Trust-Guided Weighted Federated Averaging with Tamper-Evident Audit Logging for Robust Intrusion Detection on CICIoT2023
DOI:
https://doi.org/10.70917/ijcisim-2026-4475Keywords:
Federated learning, Internet of Things, intrusion detection system, CICIoT2023, trust-guided aggregation, audit logging, poisoning robustnessAbstract
Federated learning is a promising approach for Internet of Things intrusion detection because it enables collaborative model training without centralizing sensitive traffic data. However, federated intrusion detection remains vulnerable to non-IID client distributions, poisoned updates, and unreliable clients that can degrade the global detector. This paper presents a three-part framework for robust intrusion detection on CICIoT2023: a trust-guided weighted federated averaging scheme, a tamper-evident audit logging layer, and a poisoning-aware evaluation protocol. The proposed Trust-Guided Weighted Federated Averaging with Audit Logging (TGWFA-AL) combines validation-based trust, directional agreement of updates, and temporal trust adaptation using an exponential moving average to reduce the influence of suspicious clients over time. A tamper-evident audit trail records per-round model provenance using cryptographic hashes, trust components, filtering decisions, and aggregation weights, while storing raw models off-chain when needed to control cloud cost. The manuscript defines the threat model precisely, includes robust aggregation baselines beyond FedAvg, and supports both binary and multi-class evaluation with macro-averaged metrics. The numerical results, ablations, and overhead values in this draft are synthetic example values intended to make the manuscript structurally complete; they must be replaced with empirical outputs from the human author’s experiments before submission.