arXiv論文メモ
新着一覧
cs.CR / cs.LG · 査読状況未確認

連合型侵入検知でラベル改ざんが攻撃者自身を弱める

BRFID: Toward Byzantine-Robust Federated Intrusion Detection

Asmah Muallem, Firdous Kausar, Sajid Hussain, Lei Qian

この論文をやさしく読む

ひとことで言うと

連合型侵入検知で一人の参加者がラベルを改ざんすると、全体よりも攻撃者自身の検知精度が大きく下がった。

何に役立つ?

参加者ごとの性能低下を、悪意あるクライアントを見つける手掛かりとして使える可能性がある。

この研究の面白いところ

ラベルの60%を反転した条件で、攻撃者自身の精度は99.96%から84.33%へ低下したが、全体アンサンブルは安定した。

どこまで分かった?

三クライアントのCICIDS2017と決定木連結型の集約での結果であり、FedAvgで同様かは今後の課題とされる。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

三つのクライアントからなる連合型侵入検知システムで、一つのビザンチン型クライアントが学習ラベルの60%を反転させる模型汚染を行うと、その攻撃者自身の検知精度が、汚染なしの99.96%から84.33%へ下がった。一方、連合型の全体アンサンブルの精度は、試験したすべての汚染率で安定していた。この結果は、防御機構がなく、攻撃者間の協調もない条件で得られた。本研究は、クライアントごとに攻撃の下位分類が同一分布ではないCICIDS2017データで訓練した三クライアントの連合型侵入検知システムについて、ラベル反転攻撃の影響を定量化した。攻撃者が自らの性能を損なうという信号は、対象データを持ち出さなくてもビザンチンクライアントを特定するために利用できる異常であると示した。なお、集約にはパラメータ型のFedAvgではなく、決定木を連結するFederated Forestを使う。したがって結果が測っているのはアンサンブル集約における各クライアントの性能への影響であり、パラメータ型分類器を使う本来のFedAvgへの拡張は今後の課題である。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-23(UTC)
最新改訂
2026-09-23 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Flipping 60\% of training labels from a single Byzantine client using label-flipping model poisoning self-degrades an attacker's own federated detection accuracy, $99.96\%$ (at no poisoning rate) to $84.33\%$ in a three-client federated IDS. Where the Federated global ensemble maintains stable accuracy across all tested poison rates, without a defense mechanism in place and without coordination between attackers. In this paper, we present empirical results quantifying the impact of label-flipping poisoning attacks on a three-client federated IDS trained on CICIDS2017 with non-IID attack subtype distributions across clients. We demonstrate that the signal of the adversarial self-compromise represents a detectable anomaly for exploitation for Byzantine client identification in the absence of target data exfiltration. We note that the aggregation step uses a Federated Forest (tree concatenation) rather than a parametric FedAvg; the results therefore measure the impact of poisoning on per-client performance under ensemble aggregation, and extension to genuine FedAvg with a parametric classifier is planned for future work.

arXiv ID: 2609.28599 / 要約の誤りについて