Interactive research piece

Federated poisoning sandbox

Eight simulated organizations train one intrusion detector together without sharing raw traffic. Each round, every client trains locally and sends only a model update; the server combines those updates into the next global model. Select a client to turn it malicious, then try a robust aggregation rule and watch whether the server catches it.

Toy simulation: 8 clients train a logistic regression live in your browser (in a Web Worker), on a balanced 2,000-row subset of NSL-KDD, scored on a 600-row held-out test set. Not a production federated learning system.

Client data
Round 20 of 60

Round 20: FedAvg averaged all 8 updates; accuracy 86.7%, down 1.2 points; 22.0% of attacks missed.

Static snapshot, computed when this page was built: 20 rounds of FedAvg with 8 honest clients, from 42.8% to 86.7% test accuracy. It runs live, and can be attacked, once JavaScript loads.

Clients and server

Attackers

  • No attackers. Select a client on the ring to make it malicious.

Client updates this round, 2D projection (PCA)

horizontal: PC1, 44% of variancevertical: PC2, 28%aggregate

Global model on the held-out test set

0%25%50%75%100%0102030405060round86.7%22.0%
Round data as tables
Latest round, per client
ClientRoleUpdate sizeServer decision
Client 1Honest0.062Averaged in.
Client 2Honest0.086Averaged in.
Client 3Honest0.066Averaged in.
Client 4Honest0.059Averaged in.
Client 5Honest0.058Averaged in.
Client 6Honest0.073Averaged in.
Client 7Honest0.079Averaged in.
Client 8Honest0.075Averaged in.
Global model by round
RoundAccuracyAttacks missed
042.8%18.3%
147.5%17.0%
253.7%16.0%
360.3%15.7%
467.5%16.0%
574.5%16.0%
679.2%16.7%
780.0%18.0%
880.7%17.3%
981.2%17.3%
1081.3%17.7%
1181.5%17.7%
1282.7%18.3%
1383.5%18.3%
1484.7%18.3%
1586.8%18.0%
1688.2%18.0%
1788.0%18.7%
1888.2%18.7%
1987.8%19.7%
2086.7%22.0%

Why this matters

TODO(Q): write the real explanation here.

Data: NSL-KDD dataset. Cite: M. Tavallaee, E. Bagheri, W. Lu, A. Ghorbani, 'A Detailed Analysis of the KDD CUP 99 Data Set,' 2nd IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), 2009. Original terms (unb.ca/cic/datasets/nsl.html) permit redistribution and mirroring in any form with this citation retained. Mirror: https://github.com/defcom17/NSL_KDD