发表机构
RMIT University; Auckland University of Technology(皇家墨尔本理工大学; 奥克兰理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出物理认证的联邦学习,利用自动挖掘的网络物理不变量作为准入门控,抵御遥测伪造和重放投毒,在多个水测试平台上验证了有效性,并采用零知识证明保护数据隐私。
AI 中文摘要
联邦学习使工业运营商能够训练共享的入侵检测模型,而无需披露专有的运营遥测数据。然而,现有防御机制严格在更新空间中运行,使聚合器对数据投毒视而不见;由伪造遥测数据衍生的模型更新与诚实贡献难以区分。我们将网络物理过程不变量(如守恒定律和执行器耦合)从运行时检测启发式方法重新定位为联邦更新的可验证准入要求,这些不变量从干净的运营数据中自动挖掘。我们在两个物理水测试平台(SWaT、WADI)和一个分布基准(BATADAL)上评估了这一准入门控,针对遥测伪造、仅暴露的重放投毒以及一个不变量感知的自适应对手,测试了七种聚合规则。在三个测试平台上,挖掘出的不变量拒绝了100个诚实分片中的0个,并拒绝了所有天真伪造的分片,包括FoolsGold完全接受的优化扰动。在真实遥测数据上,五个挖掘出的不变量检测到SWaT的35次攻击中的12次,而九个不变量检测到20次,且没有拒绝任何诚实分片。使用九个规则,物理门控在五个标准聚合器上恢复了因重放投毒而损失的目标攻击召回率的69%至100%,以及因伪造遥测而损失的54%至100%。为了协调物理准入控制与联邦数据隐私,我们使用零知识证明(zk-SNARKs)展示不变量合规性,允许客户端在不透露运营遥测数据的情况下证明批次合规性。
英文摘要
Federated learning enables industrial operators to train shared intrusion detection models without disclosing proprietary operational telemetry. However, existing defenses operate strictly in update space, leaving aggregators blind to data poisoning; model updates derived from fabricated telemetry remain indistinguishable from honest contributions. We repurpose cyber-physical process invariants, such as conservation laws and actuator couplings, from runtime detection heuristics into a verifiable admission requirement for federated updates, mined automatically from clean operational data. We evaluate this admission gate across two physical water testbeds (SWaT, WADI) and a distribution benchmark (BATADAL), testing seven aggregation rules against telemetry fabrication, exposure-only replay poisoning, and an invariant-aware adaptive adversary. Across three testbeds the mined invariants reject none of 100 honest shards and all naively fabricated ones, including optimised perturbations that FoolsGold admits in full. On real telemetry, five mined invariants detect 12 of SWaT's 35 attacks, while nine invariants detect 20, with no honest shard rejected. With nine rules, the physics gate recovers 69--100% of the targeted-attack recall lost to replay poisoning, and 54--100% of that lost to fabricated telemetry, across five standard aggregators. To reconcile physical admission control with federated data privacy, we show invariant compliance using zero-knowledge proofs (zk-SNARKs) to allow clients to prove batch adherence without revealing operational telemetry.
Comments36 pages, 10 figures