Verdict
🟠 Highly Suspicious. Multiple methodological, experimental, and presentation concerns collectively suggest the experimental evaluation may not faithfully reflect real-world training conditions. The verdict is provisional pending verification of code, training logs, and hardware access records.
Key findings
- Implausible compute environment (Section V.A): Training a federated Graph Convolutional Network combined with TD3 reinforcement learning on a workstation with only an i7 CPU (3.2 GHz), 16 GB RAM, and Windows 7 — submitted in 2021 — is highly inconsistent with the GPU/TPU-accelerated norms of contemporary deep-learning research and with Microsoft's Windows 7 end-of-support date (January 14, 2020).
- Dataset–scenario mismatch (Sections IV.C and V.A): The paper anchors its motivation in the 2018 Fresenius Medical Care privacy breach yet uses the UC Irvine Facebook-like Social Network dataset (student demographics: age, gender, courses) to simulate a multinational healthcare access-control scenario. The external validity of mapping student online-community interactions to clinician trust and RBAC/ABAC enforcement is not substantiated.
- Implausibly perfect comparative results (Section V.C, Figs. 5–6): Reported margins appear too clean and stable across varying malicious-user ratios and data volumes:
- Fig. 5(a): k-BGP privacy leakage ~25% vs. SACM ~1%, SACM_U ~2%.
- Fig. 5(b): k-BGP peak leakage ~35% vs. SACM ~3%, SACM_U ~7%.
- Fig. 6(b): k-BGP data integrity ~63% vs. SACM ~96%, SACM_U ~92%. Real adversarial models are typically more sensitive to perturbation; near-constant performance suggests possible fabricated or randomized comparison data.
- Reward-design concerns (Eqs. 5 and 11, Section IV.B): The reward r = Σ(ρᵢ·DIᵢ − PLᵢ) re-multiplies a composite factor ρ = (1 − PLᵢ + DIᵢ)/2 with DIᵢ, which complicates the physical interpretation of the learning signal. The TD3-based federated extension is presented as a "universal model learning algorithm," arguably an overstatement given the limited novelty.
- Hardware claim: i7 CPU, 16 GB RAM, 3.2 GHz, 64-bit Windows 7 (Section V.A, p. 2897).
- Dataset claim: Facebook-like Social Network from UC Irvine used for healthcare access-control evaluation (Section V.A).
- Reported metric gaps: SACM/SACM_U vs. k-BGP — 1–3% vs. 25–35% leakage (Fig. 5); 92–96% vs. 63% integrity (Fig. 6).
- DOI preserved for indexing: 10.1109/JIOT.2021.3112686.
- Scope limitation: No high-resolution figure files were available for pixel-level duplicate analysis (Western Blot band or background-noise forensics). Conclusions about images cannot be drawn.
- Causality caveat: Suspicious setup, dataset mismatch, and overly clean curves are strong corroborating signals but not direct proof of misconduct. Confirmation requires access to raw code, training logs, hardware logs, and statistical reproducibility tests.
- Recommended actions: Request raw code, training environment records, and logs from the authors; clarify the dataset–scenario mismatch; consider a reproducibility study and statistical re-analysis of Figs. 5 and 6. Potential reporting via PubPeer and the IEEE editorial office if concerns remain unaddressed.
- Disclaimer: This report is AI-assisted and intended for academic discussion; final determination of misconduct rests with the responsible institutions.