PoFQ: a blockchain consensus protocol for decentralized federated learning-based threat hunting approach in a trustless computing landscape
摘要
The increasing complexity of cyber threats targeting critical infrastructure necessitates robust and decentralized solutions for collaborative cybersecurity operations, such as security operation centers (SOCs) and cyber threat hunting (CTH) systems. Existing federated learning (FL) frameworks often rely on a central aggregation server, creating a single point of failure (SPoF), and inadequately address poisoned model updates that degrade the reliability of centralized FL models. To tackle these challenges, we propose proof-of-federated-learning-quality (PoFQ), a novel blockchain-based consensus protocol integrated into decentralized FL-enabled SOCs and CTH systems, designed for untrusted collaborative parties. PoFQ eliminates the need for a constant aggregation server by tracking shared model updates among participating nodes, mitigating SPoF risks, and providing data owners with greater control and flexibility over their collaborative processes. To enhance security, we integrate Differential Privacy and cosine similarity (CS) into PoFQ to detect and eliminate poisoned model updates while preserving privacy. Additionally, a Trust Management System is introduced to evaluate the reliability of participants based on their contributions and historical model performance, incentivizing meaningful collaboration. We validate PoFQ through extensive experiments on the CICIOT2023 dataset, highlighting its effectiveness in detecting attacks and maintaining robust performance. The proposed system achieves high F1-scores for FL with CS and near-perfect detection on malicious classes, while demonstrating scalable block generation times in decentralized environments, thus emphasizing its practicality for real-world cybersecurity applications.