ARAFL-BAD: adversarial resilient asynchronous federated learning framework for zero-day IoT botnet attack detection
摘要
The rapid expansion of Internet of Things (IoT) devices has heightened security vulnerabilities, particularly from Botnet Attacks that threaten system reliability. Traditional centralized detection methods often pose privacy challenges, restricting their effectiveness. This article introduces the Adversarial Resilient Asynchronous Federated Learning Framework for zero-day IoT Botnet Attack Detection (ARAFL-BAD), which is capable of detecting zero-day IoT botnet attacks and is robust to various adversarial attacks. The framework integrates edge devices, a federated server, and adversarial defense mechanisms, employing a Multi-Layer Perceptron (MLP) model to achieve a peak F1 score of 99.85%. By combining adversarial training with trust-based weighted model aggregation, ARAFL-BAD mitigates data poisoning, model poisoning, and backdoor attacks, maintaining privacy and limiting the adversarial success rate to 12.59%. Experimental results demonstrate performance comparable to existing methods, with enhanced resilience for secure IoT applications.