GowFed A novel federated network intrusion detection system

被引:11
|
作者
Belenguer, Aitor [1 ]
Pascual, Jose A. [1 ]
Navaridas, Javier [1 ]
机构
[1] Univ Basque Country UPV EHU, Dept Comp Architecture & Technol, Manuel Lardizabal 1, Donostia San Sebastian 20018, Spain
关键词
Federated Learning; Intrusion Detection Systems; Internet of Things; Gower distance;
D O I
10.1016/j.jnca.2023.103653
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems are evolving into intelligent systems that perform data analysis while searching for anomalies in their environment. Indeed, the development of deep learning techniques paved the way to build more complex and effective threat detection models. However, training those models may be computationally infeasible in most Edge or IoT devices. Current approaches rely on powerful centralized servers that receive data from all their parties - violating basic privacy constraints and substantially affecting response times and operational costs due to the huge communication overheads. To mitigate these issues, Federated Learning emerged as a promising approach, where different agents collaboratively train a shared model, without exposing training data to others or requiring a compute-intensive centralized infrastructure. This work presents GowFed, a novel network threat detection system that combines the usage of Gower Dissimilarity matrices and Federated averaging. Different approaches of GowFed have been developed based on state-of the-art knowledge: (1) a vanilla version - achieving a median point of [0.888, 0.960] in the PR space and a median accuracy of 0.930; and (2) a version instrumented with an attention mechanism - achieving comparable results when 0.8 of the best performing nodes contribute to the model. Furthermore, each variant has been tested using simulation oriented tools provided by TensorFlow Federated framework. In the same way, a centralized analogous development of the Federated systems is carried out to explore their differences in terms of scalability and performance - the median point of the experiments is [0.987, 0.987]) and the median accuracy is 0.989. Overall, GowFed intends to be the first stepping stone towards the combined usage of Federated Learning and Gower Dissimilarity matrices to detect network threats in industrial-level networks.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Enhanced Network Intrusion Detection System
    Kotecha, Ketan
    Verma, Raghav
    Rao, Prahalad, V
    Prasad, Priyanshu
    Mishra, Vipul Kumar
    Badal, Tapas
    Jain, Divyansh
    Garg, Deepak
    Sharma, Shakti
    SENSORS, 2021, 21 (23)
  • [42] Partial Federated Learning Based Network Intrusion System for Mobile Devices
    Kye, Hyoseon
    Kwon, Minhae
    PROCEEDINGS OF THE 2022 THE TWENTY-THIRD INTERNATIONAL SYMPOSIUM ON THEORY, ALGORITHMIC FOUNDATIONS, AND PROTOCOL DESIGN FOR MOBILE NETWORKS AND MOBILE COMPUTING, MOBIHOC 2022, 2022, : 283 - 284
  • [43] A NOVEL INTRUSION DETECTION SYSTEM FOR MANETS
    Panos, Christoforos
    Xenakis, Christos
    Stavrakakis, Ioannis
    SECRYPT 2010: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2010, : 25 - 34
  • [44] A Novel Architecture of Intrusion Detection System
    Zhang, Da
    Yeo, Chai Kiat
    2010 7TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE-CCNC 2010, 2010, : 164 - 168
  • [45] A Novel Hybrid Model for Network Intrusion Detection
    Tiwari, Shobhit
    Roy, Sanjiban Sekhar
    Charaborty, Saptarshi
    Kumar, Anugrah
    2013 INTERNATIONAL CONFERENCE ON GREEN COMPUTING, COMMUNICATION AND CONSERVATION OF ENERGY (ICGCE), 2013, : 685 - 688
  • [46] A NOVEL ANOMALY-NETWORK INTRUSION DETECTION SYSTEM USING ABC ALGORITHMS
    Bae, Changseok
    Yeh, Wei-Chang
    Shukran, Mohd Afizi Mohd
    Chung, Yuk Ying
    Hsieh, Tsung-Jung
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2012, 8 (12): : 8231 - 8248
  • [47] Federated Learning for IoT Intrusion Detection
    Lazzarini, Riccardo
    Tianfield, Huaglory
    Charissis, Vassilis
    AI, 2023, 4 (03) : 509 - 530
  • [48] Network processor based network intrusion detection system
    Cho, H
    Kim, D
    Kim, J
    Doh, Y
    Jang, J
    INFORMATION NETWORKING: NETWORKING TECHNOLOGIES FOR BROADBAND AND MOBILE NETWORKS, 2004, 3090 : 973 - 982
  • [49] Survey of federated learning in intrusion detection
    Zhang, Hao
    Ye, Junwei
    Huang, Wei
    Liu, Ximeng
    Gu, Jason
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2025, 195
  • [50] CHFL: A Collaborative Hierarchical Federated Intrusion Detection System for Vehicular Networks
    Mirzaee, Parya Haji
    Shojafar, Mohammad
    Cruickshank, Haitham
    Tafazolli, Rahim
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,