Evaluation of data poisoning attacks on federated learning-based network intrusion detection system

Yuemeng Zhang, Yong Zhang, Zhao Zhang, Haonan Bai, Tianyi Zhong, Mei Na Song · 2022

Recently, federated learning-based network intrusion detection system (FL-based NIDS) has been considered as an essential tool to protect network security. It enables learning an effective intrusion detection model collaboratively without data privacy leakage. However, FL- based NIDS has exhibited inherent vulnerabilities on the data poisoning attacks launched by malicious clients. In this paper, we conduct the first systematic robustness evaluations of FL-based NIDS under data poisoning attack. Firstly, in consideration of the traffic domain constraints, we design the clean-label data poisoning attack against FL-based NIDS. Specifically, we propose an improved poisoned sample generation model based on Generative Adversarial Network, called PT-GAN, which optimizes with a new loss function that incorporates the feedback of the target intrusion detection model. The minimally-perturbed and correctly-labeled traffic samples generated by PT-GAN are then injected in the local training dataset to corrupt the intrusion detection model. Then, we explore the potential defense mechanism for these data poisoning attacks against FL- based NIDS and propose a novel defense method based on poisoned sample detection. Concretely, we propose the important neuron activations extraction method based on the layerwise relevance propagation method and then apply Oneclass-SVM to detect the poisoned sample. Experiments show that the proposed PT-GAN can degrade the performance of FL-based NIDS up to 28% on UNSW-NB15 dataset. We also demonstrate the robustness of our proposed defense methods against data poisoning attacks.

Read the paper · More papers on PaperTik