arXiv:2504.04367cs.CRcs.AI2025-04被引 6

用威布尔分布识别联邦学习中的恶意节点,提升网络入侵检测安全性和准确率。

WeiDetect: Weibull Distribution-Based Defense against Poisoning Attacks in Federated Learning for Network Intrusion Detection Systems

  • 基于威布尔分布分析模型验证分数,筛选异常客户端。
  • 在非独立同分布数据下,目标类别召回率最高提升70%。
  • 适合高隐私要求的物联网入侵检测系统部署。

在数据规模扩张的背景下,保障数据隐私日益重要,传统基于AI的网络入侵检测系统面临挑战。随着物联网设备普及,传统网络入侵检测系统(NIDS)难以应对新型威胁,且隐私问题和监管限制制约其应用。联邦学习(FL)作为解决方案,可在保护数据隐私的同时实现分布式模型训练。然而,尽管采用隐私保护技术,FL仍易受对抗攻击。此外,客户端间数据分布并非完全异构。本文提出WeiDetect,一种两阶段、服务器端的防御机制,用于检测联邦学习框架下的恶意参与者。第一阶段利用验证集评估本地模型,生成验证分数;第二阶段通过威布尔分布分析这些分数,识别并剔除恶意模型。实验在两个主流数据集CIC-Darknet2020与CSE-CIC-IDS2018上进行,测试条件为非独立同分布(non-IID)数据分布。结果表明,WeiDetect优于现有先进防御方法,在目标类别召回率上最高提升70%,全局模型F1分数提高1%至14%。

原文摘要 · Abstract (English)

In the era of data expansion, ensuring data privacy has become increasingly critical, posing significant challenges to traditional AI-based applications. In addition, the increasing adoption of IoT devices has introduced significant cybersecurity challenges, making traditional Network Intrusion Detection Systems (NIDS) less effective against evolving threats, and privacy concerns and regulatory restrictions limit their deployment. Federated Learning (FL) has emerged as a promising solution, allowing decentralized model training while maintaining data privacy to solve these issues. However, despite implementing privacy-preserving technologies, FL systems remain vulnerable to adversarial attacks. Furthermore, data distribution among clients is not heterogeneous in the FL scenario. We propose WeiDetect, a two-phase, server-side defense mechanism for FL-based NIDS that detects malicious participants to address these challenges. In the first phase, local models are evaluated using a validation dataset to generate validation scores. These scores are then analyzed using a Weibull distribution, identifying and removing malicious models. We conducted experiments to evaluate the effectiveness of our approach in diverse attack settings. Our evaluation included two popular datasets, CIC-Darknet2020 and CSE-CIC-IDS2018, tested under non-IID data distributions. Our findings highlight that WeiDetect outperforms state-of-the-art defense approaches, improving higher target class recall up to 70% and enhancing the global model's F1 score by 1% to 14%.

联邦学习入侵检测安全防御威布尔分布

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。