BRFID: Toward Byzantine-Robust Federated Intrusion Detection

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of federated intrusion detection systems (IDS) to Byzantine label-flipping attacks and the inadequacy of existing defense mechanisms. Focusing on non-IID data scenarios, this work identifies and quantifies an attacker-induced "self-degradation" phenomenon, leveraging it as a Byzantine detection signal that requires neither cross-node coordination nor data leakage. By integrating federated forest ensemble aggregation with anomaly detection techniques, a malicious node identification framework is constructed and evaluated on the CICIDS2017 dataset. Experimental results demonstrate that the proposed global ensemble model maintains stable accuracy across varying poisoning ratios, confirming its inherent robustness even without explicit defenses. Ultimately, this research establishes a lightweight, privacy-preserving paradigm for Byzantine fault tolerance in federated IDS.
📝 Abstract
Flipping 60\% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, $99.96\%$ (at no poisoning rate) to $84.33\%$ in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.
Problem

Research questions and friction points this paper is trying to address.

Federated Intrusion Detection
Byzantine-robust
Label-flipping poisoning
Non-IID
Anomaly detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Byzantine-Robust
Federated Intrusion Detection
Label-Flipping Poisoning
Federated Forest
Adversarial Self-Compromise
A
Asmah Muallem
Computer Science and Data Science, Meharry Medical College, Nashville, TN, USA
Firdous Kausar
Firdous Kausar
School of Applied Computational Sciences, Meharry Medical College
BlockchainIoTMachine LearningDigital ForensicsCyber Security
Sajid Hussain
Sajid Hussain
Computer Science and Data Science, Meharry Medical College, Nashville, TN, USA
L
Lei Qian
Computer Science and Data Science, Meharry Medical College, Nashville, TN, USA