cs.CRSep 23, 2026

BRFID: Toward Byzantine-Robust Federated Intrusion Detection

Authors: Asmah Muallem, Firdous Kausar, Sajid Hussain, Lei Qian

Organizations: Computer Science and Data Science Meharry Medical College Nashville, TN, USA

Abstract

Flipping 60% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, 99.96%99.96\% (at no poisoning rate) to 84.33%84.33\% in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.

Figures & tables

Explore similar work

CardsList
  1. Privacy, Robustness, and Fairness Trade-offs in Federated Intrusion Detection: Geometric Indistinguishability at the Aggregation Interface

    Sep 3, 2026Adrita Rahman Tory, ABM Shawkat Ali, Md Abu Layek +1Federated LearningIntrusion Detection

  2. FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks

    Aug 4, 2026An Khanh Bui, Cong Thanh Nguyen, Hoang-Anh Pham +2Federated LearningIntrusion Detection