GowFed A novel federated network intrusion detection system

被引:11
|
作者
Belenguer, Aitor [1 ]
Pascual, Jose A. [1 ]
Navaridas, Javier [1 ]
机构
[1] Univ Basque Country UPV EHU, Dept Comp Architecture & Technol, Manuel Lardizabal 1, Donostia San Sebastian 20018, Spain
关键词
Federated Learning; Intrusion Detection Systems; Internet of Things; Gower distance;
D O I
10.1016/j.jnca.2023.103653
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems are evolving into intelligent systems that perform data analysis while searching for anomalies in their environment. Indeed, the development of deep learning techniques paved the way to build more complex and effective threat detection models. However, training those models may be computationally infeasible in most Edge or IoT devices. Current approaches rely on powerful centralized servers that receive data from all their parties - violating basic privacy constraints and substantially affecting response times and operational costs due to the huge communication overheads. To mitigate these issues, Federated Learning emerged as a promising approach, where different agents collaboratively train a shared model, without exposing training data to others or requiring a compute-intensive centralized infrastructure. This work presents GowFed, a novel network threat detection system that combines the usage of Gower Dissimilarity matrices and Federated averaging. Different approaches of GowFed have been developed based on state-of the-art knowledge: (1) a vanilla version - achieving a median point of [0.888, 0.960] in the PR space and a median accuracy of 0.930; and (2) a version instrumented with an attention mechanism - achieving comparable results when 0.8 of the best performing nodes contribute to the model. Furthermore, each variant has been tested using simulation oriented tools provided by TensorFlow Federated framework. In the same way, a centralized analogous development of the Federated systems is carried out to explore their differences in terms of scalability and performance - the median point of the experiments is [0.987, 0.987]) and the median accuracy is 0.989. Overall, GowFed intends to be the first stepping stone towards the combined usage of Federated Learning and Gower Dissimilarity matrices to detect network threats in industrial-level networks.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] Novel immune system model and its application to network intrusion detection
    Ling, Jun
    Cao, Yang
    Yin, Jian-Hua
    Huang, Tian-Xi
    Wuhan University Journal of Natural Sciences, 2003, 8 (2 A) : 393 - 398
  • [33] Novel Intrusion Detection System integrating Layered Framework with Neural Network
    Srivastav, Nidhi
    Challa, Rama Krishna
    PROCEEDINGS OF THE 2013 3RD IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE (IACC), 2013, : 682 - 689
  • [34] A Novel Approach of intrusion detection system design for computer network security
    Yi, Julan
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 3021 - 3025
  • [35] Federated Learning based Intrusion Detection System for Satellite Communication
    Uddin, Ryhan
    Kumar, Sathish
    2023 IEEE COGNITIVE COMMUNICATIONS FOR AEROSPACE APPLICATIONS WORKSHOP, CCAAW, 2023,
  • [36] Adversarial Attacks on Network Intrusion Detection Systems Based on Federated Learning
    Yang, Ziyuan
    Qu, Haipeng
    Hua, Ying
    Zhang, Xiaoshuai
    Lin, Xijun
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IX, ICIC 2024, 2024, 14870 : 146 - 157
  • [37] Federated Learning for Network Intrusion Detection in Ambient Assisted Living Environments
    Cholakoska, Ana
    Gjoreski, Hristijan
    Rakovic, Valentin
    Denkovski, Daniel
    Kalendar, Marija
    Pfitzner, Bjarne
    Arnrich, Bert
    IEEE INTERNET COMPUTING, 2023, 27 (04) : 15 - 22
  • [38] Distributed Network Intrusion Detection System in Satellite-Terrestrial Integrated Networks Using Federated Learning
    Li, Kun
    Zhou, Huachun
    Tu, Zhe
    Wang, Weilin
    Zhang, Hongke
    IEEE ACCESS, 2020, 8 : 214852 - 214865
  • [39] Fusion of Misuse Detection with Anomaly Detection Technique for Novel Hybrid Network Intrusion Detection System
    Hussain, Jamal
    Lalmuanawma, Samuel
    RECENT DEVELOPMENTS IN INTELLIGENT COMPUTING, COMMUNICATION AND DEVICES, ICCD 2016, 2017, 555 : 73 - 87
  • [40] Research on Network Intrusion Detection System
    Xu, Jiang
    Cao, Zhongwei
    MICRO NANO DEVICES, STRUCTURE AND COMPUTING SYSTEMS, 2011, 159 : 77 - +