Quote of the day

A person who never made a mistake never tried anything new.

- Albert Einstein

Contact

Drift-Resilient and Adversarially Robust Federated Intrusion Detection for Industrial IoT

Open Cybersecurity

Drift-Resilient and Adversarially Robust Federated Intrusion Detection for Industrial IoT

Drift-Resilient and Adversarially Robust Federated Intrusion Detection for Industrial IoT

Description

Investigate the joint resilience to concept drift and adversarial manipulation of a federated intrusion-detection system deployed on resource-constrained industrial IoT gateways.

Details

Context and Problem Statement

Intrusion-detection models often perform well on static benchmarks but degrade in production as legitimate traffic evolves and new attacks appear. Industrial IoT also restricts centralized data collection, while attackers may manipulate both traffic inputs and federated updates.

Research Question

What trade-off exists among adversarial robustness, resilience to concept drift, and communication cost in a resource-constrained federated intrusion detector?

Proposed Approach

Build a federated platform with poisoning-resistant aggregation, statistical drift detection, bounded replay for continual learning, and protocol-valid adversarial perturbations.

Expected Contribution

An experimental characterization of the trade-off among drift resilience, poisoning resistance, adversarial robustness, and communication overhead.

Expected Prototype

A reproducible multi-gateway testbed with a dashboard displaying drift, performance degradation, and communication cost per round.

Datasets

Edge-IIoTset, TON_IoT, and CICIDS reorganized as temporally ordered streams.

Challenges

Protocol-valid adversarial evaluation, limited longitudinal data, extreme client heterogeneity, and defensive mechanisms becoming attack surfaces.

Research Question

How can a federated intrusion detector maintain reliable performance over long-term operation when facing evolving traffic patterns and potentially malicious clients?

Innovation

The project jointly studies concept drift, poisoning, and adversarial perturbations within a single resource-constrained federated architecture.

Expected Deliverable

A reproducible federated experimentation platform, a longitudinal evaluation protocol, and a quantitative robustness-performance-cost analysis.

Technologies

Federated Learning and Robust Aggregation Concept Drift Detection Adversarial Machine Learning Edge Computing and IoT Gateways Network Traffic Analysis

Required Skills

  • Networks and Industrial Protocols
  • Machine Learning and Federated Learning
  • Defensive and Offensive Security in Controlled Environments
  • Systems Programming and Containerization

Datasets

  • Edge-IIoTset
  • TON_IoT
  • CICIDS2017 / CSE-CIC-IDS2018

Morocco & Africa Relevance

Rapid industrialization in Morocco, especially in automotive, aerospace, mining, and connected manufacturing, increases the relevance of distributed and resource-efficient intrusion detection.