Non-stationary Distribution Attack in Federated Intrusion Detection Systems: Formal Definition, Convergence Analysis, and Empirical Evaluation | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Non-stationary Distribution Attack in Federated Intrusion Detection Systems: Formal Definition, Convergence Analysis, and Empirical Evaluation Rahul Nayak, Aditya Prasoon This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-9275643/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 4 You are reading this latest preprint version Abstract Federated learning has emerged as the dominant paradigm for privacy-preserving intrusion detection across distributed networks, yet its vulnerability to adversarial manipulation of the training process remains incompletely characterised. Existing attack formulations—Byzantine poisoning, label flipping, and gradient inversion—treat the local data distribution of a malicious client as fixed across training rounds. We identify and formalise a fundamentally different threat: the Non-stationary Distribution Attack (NDA), in which a single adversarial client strategically rotates its local attack-traffic family across rounds to deliberately amplify gradient divergence induced by non-independent and identically distributed (non-IID) data partitioning. We prove formally (Theorem 1) that NDA degrades FedAvg convergence whenever the Dirichlet heterogeneity parameter α falls below a dataset-dependent critical threshold α*, and we show constructively (Theorem 2) that NDA evades Krum-style aggregation filters by design. We further derive a KL drift-based detection criterion (Proposition 1) and establish that NDA requires Ω(1/ε²) observation rounds to distinguish from natural concept drift (Theorem 3). Comprehensive experiments on three benchmark datasets—CICIDS2017, TON_IoT, and NSL-KDD—across three aggregation schemes (FedAvg, FedProx, SCAFFOLD) demonstrate that NDA's primary operational impact is silent Area Under the ROC Curve (AUC) degradation: up to 4.84 percentage points on TON_IoT under SCAFFOLD at α = 0.05, while accuracy decreases by only 1.65 percentage points. This stealth ratio of 2.9× renders NDA invisible to accuracy-based monitoring yet highly damaging to the model's attack-ranking capability. Our results motivate a rethinking of non-IID heterogeneity as an actively exploitable attack surface rather than a passive statistical inconvenience. Federated learning Intrusion detection Non-IID heterogeneity Byzantine resilience Adversarial machine learning Multi-agent systems Non-stationary distribution attack Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 03 Apr, 2026 Editor assigned by journal 02 Apr, 2026 Submission checks completed at journal 02 Apr, 2026 First submitted to journal 31 Mar, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-9275643","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":617077857,"identity":"9ecdfe16-9c15-4fb6-80fa-1bcc3a27b8d0","order_by":0,"name":"Rahul Nayak","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABVklEQVRIie3SPUvDQBjA8Sc8cC6nWVNS269wIRAFpZ/ljkK7pNKxg2CgkE7WtfkQQidxTAk0S9S14GBLwalDQZCCwXpXi/RNdBTMf8mF3I8n4QKQlfUnowBDOC0Awt5MpIvFsnB5JTsIh4qtdhojTy0Whimied+TSKiHuZGnFptko6PWXd/ggNp1C4dM3GK1G+u9l3qainZ8GQ/hvAQH5prMJ2cVSQg6EWFcJKTWjRDNwGciSO7lyH4ZSD5cJQa4jiSUOBGFkBNaC5oI5r7HRHfgWh6QEIjcsEr0iSIGlUTzODGquSbiG00leZpI8r5NjMUUZkiCIHzGdURiUqKmUMvT/B1kYh9zxpn8Fgd4wq0rROck8G07SFyrI9pluvVirjWYNuYXNw/RszZrzItE740f62nhsB0nbDp9LRWKnTXyGdu4//oB5JGpg/tF+POWrKysrH/UB4OocbJKBuTsAAAAAElFTkSuQmCC","orcid":"","institution":"VIT-AP University","correspondingAuthor":true,"prefix":"","firstName":"Rahul","middleName":"","lastName":"Nayak","suffix":""},{"id":617077858,"identity":"053011e8-c5cc-48f5-b944-6a49c0d57cd5","order_by":1,"name":"Aditya Prasoon","email":"","orcid":"","institution":"VIT-AP University","correspondingAuthor":false,"prefix":"","firstName":"Aditya","middleName":"","lastName":"Prasoon","suffix":""}],"badges":[],"createdAt":"2026-03-31 06:54:18","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-9275643/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-9275643/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":107412282,"identity":"12ffc163-d88c-4727-ab8e-1cde5949f253","added_by":"auto","created_at":"2026-04-21 09:13:46","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":315061,"visible":true,"origin":"","legend":"","description":"","filename":"SpringerNatureLaTeXTemplate42.pdf","url":"https://assets-eu.researchsquare.com/files/rs-9275643/v1_covered_f72ebded-e7e5-4b7d-98a9-980a84b09e86.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"\u003cp\u003eNon-stationary Distribution Attack in Federated Intrusion Detection Systems: Formal Definition, Convergence Analysis, and Empirical Evaluation\u003c/p\u003e","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"the-journal-of-supercomputing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [The Journal of Supercomputing](https://www.springer.com/journal/11227)","snPcode":"11227","submissionUrl":"https://submission.nature.com/new-submission/11227/3","title":"The Journal of Supercomputing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Federated learning, Intrusion detection, Non-IID heterogeneity, Byzantine resilience, Adversarial machine learning, Multi-agent systems, Non-stationary distribution attack","lastPublishedDoi":"10.21203/rs.3.rs-9275643/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-9275643/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Federated learning has emerged as the dominant paradigm for privacy-preserving intrusion detection across distributed networks, yet its vulnerability to adversarial manipulation of the training process remains incompletely characterised. Existing attack formulations—Byzantine poisoning, label flipping, and gradient inversion—treat the local data distribution of a malicious client as fixed across training rounds.\nWe identify and formalise a fundamentally different threat: the Non-stationary Distribution Attack (NDA), in which a single adversarial client strategically rotates its local attack-traffic family across rounds to deliberately amplify gradient divergence induced by non-independent and identically distributed (non-IID) data partitioning.\nWe prove formally (Theorem 1) that NDA degrades FedAvg convergence whenever the Dirichlet heterogeneity parameter α falls below a dataset-dependent critical threshold α*, and we show constructively (Theorem 2) that NDA evades Krum-style aggregation filters by design.\nWe further derive a KL drift-based detection criterion (Proposition 1) and establish that NDA requires Ω(1/ε²) observation rounds to distinguish from natural concept drift (Theorem 3).\nComprehensive experiments on three benchmark datasets—CICIDS2017, TON_IoT, and NSL-KDD—across three aggregation schemes (FedAvg, FedProx, SCAFFOLD) demonstrate that NDA's primary operational impact is silent Area Under the ROC Curve (AUC) degradation: up to 4.84 percentage points on TON_IoT under SCAFFOLD at α = 0.05, while accuracy decreases by only 1.65 percentage points. This stealth ratio of 2.9× renders NDA invisible to accuracy-based monitoring yet highly damaging to the model's attack-ranking capability.\nOur results motivate a rethinking of non-IID heterogeneity as an actively exploitable attack surface rather than a passive statistical inconvenience.","manuscriptTitle":"Non-stationary Distribution Attack in Federated Intrusion Detection Systems: Formal Definition, Convergence Analysis, and Empirical Evaluation","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-04-21 09:13:17","doi":"10.21203/rs.3.rs-9275643/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2026-04-03T09:54:05+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-04-02T22:03:28+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-04-02T22:02:30+00:00","index":"","fulltext":""},{"type":"submitted","content":"The Journal of Supercomputing","date":"2026-03-31T06:46:36+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"the-journal-of-supercomputing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [The Journal of Supercomputing](https://www.springer.com/journal/11227)","snPcode":"11227","submissionUrl":"https://submission.nature.com/new-submission/11227/3","title":"The Journal of Supercomputing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"645f5c64-ef6c-417d-8de8-3fff30420654","owner":[],"postedDate":"April 21st, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-04-21T09:13:17+00:00","versionOfRecord":[],"versionCreatedAt":"2026-04-21 09:13:17","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-9275643","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-9275643","identity":"rs-9275643","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.