🤖 AI Summary
This study addresses the vulnerability of federated intrusion detection systems (IDS) to Byzantine label-flipping attacks and the inadequacy of existing defense mechanisms. Focusing on non-IID data scenarios, this work identifies and quantifies an attacker-induced "self-degradation" phenomenon, leveraging it as a Byzantine detection signal that requires neither cross-node coordination nor data leakage. By integrating federated forest ensemble aggregation with anomaly detection techniques, a malicious node identification framework is constructed and evaluated on the CICIDS2017 dataset. Experimental results demonstrate that the proposed global ensemble model maintains stable accuracy across varying poisoning ratios, confirming its inherent robustness even without explicit defenses. Ultimately, this research establishes a lightweight, privacy-preserving paradigm for Byzantine fault tolerance in federated IDS.
📝 Abstract
Flipping 60\% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, $99.96\%$ (at no poisoning rate) to $84.33\%$ in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.