning and Backdoor Attacks in Multi-Tenant E-Commerce Infrastructure

Authors

  • Troy Simmons School of Information Technology, University of Cincinnati, Cincinnati, OH, USA. Author

Keywords:

federated learning, recommendation systems, data poisoning, backdoor attacks, multi-tenant infrastructure, e-commerce, robustness, security, privacy, Byzantine resilience

Abstract

The rapid expansion of multi-tenant e-commerce infrastructures has created an urgent need for recommendation systems that can operate across diverse, independently managed data silos while preserving user privacy and platform security. Federated learning offers a promising paradigm for collaborative model training without centralizing sensitive user data, yet it simultaneously introduces a broad attack surface for adversaries seeking to manipulate recommendation outputs through data poisoning or backdoor injection. This paper presents SafeRec-FL, a robust federated recommendation learning framework designed to withstand such threats in a multi-tenant e-commerce environment. The framework integrates cryptographic trust anchors, Byzantine-robust aggregation protocols, and dynamic anomaly detection mechanisms to ensure that even a substantial fraction of malicious tenants cannot degrade recommendation quality or implant targeted backdoors. Beyond technical defenses, SafeRec-FL incorporates governance-oriented design choices—including compliance-by-design data handling, incentive structures aligned with honest participation, and standardized API interfaces that facilitate adoption by small and medium-sized businesses. We provide a comprehensive system-level analysis of architectural trade-offs between robustness, latency, fairness, and sustainability, and we draw on empirical evaluations from simulated multi-tenant deployments to demonstrate that SafeRec-FL maintains high recommendation accuracy while reducing attack success rates to negligible levels. The paper concludes with a discussion of policy implications and future directions for trustworthiness in decentralized socio-technical infrastructures.

References

1. Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., & Shmatikov, V. (2020). How to backdoor federated learning. In Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics (pp. 2938–2948). PMLR.

2. Blanchard, P., El Mhamdi, E. M., Guerraoui, R., & Stainer, J. (2017). Machine learning with adversaries: Byzantine tolerant gradient descent. In Advances in Neural Information Processing Systems (Vol. 30, pp. 119–129).

3. Cao, D., Chang, S., Lin, Z., Liu, G., & Sun, D. (2021). Understanding distributed poisoning attacks in federated learning. In IEEE INFOCOM 2021 (pp. 1–10). IEEE.

4. Chen, M., Mathews, R., Ooi, B. C., & Salim, F. D. (2022). Federated recommendation systems: A survey. ACM Computing Surveys, 55(7), 1–37.

5. Defense Advanced Research Projects Agency. (2023). Guaranteeing AI Robustness against Deception (GARD) program overview. DARPA.

6. Zhou, D. (2026). AI-Driven Hybrid SAST–DAST–SCA–IAST Framework for Risk-Based Vulnerability Prioritization in Microservice Architectures.

7. Guerraoui, R., Rouault, S., & Sorin, A. (2021). Robust federated learning: The case of gradient clipping and anomaly detection. In Proceedings of the 35th AAAI Conference on Artificial Intelligence (pp. 9253–9261). AAAI.

8. Kairouz, P., McMahan, H. B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A. N., ... & Zhao, S. (2021). Advances and open problems in federated learning. Foundations and Trends in Machine Learning, 14(1–2), 1–210.

9. Li, S., Cheng, Y., Liu, Z., & Liu, J. (2023). A survey on backdoor attacks and defenses in federated learning. Neurocomputing, 528, 45–61.

10. McMahan, H. B., Moore, E., Ramage, D., Hampson, S., & y Arcas, B. A. (2017). Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (pp. 1273–1282). PMLR.

11. Shi, C., Li, S., Lu, W., Wu, W., Wang, C., Cheng, Z., ... & Chua, T. S. (2026). TraceRouter: Robust Safety for Large Foundation Models via Path-Level Intervention. arXiv preprint arXiv:2601.21900.

12. Zhang, J., Chen, J., Wu, D., Liu, B., & Yang, Q. (2021). Poisoning attacks in federated learning: A survey. IEEE Access, 9, 132540–132558.

13. Sun, Z., Kairouz, P., Suresh, A. T., & McMahan, H. B. (2019). Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963.

14. Tang, J., Korolova, A., Bai, X., & Li, B. (2023). A unified framework for differential privacy and robust aggregation in federated learning. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (pp. 1294–1311). IEEE.

15. Zhou, Y., Li, Y., & Gao, Y. (2023). A survey on trustworthy federated recommendation systems. ACM Transactions on Intelligent Systems and Technology, 14(4), 1–36.

16. Fung, C., Yoon, C. J. M., & Beschastnikh, I. (2020). Mitigating sybils in federated learning poisoning. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (pp. 1169–1185). ACM.

17. Yin, D., Chen, Y., Kannan, R., & Bartlett, P. (2018). Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the 35th International Conference on Machine Learning (pp. 5650–5659). PMLR.

18. Zhang, C., Li, Z., Li, Z., & Xu, J. (2022). Federated learning with dynamic client selection and robust aggregation for recommendation. In Proceedings of the 31st ACM International Conference on Information and Knowledge Management (pp. 2543–2552). ACM.

Downloads

Published

2026-06-29

How to Cite

SafeRec-FL: Robust Federated Recommendation Learning Against Data Poisoning and Backdoor Attacks in Multi-Tenant E-Commerce Infrastructure. (2026). International Journal of Artificial Intelligence Engineering and Systems, 1(1). https://ijaies.org/index.php/home/article/view/36