F-BIDS: Federated-Blending based Intrusion Detection System

被引:19
作者
Aouedi, Ons [1 ]
Piamrat, Kandaraj [1 ]
机构
[1] Nantes Univ, Ecole Cent Nantes, CNRS, INRIA,LS2N,UMR 6004, F-44000 Nantes, France
关键词
Data privacy; Federated learning; Ensemble learning; Deep learning; Intrusion Detection System;
D O I
10.1016/j.pmcj.2023.101750
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid development of network communication along with the drastic increase in the number of smart devices has triggered a surge in network traffic, which can contain private data and in turn affect user privacy. Recently, Federated Learning (FL) has been proposed in Intrusion Detection Systems (IDS) to ensure attack detection, privacy preservation, and cost reduction, which are crucial issues in traditional centralized machine-learning-based IDS. However, FL-based approaches still exhibit vulnerabilities that can be exploited by adversaries to compromise user data. At the same time, meta-models (including the blending models) have been recognized as one of the solutions to improve generalization for attack detection and classification since they enhance generalization and predictive performances by combining multiple base models. Therefore, in this paper, we propose a Federated Blending model-driven IDS framework for the Internet of Things (IoT) and Industrial IoT (IIoT), called F-BIDS, in order to further protect the privacy of existing ML-based IDS. The proposition consists of a Decision Tree (DT) and Random Forest (RF) as base classifiers to first produce the meta-data. Then, the meta-classifier, which is a Neural Networks (NN) model, uses the meta-data during the federated training step, and finally, it makes the final classification on the test set. Specifically, in contrast to the classical FL approaches, the federated meta-classifier is trained on the meta-data (composite data) instead of user-sensitive data to further enhance privacy. To evaluate the performance of F-BIDS, we used the most recent and open cyber-security datasets, called Edge-IIoTset (published in 2022) and InSDN (in 2020). We chose these datasets because they are recent datasets and contain a large amount of network traffic including both malicious and benign traffic. (c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页数:12
相关论文
共 27 条
[1]  
Agrawal S, 2021, Arxiv, DOI [arXiv:2106.09527, DOI 10.48550/ARXIV.2106.09527]
[2]  
Al-Marri N.A.A.-A., 2020, INT BLACK SEA C COMM, P1, DOI [10.1109/BlackSeaCom48709.2020.9234959, DOI 10.1109/BLACKSEACOM48709.2020.9234959]
[3]  
Aouedi O., 2022, IEEE T IND INFORM
[4]   Decision tree-based blending method using deep-learning for network management [J].
Aouedi, Ons ;
Piamrat, Kandaraj ;
Parrein, Benoit .
PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
[5]   Performance evaluation of feature selection and tree-based algorithms for traffic classification [J].
Aouedi, Ons ;
Piamrat, Kandaraj ;
Parrein, Benoit .
2021 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2021,
[6]   An Ensemble Multi-View Federated Learning Intrusion Detection for IoT [J].
Attota, Dinesh Chowdary ;
Mothukuri, Viraaji ;
Parizi, Reza M. ;
Pouriyeh, Seyedamin .
IEEE ACCESS, 2021, 9 :117734-117745
[7]   InSDN: A Novel SDN Intrusion Dataset [J].
Elsayed, Mahmoud Said ;
Le-Khac, Nhien-An ;
Jurcut, Anca D. .
IEEE ACCESS, 2020, 8 :165263-165284
[8]  
Ferrag M.A, 2022, TECHRXIV
[9]   Federated Deep Learning for Cyber Security in the Internet of Things: Concepts, Applications, and Experimental Analysis [J].
Ferrag, Mohamed Amine ;
Friha, Othmane ;
Maglaras, Leandros ;
Janicke, Helge ;
Shu, Lei .
IEEE ACCESS, 2021, 9 :138509-138542
[10]   On learning effective ensembles of deep neural networks for intrusion detection [J].
Folino, F. ;
Folino, G. ;
Guarascio, M. ;
Pisani, F. S. ;
Pontieri, L. .
INFORMATION FUSION, 2021, 72 :48-69