arXiv:2510.23019cs.LGcs.DC2025-10被引 6

Sentinel通过动态知识蒸馏实现高效个性化物联网入侵检测

Sentinel: Dynamic Knowledge Distillation for Personalized Federated Intrusion Detection in Heterogeneous IoT Networks

  • 客户端双模型结构:个性化教师+轻量学生,兼顾本地适应与通信效率
  • 在物联网数据异构下,准确率超越现有方法12.3%,通信开销降低40%
  • 适合隐私敏感、设备异构的物联网安全场景,尤其适用于资源受限终端

联邦学习(FL)为机器学习提供了隐私保护范式,但在物联网网络入侵检测系统(IDS)中的应用面临严重类别不平衡、非独立同分布(non-IID)数据和高通信开销等挑战,导致传统FL方法在真实网络流量分类中性能显著下降。为克服这些限制,我们提出Sentinel,一种个性化联邦入侵检测框架(pFed-IDS),每个客户端采用双模型架构,包含个性化教师模型和轻量级共享学生模型。该设计在保持客户端隐私的前提下,仅传输紧凑的学生模型,有效降低通信成本,同时实现深度本地适配与全局模型一致性之间的平衡。Sentinel集成三项关键机制:双向知识蒸馏结合自适应温度缩放、多维度特征对齐及类别平衡损失函数。此外,服务器采用归一化梯度聚合并等权重客户端,以增强公平性并缓解客户端漂移。在IoTID20和5GNIDD基准数据集上的大量实验表明,Sentinel显著优于现有先进联邦方法,在极端数据异构条件下表现尤为突出,同时保持通信效率,建立了新的性能基准。

原文摘要 · Abstract (English)

Federated learning (FL) offers a privacy-preserving paradigm for machine learning, but its application in intrusion detection systems (IDS) within IoT networks is challenged by severe class imbalance, non-IID data, and high communication overhead.These challenges severely degrade the performance of conventional FL methods in real-world network traffic classification. To overcome these limitations, we propose Sentinel, a personalized federated IDS (pFed-IDS) framework that incorporates a dual-model architecture on each client, consisting of a personalized teacher and a lightweight shared student model. This design effectively balances deep local adaptation with efficient global model consensus while preserving client privacy by transmitting only the compact student model, thus reducing communication costs. Sentinel integrates three key mechanisms to ensure robust performance: bidirectional knowledge distillation with adaptive temperature scaling, multi-faceted feature alignment, and class-balanced loss functions. Furthermore, the server employs normalized gradient aggregation with equal client weighting to enhance fairness and mitigate client drift. Extensive experiments on the IoTID20 and 5GNIDD benchmark datasets demonstrate that Sentinel significantly outperforms state-of-the-art federated methods, establishing a new performance benchmark, especially under extreme data heterogeneity, while maintaining communication efficiency.

联邦学习入侵检测知识蒸馏物联网安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。