Javascript must be enabled to continue!
TrustFed-Honeypot: Multi-Signal Trust-Aware Federated IntrusionDetection
View through CrossRef
fidelity, concept drift, and honeypot capture quality and not only when updates are malicious.Conventional federated averaging and parameter-robust aggregators (FedProx, coordinate-wise median, Krum) reweighs or filter client gradients yet cannot remove semantically corrupted training rows from the server’s effective learning distribution. This paper presents TrustFed-Honeypot, a reliability-aware hybrid federated-retraining framework for honeypot-based IDS. Each round, clients train locally; the server retrains a global logistic model on trust-weighted samples of preprocessed feature vectors, governed by a multi-signal behavioral trust model (performance, stability, update drift, uncertainty)with sub-linear trust compression (????=0.8). On real honeypot telemetry over ????=12 independent seeds, TrustFed achieves 81.79% ± 10.02% F1 and 84.91% ± 18.17% recall versus 37.55% ± 18.41% F1 for FedAvg under an identical server-retraining protocol (paired Wilcoxon, ????<0.01). Trust-weighted parameter averaging without trust-gated retraining yields only 3.64% ± 11.00% F1, showing that gains arise from reshaping the retraining distribution rather than from reweighted gradients alone. Under the same adaptive corruption schedule, FedProx, median, and Krum exhibit near-zero attack recall in this protocol, without claiming general ineffectiveness against Byzantine gradient attacks. A CTU-13 stress evaluation further documents prevalence-shift failure when global F1 collapses while trust tiersremain diagnostically useful. The primary protocol exchanges preprocessed features and does not claim end-to-end cryptographic privacy; a gradient-only Strong v1 extension reports a separate utility-privacy trade-off. These findings position telemetry-quality governance as a complementary design axis to parameter-space robustness for federated honeypot IDS.
Title: TrustFed-Honeypot: Multi-Signal Trust-Aware Federated IntrusionDetection
Description:
fidelity, concept drift, and honeypot capture quality and not only when updates are malicious.
Conventional federated averaging and parameter-robust aggregators (FedProx, coordinate-wise median, Krum) reweighs or filter client gradients yet cannot remove semantically corrupted training rows from the server’s effective learning distribution.
This paper presents TrustFed-Honeypot, a reliability-aware hybrid federated-retraining framework for honeypot-based IDS.
Each round, clients train locally; the server retrains a global logistic model on trust-weighted samples of preprocessed feature vectors, governed by a multi-signal behavioral trust model (performance, stability, update drift, uncertainty)with sub-linear trust compression (????=0.
8).
On real honeypot telemetry over ????=12 independent seeds, TrustFed achieves 81.
79% ± 10.
02% F1 and 84.
91% ± 18.
17% recall versus 37.
55% ± 18.
41% F1 for FedAvg under an identical server-retraining protocol (paired Wilcoxon, ????<0.
01).
Trust-weighted parameter averaging without trust-gated retraining yields only 3.
64% ± 11.
00% F1, showing that gains arise from reshaping the retraining distribution rather than from reweighted gradients alone.
Under the same adaptive corruption schedule, FedProx, median, and Krum exhibit near-zero attack recall in this protocol, without claiming general ineffectiveness against Byzantine gradient attacks.
A CTU-13 stress evaluation further documents prevalence-shift failure when global F1 collapses while trust tiersremain diagnostically useful.
The primary protocol exchanges preprocessed features and does not claim end-to-end cryptographic privacy; a gradient-only Strong v1 extension reports a separate utility-privacy trade-off.
These findings position telemetry-quality governance as a complementary design axis to parameter-space robustness for federated honeypot IDS.
Related Results
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Dalam era digital yang semakin kompleks ini, keamanan sistem informasi menjadi masalah penting bagi organisasi di berbagai industri. Peningkatan serangan siber serta polanya yang s...
Modeling the effects of different honeypot proportions in a deception-based security game
Modeling the effects of different honeypot proportions in a deception-based security game
Cyber-attacks, an intentional effort to steal information or interrupt the network, are growing dramatically. It is of great importance to understand how an adversary’s behavior mi...
Honeypot in the Cyber Space
Honeypot in the Cyber Space
In today’s world a large number of devices are connected to the network, which indicates that there could exist more access nodes than before from where an intruder can try to atta...
Autonomy on Trial
Autonomy on Trial
Photo by CHUTTERSNAP on Unsplash
Abstract
This paper critically examines how US bioethics and health law conceptualize patient autonomy, contrasting the rights-based, individualist...
Analysis of Cyber Attacks Using Honeypot
Analysis of Cyber Attacks Using Honeypot
In the cybersecurity world, the concept of a honeypot is generally referred to as trap systems that have real system behaviors, intentionally leave a security gap, and aim to colle...
Banking system trust, bank trust, and bank loyalty
Banking system trust, bank trust, and bank loyalty
Purpose
The purpose of this paper is to test a model of banking system trust as an antecedent of bank trust and bank loyalty. Six determinants of trust and loya...
TRUST-AWARE FEDERATED LEARNING WITH SOFT COMPUTING FOR PRIVACY-PRESERVING HEALTHCARE ANALYTICS
TRUST-AWARE FEDERATED LEARNING WITH SOFT COMPUTING FOR PRIVACY-PRESERVING HEALTHCARE ANALYTICS
The rapid adoption of the data-driven healthcare analytics has raised serious concerns regarding the patient privacy, data integrity, and collaborative intelligence across distribu...
AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
The development of adaptive and intelligent defense mechanisms will require new approaches to defending against
sophisticated cyber threats that can't be fully supported by existin...

