ZTA-FEDGUARD: A ZERO-TRUST DYNAMIC TRUST-WEIGHTED FEDERATED LEARNING FRAMEWORK FOR IOT INTRUSION DETECTION UNDER NON-IID DATA AND POISONING ATTACKS

Các tác giả

  • NGO VAN NAM

DOI:

https://doi.org/10.51453/3093-3706/2026/1480

Tóm tắt

The rapid proliferation of the Internet of Things (IoT) has increased the demand for intrusion detection systems (IDSs) capable of learning from multiple distributed data domains without centralizing sensitive network traffic. Federated learning is a suitable paradigm because it enables edge gateways, organizations, or administrative domains to train local models and share only model updates. However, real-world IoT environments do not satisfy the ideal assumptions of conventional federated learning. Device-level data are often non-independent and non-identically distributed (non-IID), network behavior evolves over time, and some devices or gateways may be compromised and may send malicious updates. This paper proposes ZTA-FedGuard, a dynamic trust-weighted federated learning framework based on Zero Trust principles for IoT intrusion detection. The central idea of ZTA-FedGuard is that no model update should receive implicit trust by default. Each client update must be continuously evaluated by geometric consistency, robust update-norm deviation, and its impact on a trusted calibration buffer. The resulting anomaly score is converted into a dynamic trust value and used in a gating mechanism to restrict or remove the influence of suspicious clients before aggregation. Unlike robust aggregation methods that rely mainly on coordinate-wise statistics, ZTA-FedGuard introduces the concept of least aggregation privilege into federated learning, thereby turning each training round into an access-control process over the global IDS model. The paper presents the threat model, mathematical formulation, algorithmic design, security analysis, deployment requirements, limitations, and future research directions. The work is positioned as a methodological and theoretical contribution focused on threat modeling, secure aggregation control, and deployability in adversarial IoT environments.

Tải xuống

Dữ liệu tải xuống chưa có sẵn.

Tài liệu tham khảo

[1]: W. Gharibi, “Machine Learning and Cybersecurity—Trends and Future Challenges,” Electronics, 2025. <https://doi.org/10.3390/electronics14204007>

[2]: A. Hozouri, A. Mirzaei, and M. Effatparvar, “A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges,” Discover Artificial Intelligence, 2025. <https://link.springer.com/article/10.1007/s44163-025-00578-1>

[3]: K. Li et al., “Zero-Trust Foundation Models: A New Paradigm for Secure and Collaborative Artificial Intelligence for Internet of Things,” arXiv, 2025. <https://arxiv.org/html/2505.23792v1>

[4]: M. B. Bankó et al., “Advancements in Machine Learning-Based Intrusion Detection in IoT: Research Trends and Challenges,” Algorithms, 2025. <https://doi.org/10.3390/a18040209>

[5]: T. D. Nguyen, P. Rieger, M. Miettinen, and A.-R. Sadeghi, “Poisoning Attacks on Federated Learning-based IoT Intrusion Detection System,” DISS Workshop / NDSS, 2020. <https://www.ndss-symposium.org/wp-content/uploads/2020/04/diss2020-23003-paper.pdf>

[6]: H. Peng, C. Wu, and Y. Xiao, “FD-IDS: Federated Learning with Knowledge Distillation for Intrusion Detection in Non-IID IoT Environments,” Sensors, 2025. <https://doi.org/10.3390/s25144309>

[7]: S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, 2020. <https://doi.org/10.6028/NIST.SP.800-207>

[8]: B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Agüera y Arcas, “Communication-Efficient Learning of Deep Networks from Decentralized Data,” AISTATS / PMLR, 2017. <https://proceedings.mlr.press/v54/mcmahan17a.html>

[9]: T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V. Smith, “Federated Optimization in Heterogeneous Networks,” MLSys, 2020. <https://proceedings.mlsys.org/paper/2020/hash/1f5fe83998a09396ebe6477d9475ba0c-Abstract.html>

[10]: P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent,” NeurIPS, 2017. <https://papers.nips.cc/paper/6617-machine-learning-with-adversaries-byzantine-tolerant-gradient-descent>

[11]: D. Yin, Y. Chen, R. Kannan, and P. Bartlett, “Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates,” ICML / PMLR, 2018. <https://proceedings.mlr.press/v80/yin18a.html>

[12]: M. Fang, S. Nabavirazavi, Z. Liu, W. Sun, S. Iyengar, and H. Yang, “Do We Really Need to Design New Byzantine-robust Aggregation Rules?” NDSS, 2025. <https://www.ndss-symposium.org/ndss-paper/do-we-really-need-to-design-new-byzantine-robust-aggregation-rules/>

[13]: C.-J. Li, P.-H. Huang, Y.-T. Ma, H. Hung, and S.-Y. Huang, “Robust Aggregation for Federated Learning by Minimum γ-Divergence Estimation,” Entropy, 2022. <https://doi.org/10.3390/e24050686>

Tải xuống

Đã Xuất bản

2026-07-06

Cách trích dẫn

NGO VAN NAM. (2026). ZTA-FEDGUARD: A ZERO-TRUST DYNAMIC TRUST-WEIGHTED FEDERATED LEARNING FRAMEWORK FOR IOT INTRUSION DETECTION UNDER NON-IID DATA AND POISONING ATTACKS . SCIENTIFIC JOURNAL OF TAN TRAO UNIVERSITY, 12(2). https://doi.org/10.51453/3093-3706/2026/1480