Design of an Integrated Modern Approach to Detect and Prevent Data Poisoning Attacks in AI Systems: A Multi-Stage Defense Framework for Robust and Secure Learning
Main Article Content
Abstract
Adversarial threats like data poisoning attacks affect the training datasets and create biased, worse, or malicious AI models. Static heuristics and high false positive rates have impeded traditional defenses against such adaptive stealthy attacks. These defenses also do not generalize well in federated and non-IID settings. It is difficult to differentiate between poisoned and clean samples, and existing solutions even lack any adaptiveness to newly developed attack strategies; exhibit computational inefficiencies in process. This work presents a Modern Approach to Detect and Prevent Data Poisoning Attacks in AI Systems, coupled with a five-prong mechanism striving for data integrity and model resilience. Those mechanisms are Contrastive Adversarial Poisoning Detector (CAPD), the Federated Memory-Augmented Poison Filter (FMPF), Generative Adversarial Poison Purifier (GAPP), Graph Neural Network Consistency Analyzer (GNNC-A) and Adaptive Meta-Learning Defense System (AML-DS).All integrated, it achieves ≥ 96% poisoning detection accuracy, reduces attack success rates to ≤ 5%, and minimizes false positives to ≤ 2%.This work is scalable and adaptive and provides low computational overhead in security enhancement measures. By showcasing the high integrity of model security without excessively burdening the computer, this work significantly increases the robustness of AI systems in real-world applications.
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
References
Alber, D. A.; Yang, Z.; Alyakin, A.; et al. Medical large language models are vulnerable to data-poisoning attacks. Nat. Med. 2025, 31, 618–626. https://doi.org/10.1038/s41591-024-03445-1
Li, Y.; Zhang, J.; Zhu, J.; et al. BlockFD: Blockchain-based federated distillation against poisoning attacks. Neural Comput. Appl. 2024, 36, 12901–12916. https://doi.org/10.1007/s00521-024-09715-w
Gonzalez-Manzano, L.; Garcia-Alfaro, J. Software vulnerability detection under poisoning attacks using CNN-based image processing. Int. J. Inf. Secur. 2025, 24, 75. https://doi.org/10.1007/s10207-025-00989-2
Chillara, A. K.; Saxena, P.; Maiti, R. R.; et al. Deceiving supervised machine learning models via adversarial data poisoning attacks: A case study with USB keyboards. Int. J. Inf. Secur. 2024, 23, 2043–2061. https://doi.org/10.1007/s10207-024-00834-y
Zhang, G.; Liu, H.; Yang, B.; et al. DWAMA: Dynamic weight-adjusted Mahalanobis defense algorithm for mitigating poisoning attacks in federated learning. Peer-to-Peer Netw. Appl. 2024, 17, 3750–3764. https://doi.org/10.1007/s12083-024-01794-9
Dai, Y.; Shao, Y.; Wang, C.; et al. Graph augmentation against structural poisoning attacks via structure and attribute reconciliation. Int. J. Mach. Learn. Cyber. 2024. https://doi.org/10.1007/s13042-024-02380-4
Kaushal, V.; Sharma, S. Securing the collective intelligence: A comprehensive review of federated learning security attacks and defensive strategies. Knowl. Inf. Syst. 2025. https://doi.org/10.1007/s10115-025-02339-z
Cinà, A. E.; Grosse, K.; Vascon, S.; et al. Backdoor learning curves: Explaining backdoor poisoning beyond influence functions. Int. J. Mach. Learn. Cyber. 2025, 16, 1779–1804. https://doi.org/10.1007/s13042-024-02363-5
Naik, D. S. B.; Dondeti, V. Trust-based secure federated learning framework to mitigate internal attacks for intelligent vehicular networks. Peer-to-Peer Netw. Appl. 2025, 18, 10. https://doi.org/10.1007/s12083-024-01835-3
Liu, X.; Huang, J. J.; Zhao, W.; et al. SPA: A poisoning attack framework for graph neural networks through searching and pairing. Mach. Learn. 2025, 114, 14. https://doi.org/10.1007/s10994-024-06706-9
Gan, C.; Xiao, X.; Zhang, Y.; et al. An asynchronous federated learning-assisted data sharing method for medical blockchain. Appl. Intell. 2025, 55, 208. https://doi.org/10.1007/s10489-024-06172-9
Chillara, A. K.; Saxena, P.; Maiti, R. R. USB-GATE: USB-based GAN-augmented transformer reinforced defense framework for adversarial keystroke injection attacks. Int. J. Inf. Secur. 2025, 24, 79. https://doi.org/10.1007/s10207-025-00997-2
Mvah, F.; Kengne Tchendji, V.; Tayou Djamegni, C.; et al. GaTeBaSep: Game theory-based security protocol against ARP spoofing attacks in software-defined networks. Int. J. Inf. Secur. 2024, 23, 373–387. https://doi.org/10.1007/s10207-023-00749-0
Zhu, Y.; Wen, H.; Zhao, R.; Jiang, Y.; Liu, Q.; Zhang, P. Research on data poisoning attack against smart grid cyber–physical system based on edge computing. Sensors 2023, 23, 4509. https://doi.org/10.3390/s23094509
Ibrahum, A. D. M.; Hussain, M.; Hong, J. E. Deep learning adversarial attacks and defenses in autonomous vehicles: A systematic literature review from a safety perspective. Artif. Intell. Rev. 2025, 58, 28. https://doi.org/10.1007/s10462-024-11014-8
Liang, J.; Liang, S.; Liu, A.; et al. VL-Trojan: Multimodal instruction backdoor attacks against autoregressive visual language models. Int. J. Comput. Vis. 2025. https://doi.org/10.1007/s11263-025-02368-9
Zhai, Z.; Li, P.; Feng, S. State of the art on adversarial attacks and defenses in graphs. Neural Comput. Appl. 2023, 35, 18851–18872. https://doi.org/10.1007/s00521-023-08839-9
Kapusta, K.; Mattioli, L.; Addad, B.; et al. Protecting ownership rights of ML models using watermarking in the light of adversarial attacks. AI Ethics 2024, 4, 95–103. https://doi.org/10.1007/s43681-023-00412-3
Anaedevha, R. N.; Trofimov, A. G. Improved robust adversarial model against evasion attacks on intrusion detection systems. Opt. Mem. Neural Networks 2024, 33 (Suppl. 3), S414–S423. https://doi.org/10.3103/S1060992X24700681
Qu, Y.; Huang, S.; Li, Y.; et al. BadCodePrompt: Backdoor attacks against prompt engineering of large language models for code generation. Autom. Softw. Eng. 2025, 32, 17. https://doi.org/10.1007/s10515-024-00485-2
Ying, Z.; Wu, B. DLP: Towards active defense against backdoor attacks with decoupled learning process. Cybersecurity 2023, 6, 9. https://doi.org/10.1186/s42400-023-00141-4
Ishtiaq, H. U.; Bhutta, A. A.; Mian, A. N. DHCP DoS and starvation attacks on SDN controllers and their mitigation. J. Comput. Virol. Hacking Tech. 2024, 20, 15–25. https://doi.org/10.1007/s11416-023-00483-0
Dupont, G.; dos Santos, D.; Dashevskyi, S.; et al. Demonstration of new attacks on three healthcare network protocols in a lab environment. J. Comput. Virol. Hacking Tech. 2024, 20, 301–314. https://doi.org/10.1007/s11416-023-00479-w
Zhao, J.; Jiang, N.; Pei, K.; Wen, J.; Zhan, H.; Tu, Z. TPoison: Data-poisoning attack against GNN-based social trust model. Mathematics 2024, 12, 1813. https://doi.org/10.3390/math12121813
Ino, T.; Yoshida, K.; Matsutani, H.; Fujino, T. Data poisoning attack against neural network-based on-device learning anomaly detector by physical attacks on sensors. Sensors 2024, 24, 6416. https://doi.org/10.3390/s24196416