用三模型协作实现零样本入侵检测,提升未知攻击识别率。
Tri-LLM Cooperative Federated Zero-Shot Intrusion Detection with Semantic Disagreement and Trust-Aware Aggregation
- 通过三大语言模型构建语义攻击原型,实现跨客户端语义对齐。
- 在未见过的攻击上达到80%以上检测准确率,比基线高10%以上。
- 基于模型间分歧与可信度加权聚合,抵御不可靠客户端干扰。
联邦学习(FL)已成为隐私保护、分布式网络入侵检测系统(IDS)的有效范式,尤其适用于因隐私和带宽限制难以集中数据的工业物联网(IoT)和信息物理系统。然而,现有方法多假设闭集学习,缺乏对未知攻击场景中不确定性、语义泛化及认知模糊性的建模能力,且在异构、不可靠客户端下鲁棒性不足。本文提出一种语义驱动的联邦入侵检测框架,将语言模型生成的语义监督融入联邦优化过程,支持开集与零样本检测。该方法利用GPT-4o、DeepSeek-V3和LLaMA-3-8B组成的三模型集成构建攻击语义原型,使分布式遥测特征与高层攻击概念对齐。通过建模跨模型语义分歧作为认知不确定性,用于零日攻击风险评估;同时采用可信度感知聚合机制,动态调整客户端更新权重。实验表明,该框架在异构客户端间保持稳定的语义对齐与一致收敛,对未见攻击模式的零样本检测准确率超过80%,相比基于相似性的基线提升10%以上,在存在不可靠或被攻陷客户端时仍保持低聚合不稳定性。
原文摘要 · Abstract (English)
Federated learning (FL) has become an effective paradigm for privacy-preserving, distributed Intrusion Detection Systems (IDS) in cyber-physical and Internet of Things (IoT) networks, where centralized data aggregation is often infeasible due to privacy and bandwidth constraints. Despite its advantages, most existing FL-based IDS assume closed-set learning and lack mechanisms such as uncertainty estimation, semantic generalization, and explicit modeling of epistemic ambiguity in zero-day attack scenarios. Additionally, robustness to heterogeneous and unreliable clients remains a challenge in practical applications. This paper introduces a semantics-driven federated IDS framework that incorporates language-derived semantic supervision into federated optimization, enabling open-set and zero-shot intrusion detection for previously unseen attack behaviors. The approach constructs semantic attack prototypes using a Tri-LLM ensemble of GPT-4o, DeepSeek-V3, and LLaMA-3-8B, aligning distributed telemetry features with high-level attack concepts. Inter-LLM semantic disagreement is modeled as epistemic uncertainty for zero-day risk estimation, while a trust-aware aggregation mechanism dynamically weights client updates based on reliability. Experimental results show stable semantic alignment across heterogeneous clients and consistent convergence. The framework achieves over 80% zero-shot detection accuracy on unseen attack patterns, improving zero-day discrimination by more than 10% compared to similarity-based baselines, while maintaining low aggregation instability in the presence of unreliable or compromised clients.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。