ZTA-FEDGUARD: A ZERO-TRUST DYNAMIC TRUST-WEIGHTED FEDERATED LEARNING FRAMEWORK FOR IOT INTRUSION DETECTION UNDER NON-IID DATA AND POISONING ATTACKS
DOI:
https://doi.org/10.51453/3093-3706/2026/1480Tóm tắt
The rapid proliferation of the Internet of Things (IoT) has increased the demand for intrusion detection systems (IDSs) capable of learning from multiple distributed data domains without centralizing sensitive network traffic. Federated learning is a suitable paradigm because it enables edge gateways, organizations, or administrative domains to train local models and share only model updates. However, real-world IoT environments do not satisfy the ideal assumptions of conventional federated learning. Device-level data are often non-independent and non-identically distributed (non-IID), network behavior evolves over time, and some devices or gateways may be compromised and may send malicious updates. This paper proposes ZTA-FedGuard, a dynamic trust-weighted federated learning framework based on Zero Trust principles for IoT intrusion detection. The central idea of ZTA-FedGuard is that no model update should receive implicit trust by default. Each client update must be continuously evaluated by geometric consistency, robust update-norm deviation, and its impact on a trusted calibration buffer. The resulting anomaly score is converted into a dynamic trust value and used in a gating mechanism to restrict or remove the influence of suspicious clients before aggregation. Unlike robust aggregation methods that rely mainly on coordinate-wise statistics, ZTA-FedGuard introduces the concept of least aggregation privilege into federated learning, thereby turning each training round into an access-control process over the global IDS model. The paper presents the threat model, mathematical formulation, algorithmic design, security analysis, deployment requirements, limitations, and future research directions. The work is positioned as a methodological and theoretical contribution focused on threat modeling, secure aggregation control, and deployability in adversarial IoT environments.
Tải xuống
Tài liệu tham khảo
[1]: W. Gharibi, “Machine Learning and Cybersecurity—Trends and Future Challenges,” Electronics, 2025. <https://doi.org/10.3390/electronics14204007>
[2]: A. Hozouri, A. Mirzaei, and M. Effatparvar, “A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges,” Discover Artificial Intelligence, 2025. <https://link.springer.com/article/10.1007/s44163-025-00578-1>
[3]: K. Li et al., “Zero-Trust Foundation Models: A New Paradigm for Secure and Collaborative Artificial Intelligence for Internet of Things,” arXiv, 2025. <https://arxiv.org/html/2505.23792v1>
[4]: M. B. Bankó et al., “Advancements in Machine Learning-Based Intrusion Detection in IoT: Research Trends and Challenges,” Algorithms, 2025. <https://doi.org/10.3390/a18040209>
[5]: T. D. Nguyen, P. Rieger, M. Miettinen, and A.-R. Sadeghi, “Poisoning Attacks on Federated Learning-based IoT Intrusion Detection System,” DISS Workshop / NDSS, 2020. <https://www.ndss-symposium.org/wp-content/uploads/2020/04/diss2020-23003-paper.pdf>
[6]: H. Peng, C. Wu, and Y. Xiao, “FD-IDS: Federated Learning with Knowledge Distillation for Intrusion Detection in Non-IID IoT Environments,” Sensors, 2025. <https://doi.org/10.3390/s25144309>
[7]: S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, 2020. <https://doi.org/10.6028/NIST.SP.800-207>
[8]: B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Agüera y Arcas, “Communication-Efficient Learning of Deep Networks from Decentralized Data,” AISTATS / PMLR, 2017. <https://proceedings.mlr.press/v54/mcmahan17a.html>
[9]: T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V. Smith, “Federated Optimization in Heterogeneous Networks,” MLSys, 2020. <https://proceedings.mlsys.org/paper/2020/hash/1f5fe83998a09396ebe6477d9475ba0c-Abstract.html>
[10]: P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent,” NeurIPS, 2017. <https://papers.nips.cc/paper/6617-machine-learning-with-adversaries-byzantine-tolerant-gradient-descent>
[11]: D. Yin, Y. Chen, R. Kannan, and P. Bartlett, “Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates,” ICML / PMLR, 2018. <https://proceedings.mlr.press/v80/yin18a.html>
[12]: M. Fang, S. Nabavirazavi, Z. Liu, W. Sun, S. Iyengar, and H. Yang, “Do We Really Need to Design New Byzantine-robust Aggregation Rules?” NDSS, 2025. <https://www.ndss-symposium.org/ndss-paper/do-we-really-need-to-design-new-byzantine-robust-aggregation-rules/>
[13]: C.-J. Li, P.-H. Huang, Y.-T. Ma, H. Hung, and S.-Y. Huang, “Robust Aggregation for Federated Learning by Minimum γ-Divergence Estimation,” Entropy, 2022. <https://doi.org/10.3390/e24050686>
Tải xuống
Đã Xuất bản
Cách trích dẫn
Số
Chuyên mục
Giấy phép
Tác phẩm này được cấp phép theo Giấy phép Quốc tế Creative Commons Attribution-ShareAlike 4.0 .
Bài báo được xuất bản ở Tạp chí Khoa học Đại học Tân Trào được cấp phép theo giấy phép Ghi công - Chia sẻ tương tự 4.0 Quốc tế (CC BY-SA). Theo đó, các tác giả khác có thể sao chép, chuyển đổi hay phân phối lại các bài báo này với mục đích hợp pháp trên mọi phương tiện, với điều kiện họ trích dẫn tác giả, Tạp chí Khoa học Đại học Tân Trào và đường link đến bản quyền; nêu rõ các thay đổi đã thực hiện và các nghiên cứu đăng lại được tiến hành theo cùng một bản quyền.
Bản quyền bài báo thuộc về các tác giả, không hạn chế số lượng. Tạp chí Khoa học Tân Trào được cấp giấy phép không độc quyền để xuất bản bài báo với tư cách nhà xuất bản nguồn, kèm theo quyền thương mại để in các bài báo cung cấp cho các thư viện và cá nhân.
Mặc dù các điều khoản của giấy phép CC BY-SA không dành cho các tác giả (với tư cách là người giữ bản quyền của bài báo, họ không bị hạn chế về quyền hạn), khi gửi bài tới Tạp chí Khoa học Đại học Tân Trào, tác giả cần đáp ứng quyền của độc giả, và cần cấp quyền cho bên thứ 3 sử dụng bài báo của họ trong phạm vi của giấy phép.