FedKD-IDS: A robust intrusion detection system using knowledge distillation-based semi-supervised federated learning and anti-poisoning attack mechanism

被引:2
|
作者
Quyen, Nguyen Huu
Duy, Phan The
Nguyen, Ngo Thao
Khoa, Nghi Hoang
Pham, Van-Hau [1 ]
机构
[1] Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
关键词
Federated learning; Semi-supervised learning; Knowledge distillation; Poisoning attacks; Intrusion detection systems; Non-independent and identically distributed; NETWORK; TAXONOMY; INTERNET; PRIVACY; THREATS;
D O I
10.1016/j.inffus.2024.102807
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the realm of the Internet of Things (IoT), there has been a notable increase in the development and efficacy of Intrusion Detection Systems (IDS) that leverage machine learning (ML). Specifically, Federated Learning- based IDSs (FL-based IDS) have witnessed significant growth. These systems aim to mitigate data privacy breaches and minimize the communication overhead associated with dataset collection. Limited hardware resources also pose a significant constraint, preventing numerous IoT devices from actively engaging in FL. However, despite these advancements, certain challenges persist in the research domain. Issues such as elevated communication overhead, the potential for recovering private data, non-independent and identically distributed (Non-IID) data and a scarcity of labeled data remain noteworthy concerns. Additionally, vulnerabilities exist in the server-client communication during the FL process, creating opportunities for attackers to execute poisoning attacks on the client side with relative ease. To address these challenges, our paper introduces a semi- supervised approach for FL-based IDS. Our approach, named FedKD-IDS, employs knowledge distillation with a voting mechanism in place of weighted parameter aggregation and incorporates an anti-poisoning method. We conducted experiments to evaluate the effectiveness of our approach across diverse scenarios, including scenarios with Non-IID and varying data distributions. Additionally, we investigated various rates of malicious collaboration to demonstrate their impact in the federated training process. The results obtained from the real- world N-BaIoT dataset indicate that our approach surpasses the performance of the state-of-the-art (SOTA) SSFL method. Especially, even in the context of a poisoning attack where 50% of all collaborators targeted label flipping attack, FedKD-IDS demonstrated an accuracy of 79%, surpassing SSFL, which achieved only 19.86%. Furthermore, the outcomes also validated that the FedKD-IDS method has the capability to exclude over 85% of malicious collaborators during the aggregation phase of the federated training process.
引用
收藏
页数:13
相关论文
共 19 条
  • [1] A Semi-Supervised Federated Learning Scheme via Knowledge Distillation for Intrusion Detection
    Zhao, Ruijie
    Yang, Linbo
    Wang, Yijun
    Xue, Zhi
    Gui, Guan
    Ohtsukit, Tomoaki
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 2688 - 2693
  • [2] GFD-SSL: generative federated knowledge distillation-based semi-supervised learning
    Karami, Ali
    Ramezani, Reza
    Baraani Dastjerdi, Ahmad
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2024, 15 (12) : 5509 - 5529
  • [3] Semi-supervised Campus Network Intrusion Detection Based on Knowledge Distillation
    Chen, Junjun
    Guo, Qiang
    Fu, Zhongnan
    Shang, Qun
    Ma, Hao
    Wang, Nai
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [4] A Knowledge Transfer-Based Semi-Supervised Federated Learning for IoT Malware Detection
    Pei, Xinjun
    Deng, Xiaoheng
    Tian, Shengwei
    Zhang, Lan
    Xue, Kaiping
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2127 - 2143
  • [5] ACTIVE LEARNING TO DEFEND POISONING ATTACK AGAINST SEMI-SUPERVISED INTRUSION DETECTION CLASSIFIER
    Long, Jun
    Zhao, Wentao
    Zhu, Fangzhou
    Cai, Zhiping
    INTERNATIONAL JOURNAL OF UNCERTAINTY FUZZINESS AND KNOWLEDGE-BASED SYSTEMS, 2011, 19 : 93 - 106
  • [6] SecFedNIDS: Robust defense for poisoning attack against federated learning-based network intrusion detection system
    Zhang, Zhao
    Zhang, Yong
    Guo, Da
    Yao, Lei
    Li, Zhao
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 134 : 154 - 169
  • [7] Effective Intrusion Detection System Using Semi-Supervised Learning
    Wagh, Sharmila Kishor
    Kolhe, Satish R.
    2014 INTERNATIONAL CONFERENCE ON DATA MINING AND INTELLIGENT COMPUTING (ICDMIC), 2014,
  • [8] Distillation-Based Semi-Supervised Federated Learning for Communication-Efficient Collaborative Training With Non-IID Private Data
    Itahara, Sohei
    Nishio, Takayuki
    Koda, Yusuke
    Morikura, Masahiro
    Yamamoto, Koji
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2023, 22 (01) : 191 - 205
  • [9] Effective Intrusion Detection in Heterogeneous Internet-of-Things Networks via Ensemble Knowledge Distillation-based Federated Learning
    Shen, Jiyuan
    Yang, Wenzhuo
    Chu, Zhaowei
    Fan, Jiani
    Niyato, Dusit
    Lam, Kwok-Yan
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 2034 - 2039
  • [10] Fuzziness based semi-supervised learning approach for intrusion detection system
    Ashfaq, Rana Aamir Raza
    Wang, Xi-Zhao
    Huang, Joshua Zhexue
    Abbas, Haider
    He, Yu-Lin
    INFORMATION SCIENCES, 2017, 378 : 484 - 497