GowFed A novel federated network intrusion detection system

被引:11
|
作者
Belenguer, Aitor [1 ]
Pascual, Jose A. [1 ]
Navaridas, Javier [1 ]
机构
[1] Univ Basque Country UPV EHU, Dept Comp Architecture & Technol, Manuel Lardizabal 1, Donostia San Sebastian 20018, Spain
关键词
Federated Learning; Intrusion Detection Systems; Internet of Things; Gower distance;
D O I
10.1016/j.jnca.2023.103653
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems are evolving into intelligent systems that perform data analysis while searching for anomalies in their environment. Indeed, the development of deep learning techniques paved the way to build more complex and effective threat detection models. However, training those models may be computationally infeasible in most Edge or IoT devices. Current approaches rely on powerful centralized servers that receive data from all their parties - violating basic privacy constraints and substantially affecting response times and operational costs due to the huge communication overheads. To mitigate these issues, Federated Learning emerged as a promising approach, where different agents collaboratively train a shared model, without exposing training data to others or requiring a compute-intensive centralized infrastructure. This work presents GowFed, a novel network threat detection system that combines the usage of Gower Dissimilarity matrices and Federated averaging. Different approaches of GowFed have been developed based on state-of the-art knowledge: (1) a vanilla version - achieving a median point of [0.888, 0.960] in the PR space and a median accuracy of 0.930; and (2) a version instrumented with an attention mechanism - achieving comparable results when 0.8 of the best performing nodes contribute to the model. Furthermore, each variant has been tested using simulation oriented tools provided by TensorFlow Federated framework. In the same way, a centralized analogous development of the Federated systems is carried out to explore their differences in terms of scalability and performance - the median point of the experiments is [0.987, 0.987]) and the median accuracy is 0.989. Overall, GowFed intends to be the first stepping stone towards the combined usage of Federated Learning and Gower Dissimilarity matrices to detect network threats in industrial-level networks.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Improving Transferability of Network Intrusion Detection in a Federated Learning Setup
    Ghosh, Shreya
    Jameel, Abu Shafin Mohammad Mahdee
    El Gamal, Aly
    2024 IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING FOR COMMUNICATION AND NETWORKING, ICMLCN 2024, 2024, : 171 - 176
  • [22] FEDDBN-IDS: federated deep belief network-based wireless network intrusion detection system
    Nivaashini, M.
    Suganya, E.
    Sountharrajan, S.
    Prabu, M.
    Bavirisetti, Durga Prasad
    EURASIP JOURNAL ON INFORMATION SECURITY, 2024, 2024 (01)
  • [23] FEDDBN-IDS: federated deep belief network-based wireless network intrusion detection system
    M. Nivaashini
    E. Suganya
    S. Sountharrajan
    M. Prabu
    Durga Prasad Bavirisetti
    EURASIP Journal on Information Security, 2024
  • [24] Network Intrusion Detection Scheme based on Federated Learning in Heterogeneous Network Environments
    Zhu, Yuedi
    Li, Chao
    Wang, Yong
    2024 13TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS, ICCCAS 2024, 2024, : 491 - 496
  • [25] A novel federated learning aggregation algorithm for AIoT intrusion detection
    Jia, Yidong
    Lin, Fuhong
    Sun, Yan
    IET COMMUNICATIONS, 2024, 18 (07) : 429 - 436
  • [26] A Novel Method for Network Intrusion Detection
    Wang, Hongmin
    Wei, Qiang
    Xie, Yaobin
    SCIENTIFIC PROGRAMMING, 2022, 2022
  • [27] Intrusion detection in federated clouds
    Ficco M.
    Tasquier L.
    Aversa R.
    Ficco, Massimo (massimo.ficco@unina2.it), 1600, Inderscience Enterprises Ltd., 29, route de Pre-Bois, Case Postale 856, CH-1215 Geneva 15, CH-1215, Switzerland (13): : 219 - 232
  • [28] FL-IIDS: A novel federated learning-based incremental intrusion detection system
    Jin, Zhigang
    Zhou, Junyi
    Li, Bing
    Wu, Xiaodong
    Duan, Chenxu
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 151 : 57 - 70
  • [29] Intrusion detection in federated clouds
    Ficco, Massimo
    Tasquier, Luca
    Aversa, Rocco
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2016, 13 (03) : 219 - 232
  • [30] Recurrent network in Network Intrusion Detection System
    Xue, JS
    Sun, JZ
    Zhang, X
    PROCEEDINGS OF THE 2004 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2004, : 2676 - 2679