Skip to content

Author

Shiddarth Dey Tusar

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

#federated learning Open access Sep 2026

When Does Trust Help? A Leakage-Free Evaluation of Representation- and Aggregation-Based Defenses Against Backdoors in Federated Intrusion Detection

Federated learning (FL) lets distributed intrusion-detection systems (IDS) train on private traffic, but exposes the global model to poisoning and backdoor attacks under non-IID client data. A popular defense family scores or filters clients using a small trusted "root" dataset and the similarity of client behaviour to a trusted reference. I re-examine these trust-based defenses under a protocol designed to remove common evaluation artifacts: train-only feature standardization, a server root set disjoint from client data, multi-seed (n=6) runs with paired significance tests, formal (ε,δ) accounting for DP-SGD, and a defense-aware adaptive attacker. Across three NIDS datasets (CSE-CIC-IDS2018, NF-ToN-IoT, NF-UNSW-NB15-v2) I find: (1) a representation-similarity aggregator (RepGuard) significantly improves classification utility and seed-stability over FLTrust under heavy non-IID poisoning, and—under severe heterogeneity or many adversaries—also lowers backdoor ASR substantially (e.g. 0.48 vs FLTrust 0.86 at Dirichlet α=0.1); (2) at strong trigger magnitudes no defense reduces backdoor attack success rate (ASR≈0.95); (3) a controlled trigger-magnitude sweep shows defenses help only for small triggers (ASR 0.10 for RepGuard at magnitude 0.5, vs. 0.40 undefended) and collapse to ASR≈1.0 by magnitude 2; (4) a triggered-canary check that assumes knowledge of the attacker's trigger—the assumption behind much prior "success"—lowers ASR from 0.49 to 0.12, i.e. trigger knowledge, not representation scoring, suppresses the backdoor; (5) correctly-accounted DP-SGD (ε∈[0.3,16]) costs little utility but does not mitigate the backdoor. I release the protocol so future FL-IDS defenses can be evaluated without the leakage and oracle assumptions that inflate reported robustness.

Shiddarth Dey Tusar · 0 citations
#federated learning Open access Sep 2026

When Does Trust Help? A Leakage-Free Evaluation of Representation- and Aggregation-Based Defenses Against Backdoors in Federated Intrusion Detection

Federated learning (FL) lets distributed intrusion-detection systems (IDS) train on private traffic, but exposes the global model to poisoning and backdoor attacks under non-IID client data. A popular defense family scores or filters clients using a small trusted "root" dataset and the similarity of client behaviour to a trusted reference. I re-examine these trust-based defenses under a protocol designed to remove common evaluation artifacts: train-only feature standardization, a server root set disjoint from client data, multi-seed (n=6) runs with paired significance tests, formal (ε,δ) accounting for DP-SGD, and a defense-aware adaptive attacker. Across three NIDS datasets (CSE-CIC-IDS2018, NF-ToN-IoT, NF-UNSW-NB15-v2) I find: (1) a representation-similarity aggregator (RepGuard) significantly improves classification utility and seed-stability over FLTrust under heavy non-IID poisoning, and—under severe heterogeneity or many adversaries—also lowers backdoor ASR substantially (e.g. 0.48 vs FLTrust 0.86 at Dirichlet α=0.1); (2) at strong trigger magnitudes no defense reduces backdoor attack success rate (ASR≈0.95); (3) a controlled trigger-magnitude sweep shows defenses help only for small triggers (ASR 0.10 for RepGuard at magnitude 0.5, vs. 0.40 undefended) and collapse to ASR≈1.0 by magnitude 2; (4) a triggered-canary check that assumes knowledge of the attacker's trigger—the assumption behind much prior "success"—lowers ASR from 0.49 to 0.12, i.e. trigger knowledge, not representation scoring, suppresses the backdoor; (5) correctly-accounted DP-SGD (ε∈[0.3,16]) costs little utility but does not mitigate the backdoor. I release the protocol so future FL-IDS defenses can be evaluated without the leakage and oracle assumptions that inflate reported robustness.

Shiddarth Dey Tusar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.