arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于梯度更新中威胁指标对比编码的联邦攻击活动检测

Federated Attack Campaign Detection via Contrastive Encoding of Threat Indicators in Gradient Updates

Manuel Röder, Bibin Babu, Frank-Michael Schleif

arXiv 2609.04815首次发表:更新:

发表机构

Technical University of Applied Sciences Würzburg-Schweinfurt; Bielefeld University; Center for Cybersecurity TTZ-WUE(维尔茨堡-施韦因富特应用技术大学; 比勒费尔德大学; TTZ-WUE网络安全中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出FedIoC模块化框架,通过客户端梯度更新中威胁指标的对比编码,在联邦学习场景下无需直接传输IoC即可跨组织检测协同网络攻击活动,明确非IID梯度结构为恢复的主要驱动因素。

AI 中文摘要

传统检测跨多个组织的协同网络攻击活动,需在机构边界和国界间共享敏感遥测数据和威胁情报,这一障碍可通过联邦学习(Federated Learning)移除——联邦学习可直接在本地数据上训练共享威胁检测器。我们提出FedIoC,这是一个模块化框架,客户端将本地可用的结构化威胁指标折叠入其梯度更新中;我们采用针对IoC匹配流的监督对比损失来实例化客户端侧编码器。在每个训练批次内,匹配任何已知指标模式的流构成正集;对比目标将其学习到的嵌入拉近,同时将非IoC嵌入推远,从而按设计使与攻击活动相关的结构在梯度方向上得以体现。共享同一攻击活动指标的客户端会产生对齐的梯度分量,服务器可通过更新的余弦相似度对这些分量进行聚类,从而在无需直接传输IoC的情况下恢复全局攻击活动模式。我们在两个公开威胁检测基准上评估FedIoC,这些基准分布于联邦学习客户端,每个客户端仅观察到每个活跃攻击活动的片段,并持有从其本地遥测数据中衍生的不相交指标集。在该场景下,联邦学习服务器可直接从梯度几何结构中恢复跨组织的攻击活动群组。我们将FedIoC作为该场景下的模块化框架提出,并用它确定非独立同分布(non-IID)梯度结构是恢复的主要驱动因素,并定义了设计编码器以改进该结构这一开放问题。

英文摘要

Detecting orchestrated cyberattack campaigns that span multiple organizations traditionally requires sharing sensitive telemetry and threat intelligence across institutional boundaries and country borders, a barrier that Federated Learning removes by training shared threat detectors directly on local data. We propose FedIoC, a modular framework in which clients fold locally available structured threat indicators into their gradient updates; we instantiate the client-side encoder with a supervised contrastive loss over IoC-matched flows. Within each training batch, flows that match any known indicator pattern form the positive set; the contrastive objective pulls their learned embeddings together and pushes non-IoC embeddings away, so that campaign-relevant structure is, by design, expressed in the gradient direction. Clients sharing indicators for the same attack campaign then produce aligned gradient components, which the server clusters by the cosine similarity of their updates to recover global campaign patterns without any direct IoC transmission. We evaluate FedIoC on two public threat-detection benchmarks distributed across FL clients that each observe only a fragment of every active campaign and hold disjoint indicator sets derived from their local telemetry. In this regime the FL server recovers cross-organizational campaign cohorts directly from gradient geometry. We contribute FedIoC as a modular framework for this setting, and use it to pinpoint the non-IID gradient structure as the main driver of recovery and to define the open problem of designing encoders that improve on it.

CommentsAccepted to ECML-PKDD 2026, 4th Workshop on Advancements in Federated Learning - Towards Trustworthy Federated Learning

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑