Junxu Hu, Ying Zhang
The Internet of Maritime Things (IoMT) enables large-scale coordination and sensing across vessels and coastal infrastructures, but the openness of Automatic Identification System (AIS) data and limited trust among participants expose learning pipelines to inference, leakage, and replay attacks. To address these challenges, this paper presents HHB-FL, a privacy-preserving federated learning framework designed for maritime environments. HHB-FL achieves end-to-end confidentiality through hierarchical homomorphic encryption and verifiable on-chain aggregation. Specifically, model updates are separated into weights and biases: weight updates are first perturbed with calibrated Laplace noise to ensure differential privacy and then encrypted using the Paillier scheme to maintain lightweight client computation, while bias updates are encrypted with CKKS to support precise homomorphic aggregation of floating-point parameters. A blockchain-based smart contract performs identity verification, deduplication, and freshness validation, ensuring transparent and tamper-evident aggregation without relying on a trusted server. A momentum-aware optimization strategy further stabilizes convergence under non-IID data and bandwidth-limited maritime links. Experimental results on AIS-driven tasks demonstrate that HHB-FL reduces the inference attack success rate from 92.59% to 41.61%, achieves 87.9% accuracy after 100 rounds, and maintains practical decryption and communication overheads. These results confirm that HHB-FL provides a secure and efficient foundation for privacy-preserving analytics in maritime IoT deployments.