Beyond Magnitude Filtering: A Dual-Stage Gradient Validation Mechanism for Defending Federated Intrusion Detection against Label-Flipping Poisoning in IoV Networks
Main Article Content
Abstract
Federated Learning (FL) enables distributed vehicular networks to collaboratively train intrusion detection models without sharing sensitive CAN-bus traffic data; however, this distributed paradigm remains vulnerable to poisoning attacks. Malicious participants can manipulate local updates through label-flipping or semantic gradient attacks that preserve plausible update magnitudes while altering gradient directions. Conventional magnitude-based defenses, such as Median Absolute Deviation (MAD) thresholding, detect only about 58% of attacks because they cannot identify semantic poisoning. This paper proposes a dual-stage gradient validation mechanism for securing federated intrusion detection in Internet of Vehicles (IoV) CAN-bus networks. The framework combines norm-deviation thresholding with cosine-similarity filtering to detect both magnitude-based and semantic poisoning attacks. The mechanism is integrated into an Adaptive Weighted Input (AWI) aggregation strategy that assigns continuous trust-based weights instead of binary exclusion, thereby preserving useful client contributions while limiting adversarial influence. Experiments using the CIC-IoV 2024 dataset under varying label-flipping attack severities show that the proposed method detects 91–95% of poisoned updates, improving detection by 33–37 percentage points over MAD-only filtering. The framework reduces global model drift from 41% while preserving an intrusion detection accuracy of 98% (ROC-AUC = 0.998). Convergence analysis demonstrates enhanced training stability with a 79% reduction in the variance of accuracy and reaching 95% of maximum performance in 19 rounds as opposed to 38 rounds without defense. Thus, the results show that directional gradient analysis is an effective, computationally feasible, and improved method for secure federated vehicular intrusion detection.