arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

FBID:面向物联网网络中鲁棒分布外攻击检测的自适应个性化联邦学习

FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks

An Khanh Bui, Cong Thanh Nguyen, Hoang-Anh Pham, Hoang Thai Dinh, Diep N. Nguyen

arXiv 2608.04073首次发表:更新:

发表机构

UTS-HCMUT JTIRC; Ho Chi Minh City University of Technology (HCMUT); Vietnam National University Ho Chi Minh City (VNU-HCM); University of Technology Sydney(UTS-HCMUT JTIRC; 胡志明市技术大学(HCMUT); 越南国家大学胡志明市分校(VNU-HCM); 悉尼科技大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对异构物联网环境中现有PFL方法易过度个性化导致OOD攻击检测性能下降的问题,提出FBID框架,通过服务器端上下文多臂老虎机与信任混合机制,提升OOD检测率、F1值及对未知攻击的鲁棒性。

AI 中文摘要

个性化联邦学习(PFL)已成为异构物联网环境中入侵检测的有前景解决方案,因其可在高度非独立同分布(non-IID)数据分布下提升本地适配能力。然而,现有PFL方法常依赖客户端自我调整,可能导致过度个性化,进而使分布外(OOD)攻击检测性能大幅下降。本文提出联邦盗入侵检测(FBID),这是一种新型自适应PFL框架,通过服务器端个性化控制解决该局限。具体而言,FBID在服务器端采用上下文多臂老虎机,根据各客户端的观测行为与更新质量动态调节其本地训练强度;此外,FBID引入基于信任的混合机制,推导全局模型与本地模型间的客户端特定插值系数,在保留全局攻击检测知识的同时,仍允许有益的本地专业化。通过在CICIoT2023数据集上,于异构客户端分布与OOD压力测试设置下开展大量实验,结果表明,相较于最强稳定基线,FBID可将各客户端OOD检测率(DR)提升最高7.66%,F1值(F1)提升最高5.08%(相对值),同时增强对先前未见过的攻击类别的鲁棒性。

英文摘要

Personalized Federated Learning (PFL) has emerged as a promising solution for intrusion detection in heterogeneous IoT environments, as it can improve local adaptation under highly Non-Independent and Identically Distributed (non-IID) data distributions. However, existing PFL methods often rely on client-side self-adjustment, which may lead to over-personalization and substantial degradation in out-of-distribution (OOD) attack detection. In this paper, we propose Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control. In particular, FBID employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality. Moreover, FBID introduces a trust-based blending mechanism to derive client-specific interpolation coefficients between the global and local models, thereby preserving global attack-detection knowledge while still allowing beneficial local specialization. Through extensive experiments on the CICIoT2023 dataset under heterogeneous client distributions and OOD stress-test settings, we show that FBID improves individual client OOD Detection Rate (DR) by up to 7.66% and F1-Score (F1) by up to 5.08% (relative) over the strongest stable baseline, while also improving robustness to previously unseen attack classes.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑