Interactive research piece
Federated poisoning sandbox
Eight simulated organizations train one intrusion detector together without sharing raw traffic. Each round, every client trains locally and sends only a model update; the server combines those updates into the next global model. Select a client to turn it malicious, then try a robust aggregation rule and watch whether the server catches it.
Toy simulation: 8 clients train a logistic regression live in your browser (in a Web Worker), on a balanced 2,000-row subset of NSL-KDD, scored on a 600-row held-out test set. Not a production federated learning system.
Round 20: FedAvg averaged all 8 updates; accuracy 86.7%, down 1.2 points; 22.0% of attacks missed.
Static snapshot, computed when this page was built: 20 rounds of FedAvg with 8 honest clients, from 42.8% to 86.7% test accuracy. It runs live, and can be attacked, once JavaScript loads.
Clients and server
Attackers
- No attackers. Select a client on the ring to make it malicious.
Client updates this round, 2D projection (PCA)
Global model on the held-out test set
Round data as tables
| Client | Role | Update size | Server decision |
|---|---|---|---|
| Client 1 | Honest | 0.062 | Averaged in. |
| Client 2 | Honest | 0.086 | Averaged in. |
| Client 3 | Honest | 0.066 | Averaged in. |
| Client 4 | Honest | 0.059 | Averaged in. |
| Client 5 | Honest | 0.058 | Averaged in. |
| Client 6 | Honest | 0.073 | Averaged in. |
| Client 7 | Honest | 0.079 | Averaged in. |
| Client 8 | Honest | 0.075 | Averaged in. |
| Round | Accuracy | Attacks missed |
|---|---|---|
| 0 | 42.8% | 18.3% |
| 1 | 47.5% | 17.0% |
| 2 | 53.7% | 16.0% |
| 3 | 60.3% | 15.7% |
| 4 | 67.5% | 16.0% |
| 5 | 74.5% | 16.0% |
| 6 | 79.2% | 16.7% |
| 7 | 80.0% | 18.0% |
| 8 | 80.7% | 17.3% |
| 9 | 81.2% | 17.3% |
| 10 | 81.3% | 17.7% |
| 11 | 81.5% | 17.7% |
| 12 | 82.7% | 18.3% |
| 13 | 83.5% | 18.3% |
| 14 | 84.7% | 18.3% |
| 15 | 86.8% | 18.0% |
| 16 | 88.2% | 18.0% |
| 17 | 88.0% | 18.7% |
| 18 | 88.2% | 18.7% |
| 19 | 87.8% | 19.7% |
| 20 | 86.7% | 22.0% |
Why this matters
TODO(Q): write the real explanation here.
Data: NSL-KDD dataset. Cite: M. Tavallaee, E. Bagheri, W. Lu, A. Ghorbani, 'A Detailed Analysis of the KDD CUP 99 Data Set,' 2nd IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), 2009. Original terms (unb.ca/cic/datasets/nsl.html) permit redistribution and mirroring in any form with this citation retained. Mirror: https://github.com/defcom17/NSL_KDD