arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

BRFID:面向拜占庭鲁棒的联邦入侵检测

BRFID: Toward Byzantine-Robust Federated Intrusion Detection

Asmah Muallem, Firdous Kausar, Sajid Hussain, Lei Qian

arXiv 2609.28599首次发表:更新:

发表机构

Meharry Medical College(梅哈里医学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对联邦入侵检测中单拜占庭客户端的标签翻转投毒攻击,实验表明该攻击会显著降低攻击者自身检测准确率,且无防御时全局集成仍稳定,其异常信号可用于识别拜占庭客户端。

AI 中文摘要

在由三个客户端组成的联邦入侵检测系统(IDS)中,使用标签翻转模型投毒,仅来自单个拜占庭客户端翻转60%的训练标签,就会使攻击者自身的联邦检测准确率从无投毒时的99.96%降至84.33%。在没有防御机制且攻击者之间不协调的情况下,联邦全局集成模型在所有测试的投毒率下均保持稳定的准确率。本文通过实验量化了标签翻转投毒攻击对基于CICIDS2017数据集、各客户端具有非独立同分布(non-IID)攻击子类型分布的三客户端联邦IDS的影响。我们证明,在不存在目标数据外泄的情况下,对抗性自我妥协的信号代表了一种可检测的异常,可用于拜占庭客户端识别。我们注意到,聚合步骤使用的是联邦森林(树拼接)而非参数化的FedAvg;因此,结果衡量了集成聚合下投毒对每个客户端性能的影响,而使用参数化分类器的真正FedAvg扩展计划在未来的工作中进行。

英文摘要

Flipping 60\% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, $99.96\%$ (at no poisoning rate) to $84.33\%$ in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑