SECFL-IDS-LPD: An Effective Clustered Federated Learning and Poisoning Defense Framework for Computing Power Network Intrusion Detection
Wei Ming Lin, Chao Chen, Bing Hao, Mengyang He · 2025
The Computing Power Network (CPN) represents an emerging architecture for large-scale distributed computing, however, it remains vulnerable to external attacks and malicious behaviors during task offloading. Federated learning (FL)-based intrusion detection systems (IDSs) have been widely adopted as an effective defense mechanism. However, it faces two significant challenges within the CPN: data heterogeneity across edge computing nodes (ECNs) and poisoning attacks from malicious ECNs. To address the first challenge, we propose SECFL-IDS, a clustered Federated Learning framework for intrusion detection in CPN. By assessing each ECN's local model performance with public data on the cloud server, the framework groups ECNs with similar data characteristics into the same clusters. To tackle the second challenge, we introduce a lightweight poisoning detection (LPD) algorithm that compares the update directions of each ECN's local model with those of the global model within the cluster. This method enables the dynamic identification of malicious ECNs during the iteration phase of FL, thereby boosting the system's robustness. Experiment results on two datasets demonstrate that SECFL-IDS achieves improvements of 4.88% and 5.93% in F1 score compared to FedAvg in highly heterogeneous data environments. Furthermore, under poisoning attacks that flip all labels, SECFL-IDS-LPD achieves improvements of 7.87%and 7.65%in F1 score compared to FedAvg.