BRFID: Toward Byzantine-Robust Federated Intrusion Detection
Organizations: Computer Science and Data Science Meharry Medical College Nashville, TN, USA
Abstract
Flipping 60% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, (at no poisoning rate) to in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.
Figures & tables
| Client | Accuracy | F1 | Recall | FPR |
|---|---|---|---|---|
| Client 0 | 0.9989 | 0.9992 | 0.9984 | 0.0000 |
| Client 1 | 0.9996 | 0.9995 | 0.9990 | 0.0000 |
| Client 2 | 0.9991 | 0.9990 | 0.9980 | 0.0000 |
| Fed. Avg | 0.9992 | 0.9992 | 0.9985 | 0.0000 |
| Poison | Fed. | Acc. | Fed. | Attacker |
|---|---|---|---|---|
| rate | Acc. | (pp) | F1 | Acc. |
| 0.9996 | (none) | 0.9996 | 0.9996 | |
| 0.9994 | 0.9995 | 0.9982 | ||
| 0.9994 | 0.9995 | 0.9765 | ||
| 0.9996 | 0.9996 | 0.8433 |