Skip to main navigation Skip to search Skip to main content

MoCC-BD-FID: Multi-Objective Clustering Combination-Based Backdoor Defense for Federated Intrusion Detection of Industrial Control Systems

  • Guo-Qiang ZENG
  • , Jun-Min SHAO
  • , Kang-Di LU
  • , Guang-Gang GENG
  • , Jian WENG

Research output: Journal PublicationsJournal Article (refereed)peer-review

Abstract

Deep learning and federated learning (FL) play a crucial role in ensuring the security of industrial control systems (ICSs), but they also face severe security threats, especially the threat of backdoor attacks. Most FL backdoor defense methods primarily focus on a single clustering strategy, resulting in low true positive rates (TPR) and true negative rates (TNR) in the attack classification task. Due to the excessive combination scheme of currently available clustering strategies, it is difficult to manually select an appropriate combination scheme of clustering strategies to defense backdoor attacks in federated ICSs. This work is the first time to automatically design a multi-objective clustering combination-based backdoor defense for federated intrusion detection in ICSs, called MoCCBD-FID. The automated design issue of clustering strategies combination for backdoor defense is formulated as a mixed-variable multi-objective optimization problem, which considers both combinatorial variables, i.e., the combination length and the specific combination of clustering strategies, and continuous variables, i.e., the confidence levels of each combined clustering as the decision variables, and considers maximization of both TPR and TNR as the two objectives. To describe and evolve the different combinations of 12 clustering strategies with confidence levels, we develop an efficient mixed and variable-length encoding mechanism, and the specifically tailored crossover operation and mutation operation under the framework of nondominated sorting genetic algorithm II. The experiments are conducted on the three widely-used ICS datasets including Secure Water Treatment, Water Distribution, and Power System Attack datasets under two different backdoor attacks. The experimental results demonstrate that MoCC-BD-FID outperforms the single clustering strategy-based backdoor defense methods and five existing backdoor defense methods, i.e., Krum, Weak-DP, FoolsGold, DeepSight, and CrowdGuard, in terms of the classification accuracy of the poisoned model on regular samples and backdoor samples, TPR, and TNR.
Original languageEnglish
Pages (from-to)6868-6883
Number of pages16
JournalIEEE Transactions on Information Forensics and Security
Volume20
DOIs
Publication statusPublished - 2025
Externally publishedYes

Bibliographical note

Publisher Copyright:
© 2005-2012 IEEE.

Funding

This work was supported in part by Zhejiang Provincial Natural Science Foundation of China under Grant LZ25F030007; in part by the National Natural Science Foundation of China under Grant 61972288, Grant 62403122, and Grant 92067108; in part by the Key-Area Research and Development Program of Guangdong Province under Grant 2020B0101090004; in part by Shanghai Sailing Program under Grant 24YF2701300; in part by the Natural Science Foundation of Guangdong Province under Grant 2021A151501131; in part by the Ministry of Industry and Information Technology (MIIT) Project Industrial Internet Identification Resolution System Security Monitoring and Protection under Grant TC220H078; and in part by Guangdong Key Laboratory of Data Security and Privacy Preserving, ational Joint Engineering Research Centerof Network Security Detection and Protection Technology.

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Keywords

  • automated clustering combination
  • backdoor defense
  • federated intrusion detection
  • Industrial control systems
  • multi-objective optimization

Fingerprint

Dive into the research topics of 'MoCC-BD-FID: Multi-Objective Clustering Combination-Based Backdoor Defense for Federated Intrusion Detection of Industrial Control Systems'. Together they form a unique fingerprint.

Cite this