WeiDetect: Weibull Distribution-Based Defense against Poisoning Attacks in Federated Learning for Network Intrusion Detection Systems
M., Sameera K., P., Vinod, Rocha, Anderson, A., Rafidha Rehiman K., Conti, Mauro
–arXiv.org Artificial Intelligence
A BSTRACT In the era of data expansion, ensuring data privacy has become increasingly critical, posing significant challenges to traditional AI-based applications. In addition, the increasing adoption of IoT devices has introduced significant cybersecurity challenges, making traditional Network Intrusion Detection Systems (NIDS) less effective against evolving threats, and privacy concerns and regulatory restrictions limit their deployment. Federated Learning (FL) has emerged as a promising solution, allowing decentralized model training while maintaining data privacy to solve these issues. However, despite implementing privacy-preserving technologies, FL systems remain vulnerable to adversarial attacks. Furthermore, data distribution among clients is not heterogeneous in the FL scenario. We propose WeiDetect, a two-phase, server-side defense mechanism for FL-based NIDS that detects malicious participants to address these challenges. In the first phase, local models are evaluated using a validation dataset to generate validation scores. These scores are then analyzed using a Weibull distribution, identifying and removing malicious models. We conducted experiments to evaluate the effectiveness of our approach in diverse attack settings. Our evaluation included two popular datasets, CIC-Darknet2020 and CSE-CIC-IDS2018, tested under non-IID data distributions. Our findings highlight that WeiDetect outperforms state-of-the-art defense approaches, improving higher target class recall up to 70% and enhancing the global model's F1 score by 1% to 14%. K eywords Federated learning Poisoning attacks Network intrusion detection systems Non-independent and identically distributed data Weibull distribution 1 Introduction The rapid advancement of the Internet has created a highly interconnected world. The adoption of IoT for connectivity has increased significantly, leading to security vulnerabilities due to the inherent nature of IoT devices and systems. According to [1], it was emphasized that IoT devices are expected to reach 55.7 billion by 2025; the increasing volume of data generated by these devices also opens the door to cyber attackers. This further signifies the critical role of the Network Intrusion Detection System (NIDS), which detects suspicious activities and improves the security of the IoT network ecosystem. The NIDS employs signature, behavior, or specification-based approaches to identify network anomalies and protect the system from unauthorized use or access [2]. However, these approaches have become less efficient in recognizing unknown attacks, rendering them incapable of detecting new or evolving threats. The paper [3, 4] highlight that Machine Learning (ML) based NIDSs are efficient alternatives that identify normal and abnormal traffic patterns in IoT Corresponding author: vinod.puthuvath@unipd.it Although these ML models have been widely employed in various solutions to enable dynamic and adaptive IDS in IoT environments.
arXiv.org Artificial Intelligence
Apr-22-2025
- Country:
- Europe (0.67)
- Genre:
- Research Report
- New Finding (1.00)
- Promising Solution (0.88)
- Research Report
- Industry:
- Information Technology > Security & Privacy (1.00)
- Government > Military
- Cyberwarfare (0.34)
- Technology: