arXiv:2512.23809cs.LGcs.AI2025-12被引 1

为工业物联网安全防御设计零信任智能联邦学习框架

Zero-Trust Agentic Federated Learning for Secure IIoT Defense Systems

  • 基于可信平台模块实现极低误接受率的设备认证
  • 在非独立同分布数据下实现可解释的拜占庭攻击检测,准确率达97.8%
  • 兼顾隐私保护与通信效率,适合高安全需求的工业场景

近期对关键基础设施的攻击,包括2021年奥尔德马水处理系统漏洞和2023年丹麦能源行业事件,凸显了工业物联网(IIoT)部署中的严重安全缺陷。尽管联邦学习(FL)能实现隐私保护下的协作入侵检测,但现有框架仍易受拜占庭污染攻击且缺乏可靠代理认证。本文提出零信任智能联邦学习(ZTA-FL),融合三项技术:(1) 基于可信平台模块(TPM)的密码学证明,实现低于0.0000001的误接受率;(2) 创新性SHAP加权聚合算法,在非独立同分布(non-IID)条件下提供可解释的拜占庭检测,并具有理论保障;(3) 隐私保护的本地对抗训练。在三个入侵检测基准(Edge-IIoTset、CIC-IDS2017、UNSW-NB15)上的综合实验表明,ZTA-FL实现97.8%检测准确率,在30%拜占庭攻击下仍保持93.2%准确率(优于FLAME 3.1%,p<0.01),对抗鲁棒性达89.3%,通信开销降低34%。本文提供理论分析、故障模式分析并开源代码以支持复现。

原文摘要 · Abstract (English)

Recent attacks on critical infrastructure, including the 2021 Oldsmar water treatment breach and 2023 Danish energy sector compromises, highlight urgent security gaps in Industrial IoT (IIoT) deployments. While Federated Learning (FL) enables privacy-preserving collaborative intrusion detection, existing frameworks remain vulnerable to Byzantine poisoning attacks and lack robust agent authentication. We propose Zero-Trust Agentic Federated Learning (ZTA-FL), a defense in depth framework combining: (1) TPM-based cryptographic attestation achieving less than 0.0000001 false acceptance rate, (2) a novel SHAP-weighted aggregation algorithm providing explainable Byzantine detection under non-IID conditions with theoretical guarantees, and (3) privacy-preserving on-device adversarial training. Comprehensive experiments across three IDS benchmarks (Edge-IIoTset, CIC-IDS2017, UNSW-NB15) demonstrate that ZTA-FL achieves 97.8 percent detection accuracy, 93.2 percent accuracy under 30 percent Byzantine attacks (outperforming FLAME by 3.1 percent, p less than 0.01), and 89.3 percent adversarial robustness while reducing communication overhead by 34 percent. We provide theoretical analysis, failure mode characterization, and release code for reproducibility.

联邦学习工业物联网安全防御零信任

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。