Distinguishing between benign and poisoned gradients hidden behind cryptographic masks is a critical challenge in privacy-preserving federated learning (FL). Existing robust aggregation defenses suffer from two primary limitations: (1) susceptibility to manipulation, where adversaries induce deviations from standard protocols to bypass statistics-based defenses (e.g., mean or median), and (2) limited detection granularity, where the reliance on coarse statistics under encryption fails to identify subtle or coordinated poisoning behaviors. To address these issues, we propose RankFL, a poison-robust and privacy-preserving FL scheme that leverages order sorting over ciphertext gradients. RankFL utilizes an efficient Paillier-based two-party comparison protocol to construct a joint order tree, facilitating quartile-driven filtering of malicious updates without compromising individual gradient privacy. Furthermore, we introduce RankFL-Extend, which incorporates zero-knowledge proof-of-knowledge and bidirectional verification to secure the ranking process against active adversaries. We provide a rigorous theoretical analysis to establish the scheme's privacy, indistinguishability, and convergence guarantees. Extensive experiments across diverse datasets and attack scenarios demonstrate that the proposed scheme achieves a$3\%$accuracy improvement over state-of-the-art defenses under poisoning attacks.
Jiayong Chai, Mo Chen, Wei Zhang, Xiaojuan Wang · 5 authors
Cross-domain data collaboration is a core requirement for the intelligent development of critical areas such as the Internet of Vehicles and intelligent transportation systems. In this scenario, vehicles and various sensors deployed roadside continuously generate massive amounts of time-series data, yet this data often forms "data silos" due to privacy regulations and a lack of trust between collaborating entities. Existing integrated schemes combining "Federated Learning + Blockchain" have achieved a certain degree of process traceability and automated payments, but risks of gradient-level privacy leakage persist, and inflexible and delayed incentive mechanisms result in low participation quality. To systematically address these bottlenecks, this paper proposes the Federated Learning with Assured Privacy and Reputation-Driven Incentives (FLARE) architecture, whose core innovation lies in the native integration of cryptographic security and mechanism design theory. It includes the Secure and Faithfully Executed Gradient aggregation (SafeGrad) protocol, which integrates partial homomorphic encryption and zero-knowledge proofs to provide verifiable privacy guarantees for gradient contributions while enabling efficient secure aggregation, defending against inversion attacks at the source; alongside this, it includes the Economy-on-Chain incentive (EconChain) mechanism, which designs an on-chain economic system based on blockchain, achieving precise measurement and sustainable incentivization of training process contributions through fine-grained instant micro-rewards and a dynamic reputation model. Experiments show that, compared to baseline schemes, FLARE can effectively enhance node participation enthusiasm and contribution quality without compromising model accuracy, providing a new paradigm with both strong security and high vitality for the trusted and efficient circulation of data.
Federated learning enables financial institutions to collaboratively develop credit risk models while maintaining data privacy, yet existing implementations prioritize accuracy and confidentiality over transparency and regulatory compliance requirements. Current federated approaches treat explainability as a secondary concern addressed through separate post-processing workflows, creating significant gaps in auditability and stakeholder trust that limit adoption in regulated environments. This article introduces the Explainable Update Auditing framework, which embeds transparency mechanisms directly into federated training protocols through local explanation bundles and privacy-preserving audit trails. The framework generates standardized, model-agnostic explanations that characterize how institutional updates influence global model behavior without exposing proprietary data or competitive information. Cryptographic attestation mechanisms verify compliance with fairness, stability, and governance constraints throughout training processes using zero-knowledge proof systems that maintain institutional confidentiality while providing mathematical assurance of appropriate collaborative behavior. The dual-layer trust mechanism addresses distinct information needs across multiple stakeholder groups, including participating institutions, regulatory authorities, internal governance bodies, and affected borrowers. Implementation considerations reveal computational overhead challenges, privacy-utility trade-offs, and cryptographic protocol efficiency requirements that must be addressed for practical deployment. The framework transforms federated learning from an opaque collaboration protocol into a transparent, auditable ecosystem that satisfies regulatory requirements while preserving privacy guarantees essential for cross-institutional partnerships in credit risk modeling applications.
The medical systems are becoming challenged by the issues associated with the secure verification of patient identities, privacy-protecting access control, and dynamic consent management of Electronic Health Records (EHRs). Conventional centralized designs infringe on patient-centered autonomy, have poor identity management, and put sensitive information at the risk of inaccessible information. The paper introduces a proposal to develop a decentralized and privacy preserving mechanism of access control using blockchain-enabled Self-Sovereign Identity (SSI), as proposing a combination of verifiable credentials (VCs), smart contracts, and zero-knowledge proofs (ZKPs). The proposed Consent-Driven Decentralized Identity Verification Algorithm (CD-DIVA) enables the patient to create decentralised identities, issue tokens of consent, and dynamically assign or remove access rights without having to involve third-party authorities. Smart contracts enable the conjurant enforcement of various consent terms and offer an inauditable audit trail and ZKPs grant healthcare providers with the ability to demonstrate their authority without revealing sensitive information. Experimental assessments show the framework to be efficient in minimizing the access latency, eliminating unauthorized disclosures and providing effective interoperability of heterogeneous healthcare systems. This contribution will be a complement to the current blockchain-based healthcare solutions since it helps adopt a patient-centric, tamper-proof, and privacy-preserving healthcare ecosystem by bridging the access control and trust gap in such systems.
The proliferation of AI-driven Customer Data Platforms (CDPs) processing vast amounts of personal data poses significant risks to minors in cross-border contexts, where existing consent mechanisms fail to ensure verifiable, granular, and revocable consent. This paper proposes a novel Blockchain-Governed Consent Infrastructure (BGCI) specifically designed to address these challenges. Leveraging blockchain’s immutability for auditability, smart contracts for automated policy enforcement, and Privacy-Enhancing Technologies (PETs) like Zero-Knowledge Proofs (ZKPs) for privacy-preserving age verification, the BGCI provides a robust framework for managing minor consent across jurisdictions. We detail a comprehensive architecture, core technical mechanisms, and cross-jurisdictional conflict resolution logic. Integration pathways with AI/CDP data ingestion, model training, and real-time personalization pipelines are defined. Rigorous analysis addresses scalability, security, regulatory compliance, and ethical considerations. The BGCI represents a critical step towards ethical, compliant, and empowering digital experiences for youth in the global data economy.
Pellakuri Vidyullatha, R. Sreejith, Amjad Ali Syed, Sanjeev Kumar · 5 authors
Digital identity in healthcare has evolved from a convenience into a necessity, yet its dependence on centralized authentication continues to expose systems to privacy breaches and operational fragility. Existing identity models, though secure in principle, often collapse under real-world conditions where IoT devices, patient data streams, and network failures coexist. Most frameworks optimize for privacy or performance but rarely both. This study proposes a Resilient Privacy-Preserving Digital Identity Framework (RePP-DIF) that fuses artificial intelligence (AI), Internet of Things (IoT), and blockchain to achieve adaptive and fault-tolerant authentication within healthcare networks. The framework integrates a CNN–LSTM edge predictor for anomaly detection, zero-knowledge proofs for selective credential disclosure, and a replica consensus mechanism to sustain verification during validator failures.
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
The current trends in the cyber threat landscape of distributed systems have required a paradigm shift to decentralized and thrustless security. The research suggests a new architecture, Federated Adversarial-AI for Zero-Trust Explainable Cybersecurity (FAZTEC), combining federated learning and adversarial artificial intelligence to help make the cybersecurity systems more resilient, and explainable. The proposed framework, with the help of federated learning, would allow interconnected threat detection on edge devices, which does not require sharing raw data since it would keep privacy and meet the criteria of regulatory requirements. The same happens through the use of adversarial AI in order to simulate advanced attack scenarios and thus strengthen the defines mechanisms of the threats that are evolving. Auditioning explainable AI (XAI) modules also increases transparency in the system, where the security analyst can understand and verify the detection results in real-time. The zero-trust architecture also verifies a device, user, and data flow continuously, which discards the implicit assumptions about trustworthiness. A wide range of experiments performed in various network environments proves the effectiveness, validity, and interpretability of FAZTEC, which represents a serious breakthrough in proactive cybersecurity protection. The work is useful to the future of security infrastructure, which is smart, decentralized and explainable, and applicable to critical applications in finance, healthcare, and government.
Privacy disclosure from model parameters and malicious attacks are critical issues in federated learning (FL). Existing research has yet to effectively address the simultaneous need for efficient communication design, privacy protection, and attack detection, which impedes the widespread adoption of FL in mobile edge networks over 6G wireless communication. In this paper, we propose a trustworthy FL framework that can ensure privacy, robustness, accountability, fairness, and explainability in mobile edge networks. Specifically, we integrate authenticated zero-knowledge proofs (ZKPs) and Pedersen commitments into the FL process. Despite the lack of direct access between servers and mobile devices, the servers can still identify trustworthy clients for specific tasks. Clients can verify the authenticity of the received global model based on the provided proofs and commitments. Furthermore, we leverage Ethereum to act as the verifier and authenticator of models. This verification and authentication process enables the servers to detect abnormal local models and perform trust-based aggregations. Numerical results demonstrate that the proposed trustworthy FL framework significantly improves the global model's in terms of accuracy, convergence rate, and security.
Federated Learning (FL) enables collaborative training of medical AI models across hospitals without centralizing patient data. However, the exchange of model updates exposes critical vulnerabilities: gradient inversion attacks can reconstruct patient information, Byzantine clients can poison the global model, and the \emph{Harvest Now, Decrypt Later} (HNDL) threat renders today's encrypted traffic vulnerable to future quantum adversaries.We introduce \textbf{ZKFL-PQ} (\emph{Zero-Knowledge Federated Learning, Post-Quantum}), a three-tiered cryptographic protocol that hybridizes (i) ML-KEM (FIPS~203) for quantum-resistant key encapsulation, (ii) lattice-based Zero-Knowledge Proofs for verifiable \emph{norm-constrained} gradient integrity, and (iii) BFV homomorphic encryption for privacy-preserving aggregation. We formalize the security model and prove correctness and zero-knowledge properties under the Module-LWE, Ring-LWE, and SIS assumptions \emph{in the classical random oracle model}. We evaluate ZKFL-PQ on synthetic medical imaging data across 5 federated clients over 10 training rounds. Our protocol achieves \textbf{100\% rejection of norm-violating updates} while maintaining model accuracy at 100\%, compared to a catastrophic drop to 23\% under standard FL. The computational overhead (factor $\sim$20$\times$) is analyzed and shown to be compatible with clinical research workflows operating on daily or weekly training cycles. We emphasize that the current defense guarantees rejection of large-norm malicious updates; robustness against subtle low-norm or directional poisoning remains future work.
Global disruptions, such as the COVID-19 pandemic, have exposed the fragility of supply chains and the critical need for coordination. However, effective collaboration is often hindered by the reluctance of firms to disclose sensitive proprietary data, such as inventory levels or logistical bottlenecks, due to competitive concerns. To resolve this dilemma, this study introduces a privacy-preserving framework integrating Zero-Knowledge Proofs (ZKPs) with blockchain technology. This approach allows stakeholders to validate compliance and operational status without revealing the underlying raw data, thereby fostering trust and resilience in decentralized networks.
Federated learning (FL) enables collaborative model training over distributed private data. However, sustaining open participation requires incentive mechanisms that compensate contributors for their resources and risks. Enabled by Web3 primitives, especially blockchains, recent FL proposals incorporate incentive mechanisms for open participation, yet most focus primarily on algorithmic design and overlook system-level challenges, including coordination efficiency, secure handling of model updates, and practical usability. We present FWeb3, a practical Web3-enabled FL framework for incentive-aware training in open environments. FWeb3 adopts a modular architecture that separates FL functions from Web3 support services, decoupling the off-chain training and data plane from on-chain settlement while preserving verifiable incentive execution. The framework supports pluggable aggregation and contribution evaluation methods and provides a browser-native DApp interface to lower the participation barrier. We evaluate FWeb3 in real-world settings and show that it supports end-to-end incentive-aware FL with transaction and data-transfer overheads of only 21.3% and 3.4% in WAN; FWeb3 also deploys from zero configuration in under 3 minutes and enables user onboarding in under 1 minute.
The use of Federated Learning (FL) in sensitive, multi-party settings has made it even more important to have trust, accountability and safe systems of governance have become increasingly critical in the context of Federated Learning (FL) being utilized in sensitive multi-party environments. FL defends locality of data, but still can be poisoned with models, tampered with malicious gradient modification and unstable client behaviour due to lack of trust verification. The current paper examines how integrating Bloackchain Technology into FL(BCFL) provides an unquestioned system of governance that facilitates clear client accountability, model provenance tracing and record tampering resistant record management. We integrate the architectural and cryptographic and consensus conditions that are necessary in the development of robust BCFL systems with a special focus on the lightweight and reputation based processes of consensus. As a case in point, we critically examine an example of solidity-based prototype, ReputationManager.sol, which executes a Proof-of-Reputation (PoR) mechanism in which the aggregation weight of each client in a model is determined by its past integrity. According to our review, we find there is a Centralization Paradox in that, despite the implementation being based on a decentralized ledger, the prototype is premised on singlet owner access control, delegating trustlessness to a centralized blockchain administrator, and creating a single point of failure. We achieve this by pointing out important future directions including decentralized PoR models, automatic reputation updates in the basis of cryptographically checkable conduct and the introduction of Zero-Knowledge Proofs to formulate privacy preserving, regulation conformable and truly trustworthy BCFL regulation.
Tuan Nguyen Kim, Ha Nguyen Hoang, Son Doan Trung, Lam Nguyen
Cloud computing has become a vital platform for large-scale data analytics, yet it poses significant privacy challenges when handling sensitive information, especially in healthcare and financial domains.Homomorphic Encryption (HE) enables computation on encrypted data, providing strong privacy guarantees, but traditional HE frameworks lack efficient query representation, do not protect query patterns, and cannot prove correctness of cloud-side computations.This paper proposes HE-Cloud, an integrated privacy-preserving framework that combines DSL-driven query compilation, HE, Zero-Knowledge Proofs (ZKP), and Oblivious RAM (ORAM).Our framework allows clients to express high-level analytical queries, securely executes them on encrypted data, protects query access patterns via ORAM, and returns verifiable results through ZKP.A proof-of-concept implementation using the Pima Diabetes dataset demonstrates feasibility: Average glucose computations can be performed entirely on encrypted data with sub-second latency for homomorphic operations and minimal accuracy loss (approximately 0.001).Scalable secure analytics, extendable to larger datasets and machine learning tasks.
Secure and bandwidth-conscious transmission of model updates is a central bottleneck in distributed machine learning. Existing secure aggregation and homomorphic encryption pipelines either reveal more than the task requires or incur prohibitive computation and communication costs. We introduce a verifiable functional encryption (VFE) framework that releases only the intended linear functions of client gradients while providing end-to-end integrity and privacy guarantees under standard lattice assumptions. Our instantiation, FlowAgg-FE, combines two novel components. First, KS-IPFE, a key-splittable inner-product FE scheme, supports per-round weighted aggregation, vector packing, and on-the-fly function changes without client re-encryption; function keys are distributed across two non-colluding helpers, eliminating a single point of trust and enabling lightweight, homomorphically verifiable tags on decrypted outputs. Second, PaS-Stream is a rate-adaptive encryption-and-compression pipeline that couples sketch-based gradient compression with batched FE ciphertext streaming, ensuring unbiased aggregation in the presence of stragglers and dropouts. We further bind client-side clipping to zero-knowledge range proofs and offer an optional differentially private release layer that composes with FE to yield (ε,δ)-privacy. A prototype based on LWE demonstrates practicality across cross-device and cross-silo training: client uplink is reduced by 1.9–3.4× and server CPU time by 1.6× versus state-of-practice encrypted secure aggregation, with accuracy within 0.3% of plaintext baselines and correctness preserved under up to 30% client dropout. These results show that verifiable FE can make secure, communication-efficient gradient transmission viable, as appropriate for theme of security and privacy in distributed machine learning of the Special Issue.
The convergence of social networking and electronic commerce has given rise to the social e-commerce paradigm, where content creators serve as the primary drivers of consumer engagement and purchase decisions. However, this ecosystem faces a critical tension between the need for high-precision ad targeting to sustain monetization and the increasingly stringent requirements for user privacy preservation. Traditional centralized recommendation systems require the aggregation of massive user behavioral datasets, creating significant risks of data leakage and violating emerging regulatory frameworks. To address this challenge, we propose a novel framework titled Fed-ZKC (Federated Zero-Knowledge Creator). This architecture synergizes Federated Learning (FL) with Zero-Knowledge Proofs (ZKP) to enable privacy-preserving ad targeting while ensuring verifiable monetization attribution for creators. In our system, user preference models are trained locally on edge devices to prevent raw data transmission, while a cryptographic verification layer ensures that ad interactions are genuine without revealing user identities to the platform or the creators. Extensive experiments conducted on large-scale real-world datasets demonstrate that Fed-ZKC achieves recommendation accuracy comparable to centralized baselines while reducing privacy leakage risks by orders of magnitude. Furthermore, the implementation of succinct non-interactive arguments of knowledge (zk-SNARKs) introduces minimal computational overhead, making the protocol feasible for deployment on modern mobile processors.
Exponentially growing data generated by networked devices in Industry 4.0 environments requires industrial analytics that are secure, scalable, and decentralized. This article proposes TADDA-4i, a new multi-layered architecture based on IOTA's Tangle-Directed Acyclic Graph (DAG)-based Distributed Ledger Technology (DLT)-combined with federated learning and edge computing to provide real-time, secure, reliable, and self-sovereign industrial analytics. The architecture minimizes centralized bottlenecks via feeless, asynchronous data validation and tamper-evident model update verification using the Tangle ledger. Adaptive Tip-Aware Data Prioritization (ATDP) and Tangle-Validated Federated Aggregation (TVFA) are two new algorithms proposed for improving responsiveness and securing federated learning integrity. Experimental evaluation in emulated industrial edge environments showed that transactions take 30 percent less time, almost all of the misbehaving updates are detected, the model is about 10 percent more accurate, and output is not reduced even if the number of devices reaches 50. These findings make TADDA-4i an executable solution for the future generations of decentralized industrial intelligence.
Abstract Can a dealer share a secret without knowing the shareholders? We provide a positive answer to this question by introducing the concept of an attribute-based secret sharing (AB-SS) scheme.With AB-SS, a dealer can distribute a secret based on attributes rather than specific individuals or shareholders. Only authorized users whose attributes satisfy a given access structure can recover the secret. Furthermore, we introduce the concept of attribute-based publicly verifiable secret sharing (AB-PVSS). An AB-PVSS scheme allows external users to verify the correctness of all broadcast messages from the dealer and shareholders, similar to a traditional PVSS scheme. Additionally, AB-SS (or AB-PVSS) distinguishes itself from traditional SS (or PVSS) by enabling a dealer to generate shares according to an arbitrary monotone access structure.To build an AB-PVSS scheme, we first implement a decentralized ciphertext-policy attribute-based encryption (CP-ABE) scheme, though not a fully-fledged one.We then incorporate non-interactive zero-knowledge (NIZK) proofs to enable public verification of the CP-ABE ciphertext. Based on the CP-ABE and NIZK proofs, we construct an AB-PVSS primitive.Finally, we conduct security analysis and comprehensive experiments on the proposed CP-ABE and AB-PVSS schemes. The results demonstrate that both schemes exhibit plausible performance compared to related works.
Joshua Edward Mamza, Idris Ismaila, Joseph A. Ojeniyi, Shafi’i Abdulhamid · 6 authors
The Common Vulnerability Scoring System (CVSS) depends on reliable vulnerability data from expert, but the current process of vulnerability score generation and transmission remain exposed to data manipulation and interception. Existing research work used supervised machine learning to automate CVSS scoring with up to 90% accuracy, but their plaintext-based approach lacked cryptographic protections, leaving it vulnerable to Man-in-the-Middle (MitM) attacks. Another research work introduced a homomorphic encryption-based framework that preserves data confidentiality during computation and offers moderate performance gains. However, their dependance on a single trusted aggregator, static key management, and absence of dynamic integrity threshold mechanisms left the system exposed if the aggregator’s key or channel were compromised. An architectural framework for an Enhanced Multi-Party Fully Homomorphic Encryption Scheme (EMHES) was designed to combat Man-in-the-Middle (MitM) attacks targeting Vulnerability Score manipulation. By employing Homomorphic Encryption, the framework enables computations on encrypted vulnerability scores, ensuring confidentiality throughout their lifecycle. Key enhancements include integrating digital signatures to authenticate classified scores before encrypted transmission to cloud environments and verify the integrity of decrypted results post-processing. Digital signatures and regulatory oversight significantly strengthen security properties like non-repudiation, integrity, and confidentiality for cloud-based data computations. The EMHES architecture features a secure transmission channel with multiple security layers within the cloud service provider infrastructure. Additional security mechanisms include secure key management protocols, zero-knowledge proofs for integrity verification, and a resilient secure aggregation protocol designed to counter MitM attacks. From a computational analysis, baseline algorithms exhibit constant time complexity O(1), while the EMHES architecture operates with linear time complexity O(n). The result shows that EMHES provides superior security, integrity and performance on large datasets.
Arka Pal, Louai Zahran, William Gvozdjak, Akilesh Potti · 5 authors
As large language models (LLMs) continue to grow in size, fewer users are able to host and run models locally. This has led to increased use of third-party hosting services. However, in this setting, there is a lack of guarantees on the computation performed by the inference provider. For example, a dishonest provider may replace an expensive large model with a cheaper-to-run weaker model and return the results from the weaker model to the user. Existing tools to verify inference typically rely on methods from cryptography such as zero-knowledge proofs (ZKPs), but these add significant computational overhead, and remain infeasible for use for large models. In this work, we develop a new insight -- that given a method for performing private LLM inference, one can obtain forms of verified inference at marginal extra cost. Specifically, we propose two new protocols which leverage privacy-preserving LLM inference in order to provide guarantees over the inference that was carried out. Our approaches are cheap, requiring the addition of a few extra tokens of computation, and have little to no downstream impact. As the fastest privacy-preserving inference methods are typically faster than ZK methods, the proposed protocols also improve verification runtime. Our work provides novel insights into the connections between privacy and verifiability in LLM inference.
Atefeh Nekouie, Majid Vafaei Jahan, Mohammad Hossein Moattar, Reza Sheibani
Access control and data privacy are two of the main necessities in managing electronic health records (EHRs) across distributed domain. There are privacy gaps that expose EHRs to risks like unauthorized access by unaffiliated medical personnel. Traditional attribute-based encryption (ABE) allows encryption based on user attributes but is unable to incorporate data-specific attributes, such as the type of medical information included in the record or the potential physician. This paper introduces a novel approach that integrates ABE with large language models (LLMs) and blockchain technology to enhance security and contextual access control in EHR systems. Specifically, a domain-specific LLM, such as ClinicalBERT, is leveraged to automatically extract semantic data attributes from unstructured medical records, enabling a more granular and context-aware encryption process. By embedding both user and data attributes into the ABE framework, access policies are dynamically refined, ensuring that only authorized users can view specific types of medical information. Furthermore, blockchain's immutable ledger enhances trust, streamlines attribute revocation, and fortifies the system against unauthorized modifications and security threats. The proposed framework significantly strengthens EHR privacy by integrating machine learning-driven attribute extraction with cryptographic access control, outperforming existing schemes in both security and flexibility. Evaluations validate the effectiveness of the proposed framework in preventing unauthorized access while maintaining efficient and transparent data management.
Secure and private sharing of electronic health records (EHRs) among multiple parties remains a significant challenge in digital healthcare. Although Blockchain technology can ensure data integrity through security and transparency, protecting patient privacy and enabling secure collaborative analysis continue to be difficult problems. To address these challenges, differential privacy (DP) and Zero-Knowledge Proofs (ZKPs) are integrated into a Blockchain-based solution in the innovative design of this multi-institutional EHR-sharing system architecture. ZKPs enable the verification of user identities and access requests without revealing sensitive information, while DP ensures that analytical results are statistically valid and that underlying data are protected against re-identification attacks. A permissioned Blockchain system is developed to support verifiable and privacy-preserving federated analytics over distributed data. Experimental results demonstrate that the proposed framework successfully achieves privacy protection, secure access, and interoperable data-sharing objectives.
This paper presents a framework that integrates blockchain-enabled Federated Learning (FL) with consensus mechanisms to mitigate poisoning attacks in healthcare environments. The framework incorporates blockchain consensus mechanisms, with Proof-of-Work (PoW) used as a baseline and Proof-of-Stake (PoS) adopted as the proposed approach; both are evaluated independently within the same Secure Multiparty Computation (SMPC)-enabled federated learning architecture for privacy preservation. The proposed system is evaluated on the OCTMNIST and TissueMNIST datasets under both centralized and federated settings, including poisoning scenarios with 10% and 50% malicious clients. Results show that consensus-aware aggregation reduces the influence of unreliable client updates and improves the robustness of the global model under poisoning conditions. In addition, the framework prioritizes trustworthy client contributions during aggregation, supporting reliable model sharing in collaborative healthcare learning environments. Unlike prior blockchain-based federated learning defenses that introduce heavy cryptographic overhead, the proposed PoS-based aggregation explicitly balances robustness and computational efficiency, enabling practical deployment under high poisoning ratios.