Resilient Federated Learning for DDoS Detection with Multi-Krum Aggregation and Anomaly Detection

Sajal Saha, Moinul Islam Sayed, Md. Motiur Rahman, Miad Faezipour, Smrity Bhatt · 2025

Distributed Denial of Service (DDoS) attacks pose a significant threat to modern network systems, exacerbated by the proliferation of IoT devices and increasingly sophisticated attack strategies. Traditional machine learning-based DDoS detection methods struggle with data privacy concerns and adversarial manipulations. Federated Learning (FL) offers a promising solution by enabling collaborative model training while preserving data locality; however, FL remains vulnerable to various adversarial attacks, including model poisoning, inference attacks, and backdoor attacks. In this work, we particularly explore backdoor attacks, where malicious clients introduce poisoned updates to compromise the global model. This research proposes a resilient FL framework for privacy-preserving DDoS detection, integrating Multi-Krum aggregation and anomaly detection to mitigate the effects of backdoor attacks. Using the UNSW-NB1S dataset, the framework employs a Transformer-based architecture to effectively capture complex network traffic patterns. Experimental results show that our proposed framework achieves an accuracy of 86.8%, a precision of 83.8%, a recall of 93.5%, and an F1 score of 87.9% under adversarial conditions, significantly outperforming the baseline models. Compared to the non-resilient FL-Transformer, our approach recovers 14.0% in accuracy and 11.9% in F1-score, demonstrating its effectiveness in mitigating backdoor attacks. These findings highlight the scalability, security, and robustness of our FL-based approach, making it a viable solution for distributed network defense in real-world settings.

Read the paper · More papers on PaperTik