This study examines how data poisoning and model poisoning attacks behave in federated learning (FL) environments shaped by the conditions common across Sub-Saharan Africa, with Namibia used as the primary reference context. The motivation for the study came from a straightforward observation: FL frameworks have been proposed as a privacy-preserving solution for distributed AI in low-bandwidth, data-sensitive settings, but the security defences built into them were designed and tested under assumptions that do not hold in most African deployments. This paper draws on a systematic literature review and a set of simulation-based experiments to examine that mismatch directly. Using a Dirichlet-partitioned non-IID environment across 50 simulated clients, the experiments show that standard Byzantine-resilient aggregation methods lose between 26% and 35% of their accuracy performance when IID conditions are replaced with non-IID ones approximating regional African heterogeneity. The study also introduces the FL-STRIDE threat taxonomy, which maps known FL attack vectors onto deployment conditions found in Namibia and similar contexts. A proposed Adaptive Robust Aggregation (ARA) framework, designed with non-IID robustness as a core requirement, achieves an accuracy gap of approximately 11.7% under the same test conditions, though this result is from simulation only and further empirical work is needed. Taken together, the findings suggest that Africa-specific FL security frameworks are both necessary and technically achievable.
Federated Learning, Data Poisoning, Adversarial Machine Learning, Byzantine Robustness, AI Security, Sub-Saharan Africa, Namibia, Non-IID Data.
Julia Phillemon, Baljinder Kaur. Adversarial Robustness and Federated Learning Security: A Simulation-Based Analysis of Data Poisoning Defence Systems for Distributed AI in Sub-Saharan Africa. Indian Journal of Modern Research and Reviews. 2026; 4(4):274-279
Download PDF