发表机构
Bangladesh University of Business and Technology (BUBT); Jagannath University; University of New South Wales (UNSW)(孟加拉国商业与技术大学(BUBT); 贾格纳特大学; 新南威尔士大学(UNSW))
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文挑战了联邦入侵检测中隐私、鲁棒性等属性可独立组合的假设,发现隐私与鲁棒聚合的结合会降低稀有攻击检测性能,提出应将三者作为整体研究。
AI 中文摘要
联邦学习可实现注重隐私的网络入侵检测协作,无需集中敏感流量数据,但其在实际环境中的部署必须同时满足三个相互竞争的要求:形式化差分隐私保障、对拜占庭式对抗参与者的容忍性,以及在严重不平衡攻击类别中可靠的检测覆盖率。现有文献将这些属性视为可独立组合的,本文从理论和实证两方面对该假设提出挑战。本文研究了类别不平衡的联邦网络入侵检测系统(NIDS)中这些要求的相互作用,并引入几何不可区分性作为一种概念视角,用于分析隐私诱导的客户端更新分散可能使鲁棒聚合更难保留少数类信号的情况。以UNSW-NB15为案例研究,本文评估了差分隐私随机梯度下降(DP-SGD)与逐坐标中位数相结合的方法,在标签翻转和模型投毒攻击下的表现,威胁覆盖范围则在各攻击类别中进行评估。研究结果提供了初步证据,表明隐私噪声与鲁棒聚合的联合使用会不成比例地降低稀有攻击相对于多数类别的检测性能。本文还表明,在强隐私约束下观察到的部分性能崩溃可能源于训练校准误差,而即使在针对epsilon进行依赖调整后,超稀有类别仍可能存在残余性能下限。这些发现促使人们将隐私、鲁棒性和稀有攻击覆盖作为一个整体进行研究,而非视为可独立组合的属性,并表明感知聚合的建模与感知样本的评估是可信联邦NIDS的有前景方向。
英文摘要
Federated learning enables privacy-conscious collaboration for network intrusion detection without centralizing sensitive traffic data, yet its deployment in operational environments must simultaneously satisfy three competing requirements: formal differential privacy guaranties, tolerance to Byzantine-adversarial participants, and reliable detection coverage across severely imbalanced attack categories. Existing literature treats these properties as independently composable, an assumption that this paper challenges both theoretically and empirically. In this paper, we study how these requirements interact in class-imbalanced federated NIDS and introduce geometric indistinguishability as a conceptual lens for a regime in which privacy-induced dispersion in client updates can make minority-class signals harder for robust aggregation to preserve. Using UNSW-NB15 as a case study, we evaluate DP-SGD combined with coordinate-wise median under label-flip and model-poisoning attacks, with threat coverage assessed across attack categories. Our results provide initial evidence that the joint use of privacy noise and robust aggregation can disproportionately degrade detection of rare attacks relative to majority classes. We also show that part of the observed collapse under strong privacy can arise from training miscalibration, while a residual performance floor may remain for ultra-rare categories even after epsilon-dependent tuning. These findings motivate studying privacy, robustness, and rare-attack coverage jointly rather than as independently composable properties, and suggest that aggregation-aware modeling and sample-aware evaluation are promising directions for trustworthy federated NIDS.
Comments16 pages