CFL-IDS: An Effective Clustered Federated Learning Framework for Industrial Internet of Things Intrusion Detection

被引:3
作者
Shan, Yao [1 ]
Yao, Yu [1 ]
Zhou, Xiaoming [2 ]
Zhao, Tong [1 ]
Hu, Bo [3 ]
Wang, Lei [2 ]
机构
[1] Northeastern Univ, Coll Comp Sci & Engn, Shenyang 110169, Peoples R China
[2] State Grid Liaoning Elect Power Supply Co Ltd, Digital Work Dept, Shenyang 110169, Peoples R China
[3] State Grid Dalian Elect Power Supply Co Ltd, Dalian 116000, Peoples R China
关键词
Clustered federated learning (FL); data imbalanced; evaluation metrics (EMs); Industrial Internet of Things (IIoT) Intrusion detection; non-independent and identically distributed (non-IID); poisoning attack; NETWORK;
D O I
10.1109/JIOT.2023.3324302
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Industrial Internet of Things (IIoT) offers the manufacturing sector opportunities for transformation and upgrade but also carries significant security risks. Traditional federated learning (FL) as a potential security solution is challenging in complicated application environments with heterogeneous data, imbalanced data, and poisoning attacks. To address these challenges, we construct a clustered FL Framework for IIoT intrusion detection (CFL-IDS) based on local models' evaluation metrics (EMs). First, we designed an intrusion detection model with a dynamic focal loss (DFL) for all edge nodes (ENs). This model's performance is enhanced under various imbalanced data partitions by dynamically altering the focus on samples during the loss minimization training process. Second, the time series of EMs of local models to reflect the data distribution of ENs implicitly, and use clustering algorithms to facilitate knowledge sharing among those ENs with similar data distribution to co-optimize a common model for them. Finally, an intelligent cooperative model aggregation mechanism (ICMAM) adaptively adjusts each local model's weight distribution, which substantially improves the benefits of FL and alleviates subpar models' alleviates interference from subpar models to FL. Experiments demonstrate that CFL-IDS has stronger robustness and displays superior performance under data imbalance and non-independent and identically distributed (non-IID) situations while being effective against poisoning attacks.
引用
收藏
页码:10007 / 10019
页数:13
相关论文
共 27 条
[21]   Fed-ESD: Federated learning for efficient epileptic seizure detection in the fog-assisted internet of medical things [J].
Ding, Weiping ;
Abdel-Basset, Mohamed ;
Hawash, Hossam ;
Abdel-Razek, Sara ;
Liu, Chuansheng .
INFORMATION SCIENCES, 2023, 630 :403-419
[22]   Securing the Internet of Health Things: Embedded Federated Learning-Driven Long Short-Term Memory for Cyberattack Detection [J].
Kumar, Manish ;
Kim, Sunggon .
ELECTRONICS, 2024, 13 (17)
[23]   Internet of things intrusion detection model and algorithm based on cloud computing and multi-feature extraction extreme learning machine [J].
Lin, Haifeng ;
Xue, Qilin ;
Feng, Jiayin ;
Bai, Di .
DIGITAL COMMUNICATIONS AND NETWORKS, 2023, 9 (01) :111-124
[24]   Meta learning-based few-shot intrusion detection for 5G-enabled industrial internet [J].
Yan, Yu ;
Yang, Yu ;
Shen, Fang ;
Gao, Minna ;
Gu, Yuheng .
COMPLEX & INTELLIGENT SYSTEMS, 2024, 10 (03) :4589-4608
[25]   FedKD-IDS: A robust intrusion detection system using knowledge distillation-based semi-supervised federated learning and anti-poisoning attack mechanism [J].
Quyen, Nguyen Huu ;
Duy, Phan The ;
Nguyen, Ngo Thao ;
Khoa, Nghi Hoang ;
Pham, Van-Hau .
INFORMATION FUSION, 2025, 117
[26]   A Double-Timescale Reinforcement Learning Based Cloud-Edge Collaborative Framework for Decomposable Intelligent Services in Industrial Internet of Things [J].
Zhang Qiuyang ;
Wang Ying ;
Wang Xue .
CHINA COMMUNICATIONS, 2024, 21 (10) :181-199
[27]   OCR-Diff: A Two-Stage Deep Learning Framework for Optical Character Recognition Using Diffusion Model in Industrial Internet of Things [J].
Park, Chae-Won ;
Palakonda, Vikas ;
Yun, Sangseok ;
Kim, Il-Min ;
Kang, Jae-Mo .
IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (15) :25997-26000