[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85056-en":3,"doc-seo-85056-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85056,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning","Federated reinforcement learning enables collaborative policy learning across multiple agents in dynamic vehicular environments while avoiding raw-data sharing, improving privacy and scalability. For safety-critical autonomous driving, poisoning attacks can subtly inject malicious parameters and undermine global control reliability, yet remain insufficiently studied. SecApp is introduced as a defensive framework that improves robustness by combining digital-twin rehearsal and historical aggregated parameters with a selected central gradient. SecApp provides theoretical convergence guarantees under poisoning and is validated on digital twins modeling realistic highway scenarios.","Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning  \nZifan Zhang∗ , Minghong Fang†, Dianwei Chen‡, Zhuqing Liu§ , Prashant Khanduri¶ , Xianfeng Yang∗ , Anupam Das∗ , Yuchen Liu∗  \n∗North Carolina State University, USA, †University of Louisville, USA,‡University of Maryland, USA, §University of North Texas, USA, ¶Wayne State University, USA  \narXiv :2607 .08 137v 1 [ cs .CR] 9 Jul 2026  \nAbstract—Federated reinforcement learning (FRL) is crucial for enabling collaborative learning across multiple agents without sharing raw data, thereby enhancing privacy and scalability in the decision-making process within dynamic vehicular environments. However, poisoning attacks pose a significant threat to the security and reliability of FRL-based systems, particularly in safety-critical autonomous driving, where this vulnerability remains largely unexplored. These attacks can compromise the global control model by subtly injecting malicious system parameters, leading to potential hazards. To counter these challenges, we present SecApp (Secure Aggregation with poisoning-prevention and historical reinforcement) as a defensive framework aimed at enhancing the robustness of FRL systems designed for safety-critical driving scenarios. SecApp strategically integrates digital twins for rehearsal-based learning and leverages historical aggregated model parameters along with a selected central gradient to ensure that only benign data is aggregated, effectively mitigating the influence of malicious agents. Theoretical guarantees are provided for the convergence performance of SecApp in the presence of poisoning attacks. We also validate the effectiveness of SecApp using developed digital twins that model realistic highway environments to evaluate the control of autonomous vehicles under adversarial conditions.  \nI. INTRODUCTION  \nAdvancements in computing power have significantly improved decision-making and problem-solving. Among various approaches, reinforcement learning (RL) has proven effective in real-world mobile applications, including robotics [1], autonomous driving (AD) [2], [3], GPT-4 [4], wireless networks [5], [6], and healthcare [7] . In essence, agents on mobile entities or controllers receive observations to perceive the dynamics of their environments and train RL models to perform actions that maximize long-term cumulative rewards. However, single-agent RL suffers from low sampling efficiency and limited observability in mobile environments [8] . In safety-critical scenarios like AD, such agents often struggle to find optimal solutions for a wide range of operational conditions, especially in handling accident cases. Overlooking these sparsely distributed corner cases can lead to severe consequences, including threats to human safety. As a remedy, federated reinforcement learning (FRL) is employed by combining the strengths of federated learning (FL) and RL, enabling multiple distributed agents to collaboratively learn optimal policies from a holistic view while preserving the privacy of their individual data. FRL has been widely used in various domains [9]–[12], which enhances efficiency and generalization of decision-making models by leveraging  \ndiverse data sources from different perspectives of agents in dynamic environments.  \nWhile FRL offers significant advantages, it presents several risks when applied in safety-critical mobile systems [13] . The most critical challenge is the vulnerability to poisoning attacks, where malicious agents deliberately provide incorrect or misleading update signals, compromising the integrity of the global control for decision-making [14]–[17] . These attacks can significantly degrade the performance of FRL-based systems and potentially lead to failures in completing critical tasks. Although prior research has studied several defensive strategies to mitigate the impact of malicious agents [15],[18]–[24], these defense mechanisms are primarily designed for pure FL ","cbCaif802Dk2Z02E","https://ap.wps.com/l/cbCaif802Dk2Z02E","pdf",2887516,3,1,23,"English","en",105,"# Abstract\n# Introduction\n## Challenges of Secure FRL in Autonomous Driving\n## Key Goal and Proposed Framework","[{\"question\":\"What evidence and guarantees does SecApp provide for its defense approach?\",\"answer\":\"SecApp includes theoretical convergence guarantees under poisoning attacks and is validated using developed digital twins that model realistic highway environments under adversarial conditions.\"}]",1784200683,58,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"securing-autonomous-vehicle-systems-via-twin-aware-federated-reinforcement-learning","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/securing-autonomous-vehicle-systems-via-twin-aware-federated-reinforcement-learning/85056/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"What evidence and guarantees does SecApp provide for its defense approach?","Question",{"text":75,"@type":76},"SecApp includes theoretical convergence guarantees under poisoning attacks and is validated using developed digital twins that model realistic highway environments under adversarial conditions.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]