ARFU-IDS: Robust Federated Unlearning for Transformer-Based Intrusion Detection in IoT and Sensor Networks
Federated intrusion detection systems (FL-IDSs) for IoT and wireless sensor networks (WSNs) must remove client contributions after training when consent changes, devices retire, or compromised nodes are identified. Existing federated unlearning methods are not well aligned with transformer-based IDSs because they use coarse attribution, provide limited trajectory verification, and handle concurrent deletion requests weakly under rare-attack imbalance conditions. This paper proposes ARFU-IDS, a robust federated unlearning framework for transformer-based IoT and sensor-network IDSs. ARFU-IDS combines attention-head attribution, dual-path layer criticality probing, manipulation-resistant iterative verification, and conflict-graph scheduling to remove target-client influence while preserving retained detection utility. Experiments on UNSW-NB15, CICIoT2023, and IoTID20 evaluated detection utility, rare-category recall, adversarial robustness with network-flow feature triggers, and concurrent unlearning. On UNSW-NB15, ARFU-IDS achieves 87.1% Macro-F1 and 77.6% rare-category recall, within 0.2 percentage points of full retraining. Under flow-feature trigger attacks, it reduces attack success rate to 8.2% at f=0.1 and 9.7% at f=0.2. For three concurrent deletion requests, it shortens online unlearning latency by 43.3% relative to sequential processing. These results show that ARFU-IDS offers a practical route to robust and efficient federated unlearning for transformer-based IDSs in IoT and sensor-network deployments.
0 Comments
The summary above is machine-written and the abstract is the authors' own pitch. This is where people who read the paper say what it actually found, what the summary missed, and which part is worth your time.
Log in to join the discussion.