TY - JOUR
T1 - MoCC-BD-FID: Multi-Objective Clustering Combination-Based Backdoor Defense for Federated Intrusion Detection of Industrial Control Systems
AU - ZENG, Guo-Qiang
AU - SHAO, Jun-Min
AU - LU, Kang-Di
AU - GENG, Guang-Gang
AU - WENG, Jian
N1 - Publisher Copyright:
© 2005-2012 IEEE.
PY - 2025
Y1 - 2025
N2 - Deep learning and federated learning (FL) play a crucial role in ensuring the security of industrial control systems (ICSs), but they also face severe security threats, especially the threat of backdoor attacks. Most FL backdoor defense methods primarily focus on a single clustering strategy, resulting in low true positive rates (TPR) and true negative rates (TNR) in the attack classification task. Due to the excessive combination scheme of currently available clustering strategies, it is difficult to manually select an appropriate combination scheme of clustering strategies to defense backdoor attacks in federated ICSs. This work is the first time to automatically design a multi-objective clustering combination-based backdoor defense for federated intrusion detection in ICSs, called MoCCBD-FID. The automated design issue of clustering strategies combination for backdoor defense is formulated as a mixed-variable multi-objective optimization problem, which considers both combinatorial variables, i.e., the combination length and the specific combination of clustering strategies, and continuous variables, i.e., the confidence levels of each combined clustering as the decision variables, and considers maximization of both TPR and TNR as the two objectives. To describe and evolve the different combinations of 12 clustering strategies with confidence levels, we develop an efficient mixed and variable-length encoding mechanism, and the specifically tailored crossover operation and mutation operation under the framework of nondominated sorting genetic algorithm II. The experiments are conducted on the three widely-used ICS datasets including Secure Water Treatment, Water Distribution, and Power System Attack datasets under two different backdoor attacks. The experimental results demonstrate that MoCC-BD-FID outperforms the single clustering strategy-based backdoor defense methods and five existing backdoor defense methods, i.e., Krum, Weak-DP, FoolsGold, DeepSight, and CrowdGuard, in terms of the classification accuracy of the poisoned model on regular samples and backdoor samples, TPR, and TNR.
AB - Deep learning and federated learning (FL) play a crucial role in ensuring the security of industrial control systems (ICSs), but they also face severe security threats, especially the threat of backdoor attacks. Most FL backdoor defense methods primarily focus on a single clustering strategy, resulting in low true positive rates (TPR) and true negative rates (TNR) in the attack classification task. Due to the excessive combination scheme of currently available clustering strategies, it is difficult to manually select an appropriate combination scheme of clustering strategies to defense backdoor attacks in federated ICSs. This work is the first time to automatically design a multi-objective clustering combination-based backdoor defense for federated intrusion detection in ICSs, called MoCCBD-FID. The automated design issue of clustering strategies combination for backdoor defense is formulated as a mixed-variable multi-objective optimization problem, which considers both combinatorial variables, i.e., the combination length and the specific combination of clustering strategies, and continuous variables, i.e., the confidence levels of each combined clustering as the decision variables, and considers maximization of both TPR and TNR as the two objectives. To describe and evolve the different combinations of 12 clustering strategies with confidence levels, we develop an efficient mixed and variable-length encoding mechanism, and the specifically tailored crossover operation and mutation operation under the framework of nondominated sorting genetic algorithm II. The experiments are conducted on the three widely-used ICS datasets including Secure Water Treatment, Water Distribution, and Power System Attack datasets under two different backdoor attacks. The experimental results demonstrate that MoCC-BD-FID outperforms the single clustering strategy-based backdoor defense methods and five existing backdoor defense methods, i.e., Krum, Weak-DP, FoolsGold, DeepSight, and CrowdGuard, in terms of the classification accuracy of the poisoned model on regular samples and backdoor samples, TPR, and TNR.
KW - automated clustering combination
KW - backdoor defense
KW - federated intrusion detection
KW - Industrial control systems
KW - multi-objective optimization
UR - https://www.scopus.com/pages/publications/105010422180
U2 - 10.1109/TIFS.2025.3586479
DO - 10.1109/TIFS.2025.3586479
M3 - Journal Article (refereed)
AN - SCOPUS:105010422180
SN - 1556-6013
VL - 20
SP - 6868
EP - 6883
JO - IEEE Transactions on Information Forensics and Security
JF - IEEE Transactions on Information Forensics and Security
ER -