CLAD通过聚类与双模式架构,实现边缘设备上无标签数据的异常检测与攻击分类。
CLAD: A Clustered Label-Agnostic Federated Learning Framework for Joint Anomaly Detection and Attack Classification

- 采用聚类联邦学习与双分支网络,同时处理有标签和无标签数据。
- 在80%数据无标签时,检测性能提升30%,通信开销减半。
- 适合物联网中设备异构、标注稀缺的安全场景。
物联网(IoT)与工业物联网(IIoT)的快速扩展带来了巨大且异构的攻击面,传统网络安全机制面临挑战。联邦学习(FL)为集中式入侵检测系统(IDS)提供隐私保护替代方案,但标准方法难以适应多样设备行为,且无法利用边缘环境中大量无标签数据。为此,我们提出CLAD框架,融合聚类联邦学习(CFL)与新型双模微型架构(DM²A)。该架构包含共享编码器和双分支结构,实现联合无监督异常检测与有监督攻击分类,充分利用有标签与无标签客户端数据。同时,聚类组件动态分组具有相似流量模式的设备,防止全局模型偏离。通过合理整合,CLAD确保不丢弃任何数据,并保留不同运行模式。大量实验表明,该集成方法显著优于现有基线,在80%客户端无标签场景下,检测性能相对提升30%,通信成本仅需一半。
原文摘要 · Abstract (English)
The rapid expansion of the Internet of Things (IoT) and Industrial IoT (IIoT) has created a massive, heterogeneous attack surface that challenges traditional network security mechanisms. While Federated Learning (FL) offers a privacy-preserving alternative to centralized Intrusion Detection Systems (IDS), standard approaches struggle to generalize across diverse device behaviors and typically fail to utilize the vast amounts of unlabeled data present in realistic edge environments. To bridge these gaps, we propose CLAD, a holistic framework that seamlessly incorporates Clustered Federated Learning (CFL) with a novel Dual-Mode Micro-Architecture ($\text{DM}^2\text{A}$). This unified approach simultaneously tackles the two primary bottlenecks of IoT security: device heterogeneity and label scarcity. The $\text{DM}^2\text{A}$ component features a shared encoder followed by two branches, enabling joint unsupervised anomaly detection and supervised attack classification; this allows the framework to harvest intelligence from both labeled and unlabeled clients. Concurrently, the clustering component dynamically groups devices with congruent traffic patterns, preventing global model divergence. By carefully combining these elements, CLAD ensures that no data is discarded and distinct operational patterns are preserved. Extensive evaluations demonstrate that this integrated approach significantly outperforms state-of-the-art baselines, achieving a 30% relative improvement in detection performance in scenarios with 80% unlabeled clients, with only half the communication cost.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。