arXiv:2608.04073cs.CRcs.AI2026-08

FBID通过服务器端动态调控,提升物联网中异常攻击检测的鲁棒性。

FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks

论文配图:FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks
图 1 · 摘自论文原文
  • 服务器用上下文多臂老虎机控制客户端训练强度,避免过度个性化。
  • 在CICIoT2023数据集上,OOD检测率最高提升7.66%,F1分数提升5.08%。
  • 适合需要高鲁棒性的异构物联网入侵检测场景。

个性化联邦学习(PFL)在异构物联网环境中具有潜力,可提升本地适应能力,但现有方法依赖客户端自我调节,易导致过度个性化,损害分布外(OOD)攻击检测性能。本文提出联邦贝叶斯入侵检测(FBID),一种基于服务器端个性化的自适应PFL框架。FBID在服务器端采用上下文多臂老虎机,根据客户端行为和更新质量动态调节其本地训练强度;同时引入基于信任的融合机制,生成客户端特异性插值系数,在保留全局检测知识的同时实现有益的局部定制。在CICIoT2023数据集上,针对异构客户端分布和OOD压力测试场景的大量实验表明,相较于最强稳定基线,FBID使各客户端的OOD检测率最高提升7.66%,F1分数相对提升5.08%,且对未见过的攻击类别具备更强鲁棒性。

原文摘要 · Abstract (English)

Personalized Federated Learning (PFL) has emerged as a promising solution for intrusion detection in heterogeneous IoT environments, as it can improve local adaptation under highly Non-Independent and Identically Distributed (non-IID) data distributions. However, existing PFL methods often rely on client-side self-adjustment, which may lead to over-personalization and substantial degradation in out-of-distribution (OOD) attack detection. In this paper, we propose Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control. In particular, FBID employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality. Moreover, FBID introduces a trust-based blending mechanism to derive client-specific interpolation coefficients between the global and local models, thereby preserving global attack-detection knowledge while still allowing beneficial local specialization. Through extensive experiments on the CICIoT2023 dataset under heterogeneous client distributions and OOD stress-test settings, we show that FBID improves individual client OOD Detection Rate (DR) by up to 7.66% and F1-Score (F1) by up to 5.08% (relative) over the strongest stable baseline, while also improving robustness to previously unseen attack classes.

联邦学习入侵检测物联网分布外检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。