FedCIPHER: Causal-Invariant and Privacy-Hardened Prototype Federation for Robust Network Intrusion Detection under Non-IID Traffic
Main Article Content
Abstract
Collaborative network intrusion detection requires security operation centers, cloud platforms, and industrial edge domains to learn from distributed traffic without centralizing packet traces, asset identifiers, or attack evidence. Federated learning limits direct data movement, yet conventional parameter averaging is fragile when attack classes are rare, traffic distributions are non-independent and identically distributed (non-IID), and model updates can be inspected or poisoned. This paper proposes FedCIPHER, a causal-invariant and privacy-hardened prototype federation framework for multi-class network threat detection. Each client learns a gated causal representation by exchanging nuisance components between traffic samples and enforcing counterfactual prediction consistency. Instead of uploading full model gradients, the client releases clipped, orthogonally sketched first- and second-order class prototypes protected by distributed Gaussian noise and secure summation. An evidential uncertainty score and a class-conditional deviation statistic jointly control robust server aggregation, while a private global prototype bank regularizes locally personalized detectors. We provide a Rényi differential privacy bound, a bounded-influence analysis for malicious clients, and a convergence characterization that explicitly separates client drift, sketch distortion, and privacy noise. Experiments on UNSW-NB15, CICIDS2017, ToN-IoT, and BoT-IoT with 20 clients show that FedCIPHER obtains average Macro-F1 of 88.70% under Dirichlet concentration α = 0.3, exceeding FedAvg, FedProto, FEDIIR, and PROTEAN by 6.68, 3.69, 3.61, and 2.43 percentage points, respectively. At ε = 4 and δ = 10−5, membership-inference AUC is reduced to 0.566 while Macro-F1 decreases by only 0.42 points relative to the non-private variant. FedCIPHER also retains 82.83% Macro-F1 with 30% malicious clients and reduces per-round upload by 99.59% compared with full-model federation. These results indicate that causal prototype federation offers an effective balance among detection utility, privacy, poisoning resilience, and communication efficiency for cross-domain network data security.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-Efficient Learning of Deep Networks from Decentralized Data,” in Proc. AISTATS, 2017, pp. 1273-1282.
L. Zhu, Z. Liu, and S. Han, “Deep Leakage from Gradients,” in Advances in Neural Information Processing Systems, vol. 32, 2019.
K. Bonawitz et al., “Practical Secure Aggregation for Privacy-Preserving Machine Learning,” in Proc. ACM CCS, 2017, pp. 1175-1191, doi: 10.1145/3133956.3133982.
X. Li, K. Huang, W. Yang, S. Wang, and Z. Zhang, “On the Convergence of FedAvg on Non-IID Data,” in Proc. ICLR, 2020.
T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V. Smith, “Federated Optimization in Heterogeneous Networks,” Proc. MLSys, vol. 2, pp. 429-450, 2020.
S. P. Karimireddy, S. Kale, M. Mohri, S. Reddi, S. Stich, and A. T. Suresh, “SCAFFOLD: Stochastic Controlled Averaging for Federated Learning,” in Proc. ICML, 2020, pp. 5132-5143.
J. Wang, Q. Liu, H. Liang, G. Joshi, and H. V. Poor, “Tackling the Objective Inconsistency Problem in Heterogeneous Federated Optimization,” in Advances in Neural Information Processing Systems, vol. 33, 2020, pp. 7611-7623.
T. Li, S. Hu, A. Beirami, and V. Smith, “Ditto: Fair and Robust Federated Learning Through Personalization,” in Proc. ICML, 2021, pp. 6357-6368.
Y. Tan et al., “FedProto: Federated Prototype Learning Across Heterogeneous Clients,” in Proc. AAAI, vol. 36, no. 8, 2022, pp. 8432-8440.
J. Zhang et al., “GPFL: Simultaneously Learning Global and Personalized Feature Information for Personalized Federated Learning,” in Proc. ICCV, 2023, pp. 5041-5051.
S. Chennoufi, Y. Han, G. Blanc, E. De Cristofaro, and C. Kiennert, “PROTEAN: Federated Intrusion Detection in Non-IID Environments through Prototype-Based Knowledge Sharing,” arXiv:2507.05524, 2025.
D. A. E. Acar et al., “Federated Learning Based on Dynamic Regularization,” in Proc. ICLR, 2021.
Q. Li, B. He, and D. Song, “Model-Contrastive Federated Learning,” in Proc. CVPR, 2021, pp. 10713-10722.
K. Pillutla et al., “Federated Learning with Partial Model Personalization,” in Proc. ICML, 2022, pp. 17716-17758.
Y. Guo, B. Guo, and Z. Wang, “Out-of-Distribution Generalization of Federated Learning via Implicit Invariant Relationships,” in Proc. ICML, 2023, pp. 11905-11933.
M. Arjovsky, L. Bottou, I. Gulrajani, and D. Lopez-Paz, “Invariant Risk Minimization,” arXiv:1907.02893, 2019.
I. Mironov, “Rényi Differential Privacy,” in Proc. IEEE CSF, 2017, pp. 263-275, doi: 10.1109/CSF.2017.11.
M. Abadi et al., “Deep Learning with Differential Privacy,” in Proc. ACM CCS, 2016, pp. 308-318, doi: 10.1145/2976749.2978318.
E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, “How To Backdoor Federated Learning,” in Proc. AISTATS, 2020, pp. 2938-2948.
P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent,” in Advances in Neural Information Processing Systems, vol. 30, 2017.
D. Yin, Y. Chen, R. Kannan, and P. Bartlett, “Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates,” in Proc. ICML, 2018, pp. 5650-5659.
N. Moustafa and J. Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems,” in Proc. MilCIS, 2015, pp. 1-6, doi: 10.1109/MilCIS.2015.7348942.
I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward Gen- erating a New Intrusion Detection Dataset and Intrusion Traffic Characterization,” in Proc. ICISSP, 2018, pp. 108-116.
N. Moustafa, “A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems,” IEEE Access, vol. 8, pp. 165130-165150, 2020, doi: 10.1109/ACCESS.2020.3022862.
N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the Development of Realistic Botnet Dataset in the Internet of Things for Network Forensic Analytics: Bot-IoT Dataset,” Future Generation Computer Systems, vol. 100, pp. 779-796, 2019, doi: 10.1016/j.future.2019.05.041.
M. Mohri, G. Sivek, and A. T. Suresh, “Agnostic Federated Learning,” in Proc. ICML, 2019, pp. 4615-4625.
Z. Li, T. Lin, X. Shang, and C. Wu, “Revisiting Weighted Aggregation in Federated Learning with Neural Networks,” in Proc. ICML, 2023, pp. 19767-19788.
M. Cuturi, “Sinkhorn Distances: Lightspeed Computation of Optimal Transport,” in Advances in Neural Information Processing Systems, vol. 26, 2013.
P. Kairouz et al., “Advances and Open Problems in Federated Learning,” Foundations and Trends in Machine Learning, vol. 14, no. 1-2, pp. 1-210, 2021.
H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang, “Learning Differentially Private Recurrent Language Models,” in Proc. ICLR, 2018.