<p>Anomaly detection is a critical component for ensuring the security and reliability of Internet of Things (IoT) systems. Early detection of cyberattacks helps mitigate financial and operational risks for service providers. While many neural network-based anomaly detection models have been developed using centralized data, such centralized training introduces significant privacy and security vulnerabilities. Federated Learning (FL) has emerged as a promising paradigm to overcome this limitation by collaboratively training models without exchanging raw data. However, FL systems remain highly vulnerable to data poisoning attacks, where compromised IoT clients inject corrupted samples or manipulated labels into local training data, leading to degraded global model integrity and unreliable anomaly detection performance. To address this problem, we propose a robust and attack-resilient framework named Federated Learning with Shrink Denoising AutoEncoder (FL-SDAE), specifically designed to defend against data poisoning attacks in federated IoT environments. The proposed SDAE locally compresses data into a shared latent space and reconstructs it from corrupted inputs, allowing poisoned clients to exhibit higher training loss values. Leveraging this property, we introduce a novel Loss-Aware Aggregation (LAA) mechanism that adaptively identifies and filters out malicious client updates based on their abnormal training loss behavior during the aggregation process. Comprehensive experiments conducted on five benchmark IoT datasets (N-BaIoT, CICIDS, NSL-KDD, Spambase, and CTU13-08) demonstrate that FL-SDAE achieves higher anomaly detection accuracy and stronger robustness against both dirty-label (label flipping) and clean-label (Gaussian noise) attacks. Furthermore, comparisons with state-of-the-art defenses (Krum, Multi-Krum, Trimmed Mean, FoolsGold, and FLTrust) show that FL-SDAE consistently enhances model stability and resilience. Overall, FL-SDAE provides an effective defense framework that strengthens the robustness of federated anomaly detection models against diverse data-level poisoning threats in realistic IoT environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Robust Federated Learning System Against Data Poisoning Attacks in IoT Networks

  • Ly Vu,
  • Tuan Phong Tran

摘要

Anomaly detection is a critical component for ensuring the security and reliability of Internet of Things (IoT) systems. Early detection of cyberattacks helps mitigate financial and operational risks for service providers. While many neural network-based anomaly detection models have been developed using centralized data, such centralized training introduces significant privacy and security vulnerabilities. Federated Learning (FL) has emerged as a promising paradigm to overcome this limitation by collaboratively training models without exchanging raw data. However, FL systems remain highly vulnerable to data poisoning attacks, where compromised IoT clients inject corrupted samples or manipulated labels into local training data, leading to degraded global model integrity and unreliable anomaly detection performance. To address this problem, we propose a robust and attack-resilient framework named Federated Learning with Shrink Denoising AutoEncoder (FL-SDAE), specifically designed to defend against data poisoning attacks in federated IoT environments. The proposed SDAE locally compresses data into a shared latent space and reconstructs it from corrupted inputs, allowing poisoned clients to exhibit higher training loss values. Leveraging this property, we introduce a novel Loss-Aware Aggregation (LAA) mechanism that adaptively identifies and filters out malicious client updates based on their abnormal training loss behavior during the aggregation process. Comprehensive experiments conducted on five benchmark IoT datasets (N-BaIoT, CICIDS, NSL-KDD, Spambase, and CTU13-08) demonstrate that FL-SDAE achieves higher anomaly detection accuracy and stronger robustness against both dirty-label (label flipping) and clean-label (Gaussian noise) attacks. Furthermore, comparisons with state-of-the-art defenses (Krum, Multi-Krum, Trimmed Mean, FoolsGold, and FLTrust) show that FL-SDAE consistently enhances model stability and resilience. Overall, FL-SDAE provides an effective defense framework that strengthens the robustness of federated anomaly detection models against diverse data-level poisoning threats in realistic IoT environments.