GowFed A novel federated network intrusion detection system

被引:11
|
作者
Belenguer, Aitor [1 ]
Pascual, Jose A. [1 ]
Navaridas, Javier [1 ]
机构
[1] Univ Basque Country UPV EHU, Dept Comp Architecture & Technol, Manuel Lardizabal 1, Donostia San Sebastian 20018, Spain
关键词
Federated Learning; Intrusion Detection Systems; Internet of Things; Gower distance;
D O I
10.1016/j.jnca.2023.103653
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems are evolving into intelligent systems that perform data analysis while searching for anomalies in their environment. Indeed, the development of deep learning techniques paved the way to build more complex and effective threat detection models. However, training those models may be computationally infeasible in most Edge or IoT devices. Current approaches rely on powerful centralized servers that receive data from all their parties - violating basic privacy constraints and substantially affecting response times and operational costs due to the huge communication overheads. To mitigate these issues, Federated Learning emerged as a promising approach, where different agents collaboratively train a shared model, without exposing training data to others or requiring a compute-intensive centralized infrastructure. This work presents GowFed, a novel network threat detection system that combines the usage of Gower Dissimilarity matrices and Federated averaging. Different approaches of GowFed have been developed based on state-of the-art knowledge: (1) a vanilla version - achieving a median point of [0.888, 0.960] in the PR space and a median accuracy of 0.930; and (2) a version instrumented with an attention mechanism - achieving comparable results when 0.8 of the best performing nodes contribute to the model. Furthermore, each variant has been tested using simulation oriented tools provided by TensorFlow Federated framework. In the same way, a centralized analogous development of the Federated systems is carried out to explore their differences in terms of scalability and performance - the median point of the experiments is [0.987, 0.987]) and the median accuracy is 0.989. Overall, GowFed intends to be the first stepping stone towards the combined usage of Federated Learning and Gower Dissimilarity matrices to detect network threats in industrial-level networks.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] An Efficient Federated Learning System for Network Intrusion Detection
    Li, Jianbin
    Tong, Xin
    Liu, Jinwei
    Cheng, Long
    IEEE SYSTEMS JOURNAL, 2023, 17 (02): : 2455 - 2464
  • [2] The sound of intrusion: A novel network intrusion detection system
    Aldarwbi, Mohammed Y.
    Lashkari, Arash H.
    Ghorbani, Ali A.
    COMPUTERS & ELECTRICAL ENGINEERING, 2022, 104
  • [3] Federated Wireless Network Intrusion Detection
    Cetin, Burak
    Lazar, Alina
    Kim, Jinoh
    Sim, Alex
    Wu, Kesheng
    2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 6004 - 6006
  • [4] A Novel Federated Learning Based Intrusion Detection System for IoT Networks
    Benameur, Rabaie
    Dahane, Amine
    Souihi, Sami
    Mellouk, Abdelhamid
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 2402 - 2407
  • [5] A federated learning method for network intrusion detection
    Tang, Zhongyun
    Hu, Haiyang
    Xu, Chonghuan
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (10):
  • [6] F-NIDS - A Network Intrusion Detection System based on federated learning
    de Oliveira, Jonathas A.
    Goncalves, Vinicius P.
    Meneguette, Rodolfo I.
    de Sousa Jr, Rafael T.
    Guidoni, Daniel L.
    Oliveira, Jose C. M.
    Filho, Geraldo P. Rocha
    COMPUTER NETWORKS, 2023, 236
  • [7] A Federated Network Intrusion Detection System with Multi-Branch Network and Vertical Blocking Aggregation
    Wang, Yunhui
    Zheng, Weichu
    Liu, Zifei
    Wang, Jinyan
    Shi, Hongjian
    Gu, Mingyu
    Di, Yicheng
    ELECTRONICS, 2023, 12 (19)
  • [8] A Novel Network Intrusion Detection System Based on CNN
    Chen, Lin
    Kuang, Xiaoyun
    Xu, Aidong
    Suo, Siliang
    Yang, Yiwei
    2020 EIGHTH INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD 2020), 2020, : 243 - 247
  • [9] A novel intrusion detection system for a local computer network
    Tokhtabayev, A.
    Altaibek, A.
    Skormin, V.
    Tukeyev, U.
    COMPUTER NETWORK SECURITY, PROCEEDINGS, 2007, 1 : 320 - +
  • [10] Campus Network Intrusion Detection based on Federated Learning
    Chen, Junjun
    Guo, Qiang
    Fu, Zhongnan
    Shang, Qun
    Ma, Hao
    Wu, Di
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,