FedKD-IDS: A robust intrusion detection system using knowledge distillation-based semi-supervised federated learning and anti-poisoning attack mechanism

被引:5
作者
Quyen, Nguyen Huu
Duy, Phan The
Nguyen, Ngo Thao
Khoa, Nghi Hoang
Pham, Van-Hau [1 ]
机构
[1] Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
关键词
Federated learning; Semi-supervised learning; Knowledge distillation; Poisoning attacks; Intrusion detection systems; Non-independent and identically distributed; NETWORK; TAXONOMY; INTERNET; PRIVACY; THREATS;
D O I
10.1016/j.inffus.2024.102807
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the realm of the Internet of Things (IoT), there has been a notable increase in the development and efficacy of Intrusion Detection Systems (IDS) that leverage machine learning (ML). Specifically, Federated Learning- based IDSs (FL-based IDS) have witnessed significant growth. These systems aim to mitigate data privacy breaches and minimize the communication overhead associated with dataset collection. Limited hardware resources also pose a significant constraint, preventing numerous IoT devices from actively engaging in FL. However, despite these advancements, certain challenges persist in the research domain. Issues such as elevated communication overhead, the potential for recovering private data, non-independent and identically distributed (Non-IID) data and a scarcity of labeled data remain noteworthy concerns. Additionally, vulnerabilities exist in the server-client communication during the FL process, creating opportunities for attackers to execute poisoning attacks on the client side with relative ease. To address these challenges, our paper introduces a semi- supervised approach for FL-based IDS. Our approach, named FedKD-IDS, employs knowledge distillation with a voting mechanism in place of weighted parameter aggregation and incorporates an anti-poisoning method. We conducted experiments to evaluate the effectiveness of our approach across diverse scenarios, including scenarios with Non-IID and varying data distributions. Additionally, we investigated various rates of malicious collaboration to demonstrate their impact in the federated training process. The results obtained from the real- world N-BaIoT dataset indicate that our approach surpasses the performance of the state-of-the-art (SOTA) SSFL method. Especially, even in the context of a poisoning attack where 50% of all collaborators targeted label flipping attack, FedKD-IDS demonstrated an accuracy of 79%, surpassing SSFL, which achieved only 19.86%. Furthermore, the outcomes also validated that the FedKD-IDS method has the capability to exclude over 85% of malicious collaborators during the aggregation phase of the federated training process.
引用
收藏
页数:13
相关论文
共 50 条
[1]   A comprehensive deep learning benchmark for IoT IDS [J].
Ahmad, Rasheed ;
Alsmadi, Izzat ;
Alhamdani, Wasim ;
Tawalbeh, Lo'ai .
COMPUTERS & SECURITY, 2022, 114
[2]  
Aledhari M, 2020, IEEE ACCESS, V8, P140699, DOI [10.1109/ACCESS.2020.3013541, 10.1109/access.2020.3013541]
[3]  
Ansari Mohammad Samar, 2020, Procedia Computer Science, V171, P644, DOI 10.1016/j.procs.2020.04.070
[4]   Federated Semisupervised Learning for Attack Detection in Industrial Internet of Things [J].
Aouedi, Ons ;
Piamrat, Kandaraj ;
Muller, Guillaume ;
Singh, Kamal .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (01) :286-295
[5]   A Survey on IoT Intrusion Detection: Federated Learning, Game Theory, Social Psychology, and Explainable AI as Future Directions [J].
Arisdakessian, Sarhad ;
Wahab, Omar Abdel ;
Mourad, Azzam ;
Otrok, Hadi ;
Guizani, Mohsen .
IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (05) :4059-4092
[6]   Vulnerabilities in Federated Learning [J].
Bouacida, Nader ;
Mohapatra, Prasant .
IEEE ACCESS, 2021, 9 :63229-63249
[7]  
Campos EM, 2024, Arxiv, DOI arXiv:2405.09903
[8]   FedDef: Defense Against Gradient Leakage in Federated Learning-Based Network Intrusion Detection Systems [J].
Chen, Jiahui ;
Zhao, Yi ;
Li, Qi ;
Feng, Xuewei ;
Xu, Ke .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 :4561-4576
[9]   Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning Approach [J].
Cui, Jie ;
Sun, Hu ;
Zhong, Hong ;
Zhang, Jing ;
Wei, Lu ;
Bolodurina, Irina ;
He, Debiao .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2023, 34 (09) :2512-2528
[10]   Internet of Things: A survey on machine learning-based intrusion detection approaches [J].
da Costa, Kelton A. P. ;
Papa, Joao P. ;
Lisboa, Celso O. ;
Munoz, Roberto ;
de Albuquerque, Victor Hugo C. .
COMPUTER NETWORKS, 2019, 151 :147-157